Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows sdiagnhost.exe Spawns Suspicious Child Process (PowerShell/CMD/MSHTA/etc.)
Alert when sdiagnhost.exe launches high-risk child processes like PowerShell or CMD, excluding selected benign-like command patterns.
Nextron Systems, @Kostastsale, Huntrule TeamWindowsprocess_creationHigh122Free2022-06-01PowerShell: Signed UtilityFunctions.ps1 Loading Managed DLL via Proxy Execution
Flags PowerShell command lines referencing UtilityFunctions.ps1 with RegSnapin usage consistent with managed DLL proxy execution.
frack113, Huntrule TeamWindowsprocess_creationMedium121Free2022-05-28Windows PowerShell detects obfuscated Net.Webclient casing anomalies in command line
Alerts when PowerShell command lines contain encoded obfuscation patterns referencing Net.Webclient with anomalous casing.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh229Free2022-05-24Windows PowerShell Process Command Lines With Encoded Command Flags
Alerts on PowerShell (pwsh) command lines using encoded command flags and encoded-looking substrings, excluding gc_worker.exe-related activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-05-24Windows: Jlaive In-Memory Assembly Execution via Copied Batch Executable
Detects chained cmd/.bat staging that uses xcopy plus PowerShell/pwsh and attrib +h/+s to run a .bat.exe payload associated with Jlaive.
Jose Luis Sanchez Martinez (@Joseliyo_Jstnk), Huntrule TeamWindowsprocess_creationMedium153Free2022-05-24Windows PowerShell Script Proxy Execution via CL_mutexverifiers.ps1
Alerts on PowerShell being launched with CL_mutexverifiers that proxies additional script execution.
Nasreddine Bencherchali (Nextron Systems), oscd.community, Natalia Shornikova, frack113, Huntrule TeamWindowsprocess_creationMedium60Free2022-05-21PowerShell Assembly Loading via CL_LoadAssembly.ps1 Functions
Alerts on PowerShell command lines that call LoadAssemblyFromPath/LoadAssemblyFromNS in CL_LoadAssembly.ps1 context.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2022-05-21Windows PowerShell Base64 Encoded Commands Containing Invoke- ( -e )
Flags PowerShell executions using the -e encoded command flag with Base64 patterns consistent with an Invoke- call.
pH-T (Nextron Systems), Harjot Singh, @cyb3rjy0t, Huntrule TeamWindowsprocess_creationHigh131Free2022-05-20Windows PowerShell Execution of Obfuscated One-Liner for In-Memory Module Download
Alerts on Windows PowerShell one-liners containing an obfuscated in-memory download/execute pattern from an HTTP URL.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh132Free2022-05-09Windows Process Creation: Suspicious Child Processes Spawned by regsvr32.exe
Alerts when regsvr32.exe spawns suspicious child processes like PowerShell, mshta, or scripting utilities.
elhoim, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-05-05Suspicious Child Process Spawning by PowerShell on Windows
Alerts when PowerShell spawns potentially suspicious child binaries (e.g., certutil, mshta, wmic, rundll32), with exclusions for known benign patterns.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationMedium100Free2022-04-26Windows Process Creation: Suspicious PowerShell Child of Tomcat prunsrv.exe (CVE-2022-22954 Attempt)
Alerts when prunsrv.exe spawns PowerShell or cmd.exe running PowerShell, consistent with potential Workspace ONE Access RCE attempts.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium161Free2022-04-25PowerShell WMI Win32_Product MSI Installation via Invoke-CimMethod
Flags PowerShell using WMI Win32_Product via Invoke-CimMethod to invoke an MSI install.
frack113, Huntrule TeamWindowsps_scriptMedium91Free2022-04-24Windows: File Creation of Get-Variable.exe in PowerShell WindowsApps Path
Alerts on creation of Get-Variable.exe in Local\Microsoft\WindowsApps, a potential cmdlet-path hijack.
frack113, Huntrule TeamWindowsfile_eventHigh162Free2022-04-23Windows: Emotet .LNK Loader Execution via cmd.exe or PowerShell
Alerts on cmd/powershell-launched commands referencing findstr, a .vbs script, and a .lnk file—indicative of shortcut-triggered loader activity.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh121Free2022-04-22