Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows PowerShell ScriptBlock with Encoded, Hidden, or Noninteractive Execution Parameters
Alerts on PowerShell ScriptBlockText containing encoded command, hidden window, or noninteractive execution parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh123Free2017-03-12Suspicious PowerShell Module Execution Using Encoded, Hidden, or Noninteractive Context (Windows)
Alerts on PowerShell module executions using encoded commands, hidden windows, or noninteractive flags to evade visibility and interaction.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_moduleHigh167Free2017-03-12Windows BITSAdmin File Download via bitsadmin.exe with Transfer/Addfile Arguments
Flags bitsadmin.exe being started with parameters consistent with transferring/downloading files from an http URL.
Michael Haag, FPT.EagleEye, Huntrule TeamWindowsprocess_creationMedium289Free2017-03-09Windows Security: Detects SAM User/Group Access During Domain Recon (Event ID 4661)
Alerts on Event ID 4661 accesses to SAM user/group objects for domain Administrator and Domain Admins.
Florian Roth (Nextron Systems), Jack Croock (method), Jonhnathan Ribeiro (improvements), oscd.community, Huntrule TeamWindowssecurityHigh394Free2017-03-07Windows Service Install: NtsSrv (StoneDrill) via Service Control Manager Event 7045
Flags Windows service installs of NtsSrv by Service Control Manager with an ImagePath ending in " LocalService".
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh398Free2017-03-07Suspicious PowerShell Script Block Invocations Using Encoded/Hidden Execution and Persistence Commands
Flags PowerShell script blocks using hidden/non-interactive execution, encoded/decode patterns, iex execution, web downloads, or run key modifications.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule TeamWindowsps_scriptHigh92Free2017-03-05PowerShell ScriptBlock WebClient Download Calls
Alert on PowerShell ScriptBlock text that uses System.Net.WebClient to download files or strings from the Internet.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptMedium101Free2017-03-05Windows PowerShell Script Block Logging: PSAttack marker string
Alerts when PowerShell script blocks contain the "PS ATTACK!!!" marker on Windows.
Sean Metcalf (source), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh344Free2017-03-05Windows PowerShell Script Block Contains Exploitation Framework and Credential Theft Keywords
Alerts on PowerShell script block text containing known exploitation, token, and memory-related keywords.
Sean Metcalf (source), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptMedium168Free2017-03-05Windows PowerShell ScriptBlock detects known malicious commandlet names used by exploitation frameworks
Alerts when PowerShell ScriptBlock text includes strings matching known malicious commandlets from common exploitation toolsets.
Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer, Huntrule TeamWindowsps_scriptHigh424Free2017-03-05Suspicious PowerShell Module Usage with Hidden/Encoded Execution Parameters on Windows
Flags hidden or encoded PowerShell invocations that decode/execute code or download-and-execute patterns, while filtering a Chocolatey installer snippet.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule TeamWindowsps_moduleHigh295Free2017-03-05Suspicious PowerShell WebClient Downloads via PoshModule
Alerts on PowerShell module activity referencing System.Net.WebClient with DownloadFile/DownloadString calls to fetch remote content.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_moduleMedium101Free2017-03-05Windows PowerShell Execution via EngineVersion/HostVersion Mismatch in Command Start Telemetry
Detects PowerShell execution attempts that match a specific executable EngineVersion/HostVersion mismatch pattern on Windows.
Sean Metcalf (source), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_classic_startHigh92Free2017-03-05PowerShell Net.WebClient DownloadFile/DownloadString Usage (Classic)
Flags PowerShell Classic commands using Net.WebClient to download content via DownloadFile or DownloadString.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_classic_startLow233Free2017-03-05Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Flags Service Control Manager service creation with ImagePath names tied to credential dumping tools (Event ID 7045).
Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowssystemHigh121Free2017-03-05