Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,286 rules
PowerShell Module Obfuscated IEX Invocation via Invoke-Obfuscation Payload Patterns
Alerts when PowerShell module payloads contain patterns consistent with obfuscated IEX generation via Invoke-Obfuscation.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowsps_moduleHigh71Free2019-11-08Windows System Service Creation of Obfuscated PowerShell IEX (Invoke-Obfuscation)
Flags Windows service creations whose ImagePath contains obfuscated PowerShell IEX invocation strings.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowssystemHigh3010Free2019-11-08Windows Security: Detect Obfuscated PowerShell IEX Invocation via ServiceFileName Patterns (Event ID 4697)
Alerts on EventID 4697 instances where ServiceFileName matches obfuscated IEX-style PowerShell invocation patterns consistent with Invoke-Obfuscation.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowssecurityHigh141Free2019-11-08Windows Credential Dump Tool Artifacts Written to Disk via File Events
Detects Windows file creation where the target filename contains or ends with known credential-dump tool or output names.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsfile_eventHigh257Free2019-11-01Windows Security: Suspicious Local Account Created with ANONYMOUS LOGON SamAccountName
Alerts on Windows local account creation where the new SamAccountName contains “ANONYMOUS” and “LOGON”.
James Pemberton / @4A616D6573, Huntrule TeamWindowssecurityHigh40Free2019-10-31Windows PowerShell Script Execution from Alternate Data Stream (ADS)
Flags PowerShell processes using Get-Content -Stream to execute or retrieve script content from an ADS.
Sergey Soldatov, Kaspersky Lab, oscd.community, Huntrule TeamWindowsprocess_creationHigh41Free2019-10-30Windows Process Creation Matching Mustang Panda Dropper Command-Line and winwsh.exe
Alerts on Windows process creation with temp-based wtaks/winwsh execution and script-launch command-line parameters.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsprocess_creationHigh103Free2019-10-30Windows Image Load: Unsigned dbghelp.dll/dbgcore.dll Loaded by Suspicious Process
Alerts on unsigned loading of dbghelp.dll/dbgcore.dll, often associated with memory dump creation and credential-access workflows.
Perez Diego (@darkquassar), oscd.community, Ecco, Huntrule TeamWindowsimage_loadHigh348Free2019-10-27Windows Remote Thread Creation from Uncommon Parent Image
Alerts on remote thread creation on Windows when the source executable is rare, with exclusions for known benign image pairings.
Perez Diego (@darkquassar), oscd.community, Huntrule TeamWindowscreate_remote_threadHigh342Free2019-10-27Windows: Child Process Spawned with SYSTEM Integrity by LOCAL/NETWORK SERVICE Parent
Alert on Windows executions where a SYSTEM-integrity child is spawned by a LOCAL SERVICE or NETWORK SERVICE parent, excluding a specific rundll32 pattern.
Teymur Kheirkhabarov, Roberto Rodriguez (@Cyb3rWard0g), Open Threat Research (OTR), Huntrule TeamWindowsprocess_creationHigh219Free2019-10-26Windows: sc.exe Service Configuration Changed by Medium-Integrity Users
Alerts on sc.exe runs from Medium-integrity users that include service config/binPath or failure command changes.
Teymur Kheirkhabarov, Huntrule TeamWindowsprocess_creationHigh111Free2019-10-26Windows Service Configuration Tampering by Medium-Integrity Processes
Alerts on medium-integrity processes running commands that target registry service configuration values for potential privilege escalation.
Teymur Kheirkhabarov, Huntrule TeamWindowsprocess_creationHigh163Free2019-10-26Windows getsystem via Meterpreter/Cobalt Strike when services.exe starts a likely privilege escalation command
Alerts when services.exe spawns cmd/%COMSPEC% commands writing to a named pipe consistent with getsystem behavior.
Teymur Kheirkhabarov, Ecco, Florian Roth, Huntrule TeamWindowsprocess_creationHigh228Free2019-10-26Windows Registry: Add-on DelegateExecute persistence via Narrator Feedback-Hub AppX key
Flags registry value deletions on a Narrator Feedback-Hub AppX DelegateExecute path used for persistence.
Dmitriy Lifanov, oscd.community, Huntrule TeamWindowsregistry_eventHigh41Free2019-10-25Windows: Registry CreateKey/Rename of HKLM\SYSTEM\CurrentControlSet\Control\MiniNt
Flags registry creation or renaming of the MiniNt key that can impair Windows event logging after reboot.
Ilyas Ochkov, oscd.community, Huntrule TeamWindowsregistry_eventHigh83Free2019-10-25