Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows PowerShell via sqltoolsps.exe (sqltoolsps.exe child process exclusion)
Flags suspicious sqltoolsps.exe executions that may launch PowerShell, excluding cases where smss.exe spawned the utility.
Agro (@agro_sev) oscd.communitly, Huntrule TeamWindowsprocess_creationMedium322Free2020-10-13Windows manage-bde.wsf via wscript/cscript Proxy Execution
Flags Windows process executions where wscript/cscript runs manage-bde.wsf, indicating potential proxy execution via LOLBIN.
oscd.community, Natalia Shornikova, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2020-10-13Windows Process Command Line: Detect VAR++ LAUNCHER Obfuscated PowerShell
Flags Windows command lines showing VAR++ launcher-style obfuscated PowerShell execution through Invoke-Expression patterns.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationHigh3710Free2020-10-13Windows Process Creation: Obfuscated Cmd Uses clip.exe to Execute PowerShell
Alerts when cmd.exe uses obfuscated Clip.exe/clipboard calls to launch PowerShell.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsprocess_creationHigh225Free2020-10-13Detect VAR++ LAUNCHER-Style Obfuscated PowerShell Command Block
Detects VAR++ LAUNCHER-like PowerShell obfuscation patterns in ScriptBlockText.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptHigh4010Free2020-10-13PowerShell Script Block Obfuscation via cmd/clipboard and clip.exe execution
Identifies obfuscated PowerShell script blocks launching clip.exe and chaining clipboard-related execution.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_scriptHigh143Free2020-10-13PowerShell Module: VAR++ LAUNCHER Obfuscation in Obfuscated Command Payload
Identifies obfuscated PowerShell module payloads matching a VAR++ LAUNCHER-style invocation pattern.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_moduleHigh92Free2020-10-13PowerShell Module: Obfuscated Clip.exe launcher using cmd with clipboard download payload
Detects obfuscated PowerShell module commands that run cmd with clip.exe/clipboard payload formatting.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_moduleHigh218Free2020-10-13Windows System: Detects Service Control Manager spawning obfuscated PowerShell via VAR++ LAUNCHER
Flags newly created Windows services whose ImagePath contains cmd chaining and obfuscated PowerShell launcher indicators.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssystemHigh414Free2020-10-13Windows System Service Control: Obfuscated cmd Launching clip.exe for PowerShell
Flags service creation (Event 7045) with obfuscated cmd ImagePath using clip.exe/clipboard PowerShell execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh60Free2020-10-13Windows Zerologon Exploitation Attempts via Mimikatz or Tools from Kali Host
Identifies Windows Zerologon exploitation attempts tied to Kali-hosted activity and mimikatz-related keywords.
Demyan Sokolin @_drd0c, Teymur Kheirkhabarov @HeirhabarovT, oscd.community, Huntrule TeamWindowssystemCritical479Free2020-10-13Windows Security 4697 Alert for Obfuscated PowerShell Invoke via VAR++ LAUNCHER
Alerts on obfuscated PowerShell launcher patterns in Windows service creation events (EID 4697) consistent with VAR++ LAUNCHER.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssecurityHigh152Free2020-10-13Windows Security Log: Obfuscated cmd Execution of clip.exe via PowerShell Clipboard Patterns (EID 4697)
Alerts on service creation (Windows 4697) with CLIP.exe command-line patterns that indicate obfuscated PowerShell execution.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh163Free2020-10-13macOS Screen Capture via /usr/sbin/screencapture Process Execution
Identifies macOS instances where /usr/sbin/screencapture is executed to collect screenshots.
remotephone, oscd.community, Huntrule TeamMacosprocess_creationLow142Free2020-10-13macOS GUI Credential Prompt Capture via osascript
Flags osascript command lines that script system dialogs referencing authentication and password-related terms.
remotephone, oscd.community, Huntrule TeamMacosprocess_creationLow173Free2020-10-13