Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,144 rules
PowerShell Execution via sqlps.exe (Windows Process Creation)
Flags sqlps.exe process launches consistent with PowerShell execution on Windows, excluding common sqlagent.exe-driven cases.
Agro (@agro_sev) oscd.community, Huntrule TeamWindowsprocess_creationMedium383Free2020-10-10PowerShell Root Certificate Added via LocalMachine\Root Path
Flags PowerShell scripts that move and import certificates into the local machine root store (Cert:\LocalMachine\Root).
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsps_scriptMedium102Free2020-10-10Windows PowerShell ICMP Exfiltration via Ping and Socket Send
Alerts on PowerShell that instantiates System.Net.NetworkInformation.Ping and calls .Send, consistent with ICMP-based exfiltration.
Bartlomiej Czyz @bczyz1, oscd.community, Huntrule TeamWindowsps_scriptMedium161Free2020-10-10macOS Hidden User Creation via dscl (Hidden Account or UniqueID<500)
Detects dscl commands on macOS creating hidden users (UniqueID < 500 or IsHidden true).
Daniil Yugoslavskiy, oscd.community, Huntrule TeamMacosprocess_creationMedium162Free2020-10-10Windows verclsid.exe executes COM object via GUID parameters
Flags verclsid.exe process launches using /S /C COM GUID-style arguments on Windows.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium351Free2020-10-09Windows: Identify RpcPing.exe -s RPC test that requests NTLM authentication
Detects RpcPing.exe RPC test usage with parameters indicating NTLM authentication attempts.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium142Free2020-10-09Windows Renamed ftp.exe Execution via OriginalFileName PE Metadata
Flags Windows executions where PE OriginalFileName is ftp.exe but the image path is not named ftp.exe.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium207Free2020-10-09Suspicious WINWORD.exe DLL loading via /l flag and .dll path on Windows
Flags WINWORD.exe runs that include /l and a .dll indicator, suggesting potential DLL sideloading on Windows.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium133Free2020-10-09Windows: Detect Runscripthelper.exe executing PowerShell scripts with 'surfacecheck'
Detects Runscripthelper.exe executions with "surfacecheck" in the command line on Windows.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium122Free2020-10-09Windows Rasautou.exe DLL loading with -d and export execution via -p
Flags Rasautou.exe running with -d and -p to load a DLL and execute a specified export.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium383Free2020-10-09Windows Process Creation: PowerShell Obfuscation Executed via Clip.exe and Clipboard
Flags Windows command lines indicating clip.exe clipboard use followed by obfuscated PowerShell invoke behavior.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh161Free2020-10-09Windows Arbitrary File Download via GfxDownloadWrapper.exe URL Argument Execution
Flags GfxDownloadWrapper.exe executions that include http/https URLs for downloading files, excluding a known Intel gameplay API URL.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium241Free2020-10-09Windows: Detect ftp.exe Executed With -s or /s for Script-Based Command Execution
Flags Windows executions of ftp.exe using -s or /s, indicating potential scripted command abuse.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium227Free2020-10-09PowerShell Script Obfuscation Triggered by Use of clip.exe and Clipboard Invocation
Flags PowerShell Script Block Logging containing clip.exe/clipboard chaining and clipboard-driven execution markers.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh186Free2020-10-09PowerShell module obfuscation using clip.exe with echo and clipboard invocation
Flags obfuscated PowerShell module scripts that echo “clip” and invoke clipboard-related behavior.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh101Free2020-10-09