Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows PowerShell Import-Module Cmdlet Execution
Flags PowerShell command lines containing Import-Module, indicating module loading into the current session.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow80Free2023-05-09PowerShell Script Reading Files and Resolving DNS Host Entries
Identifies PowerShell scripts that read files, resolve DNS host entries, and output results to disk.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium1810Free2023-05-05Windows: Suspicious child processes spawned from Veeam SQL Server service
Alerts on suspicious cmd/PowerShell/LOLBin and recon utilities spawned by the Veeam SQL service (sqlservr.exe with VEEAMSQL).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical415Free2023-05-04Windows PowerShell Credential Dumping Script Targeting Veeam Backup ProtectedStorage
Alerts on PowerShell scripts that reference Veeam protected storage and credential extraction indicators, enabling stored credential dumping on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh122Free2023-05-04Windows PowerShell Script Block Matching POWERTRASH Behavior Indicators
Detects PowerShell ScriptBlock text containing POWERTRASH-related in-memory and dynamic execution indicators on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2023-05-04PowerShell ScriptBlock Launching wscript.exe via PowerHold-like Code Patterns on Windows
Flags PowerShell ScriptBlock text that writes staged bytes in APPDATA and launches wscript.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh161Free2023-05-04Windows PowerShell Script File Creation Matching FIN7-Style Filenames
Alerts on Windows PowerShell script drops named host_ip.ps1 or ending with _64refl.ps1.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh112Free2023-05-04Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)
Identifies PowerShell ScriptBlock content that includes Rubeus-specific Kerberos and ticket manipulation flags.
Christian Burkard (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh386Free2023-04-27Windows Process Creation Indicators for PowerShell MSI Download and Silent Install (PaperCut MF/NG)
Detects hidden PowerShell downloading a setup.msi and silent msiexec installation tied to PaperCut MF/NG exploitation indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh231Free2023-04-25Windows PowerShell Invoke-WebRequest Execution via Direct IP in Command Line
Alerts when PowerShell executes web-request aliases targeting direct IP URLs, indicating possible remote content access.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2023-04-21Windows: Detect suspicious PowerShell/Lsass tool execution launched by ManageEngine (ServiceDesk)
Alerts on suspicious child PowerShell/LSASS/tool activity launched by ManageEngine ServiceDesk (Java parent) on Windows.
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule TeamWindowsprocess_creationCritical160Free2023-04-20Windows Process Creation: AsperaFaspex Parent Spawning PowerShell or Credential-Access Tooling
Detects AsperaFaspex (aspera\ruby parent) spawning suspicious PowerShell, LSASS, web download, privilege, or defensive-evasion commands on Windows.
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule TeamWindowsprocess_creationCritical120Free2023-04-20Windows: Detect Action1 agent deployment, command execution, and remote session startup
Finds Action1 agent deployments, script-launched command/PowerShell execution, and remote session starts on Windows.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium90Free2023-04-13Windows PowerShell File Dropper Activity: Creating Executables or Script Files
Alerts when PowerShell writes .exe/.dll or script-like files, consistent with binary/script staging or dropping.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium151Free2023-03-17Windows PowerShell Downloading DLLs via Invoke-WebRequest or Invoke-RestMethod
Alerts on PowerShell using web request cmdlets to download an HTTP DLL to disk.
Florian Roth (Nextron Systems), Hieu Tran, Huntrule TeamWindowsprocess_creationMedium70Free2023-03-13