Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows PowerShell ScriptBlock: Remove-MpPreference Tampering of Defender Configuration
Detects PowerShell commands removing Defender preferences via Remove-MpPreference with additional Defender setting indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh436Free2022-08-05Windows Suspicious IIS Module Registration via w3wp.exe, appcmd.exe, and PowerShell/gacutil
Flags w3wp.exe-launched appcmd.exe module registrations involving PowerShell publication or gacutil GAC installation.
Florian Roth (Nextron Systems), Microsoft (idea), Huntrule TeamWindowsprocess_creationHigh90Free2022-08-04Windows Command-Line Tools Performing Web POST Exfiltration via IWR/curl/wget
Identifies PowerShell/curl/wget commands on Windows that use POST-style web requests combined with data-dumping or discovery payloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2310Free2022-08-02Windows PowerShell Invoke-WebRequest Download to Suspicious Paths
Alert when PowerShell uses Invoke-WebRequest/aliases with download flags and targets suspicious file locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2022-08-02Windows Suspicious Service Creation via sc.exe or PowerShell New-Service with Abnormal Binary Paths
Flags service creation commands (sc.exe/New-Service) when the specified binary path includes suspicious directories or script/loader utilities.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2022-07-14Windows PowerShell: Detect Command Lines with Suspicious UTF-16 Base64 Obfuscation Patterns
Alerts on PowerShell command lines containing suspicious UTF-16/Base64 obfuscation fragments indicative of hidden script logic.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh458Free2022-07-11PowerShell TCP Tunnel Indicators: HttpWebRequest and TcpListener Usage (Windows
Flags PowerShell scripts referencing TcpListener/AcceptTcpClient and HttpWebRequest as potential TCP tunneling behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium162Free2022-07-08Windows PowerShell: Import-Module From Temp, AppData, or Public Directories
Detects PowerShell module imports (Import-Module/ipmo) from Temp, AppData, or Public directories via Script Block Logging.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium153Free2022-07-07PowerShell disables or removes ETW Trace via Set-EtwTraceProvider or Remove-EtwTraceProvider
Flags PowerShell commands that remove or disable ETW trace providers to impair Windows telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2022-06-28Windows PowerShell: Execution of TroubleshootingPack Cmdlets (msdt-related usage)
Flags PowerShell script blocks invoking TroubleshootingPack with unattended answer-file arguments.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium143Free2022-06-21Windows PowerShell Hotfix Enumeration via Win32_QuickFixEngineering
Detects PowerShell scripts enumerating installed hotfixes by querying Win32_QuickFixEngineering for HotFixID.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium211Free2022-06-21PowerShell WMI Service Enumeration for Unquoted Service Path Recon
Flags PowerShell WMI queries for Win32_Service fields to enumerate potential unquoted service path issues.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium82Free2022-06-20Windows: FakeUpdates/SocGholish execution via wscript loading a zip-based update script
Flags wscript launched from Temp update .js within a .zip to spawn cmd.exe or PowerShell on Windows.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh141Free2022-06-16Windows Registry Custom File Open Handler Executes PowerShell
Alerts when a registry shell open handler is created to run PowerShell with -command.
CD_R0M_, Huntrule TeamWindowsregistry_setHigh112Free2022-06-11Windows PowerShell: Suspicious GPO Discovery via Get-GPO
Detects PowerShell script blocks using Get-GPO to enumerate domain Group Policy Objects.
frack113, Huntrule TeamWindowsps_scriptLow111Free2022-06-04