Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows PowerShell Script Block Local Email Collection via Outlook COM Automation
Flags PowerShell script block text referencing Outlook COM automation used to collect locally stored email.
frack113, Huntrule TeamWindowsps_scriptMedium369Free2021-07-21PowerShell command line containing powercat invocation on Windows
Alerts when classic PowerShell starts with Powercat-related command-line strings ('powercat ' or 'powercat.ps1').
frack113, Huntrule TeamWindowsps_classic_startMedium2710Free2021-07-21Windows Private Key File Recon via cmd.exe, PowerShell, or findstr.exe
Flags Windows command-line searches for key/certificate file extensions using cmd.exe, PowerShell, or findstr.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2021-07-20PowerShell Compress-Archive Creates Archive in Temp or System Temp Paths
Flags PowerShell Compress-Archive usage writing archives to %TEMP%, AppData Local Temp, or Windows Temp.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium141Free2021-07-20PowerShell: Compress-Archive to TEMP/AppData/Windows Temp for Staging
Flags PowerShell scripts compressing data with Compress-Archive into $env:TEMP or Temp folders.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_scriptMedium143Free2021-07-20Windows PowerShell module usage: Compress-Archive to store archives in Temp locations
Alerts on PowerShell Compress-Archive output written to common temp staging directories.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_moduleMedium81Free2021-07-20PowerShell Classic Compress-Archive staging in TEMP or Temp directories
Alerts on PowerShell Compress-Archive output targeting common Temp directories for data staging.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowspowershell-classicMedium4810Free2021-07-20Windows mshta.exe Process Creation Triggered by Suspicious Command Lines
Alert on mshta.exe launches from suspicious parents and script-like command lines/paths.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2021-07-17Windows Process Execution of SyncAppvPublishingServer.vbs with Inline PowerShell Commands
Flags Windows executions of SyncAppvPublishingServer.vbs with a semicolon-augmented command line consistent with embedded PowerShell.
frack113, Huntrule TeamWindowsprocess_creationMedium141Free2021-07-16PowerShell executes ADRecon.ps1 AD reconnaissance functions and writes ADRecon-Report.xlsx
Detects PowerShell ADRecon reconnaissance script content by matching AD discovery functions and the default ADRecon report output name.
Bhabesh Raj, Huntrule TeamWindowsps_scriptHigh285Free2021-07-16Windows Registry Modification Indicative of CVE-2021-31979 and CVE-2021-33771 Exploitation
Flags registry changes to targeted COM InprocServer32 CLSID paths tied to CVE-2021-31979/33771 exploitation behavior on Windows.
Sittikorn S, frack113, Huntrule TeamWindowsregistry_setCritical318Free2021-07-16Windows file event detection for CVE-2021-31979 and CVE-2021-33771 exploitation artifact paths
Flags Windows file events where the target filename matches paths tied to CVE-2021-31979/CVE-2021-33771 exploitation patterns.
Sittikorn S, Huntrule TeamWindowsfile_eventCritical192Free2021-07-16Windows: Suspicious Parent-Serv-U.exe Command-Line Process Spawning
Alerts when Serv-U (\Serv-U.exe) spawns typical command interpreters or execution utilities on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2021-07-14Windows reg.exe Used to Modify Security Service Start Parameters
Flags reg.exe registry changes that target Start parameters for common security and Windows Defender-related services.
Florian Roth (Nextron Systems), John Lambert (idea), elhoim, Huntrule TeamWindowsprocess_creationHigh389Free2021-07-14Suspicious PowerShell Execution From Windows Temporary Folders on Windows
Alerts when PowerShell runs with command-line paths pointing to Windows temp directories, excluding some common benign installers.
Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationMedium267Free2021-07-14