Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows Registry Run Key Entries Containing PowerShell Execution Strings
Alerts when registry Run key value data contains PowerShell launch or encoded download/execution strings on Windows.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setMedium91Free2022-03-17Windows PowerShell: Suspicious Process Discovery Using Get-Process
Alerts when PowerShell script blocks contain Get-Process, indicating local process discovery activity.
frack113, Huntrule TeamWindowsps_scriptLow133Free2022-03-17PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)
Alerts when PowerShell calls Get-AdDefaultDomainPasswordPolicy to enumerate an AD domain’s default password policy.
frack113, Huntrule TeamWindowsps_scriptLow404Free2022-03-17Windows PowerShell Directory Enumeration via Get-ChildItem and Output Redirection
Flags PowerShell directory enumeration patterns using Get-ChildItem, error suppression, and appended output to a file.
frack113, Huntrule TeamWindowsps_scriptMedium215Free2022-03-17Windows PowerShell Active Directory Group Enumeration via Get-AdGroup Cmdlet
Flags PowerShell script blocks that call Get-ADGroup with -Filter to enumerate Active Directory groups.
frack113, Huntrule TeamWindowsps_scriptLow163Free2022-03-17PowerShell: Active Directory computer enumeration via Get-AdComputer
Flags PowerShell script blocks using Get-ADComputer with enumeration-related parameters for AD computer discovery.
frack113, Huntrule TeamWindowsps_scriptLow357Free2022-03-17PowerShell Get-ADUser Enumeration Using UserAccountControl DONT_REQ_PREAUTH Flag
Flags Get-ADUser PowerShell scripts enumerating accounts by UserAccountControl DONT_REQ_PREAUTH (4194304).
frack113, Huntrule TeamWindowsps_scriptMedium131Free2022-03-17Windows PowerShell: Suspicious Get-ADDBAccount access to ntds.dit via BootKey and DatabasePath
Alerts on PowerShell invocations of Get-ADDBAccount that reference BootKey and DatabasePath for ntds.dit credential access.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_moduleHigh133Free2022-03-16PowerShell Base64 Encoded MpPreference Command Lines for Windows Defender Modification
Detects PowerShell Base64 command lines referencing Add-MpPreference/Set-MpPreference to modify Microsoft Defender AV settings.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh147Free2022-03-04Windows PowerShell: Disable Microsoft Defender Scanning via Set-MpPreference
Flags PowerShell commands that disable Microsoft Defender scanning/protection settings using Set-MpPreference, including encoded variants.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh308Free2022-03-03Windows: fsutil SymlinkEvaluation behavior modification via command line
Alerts on fsutil commands from cmd/PowerShell that change NTFS SymlinkEvaluation behavior, potentially enabling remote symlink access.
frack113, The DFIR Report, Huntrule TeamWindowsprocess_creationMedium327Free2022-03-02Windows PowerShell: Base64 Encoded Reflective .NET Assembly Load
Flags PowerShell command lines containing Base64 fragments consistent with reflective .NET Assembly.Load usage.
Christian Burkard (Nextron Systems), pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh194Free2022-03-01Windows BITS Job Creation Triggered by PowerShell
Flags new BITS job creation on Windows when initiated by PowerShell (Event ID 3).
frack113, Huntrule TeamWindowsbits-clientLow111Free2022-03-01Windows PowerShell CommandLine downloads and executes via WebClient with IEX or DownloadFile
Alerts on PowerShell command lines that use WebClient downloads combined with IEX or DownloadFile, typical of staged payload execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-02-28Windows: ScreenConnect Client Service Spawning Suspicious Utility Commands
Alerts when ScreenConnect run.cmd leads to child processes like cmd.exe, PowerShell, curl, or other utilities.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), @Kostastsale, Huntrule TeamWindowsprocess_creationMedium123Free2022-02-25