Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,147 rules
PowerShell Obfuscation Delivered via Stdin Using Set-and-Invoke Pattern
Detects obfuscated PowerShell script blocks that use chained stdin/environment/input patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh4510Free2020-10-12PowerShell Module: Obfuscated Script Execution via Stdin Pattern
Detects obfuscated PowerShell module payloads using chained set and stdin/input invoke patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh366Free2020-10-12Windows WMIPRVSE DLL Hijack via Network-Created wbemcomn.dll in System32\wbem
Flags wmiprvse.exe loading wbemcomn.dll from the System32\wbem directory, consistent with a WMI DLL hijack.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadHigh125Free2020-10-12Windows DCOM InternetExplorer.Application DLL Hijack via iertutil.dll Image Load
Alerts when iexplore.exe loads iertutil.dll from an Internet Explorer path, indicating possible DLL hijacking.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga, Huntrule TeamWindowsimage_loadCritical183Free2020-10-12Windows WMI DLL Hijack via Network-placed wbemcomn.dll in System32\wbem
Alerts when System creates wbemcomn.dll in C:\Windows\System32\wbem\, consistent with WMI DLL hijack file staging.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventCritical359Free2020-10-12Windows DCOM InternetExplorer.Application iertutil.dll DLL Hijack Suspicion
Alerts when System writes iertutil.dll in the DCOM InternetExplorer.Application path, consistent with potential DLL hijacking.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga, Huntrule TeamWindowsfile_eventCritical183Free2020-10-12Windows System: Service Control Manager runs command with obfuscated PowerShell keywords via set and stdin
Alerts on service creation where ImagePath includes obfuscation-like command chaining with environment/invoke/input strings.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh70Free2020-10-12Windows Security Log: Network Write of wbemcomn.dll in System32\wbem for WMI DLL Hijack (T1047)
Flags remote creation of wbemcomn.dll in System32\wbem associated with WMI DLL hijack activity.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssecurityHigh4110Free2020-10-12Windows Security Event 4697: Obfuscated PowerShell Invocation Through Stdin
Alerts on Service creation events where the service command line includes stdin-style PowerShell obfuscation indicators.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh101Free2020-10-12Windows Security: Remote DCOM IE DLL Hijack via iertutil.dll in Internet Explorer path
Flags network file writes of iertutil.dll under IE’s Program Files path associated with potential DCOM DLL hijacking.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssecurityHigh155Free2020-10-12Windows Registry Screensaver Path Value Modified (SCRNSAVE.EXE)
Alerts on registry changes to the SCRNSAVE.EXE screensaver binary path under HKCU.
Bartlomiej Czyz @bczyz1, oscd.community, Huntrule TeamWindowsregistry_eventMedium131Free2020-10-11Windows PowerShell Command Line Encoded-Content Indicators via Type Conversion and String Building
Detects PowerShell command lines containing type-conversion and join/split character assembly indicators consistent with encoded content handling.
Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton, Huntrule TeamWindowsprocess_creationLow453Free2020-10-11Windows Process Creation: Detect Reversed PowerShell Command Tokens in CommandLine
Alerts on suspicious reversed token usage in PowerShell command lines on Windows, excluding -EncodedCommand / -enc.
Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton, Huntrule TeamWindowsprocess_creationHigh257Free2020-10-11PowerShell ConvertTo-SecureString Cmdlet Execution from Command Line (Windows)
Alerts when PowerShell is launched with a command line containing ConvertTo-SecureString, a credential-related cmdlet uncommon in normal execution.
Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton, Huntrule TeamWindowsprocess_creationMedium70Free2020-10-11Windows msbuild.exe Network Connections to Ports 80/443
Alerts on initiated outbound 80/443 connections from msbuild.exe on Windows.
Kiran kumar s, oscd.community, Huntrule TeamWindowsnetwork_connectionHigh81Free2020-10-11