Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows PowerShell ICMP Exfiltration via Ping and Socket Send
Alerts on PowerShell that instantiates System.Net.NetworkInformation.Ping and calls .Send, consistent with ICMP-based exfiltration.
Bartlomiej Czyz @bczyz1, oscd.community, Huntrule TeamWindowsps_scriptMedium161Free2020-10-10macOS Hidden User Creation via dscl (Hidden Account or UniqueID<500)
Detects dscl commands on macOS creating hidden users (UniqueID < 500 or IsHidden true).
Daniil Yugoslavskiy, oscd.community, Huntrule TeamMacosprocess_creationMedium162Free2020-10-10Windows verclsid.exe executes COM object via GUID parameters
Flags verclsid.exe process launches using /S /C COM GUID-style arguments on Windows.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium351Free2020-10-09Windows: Identify RpcPing.exe -s RPC test that requests NTLM authentication
Detects RpcPing.exe RPC test usage with parameters indicating NTLM authentication attempts.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium142Free2020-10-09Windows Renamed ftp.exe Execution via OriginalFileName PE Metadata
Flags Windows executions where PE OriginalFileName is ftp.exe but the image path is not named ftp.exe.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium207Free2020-10-09Suspicious WINWORD.exe DLL loading via /l flag and .dll path on Windows
Flags WINWORD.exe runs that include /l and a .dll indicator, suggesting potential DLL sideloading on Windows.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium143Free2020-10-09Windows: Detect Runscripthelper.exe executing PowerShell scripts with 'surfacecheck'
Detects Runscripthelper.exe executions with "surfacecheck" in the command line on Windows.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium122Free2020-10-09Windows Rasautou.exe DLL loading with -d and export execution via -p
Flags Rasautou.exe running with -d and -p to load a DLL and execute a specified export.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium383Free2020-10-09Windows Process Creation: PowerShell Obfuscation Executed via Clip.exe and Clipboard
Flags Windows command lines indicating clip.exe clipboard use followed by obfuscated PowerShell invoke behavior.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh171Free2020-10-09Windows Arbitrary File Download via GfxDownloadWrapper.exe URL Argument Execution
Flags GfxDownloadWrapper.exe executions that include http/https URLs for downloading files, excluding a known Intel gameplay API URL.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium241Free2020-10-09Windows: Detect ftp.exe Executed With -s or /s for Script-Based Command Execution
Flags Windows executions of ftp.exe using -s or /s, indicating potential scripted command abuse.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium227Free2020-10-09PowerShell Script Obfuscation Triggered by Use of clip.exe and Clipboard Invocation
Flags PowerShell Script Block Logging containing clip.exe/clipboard chaining and clipboard-driven execution markers.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh196Free2020-10-09PowerShell module obfuscation using clip.exe with echo and clipboard invocation
Flags obfuscated PowerShell module scripts that echo “clip” and invoke clipboard-related behavior.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh111Free2020-10-09Windows PowerShell: Detect Suspicious Opsec Artifacts in Script Module Content
Identifies PowerShell module content containing frequent offensive payload string markers associated with poor operational security.
ok @securonix invrep_de, oscd.community, Huntrule TeamWindowsps_moduleCritical445Free2020-10-09Windows Service Control Manager Rundll32 Obfuscation via Command-Line Encoded PowerShell
Detects service creation where ImagePath invokes rundll32 (shell32) with command-chain tokens indicative of obfuscated PowerShell.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh70Free2020-10-09