Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows PowerShell Script Modifies File Permissions with Set-Acl
Flags PowerShell scripts that call Set-Acl to change ACL permissions on a specified path.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptLow80Free2023-07-18Windows PowerShell WMI Win32_NTEventlogFile Calls with Event Log Tampering Methods
Flags PowerShell calling Win32_NTEventlogFile WMI methods commonly used to clear, delete, backup, or alter Windows event logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2023-07-13Suspicious PowerShell WMI Win32_NTEventlogFile Usage (Event Log Tampering)
Detects PowerShell scripts calling Win32_NTEventlogFile methods associated with event log deletion, backup, renaming, or permission changes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium163Free2023-07-13PowerShell NetFirewallRule Cmdlet Enumeration of Local Windows Firewall Rules
Flags PowerShell attempts to enumerate local Windows firewall rules via Get-NetFirewallRule or Show-NetFirewallRule.
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule TeamWindowsps_moduleLow80Free2023-07-13Windows PowerShell Script Accessing Windows MailApp MailBox Data Path
Identifies PowerShell scripts referencing the Windows MailApp mailbox data path, which may indicate email data access or manipulation.
frack113, Huntrule TeamWindowsps_scriptMedium70Free2023-07-08PowerShell Registry Reconnaissance Indicators on Windows via Script Block Logging
Identifies PowerShell script blocks querying sensitive registry keys tied to services and Run/Explorer/winlogon locations.
frack113, Huntrule TeamWindowsps_scriptMedium70Free2023-07-02Windows PowerShell Decryption-Like Activity Involving .LNK File Processing
Identifies PowerShell runs that enumerate and process *.lnk content using byte-level reads/writes consistent with decryption staging.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh181Free2023-06-30Windows: PowerShell Core DLL Loaded by Office Application
Flags Office apps that load System.Management.Automation DLLs associated with PowerShell Core.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium143Free2023-06-01Windows File Events: PSScriptPolicyTest Script Creation by Uncommon Process
Alert on __PSScriptPolicyTest_ PowerShell script file creation when the writing process is not an expected PowerShell component.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium203Free2023-06-01Windows rundll32.exe Execution via cmd/cscript/powershell with .dll and Suspicious Directories
Alerts on rundll32.exe execution with DLL arguments from common Windows script/LOLBins and suspicious staging paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2023-05-24PowerShell Certificate Export Cmdlets in Windows Process Creation
Flags PowerShell command lines invoking certificate export cmdlets (Export-PfxCertificate/Export-Certificate) on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium428Free2023-05-18PowerShell ScriptBlock Function Get-VMRemoteFXPhysicalVideoAdapter Module Creation
Flags PowerShell module content that defines Get-VMRemoteFXPhysicalVideoAdapter in a ScriptBlock, consistent with load-order abuse patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh235Free2023-05-09Windows: New PowerShell Module Files Created by Non-PowerShell Processes
Detects new PowerShell module files written into Modules directories by processes other than expected PowerShell hosts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium141Free2023-05-09Windows PowerShell Module File Creation via PowerShell Processes
Alert when PowerShell creates module-related files under WindowsPowerShell or PowerShell 7 module directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow152Free2023-05-09Windows PowerShell dropping a .ps1 script from powershell.exe or pwsh.exe
Alerts when PowerShell creates a dropped .ps1 script file on Windows, excluding common benign temp and test outputs.
frack113, Huntrule TeamWindowsfile_eventLow374Free2023-05-09