Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows Process Execution via 7zFM.exe Indicative of CVE-2022-29072 Exploitation
Alerts when 7zFM.exe spawns cmd.exe or PowerShell with command-line patterns consistent with CVE-2022-29072 exploitation attempts.
frack113, @kostastsale, Huntrule TeamWindowsprocess_creationHigh383Free2022-04-17Windows Process Creation: msiexec.exe Embedding Spawned by PowerShell/cmd/pwsh
Alerts when cmd/powershell launches msiexec.exe with -Embedding, a proxy execution pattern.
frack113, Huntrule TeamWindowsprocess_creationMedium102Free2022-04-16Windows schtasks.exe scheduled task creation from suspicious folders
Alerts on schtasks.exe /create using PowerShell/cmd and suspicious folder paths like ProgramData.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh404Free2022-04-15Windows File Creation: PowerShell webAdministration Module Path Used in CVE-2022-24527 LPE
Flags Windows file events creating webAdministration.psm1 under PowerShell modules, consistent with CVE-2022-24527 LPE behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh214Free2022-04-13PowerShell Hyper-V Cmdlets Execution via Script Blocks (New-VM, Set-VMFirmware, Start-VM)
Alerts when PowerShell script blocks use Hyper-V VM creation or start cmdlets (New-VM, Set-VMFirmware, Start-VM).
frack113, Huntrule TeamWindowsps_scriptMedium122Free2022-04-09Windows Task Scheduler persistence using svchost-launched PowerShell with hidden/Bypass flags
Alerts on svchost.exe Schedule tasks spawning PowerShell with hidden window and execution policy bypass flags.
pH-T (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-04-08Windows PowerShell execution from C:\Users\Public
Flags PowerShell command lines that reference C:\Users\Public, indicating likely script execution from a common public staging area.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2022-04-06Windows PowerShell User Discovery via Current Username APIs
Alerts on PowerShell script blocks that retrieve the current username or user identity using common environment/.NET calls.
frack113, Huntrule TeamWindowsps_scriptLow153Free2022-04-04Windows Registry Key Changes Disabling PowerShell Logging for Current User
Detects registry changes that disable PowerShell module/script logging and transcription by setting logging keys to DWORD 0.
frack113, Huntrule TeamWindowsregistry_setHigh448Free2022-04-02Windows PowerShell: Suspicious GetTypeFromCLSID and ShellExecute usage
Flags PowerShell script blocks that use GetTypeFromCLSID followed by ShellExecute.
frack113, Huntrule TeamWindowsps_scriptMedium133Free2022-04-02Windows PowerShell IEX Invocation Patterns in Process Creation Command Lines
Alerts on suspicious PowerShell command lines that pipe or otherwise invoke IEX and may include Base64 decoding.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh161Free2022-03-24Windows PowerShell Download and Execution Cradles
Flags PowerShell commands that download remote content and immediately execute it using IEX/Invoke-Expression.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh282Free2022-03-24Windows LSA PPL Protection Setting Modification via reg.exe or PowerShell Command Line
Flags Windows command lines that alter LSA PPL-related Control\Lsa registry settings using reg.exe/PowerShell property changes.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium132Free2022-03-22Windows Scheduled Task Backdoor Execution via cmd.exe or PowerShell (System EventID /create /delete)
Flags cmd.exe/powershell.exe command lines that create a System/EventID-based scheduled task to run a payload.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh233Free2022-03-21Windows Service Installation with PowerShell Download and Hidden Execution
Alerts on Windows service creation (7045) with ImagePath patterns indicating hidden/staged command execution.
pH-T (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh152Free2022-03-18