Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,151 rules
Windows Process Execution Proxy Using SyncInvoke in CL_Invocation.ps1
Alerts on Windows command lines containing "SyncInvoke" consistent with CL_Invocation.ps1 execution proxy behavior.
Nasreddine Bencherchali (Nextron Systems), oscd.community, Natalia Shornikova, Huntrule TeamWindowsprocess_creationMedium271Free2020-10-14Windows Script and LOLBins Loading .NET CLR DLLs via clr.dll, mscoree.dll, mscorlib.dll
Alerts when common scripting/execution binaries load .NET CLR DLLs like clr.dll and mscoree.dll on Windows.
omkar72, oscd.community, Huntrule TeamWindowsimage_loadHigh4310Free2020-10-14macOS Network Sniffing Tool Execution via tcpdump or tshark
Identifies macOS execution of tcpdump or tshark, indicating potential network traffic sniffing activity.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationInformational123Free2020-10-14macOS Startup Item Plist Created in StartupItems Folders
Alerts on creation of startup item .plist files in macOS StartupItems directories, potential boot persistence setup.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosfile_eventLow306Free2020-10-14Windows Registry-Based DLL Hijack via WAB.EXE Using WAB Registry DLLPath
Flags WAB.EXE DLLPath registry writes where the configured DLL path differs from the default.
oscd.community, Natalia Shornikova, Huntrule TeamWindowsregistry_setHigh82Free2020-10-13Windows Process Creation: accesschk.exe Permission Audit Execution
Flags AccessChk (accesschk.exe) permission/audit executions using common query flags in Windows process creation logs.
Teymur Kheirkhabarov (idea), Mangatas Tondang, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium2110Free2020-10-13Windows te.exe Execution of Test Components (TAEF) via Process Creation
Alerts on process activity involving te.exe, which may indicate TAEF-based execution of malicious test components.
Agro (@agro_sev) oscd.community, Huntrule TeamWindowsprocess_creationLow71Free2020-10-13Windows msiexec.exe Installer Process Spawning cmd.exe or PowerShell
Flags installer-initiated spawning of cmd.exe or PowerShell from Windows\Installer temporary msi-related processes.
Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community, Huntrule TeamWindowsprocess_creationMedium279Free2020-10-13Detect Elevated Windows Installer (msiexec) Running as SYSTEM
Flags msiexec.exe MSI activity from Windows Installer running with SYSTEM integrity, excluding known benign parent contexts.
Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community, Huntrule TeamWindowsprocess_creationMedium125Free2020-10-13Windows PowerShell via sqltoolsps.exe (sqltoolsps.exe child process exclusion)
Flags suspicious sqltoolsps.exe executions that may launch PowerShell, excluding cases where smss.exe spawned the utility.
Agro (@agro_sev) oscd.communitly, Huntrule TeamWindowsprocess_creationMedium312Free2020-10-13Windows manage-bde.wsf via wscript/cscript Proxy Execution
Flags Windows process executions where wscript/cscript runs manage-bde.wsf, indicating potential proxy execution via LOLBIN.
oscd.community, Natalia Shornikova, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2020-10-13Windows Process Command Line: Detect VAR++ LAUNCHER Obfuscated PowerShell
Flags Windows command lines showing VAR++ launcher-style obfuscated PowerShell execution through Invoke-Expression patterns.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationHigh3610Free2020-10-13Windows Process Creation: Obfuscated Cmd Uses clip.exe to Execute PowerShell
Alerts when cmd.exe uses obfuscated Clip.exe/clipboard calls to launch PowerShell.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsprocess_creationHigh215Free2020-10-13Detect VAR++ LAUNCHER-Style Obfuscated PowerShell Command Block
Detects VAR++ LAUNCHER-like PowerShell obfuscation patterns in ScriptBlockText.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptHigh3910Free2020-10-13PowerShell Script Block Obfuscation via cmd/clipboard and clip.exe execution
Identifies obfuscated PowerShell script blocks launching clip.exe and chaining clipboard-related execution.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_scriptHigh133Free2020-10-13