Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
PowerShell Script Block Logging: Suspicious Windows Event Log Clearing Cmdlets
Flags PowerShell script blocks that call event log clearing cmdlets or ClearLog to impair Windows log visibility.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptMedium92Free2022-09-12PowerShell Enable-WindowsOptionalFeature Enables Suspicious Windows Optional Features (Windows)
Alerts on PowerShell enabling Windows optional features online for specific, potentially risky feature names.
frack113, Huntrule TeamWindowsps_scriptMedium163Free2022-09-10PowerShell Disable-WindowsOptionalFeature -Online -FeatureName for Windows Defender features
Detects PowerShell disabling online Windows Defender features via Disable-WindowsOptionalFeature -FeatureName.
frack113, Huntrule TeamWindowsps_scriptHigh411Free2022-09-10PowerShell User Discovery and Export with Get-ADUser
Flags PowerShell Get-ADUser enumeration (filter *) followed by exporting results to a file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium481Free2022-09-09Windows Root Certificate Installation from Suspicious Paths via PowerShell Import-Certificate
Alerts on PowerShell importing a root certificate into Cert:\LocalMachine\Root from suspicious file paths on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-09-09PowerShell Email Address Exfiltration via EXIF-style Recipient Harvesting on Windows
Alerts when PowerShell command lines enumerate Exchange recipients and expand email address properties, indicating potential email data exfiltration.
Nasreddine Bencherchali (Nextron Systems), Azure-Sentinel (idea), Huntrule TeamWindowsprocess_creationHigh91Free2022-09-09Windows PowerShell DNS TXT Download Cradle via nslookup (Process Creation)
Flags PowerShell spawning nslookup configured to query DNS TXT records as a download cradle.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2022-09-05Windows Process Creation: Suspicious Service Stop/Pause/Delete/Disable via net, sc, PowerShell
Alerts on net/sc/wmic/PowerShell commands that stop, pause, delete, or disable Windows services, especially security/backup services.
Nasreddine Bencherchali (Nextron Systems), frack113 , X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-09-01Windows Process Execution: Suspicious PowerShell Encoded Command with Exec Bypass
Flags Windows process creations with a bypass-and-encoded PowerShell Start-Job command-line pattern linked to Mercury-related activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh324Free2022-08-26Windows process command line matching Sliver C2 implant NoExit PowerShell UTF8 pattern
Alerts on Windows process command lines matching a Sliver-style PowerShell -NoExit encoding pattern.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical152Free2022-08-25Windows File Changes to Microsoft.VSCode_profile.ps1 via PowerShell Profile
Detects creation or modification of Microsoft.VSCode_profile.ps1 based on Windows file events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium91Free2022-08-24Windows PowerShell Command History Disable via Remove-Module psreadline
Detects PowerShell scripts that remove psreadline with Remove-Module to suppress command history evidence.
Ali Alwashali, Huntrule TeamWindowsps_scriptHigh327Free2022-08-21Windows: Code execution via Pester.bat invoked by PowerShell (Invoke-Pester/Get-Help)
Alerts when PowerShell spawns Pester.bat with parent command lines referencing Pester invocation or help usage.
frack113, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium113Free2022-08-20Windows PowerShell: GPO ScriptBlock Modifying Group Policy and SmartScreen Settings
Alerts on PowerShell ScriptBlock content referencing Group Policy policy keys and specific security policy value names.
frack113, Huntrule TeamWindowsps_scriptMedium259Free2022-08-19PowerShell Write-EventLog with -RawData Flag
Alerts when PowerShell script blocks call Write-EventLog using the -RawData flag.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium133Free2022-08-16