Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Potential Windows Registry Persistence via AppCompatFlags TelemetryController Commands
Flags registry entries under TelemetryController\Command that reference executable/script payloads potentially abusing telemetry for persistence.
Lednyov Alexey, oscd.community, Sreeman, Huntrule TeamWindowsregistry_setHigh466Free2020-10-16Windows sc.exe Security Descriptor Tampering to Deny Service Access via sdset
Alerts on sc.exe sdset commands that modify service security descriptors to deny access to critical trustees.
Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh70Free2020-10-16Windows Process: reg.exe Software Version Discovery via svcVersion Query
Alerts when reg.exe is used to query \Software\ for svcVersion, indicating Windows software version discovery.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationMedium92Free2020-10-16Windows PowerShell Software Enumeration via Script Block Content
Flags PowerShell registry queries for installed software metadata combined with selection and table formatting.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptMedium457Free2020-10-16PowerShell command-line obfuscation indicators from special-character patterns (Windows)
Alerts on PowerShell executions whose command lines contain repeated special-character obfuscation patterns.
Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton (fp), Huntrule TeamWindowsprocess_creationHigh3510Free2020-10-15Windows Process Creation: Cmd Invokes PowerShell via Obfuscated Environment Variable Expansion
Alerts on cmd.exe command lines that use obfuscated environment-variable SET to execute PowerShell.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsprocess_creationHigh152Free2020-10-15Windows Process Execution Using Obfuscated CMD to Pipe STDIN into PowerShell
Detects obfuscated cmd executions that launch PowerShell and reference $input/noexit patterns for STDIN-based execution.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsprocess_creationHigh133Free2020-10-15PowerShell: Obfuscated invocation via Environment Variables in Script Block
Alerts on PowerShell script blocks launching cmd /c or /r with obfuscated set-and-{n} variable expansion patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_scriptHigh111Free2020-10-15PowerShell Obfuscated stdin launcher using cmd /c or cmd /r patterns
Detects PowerShell script blocks that use obfuscated STDIN-driven cmd/powershell execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_scriptHigh2210Free2020-10-15PowerShell Module: Obfuscated Environment Variable Expansion via cmd /c set -f Pattern
Alerts when PowerShell module payloads obfuscate execution via cmd /c|/r and environment-variable-based set patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_moduleHigh123Free2020-10-15PowerShell Module: Obfuscated STDIN Execution via cmd /c or cmd /r
Alerts when an obfuscated cmd->PowerShell payload uses stdin-style input and noexit/no-execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_moduleHigh151Free2020-10-15Windows Service Control Manager: Obfuscated Environment Variable PowerShell via cmd /c set -f
Alerts on Service Control Manager event 7045 where a service ImagePath uses cmd /c|/r with "set" and -f formatting.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh142Free2020-10-15Windows System Service Control Manager spawning cmd with PowerShell and stdin input obfuscation
Flags SCM-created services whose ImagePath runs cmd to invoke PowerShell using stdin/input and -NoExit patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh70Free2020-10-15Windows Security 4697: cmd.exe Launching Obfuscated PowerShell via Environment Variable Expansion
Alerts on EID 4697 service installation command lines containing obfuscated cmd.exe SET patterns used to execute PowerShell via environment variables.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh113Free2020-10-15Windows Security Event 4697 PowerShell Launch via cmd/stdin Obfuscation
Alerts on service creation events that run PowerShell through cmd with stdin-style obfuscation markers.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh70Free2020-10-15