Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
macOS Process Execution: dd and truncate used for binary padding
Flags macOS dd plus truncate command lines consistent with adding junk data for binary padding.
Igor Fits, Mikhail Larin, oscd.community, Huntrule TeamMacosprocess_creationHigh71Free2020-10-19Windows PowerShell Script Execution via Redirected Input Stream
Flags PowerShell/pwsh executions where the command line includes redirected input ("- <").
Moriarty Meng (idea), Anton Kutepov (rule), oscd.community, Huntrule TeamWindowsprocess_creationHigh204Free2020-10-17Potential Windows Registry Persistence via AppCompatFlags TelemetryController Commands
Flags registry entries under TelemetryController\Command that reference executable/script payloads potentially abusing telemetry for persistence.
Lednyov Alexey, oscd.community, Sreeman, Huntrule TeamWindowsregistry_setHigh506Free2020-10-16Windows sc.exe Security Descriptor Tampering to Deny Service Access via sdset
Alerts on sc.exe sdset commands that modify service security descriptors to deny access to critical trustees.
Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh130Free2020-10-16PowerShell command-line obfuscation indicators from special-character patterns (Windows)
Alerts on PowerShell executions whose command lines contain repeated special-character obfuscation patterns.
Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton (fp), Huntrule TeamWindowsprocess_creationHigh3710Free2020-10-15Windows Process Creation: Cmd Invokes PowerShell via Obfuscated Environment Variable Expansion
Alerts on cmd.exe command lines that use obfuscated environment-variable SET to execute PowerShell.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsprocess_creationHigh162Free2020-10-15Windows Process Execution Using Obfuscated CMD to Pipe STDIN into PowerShell
Detects obfuscated cmd executions that launch PowerShell and reference $input/noexit patterns for STDIN-based execution.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsprocess_creationHigh173Free2020-10-15PowerShell: Obfuscated invocation via Environment Variables in Script Block
Alerts on PowerShell script blocks launching cmd /c or /r with obfuscated set-and-{n} variable expansion patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_scriptHigh131Free2020-10-15PowerShell Obfuscated stdin launcher using cmd /c or cmd /r patterns
Detects PowerShell script blocks that use obfuscated STDIN-driven cmd/powershell execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_scriptHigh2610Free2020-10-15PowerShell Module: Obfuscated Environment Variable Expansion via cmd /c set -f Pattern
Alerts when PowerShell module payloads obfuscate execution via cmd /c|/r and environment-variable-based set patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_moduleHigh163Free2020-10-15PowerShell Module: Obfuscated STDIN Execution via cmd /c or cmd /r
Alerts when an obfuscated cmd->PowerShell payload uses stdin-style input and noexit/no-execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_moduleHigh171Free2020-10-15Windows Service Control Manager: Obfuscated Environment Variable PowerShell via cmd /c set -f
Alerts on Service Control Manager event 7045 where a service ImagePath uses cmd /c|/r with "set" and -f formatting.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh172Free2020-10-15Windows System Service Control Manager spawning cmd with PowerShell and stdin input obfuscation
Flags SCM-created services whose ImagePath runs cmd to invoke PowerShell using stdin/input and -NoExit patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh90Free2020-10-15Windows Security 4697: cmd.exe Launching Obfuscated PowerShell via Environment Variable Expansion
Alerts on EID 4697 service installation command lines containing obfuscated cmd.exe SET patterns used to execute PowerShell via environment variables.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh133Free2020-10-15Windows Security Event 4697 PowerShell Launch via cmd/stdin Obfuscation
Alerts on service creation events that run PowerShell through cmd with stdin-style obfuscation markers.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh90Free2020-10-15