Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows System: mshta Launches vbscript:createobject via Service Control Manager (Event ID 7045)
Flags Windows service creation (7045) where ImagePath includes mshta and vbscript:createobject.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh163Free2020-10-09Windows System: Suspicious Clip.exe Execution via Service Control Manager (Event ID 7045)
Alerts on Windows service creation starting clipboard/Clip.exe-related binaries via Service Control Manager ImagePath.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh182Free2020-10-09Windows Security 4697: Obfuscated command uses rundll32 with shell32.dll
Alerts on EventID 4697 service command lines containing rundll32 with shell32.dll/shellexec_rundll and obfuscation-like script fragments.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh102Free2020-10-09Windows Security EID 4697: mshta Used to Run Obfuscated VBScript PowerShell
Detects service creation where the binary path includes mshta plus VBS/automation indicators consistent with script-based obfuscation.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh123Free2020-10-09Windows Security 4697: Obfuscated PowerShell via use of Clip.exe from scripts
Alerts on EID 4697 service installations where the service file name matches Clip/clipboard indicators tied to obfuscated PowerShell.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh152Free2020-10-09Windows regini.exe Execution Leading to Registry Key Changes
Alerts on Windows executions of regini.exe that can import registry changes from text files.
Eli Salem, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationLow171Free2020-10-08Windows net.exe Unmount Share (/delete) Execution
Alerts on net.exe/net1.exe commands that include "share" and "/delete", indicating share unmount/removal on Windows.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsprocess_creationLow152Free2020-10-08Windows Process Dumping via sqldumper.exe with 0x0110 Command-Line Flags
Alerts on sqldumper.exe executions with command-line dump parameters indicative of process dumping.
Kirill Kiryanov, oscd.community, Huntrule TeamWindowsprocess_creationMedium91Free2020-10-08Windows: Code Execution via Pester.bat Using PowerShell Help or cmd.exe
Flags Windows process executions that invoke Pester-related help/commands via PowerShell or cmd, consistent with Pester.bat usage.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium100Free2020-10-08Windows Process Execution: Obfuscated PowerShell Invocation Using mshta with VBScript CreateObject
Flags Windows process command lines containing an obfuscated PowerShell+MSHTA VBScript execution pattern.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh216Free2020-10-08PowerShell share removal via Remove-SmbShare or Remove-FileShare on Windows
Flags PowerShell commands that remove SMB or file shares through Remove-SmbShare/Remove-FileShare.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsps_scriptMedium205Free2020-10-08PowerShell ScriptBlock Obfuscation via MSHTA VBScript CreateObject Execution
Alerts on PowerShell script blocks containing mshta and VBScript createobject/.run/window.close patterns consistent with obfuscated execution.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh123Free2020-10-08PowerShell Module: Obfuscated MSHTA Invocation via VBS CreateObject
Alerts when PowerShell module payload text includes an obfuscated MSHTA/VBScript invocation sequence.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh311Free2020-10-08macOS Local System Account Enumeration via dscl, dscacheutil, and user listing commands
Detects macOS commands used to enumerate local system accounts via dscl, dscacheutil, id, lsof, who, and preference/query utilities.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationLow92Free2020-10-08Linux System Information Discovery via Common Command-Line Utilities
Flags Linux executions of uname, hostname, uptime, lspci, dmidecode, lscpu, and lsmod for system discovery behavior.
Ömer Günal, oscd.community, Huntrule TeamLinuxprocess_creationInformational173Free2020-10-08