Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows Process Creation: Hermetic Wiper–style Postgres/PowerShell Command-Line Patterns
Flags Windows process creation with wiper-like PowerShell comsvcs MiniDump and related command-line/paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-02-25Suspicious Reset-ComputerMachinePassword Usage via PowerShell on Windows
Detects PowerShell executions of Reset-ComputerMachinePassword that may indicate attempts to alter domain computer account authentication.
frack113, Huntrule TeamWindowsps_moduleMedium134Free2022-02-21Windows schtasks Creates Registry-Backed Base64 PowerShell Payload via Encoded Command
Flags schtasks.exe scheduling that triggers PowerShell to decode a base64 payload pulled from Windows Registry.
pH-T (Nextron Systems), @Kostastsale, TheDFIRReport, X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-02-12PowerShell DirectorySearcher AD Computer Enumeration via System.DirectoryServices.DirectorySearcher
Flags PowerShell DirectorySearcher queries that load directory properties and enumerate results from Active Directory.
frack113, Huntrule TeamWindowsps_scriptMedium151Free2022-02-12Windows Process Execution: ZeroLogon PoC Tool (cool.exe/zero.exe) via cmd.exe
Alerts on cmd.exe launching cool.exe/zero.exe with ZeroLogon PoC-style arguments and follow-on taskkill or PowerShell activity.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh193Free2022-02-12Windows process creation: flag suspicious program names and PowerShell script indicators
Alerts on suspicious Windows process image names and PowerShell command-line script/tool patterns commonly used in malicious tooling.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-02-11Windows Process Creation: cmd.exe Launching with PowerShell in .lnk Link Command
Alerts when explorer launches cmd.exe with command lines containing both PowerShell and a .lnk reference.
frack113, Huntrule TeamWindowsprocess_creationMedium131Free2022-02-06Windows PowerShell: DSInternals Get-ADReplAccount Enumeration
Alerts on PowerShell execution of Get-ADReplAccount with -All and -Server parameters for AD replication account enumeration.
frack113, Huntrule TeamWindowsps_scriptMedium172Free2022-02-06Windows PowerShell: Suspicious Unblock-File to Remove Zone.Identifier
Flags PowerShell use of Unblock-File (-Path) that can remove Zone.Identifier downloaded-file metadata.
frack113, Huntrule TeamWindowsps_scriptMedium4510Free2022-02-01PowerShell Mount-DiskImage with -ImagePath to Access Disk Images
Alerts on PowerShell script blocks calling Mount-DiskImage with -ImagePath, indicative of disk-image-based payload staging.
frack113, Huntrule TeamWindowsps_scriptLow342Free2022-02-01Windows PowerShell: Suspicious Invoke-Item After Mount-DiskImage
Flags PowerShell that mounts an image, derives a drive letter, then runs content via invoke-item from that mount.
frack113, Huntrule TeamWindowsps_scriptMedium60Free2022-02-01Windows PowerShell ScriptBlock Accessing Browser 'Login Data' Files
Flags PowerShell Copy-Item operations targeting browser Login Data credential database paths on Windows.
frack113, Huntrule TeamWindowsps_scriptMedium163Free2022-01-30Windows PowerShell Scripts Testing Uncommon Port Connectivity via Test-NetConnection
Detects PowerShell scripts using Test-NetConnection to reach a target on non-443/80 ports.
frack113, Huntrule TeamWindowsps_scriptMedium111Free2022-01-23Windows PowerShell: Suspicious SslStream Client Certificate Validation in Script Block
Flags PowerShell scripts referencing SslStream and client-side certificate validation during SSL client authentication.
frack113, Huntrule TeamWindowsps_scriptLow143Free2022-01-23Windows PowerShell: WebRequest User-Agent Modification in ScriptBlockText
Detects PowerShell scripts that make web requests and set a custom -UserAgent value.
frack113, Huntrule TeamWindowsps_scriptMedium142Free2022-01-23