Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows Process Execution for PowerShell Cobalt Strike Download via Hidden IEX
Flags PowerShell command lines that use IEX and hidden downloadstring to fetch a Cobalt Strike payload.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2023-11-09Windows PowerShell script launcher matching SysAidServer Tomcat paths
Flags PowerShell script block text tied to SysAid Tomcat webapp paths and user.exe staging/launch actions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh123Free2023-11-09PowerShell Script Evidence Eraser Searching for cleanLL and usersfiles.war
Identifies PowerShell script blocks containing evidence-cleanup indicators and a repeating while(1) loop.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh407Free2023-11-09Windows PowerShell Script File Creation: SysAidServer Webapp User/User.exe Indicators
Detects creation of specific SysAidServer Tomcat webapp files indicative of PowerShell script staging on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh334Free2023-11-09Windows: VS Code Tunnel Launching PowerShell or WSL/Bash Shell
Flags VS Code tunnel (node.exe) spawning PowerShell, WSL, or bash shell processes on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2023-10-25Windows PowerShell EnableScripts Policy Enabled via Registry DWORD
Flags registry changes that enable PowerShell script execution via the EnableScripts policy (DWORD 0x00000001).
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule TeamWindowsregistry_setLow132Free2023-10-18Suspicious Child Process Spawned by Diskshadow.exe (Windows Process Creation)
Alerts on process creation where Diskshadow.exe spawns certutil, cscript, mshta, PowerShell, regsvr32, rundll32, or wscript.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium110Free2023-09-15Suspicious LOLBIN Copy From Windows System Directories Using Windows Copy Tools
Flags cmd/PowerShell/robocopy/xcopy commands that copy known LOLBINs out of System32/SysWOW64/WinSxS.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh193Free2023-08-29Windows Fake wermgr.exe Execution via Renamed cmd/powershell/powershell_ise
Detects disguised execution of cmd or PowerShell by matching original file name with a wermgr.exe process image.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2023-08-23Windows Process Execution Triggered from WebDAV LNK Paths
Alerts on explorer.exe launching cmd/cscript/mshta/powershell/wscript/pwsh when the command line references a WebDAV \DavWWWRoot\ LNK path.
Micah Babinski, Huntrule TeamWindowsprocess_creationMedium123Free2023-08-21Suspicious Child Process Creation from BgInfo.EXE on Windows
Alerts when BgInfo.exe spawns suspicious calc/cmd/cscript/mshta/powershell/wscript or runs from common AppData/Temp paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2023-08-16Windows PowerShell ScriptBlock WinAPI Function Calls
Find PowerShell script blocks that reference WinAPI/native-call function names tied to process, memory, token, or thread operations.
Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium70Free2023-07-21PowerShell Scripts Calling WinAPI DLLs on Windows
Detects PowerShell script blocks that reference WinAPI-related Windows DLLs such as kernel32.dll and ntdll.dll.
Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium70Free2023-07-21PowerShell Script Block: SMB QUIC Share Mapping via New-SmbMapping
Alerts when PowerShell maps Windows SMB shares using New-SmbMapping with -TransportType QUIC.
frack113, Huntrule TeamWindowsps_scriptMedium70Free2023-07-21Windows Process Creation: schtasks.exe Creating Scheduled Task Launching Registry-Stored PowerShell Payload
Flags schtasks.exe /Create scheduled tasks that launch PowerShell decoding and executing a base64 payload retrieved from Windows Registry.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2023-07-18