Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,154 rules
Windows PowerShell Software Enumeration via Script Block Content
Flags PowerShell registry queries for installed software metadata combined with selection and table formatting.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptMedium457Free2020-10-16PowerShell command-line obfuscation indicators from special-character patterns (Windows)
Alerts on PowerShell executions whose command lines contain repeated special-character obfuscation patterns.
Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton (fp), Huntrule TeamWindowsprocess_creationHigh3510Free2020-10-15Windows Process Creation: Cmd Invokes PowerShell via Obfuscated Environment Variable Expansion
Alerts on cmd.exe command lines that use obfuscated environment-variable SET to execute PowerShell.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsprocess_creationHigh152Free2020-10-15Windows Process Execution Using Obfuscated CMD to Pipe STDIN into PowerShell
Detects obfuscated cmd executions that launch PowerShell and reference $input/noexit patterns for STDIN-based execution.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsprocess_creationHigh123Free2020-10-15PowerShell: Obfuscated invocation via Environment Variables in Script Block
Alerts on PowerShell script blocks launching cmd /c or /r with obfuscated set-and-{n} variable expansion patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_scriptHigh111Free2020-10-15PowerShell Obfuscated stdin launcher using cmd /c or cmd /r patterns
Detects PowerShell script blocks that use obfuscated STDIN-driven cmd/powershell execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_scriptHigh2110Free2020-10-15PowerShell Module: Obfuscated Environment Variable Expansion via cmd /c set -f Pattern
Alerts when PowerShell module payloads obfuscate execution via cmd /c|/r and environment-variable-based set patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_moduleHigh113Free2020-10-15PowerShell Module: Obfuscated STDIN Execution via cmd /c or cmd /r
Alerts when an obfuscated cmd->PowerShell payload uses stdin-style input and noexit/no-execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_moduleHigh151Free2020-10-15Windows Service Control Manager: Obfuscated Environment Variable PowerShell via cmd /c set -f
Alerts on Service Control Manager event 7045 where a service ImagePath uses cmd /c|/r with "set" and -f formatting.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh132Free2020-10-15Windows System Service Control Manager spawning cmd with PowerShell and stdin input obfuscation
Flags SCM-created services whose ImagePath runs cmd to invoke PowerShell using stdin/input and -NoExit patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh70Free2020-10-15Windows Security 4697: cmd.exe Launching Obfuscated PowerShell via Environment Variable Expansion
Alerts on EID 4697 service installation command lines containing obfuscated cmd.exe SET patterns used to execute PowerShell via environment variables.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh113Free2020-10-15Windows Security Event 4697 PowerShell Launch via cmd/stdin Obfuscation
Alerts on service creation events that run PowerShell through cmd with stdin-style obfuscation markers.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh70Free2020-10-15macOS split Command Used to Divide Files into Parts
Flags macOS process execution of split, indicating file splitting activity that may support staging or exfiltration.
Igor Fits, Mikhail Larin, oscd.community, Huntrule TeamMacosprocess_creationLow141Free2020-10-15Linux split Command Used to Divide Files for Possible Exfiltration
Identifies use of the Linux split command to break files into parts, potentially for staging or exfiltration.
Igor Fits, oscd.community, Huntrule TeamLinuxauditdLow315Free2020-10-15Linux auditd: Shutdown, reboot, halt, poweroff or init-triggered system reboot
Identifies Linux shutdown/reboot command execution patterns using auditd execve telemetry.
Igor Fits, oscd.community, Huntrule TeamLinuxauditdInformational93Free2020-10-15