Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows PowerShell Base64-Encoded WMI Class Invocation
Flags PowerShell command lines containing Base64 fragments indicative of WMI class usage (e.g., ShadowCopy, ScheduledJob) on Windows.
Christian Burkard (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2023-01-30Windows Registry: Monitor PendingFileRenameOperations changes from suspicious images
Alerts on registry tampering of PendingFileRenameOperations by processes running from suspicious image paths.
frack113, Huntrule TeamWindowsregistry_setMedium71Free2023-01-27Windows WMIC System Information Discovery via WMIC.EXE Recon
Flags WMIC.EXE executions running system info queries for OS and disk details.
TropChaud, Huntrule TeamWindowsprocess_creationMedium272Free2023-01-26Windows: Suspicious Child Process Spawned by VsCode code.exe
Alerts when code.exe spawns suspicious binaries, script hosts, or command-line activity that matches common execution patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium141Free2023-01-26Windows WSL Process Spawning Uncommon Child Executables
Alerts when wsl.exe or wslhost.exe spawns suspicious child binaries from common temp/public/user directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium71Free2023-01-23Windows PowerShell Module Execution Matches Known Offensive PoshModule Script Names
Alerts on Windows PowerShell module executions where the script context matches known offensive PowerShell script/module names.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_moduleHigh445Free2023-01-23PowerShell on Windows adding Windows capabilities via Add-WindowsCapability
Alerts when PowerShell adds an OpenSSH-related Windows capability using Add-WindowsCapability.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-01-22Windows PowerShell imports Microsoft.ActiveDirectory.Management.dll via Import-Module (AD enumeration)
Alerts when PowerShell imports Microsoft.ActiveDirectory.Management.dll using Import-Module, indicating potential AD enumeration.
frack113, Huntrule TeamWindowsprocess_creationMedium60Free2023-01-22Windows IIS appcmd Creating GlobalRules URL Rewrite Configuration
Flags appcmd.exe commands that modify IIS global URL rewrite globalRules and commit the configuration.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium161Free2023-01-22Windows Capability Added via PowerShell Add-WindowsCapability (OpenSSH)
Flags PowerShell commands that add Windows capabilities, specifically OpenSSH, via Add-WindowsCapability in logged script blocks.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium166Free2023-01-22Windows PowerShell Active Directory Module Import for Enumeration
Detects PowerShell importing Microsoft.ActiveDirectory.Management.dll with Import-Module, often seen during AD enumeration.
frack113, Nasreddine Bencherchali, Huntrule TeamWindowsps_scriptMedium82Free2023-01-22Windows PowerShell AD Module DLL Import for Active Directory Enumeration
Flags PowerShell importing Microsoft.ActiveDirectory.Management.dll via Import-Module, a common step in AD discovery and enumeration.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_moduleMedium182Free2023-01-22Windows: Detect Aruba Netsvc DLL Search Order Hijacking via arubanetsvc.exe Loaded DLLs
Flags arubanetsvc.exe loading targeted DLLs outside standard system paths, suggesting possible DLL search order hijacking.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh374Free2023-01-22Windows: OneNote .one/.onepkg File Creation in Suspicious Locations
Flags creation of OneNote attachment files (.one/.onepkg) in temp/public-style paths on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium337Free2023-01-22Windows rundll32 Launching DLL From Alternate Data Stream (ADS) Paths
Detects rundll32 executions that reference DLLs stored in Alternate Data Streams via ADS-style paths.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamWindowsprocess_creationHigh103Free2023-01-21