Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
PowerShell Set-Acl targeting Windows folder paths on Windows
Flags PowerShell Set-Acl commands that modify ACLs for Windows folder paths, often using FullControl/Allow.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2022-10-18PowerShell Set-Acl Script Execution Changes File or Folder Permissions on Windows
Flags PowerShell commands using Set-Acl (-AclObject and -Path) to alter Windows file or folder permissions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2022-10-18PowerShell Set-Service SecurityDescriptorSddl DACL Modification for Windows Services
Detects PowerShell Set-Service commands with SecurityDescriptorSddl SDDL patterns that modify Windows service DACLs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh373Free2022-10-18Windows PowerShell Set-Service SDDL Usage to Hide Services
Flags pwsh Set-Service commands that set a SecurityDescriptorSddl to hide a Windows service from other tools.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-10-17PowerShell Set-Service SecurityDescriptor (DCLCWPDTSD) to Hide Services
Flags PowerShell Set-Service calls that set a SecurityDescriptor SDDL (DCLCWPDTSD) to hide services from other utilities.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh132Free2022-10-17Windows PowerShell Recon Using Get-LocalGroupMember on Local/Well-Known Groups
Flags PowerShell Get-LocalGroupMember usage targeting notable local group names in process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium175Free2022-10-10Windows Process Creation: SharpWSUS or WSUSpendu Execution via PowerShell Parameters
Detects command-line execution patterns for SharpWSUS or WSUSpendu on Windows.
"@Kostastsale, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsprocess_creationHigh246Free2022-10-07PowerShell PSAsyncShell Reverse Shell Activity via Script Block Logging
Detects PowerShell use of PSAsyncShell by matching the tool name in logged script block text.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh121Free2022-10-04PowerShell ScriptBlock Matching Invoke-Mimikatz Credential Dump Commands (Windows)
Detects PowerShell ScriptBlocks containing Mimikatz-like credential dump and certificate extraction command strings.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsps_scriptHigh112Free2022-09-28PowerShell Script Exfiltration Attempt: Send-MailMessage with Attachments
Detects PowerShell Send-MailMessage usage with -Attachments, which may indicate SMTP-based data exfiltration.
frack113, Huntrule TeamWindowsps_scriptMedium60Free2022-09-26Windows PowerShell WMI Volume Shadow Copy Deletion
Flags PowerShell WMI/CIM commands that query Win32_ShadowCopy and attempt deletion.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationHigh81Free2022-09-20PowerShell WMI Script Deletes Windows Volume Shadow Copies
Flags PowerShell WMI/CIM scripts that enumerate Win32_ShadowCopy and attempt to delete it.
Tim Rauch, frack113, Huntrule TeamWindowsps_scriptHigh204Free2022-09-20PowerShell Adds Windows Defender Exclusions via Add-MpPreference/Set-MpPreference
Flags PowerShell commands that add Windows Defender exclusions using Add-MpPreference/Set-MpPreference with exclusion parameters.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsps_scriptMedium415Free2022-09-16Windows PowerShell Sensitive File Discovery via ScriptBlock Enumeration
PowerShell script blocks using recursive file enumeration that target sensitive file extensions.
frack113, Huntrule TeamWindowsps_scriptMedium2310Free2022-09-16Windows PowerShell Disables Windows Firewall Profiles via Set-NetFirewallProfile
Flags PowerShell commands attempting to turn off Windows Firewall profiles using Set-NetFirewallProfile.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium192Free2022-09-14