Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows: Explorer opened from cmd.exe/powershell using shell:MyComputerFolder shortcut
Flags explorer.exe opened for My Computer via shell:mycomputerfolder when started by cmd or PowerShell.
"@Kostastsale, Huntrule Team"Windowsprocess_creationHigh233Free2022-12-22Webserver: OWASSRF exploitation attempt via OWA to PowerShell backend
Flags webserver POSTs returning 200 that request both /owa/mastermailbox and /powershell, consistent with OWASSRF exploitation attempts.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverCritical182Free2022-12-22Detect OWASSRF Webserver Exploitation Pattern Targeting PowerShell Backend
Alerts on successful POST requests to OWA URLs containing PowerShell backend indicators and Exchange-like probe user agents.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh111Free2022-12-22Detects OWASSRF Proxy Exploitation Attempt via OWA to PowerShell Backend
Identifies proxy POSTs that return 200 and request both /owa/mastermailbox and /powershell, indicating potential OWASSRF exploitation.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyCritical162Free2022-12-22Potential OWASSRF Exploitation via OWA Proxy Requests (HTTP 200) - Exchange
Alerts on 200-status proxy POSTs targeting OWA-to-PowerShell backend paths with encoded user info markers.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyHigh161Free2022-12-22Windows Registry Set Detection of Suspicious Environment Variable Commands
Flags Windows registry environment variable registrations that include PowerShell and base64-encoded command fragments.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh297Free2022-12-20Windows PowerShell nslookup DNS TXT Download Cradle
Identifies PowerShell launching an nslookup-based cradle that queries TXT records with HTTP-related nslookup parameters.
Sai Prashanth Pulisetti @pulisettis, Aishwarya Singam, Huntrule TeamWindowsps_classic_startMedium357Free2022-12-10Windows: Elevated PowerShell or CMD Spawned from Uncommon Parent Location
Alerts on elevated PowerShell/CMD executions whose parent process comes from uncommon Windows locations, indicating likely privilege escalation.
frack113, Tim Shelton (update fp), Huntrule TeamWindowsprocess_creationMedium202Free2022-12-05PowerShell Get-ADUser User Discovery and Data Export via File Output
Detects PowerShell Get-ADUser-based user enumeration combined with exporting results to files or output streams.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium91Free2022-11-17PowerShell Get-ADComputer Cmdlet Used for Computer Discovery and File Export
Flags PowerShell Get-ADComputer wildcard enumeration followed by writing exported computer data to a file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium80Free2022-11-17PowerShell Get-ADComputer Export of Active Directory Computer Data to File (Windows)
Detects PowerShell running Get-ADComputer (* filter) and exporting results to a file via output/content cmdlets.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2022-11-10PowerShell AMSI Bypass Assembly GetType Pattern in Script Block Text
Flags PowerShell scripts containing a reflection-based AMSI bypass fragment with GetType and SetValue($null,$true).
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2022-11-09Windows process creation: suspicious ping wait followed by del file deletion
Flags cmd/powershell command lines that use ping -n with Nul redirection followed by Del /f /q to delete a file.
Ilya Krestinichev, Huntrule TeamWindowsprocess_creationHigh131Free2022-11-03Windows Exchange PowerShell Cmdlet History Log Files Deleted
Flags deletion of Exchange PowerShell cmdlet history log files in the expected logging directory.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteHigh161Free2022-10-26PowerShell: Suspicious Set-Service DACL/SecurityDescriptor Modification for Hidden Services
Flags PowerShell ScriptBlock activity using Set-Service with specific SDDL elements consistent with hiding services from tools like sc.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh82Free2022-10-24