Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,292 rules
Windows regini.exe Used to Modify Registry via Alternate Data Streams (ADS)
Alert on regini.exe process executions whose command line contains an ADS-style colon pattern used for registry modification.
Eli Salem, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh199Free2020-10-12Windows: regedit.exe imports .reg via an alternate data stream (ADS)
Alerts when regedit.exe is used to import a .reg file using an alternate data stream pattern in the command line.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh70Free2020-10-12Windows Regedit Exports Registry Hives to Files
Flags regedit.exe command lines exporting SYSTEM/SAM/SECURITY hives from HKLM to files.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh322Free2020-10-12Windows Process Creation: PowerShell or sc.exe Disabling Windows Defender Behavior Monitoring
Detects PowerShell flags or sc.exe service actions that disable WinDefend monitoring on Windows.
ok @securonix invrep-de, oscd.community, frack113, Huntrule TeamWindowsprocess_creationHigh164Free2020-10-12Detect Obfuscated PowerShell Command Invocation via Stdin on Windows
Flags PowerShell-like command-line patterns indicating obfuscated execution using stdin or input substitution.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh313Free2020-10-12PowerShell Obfuscation Delivered via Stdin Using Set-and-Invoke Pattern
Detects obfuscated PowerShell script blocks that use chained stdin/environment/input patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh4610Free2020-10-12PowerShell Module: Obfuscated Script Execution via Stdin Pattern
Detects obfuscated PowerShell module payloads using chained set and stdin/input invoke patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh386Free2020-10-12Windows WMIPRVSE DLL Hijack via Network-Created wbemcomn.dll in System32\wbem
Flags wmiprvse.exe loading wbemcomn.dll from the System32\wbem directory, consistent with a WMI DLL hijack.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadHigh125Free2020-10-12Windows System: Service Control Manager runs command with obfuscated PowerShell keywords via set and stdin
Alerts on service creation where ImagePath includes obfuscation-like command chaining with environment/invoke/input strings.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh90Free2020-10-12Windows Security Log: Network Write of wbemcomn.dll in System32\wbem for WMI DLL Hijack (T1047)
Flags remote creation of wbemcomn.dll in System32\wbem associated with WMI DLL hijack activity.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssecurityHigh4110Free2020-10-12Windows Security Event 4697: Obfuscated PowerShell Invocation Through Stdin
Alerts on Service creation events where the service command line includes stdin-style PowerShell obfuscation indicators.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh121Free2020-10-12Windows Security: Remote DCOM IE DLL Hijack via iertutil.dll in Internet Explorer path
Flags network file writes of iertutil.dll under IE’s Program Files path associated with potential DCOM DLL hijacking.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssecurityHigh175Free2020-10-12Windows Process Creation: Detect Reversed PowerShell Command Tokens in CommandLine
Alerts on suspicious reversed token usage in PowerShell command lines on Windows, excluding -EncodedCommand / -enc.
Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton, Huntrule TeamWindowsprocess_creationHigh297Free2020-10-11Windows msbuild.exe Network Connections to Ports 80/443
Alerts on initiated outbound 80/443 connections from msbuild.exe on Windows.
Kiran kumar s, oscd.community, Huntrule TeamWindowsnetwork_connectionHigh111Free2020-10-11Windows Process Creation: PowerShell Obfuscation Executed via Clip.exe and Clipboard
Flags Windows command lines indicating clip.exe clipboard use followed by obfuscated PowerShell invoke behavior.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh231Free2020-10-09