Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows PowerShell ScriptBlock alerts for DSInternals cmdlets
Triggers when PowerShell script blocks include DSInternals cmdlets tied to AD/Azure AD key and password auditing or manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh191Free2024-06-26Suspicious Child Process of KeyScrambler.exe on Windows
Alerts on KeyScrambler.exe launching cmd.exe, PowerShell, script hosts, regsvr32, or rundll32 as child processes.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium130Free2024-05-13PowerShell Start-NetEventSession Script Block Execution Indicating Potential Network Capture (Windows)
Alerts when PowerShell ScriptBlocks reference Start-NetEventSession, indicating potential network packet or event capture.
frack113, Huntrule TeamWindowsps_scriptMedium131Free2024-05-12Windows PowerShell ScriptBlock Adds Allow Firewall Rule via New-NetFirewallRule
Flags PowerShell ScriptBlock text that invokes New-NetFirewallRule to add an Allow firewall rule.
frack113, Huntrule TeamWindowsps_scriptLow110Free2024-05-10PowerShell New-NetFirewallRule Adds Windows Allow Firewall Rule
Alert on PowerShell creating a new Windows firewall rule that sets the action to Allow via New-NetFirewallRule.
frack113, Huntrule TeamWindowsprocess_creationLow90Free2024-05-03Windows Process Creation: Forest Blizzard-related hashes and scheduled task activity
Detects suspicious Windows process execution tied to known hashes or schtasks/PowerShell command-line patterns used for staging and compression.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2024-04-23Winlogon Shell Registry Persistence Attempt (KamiKakaBot Indicators) on Windows
Flags registry changes to Winlogon Shell that include PowerShell-style startup and explorer.exe indicators.
Nasreddine Bencherchali (Nextron Systems), X__Junior, Huntrule TeamWindowsregistry_setHigh312Free2024-03-22Windows: User Added to Highly Privileged Local/Directory Groups via net.exe or Add-LocalGroupMember
Flags net.exe or PowerShell commands adding users to privileged groups like Group Policy Creator Owners or Schema Admins.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2024-02-23Suspicious File Downloads via PowerShell.EXE from File Sharing Domains on Windows
Flags PowerShell downloading content from known file-sharing/paste domains using DownloadString/DownloadFile or web request syntax.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2024-02-23Windows PowerShell ScriptBlock keyword match for WinPwn tool usage
Alerts when PowerShell ScriptBlock text contains WinPwn execution or script/file reference keywords.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsps_scriptHigh152Free2023-12-04Windows Registry Set in Shell Open Command Using PowerShell Cryptography .NET Classes
Flags registry set of \Shell\Open\Command where PowerShell references System.Security.Cryptography crypto classes.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsregistry_setMedium70Free2023-12-01PowerShell Crypto Namespace Class Invocation for Windows Process Creation
Alerts on PowerShell executions that reference System.Security.Cryptography and common crypto class names.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsprocess_creationMedium70Free2023-12-01Windows Elevated Shell Spawn via Process Creation (PowerShell or CMD)
Flags creation of privileged PowerShell or cmd.exe processes tied to an elevated logon context.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium70Free2023-11-23Windows Process Creation: Detect Event Log Query via wmic.exe, wevtutil.exe, or PowerShell
Detects command-line attempts to query Windows Event Logs using wevtutil, wmic, or Get-WinEvent/Get-EventLog.
Ali Alwashali, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2023-11-20Windows: Detects Suspicious cmd.exe or PowerShell spawned from Confluence (tomcat) Processes
Alerts when Confluence/embedded Tomcat spawns cmd.exe or PowerShell on Windows, indicating possible command execution after exploitation.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsprocess_creationMedium81Free2023-11-14