Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,156 rules
PowerShell ScriptBlock Logging: Obfuscated RUNDLL Launcher using rundll32.exe and shell32.dll
Identifies PowerShell script content invoking rundll32.exe/shell32.dll via shellexec_rundll and referencing PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptMedium152Free2020-10-18Detect PowerShell COMPRESS OBFUSCATION using ASCII text encoding and stream/compression APIs
Flags PowerShell script blocks that combine ASCII encoding with Deflate/stream handling indicative of obfuscated payload compression.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptMedium364Free2020-10-18PowerShell module activity launching rundll32 via shell32.dll obfuscation content
Alerts when PowerShell module payloads reference a shell32/rundll32 launcher pattern that includes PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_moduleMedium173Free2020-10-18PowerShell Module Payload Obfuscation Using COMPRESS OBFUSCATION
Identifies PowerShell module payloads containing ASCII encoding and compression/stream obfuscation strings.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_moduleMedium408Free2020-10-18Windows System: Detect rundll32 Service Control Manager launches PowerShell via obfuscated parameters
Flags service creation where ImagePath uses rundll32/shell32 (shellexec_rundll) to invoke PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssystemMedium70Free2020-10-18Windows System: Service Control Manager PowerShell Obfuscation Using COMPRESS OBFUSCATION
Flags new Windows services whose ImagePath includes obfuscated PowerShell markers using COMPRESS/stream decompression.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssystemMedium133Free2020-10-18Windows Security 4697: Obfuscated PowerShell via rundll32 shell32 shellexec_rundll
Alert on Security EID 4697 where service installation references rundll32/shell32.dll to launch PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssecurityMedium80Free2020-10-18Windows Security 4697 PowerShell obfuscated content using COMPRESS OBFUSCATION components
Alerts on service creation events where the ServiceFileName includes PowerShell obfuscation patterns tied to compression stream and ASCII encoding.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssecurityMedium91Free2020-10-18LockerGoga Ransomware Indicators in Windows Process Command Line
Flags Windows processes with a specific LockerGoga-style command-line argument pattern.
Vasiliy Burov, oscd.community, Huntrule TeamWindowsprocess_creationCritical192Free2020-10-18Windows PowerShell Script Execution via Redirected Input Stream
Flags PowerShell/pwsh executions where the command line includes redirected input ("- <").
Moriarty Meng (idea), Anton Kutepov (rule), oscd.community, Huntrule TeamWindowsprocess_creationHigh154Free2020-10-17Windows Process Creation: Suspicious Microsoft Csi.exe or Rcsi.exe with C# Execution Capability
Alerts on Windows executions of Microsoft’s csi.exe/rcsi.exe that can be used to run C# code from command-line.
Konstantin Grishchenko, oscd.community, Huntrule TeamWindowsprocess_creationMedium153Free2020-10-17Windows WMIC loading JavaScript/VBScript engine libraries
Alerts on wmic.exe loading jscript.dll or vbscript.dll, a common sign of script execution via Windows Management Instrumentation.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium444Free2020-10-17macOS Process Creation: Command Line Access to Shell History Files
Flags macOS command lines referencing common shell history files, which may indicate credential access or cover-tracks behavior.
Mikhail Larin, oscd.community, Huntrule TeamMacosprocess_creationMedium113Free2020-10-17Linux: Command-Line Access to Shell History Files via execve
Alerts when executed commands reference common Linux shell history files.
Mikhail Larin, oscd.community, Huntrule TeamLinuxauditdMedium332Free2020-10-17Potential Windows Registry Persistence via AppCompatFlags TelemetryController Commands
Flags registry entries under TelemetryController\Command that reference executable/script payloads potentially abusing telemetry for persistence.
Lednyov Alexey, oscd.community, Sreeman, Huntrule TeamWindowsregistry_setHigh466Free2020-10-16