Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,292 rules
PowerShell Script Obfuscation Triggered by Use of clip.exe and Clipboard Invocation
Flags PowerShell Script Block Logging containing clip.exe/clipboard chaining and clipboard-driven execution markers.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh216Free2020-10-09PowerShell module obfuscation using clip.exe with echo and clipboard invocation
Flags obfuscated PowerShell module scripts that echo “clip” and invoke clipboard-related behavior.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh161Free2020-10-09Windows Service Control Manager Rundll32 Obfuscation via Command-Line Encoded PowerShell
Detects service creation where ImagePath invokes rundll32 (shell32) with command-chain tokens indicative of obfuscated PowerShell.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh100Free2020-10-09Windows System: mshta Launches vbscript:createobject via Service Control Manager (Event ID 7045)
Flags Windows service creation (7045) where ImagePath includes mshta and vbscript:createobject.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh213Free2020-10-09Windows System: Suspicious Clip.exe Execution via Service Control Manager (Event ID 7045)
Alerts on Windows service creation starting clipboard/Clip.exe-related binaries via Service Control Manager ImagePath.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh232Free2020-10-09Windows Security 4697: Obfuscated command uses rundll32 with shell32.dll
Alerts on EventID 4697 service command lines containing rundll32 with shell32.dll/shellexec_rundll and obfuscation-like script fragments.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh112Free2020-10-09Windows Security EID 4697: mshta Used to Run Obfuscated VBScript PowerShell
Detects service creation where the binary path includes mshta plus VBS/automation indicators consistent with script-based obfuscation.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh143Free2020-10-09Windows Security 4697: Obfuscated PowerShell via use of Clip.exe from scripts
Alerts on EID 4697 service installations where the service file name matches Clip/clipboard indicators tied to obfuscated PowerShell.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh192Free2020-10-09Windows Process Execution: Obfuscated PowerShell Invocation Using mshta with VBScript CreateObject
Flags Windows process command lines containing an obfuscated PowerShell+MSHTA VBScript execution pattern.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh226Free2020-10-08PowerShell ScriptBlock Obfuscation via MSHTA VBScript CreateObject Execution
Alerts on PowerShell script blocks containing mshta and VBScript createobject/.run/window.close patterns consistent with obfuscated execution.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh163Free2020-10-08PowerShell Module: Obfuscated MSHTA Invocation via VBS CreateObject
Alerts when PowerShell module payload text includes an obfuscated MSHTA/VBScript invocation sequence.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh351Free2020-10-08UAC Bypass Using wsreset.exe Registry Command Path (Windows)
Identifies registry TargetObject values associated with a wsreset-style UAC bypass execution command path on Windows.
oscd.community, Dmitry Uchakin, Huntrule TeamWindowsregistry_eventHigh171Free2020-10-07Windows Visual Basic vbc.exe Compiles to .obj via cvtres.exe Resource Converter
Alerts when vbc.exe spawns cvtres.exe during Windows VB command-line compilation activity.
Ensar Şamil, @sblmsrsn, @oscd_initiative, Huntrule TeamWindowsprocess_creationHigh151Free2020-10-07Windows regedit.exe exports a registry key into an alternate data stream
Flags regedit.exe executions where the process image ends with '\regedit.exe', consistent with exporting Registry data to an alternate data stream.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowscreate_stream_hashHigh193Free2020-10-07PowerShell Service Persistence via Registry ImagePath on Windows
Flags Windows registry service ImagePath entries that reference PowerShell (powershell/pwsh).
oscd.community, Natalia Shornikova, Huntrule TeamWindowsregistry_setHigh202Free2020-10-06