Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,140 rules
Windows Security 4697: Obfuscated command uses rundll32 with shell32.dll
Alerts on EventID 4697 service command lines containing rundll32 with shell32.dll/shellexec_rundll and obfuscation-like script fragments.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh92Free2020-10-09Windows Security EID 4697: mshta Used to Run Obfuscated VBScript PowerShell
Detects service creation where the binary path includes mshta plus VBS/automation indicators consistent with script-based obfuscation.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh103Free2020-10-09Windows Security 4697: Obfuscated PowerShell via use of Clip.exe from scripts
Alerts on EID 4697 service installations where the service file name matches Clip/clipboard indicators tied to obfuscated PowerShell.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh142Free2020-10-09Windows regini.exe Execution Leading to Registry Key Changes
Alerts on Windows executions of regini.exe that can import registry changes from text files.
Eli Salem, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationLow171Free2020-10-08Windows net.exe Unmount Share (/delete) Execution
Alerts on net.exe/net1.exe commands that include "share" and "/delete", indicating share unmount/removal on Windows.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsprocess_creationLow152Free2020-10-08Windows Process Dumping via sqldumper.exe with 0x0110 Command-Line Flags
Alerts on sqldumper.exe executions with command-line dump parameters indicative of process dumping.
Kirill Kiryanov, oscd.community, Huntrule TeamWindowsprocess_creationMedium91Free2020-10-08Windows: Code Execution via Pester.bat Using PowerShell Help or cmd.exe
Flags Windows process executions that invoke Pester-related help/commands via PowerShell or cmd, consistent with Pester.bat usage.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium80Free2020-10-08Windows Process Execution: Obfuscated PowerShell Invocation Using mshta with VBScript CreateObject
Flags Windows process command lines containing an obfuscated PowerShell+MSHTA VBScript execution pattern.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh196Free2020-10-08PowerShell share removal via Remove-SmbShare or Remove-FileShare on Windows
Flags PowerShell commands that remove SMB or file shares through Remove-SmbShare/Remove-FileShare.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsps_scriptMedium185Free2020-10-08PowerShell ScriptBlock Obfuscation via MSHTA VBScript CreateObject Execution
Alerts on PowerShell script blocks containing mshta and VBScript createobject/.run/window.close patterns consistent with obfuscated execution.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh123Free2020-10-08PowerShell Module: Obfuscated MSHTA Invocation via VBS CreateObject
Alerts when PowerShell module payload text includes an obfuscated MSHTA/VBScript invocation sequence.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh301Free2020-10-08macOS Local System Account Enumeration via dscl, dscacheutil, and user listing commands
Detects macOS commands used to enumerate local system accounts via dscl, dscacheutil, id, lsof, who, and preference/query utilities.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationLow92Free2020-10-08Linux System Information Discovery via Common Command-Line Utilities
Flags Linux executions of uname, hostname, uptime, lspci, dmidecode, lscpu, and lsmod for system discovery behavior.
Ömer Günal, oscd.community, Huntrule TeamLinuxprocess_creationInformational173Free2020-10-08Linux Local Account Enumeration via lastlog, /etc/* file reads, id, and lsof -u
Flags Linux process activity consistent with enumerating local system accounts using /etc account data and related tools.
Alejandro Ortuno, oscd.community, CheraghiMilad, Huntrule TeamLinuxprocess_creationLow495Free2020-10-08Linux System & Hardware Information Discovery via File and Version Reads
Detects Linux file access to BIOS/DMI, hardware model, kernel, and OS release/issue identifiers used for system profiling.
Ömer Günal, oscd.community, Huntrule TeamLinuxauditdInformational2410Free2020-10-08