Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows PowerShell: Query TCP connections with Get-NetTCPConnection
Detects PowerShell usage of Get-NetTCPConnection to enumerate TCP network connections.
frack113, Huntrule TeamWindowsps_classic_startLow402Free2021-12-10Windows PowerShell Process Creation with DInjector Cradle Flags (/am51 and /password)
Identifies Dinject PowerShell cradle usage by matching command-line flags '/am51' and '/password' in Windows process creation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical4810Free2021-12-07Windows: Suspicious PowerShell Interactive History Files Created as SYSTEM
Alerts on creation of PowerShell interactive history/profile files under SYSTEM, signaling privileged PowerShell activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh114Free2021-12-07Windows: User Added to Local Remote Desktop Users Group via Net or PowerShell
Detects Windows command-line activity that adds a user to the local Remote Desktop Users group using net localgroup or Add-LocalGroupMember.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh302Free2021-12-06Windows PowerShell Clears Console History via Clear-History
Flags PowerShell attempts to clear or delete console/PSReadline command history to hinder command forensics.
Austin Songer @austinsonger, Huntrule TeamWindowsps_scriptHigh60Free2021-11-25Windows Process Creation: cmd.exe Spawned from Edge Elevation Service (CVE-2021-41379)
Alerts when cmd.exe or PowerShell spawns under Edge elevation service with SYSTEM integrity, consistent with CVE-2021-41379 exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical183Free2021-11-22Windows ZipExec-Style Suspicious PowerShell/Command Execution with Password-Protected ZIP
Flags Windows processes running ZipFolder zip commands with password and .zip filename parameters, optionally including deletion.
frack113, Huntrule TeamWindowsprocess_creationMedium162Free2021-11-07Windows Process Creation: PowerShell ExecutionPolicy Set to Bypass/Unrestricted
Alerts on PowerShell started with -ExecutionPolicy set to Bypass/Unrestricted, indicating a potentially insecure script execution posture.
frack113, Huntrule TeamWindowsprocess_creationMedium103Free2021-11-01PowerShell Creating Startup .lnk Shortcut Persistence (Windows File Events)
Detects PowerShell writing .lnk files into the Windows Startup folder, a common persistence mechanism.
Christopher Peacock '@securepeacock', SCYTHE, Huntrule TeamWindowsfile_eventHigh1810Free2021-10-24PowerShell Hidden WindowStyle Indicator in Script Block Text (Windows)
Flags PowerShell script block text indicating WindowStyle set to Hidden, suggesting concealed execution.
frack113, Tim Shelton (fp AWS), Huntrule TeamWindowsps_scriptMedium235Free2021-10-20PowerShell: Set-ExecutionPolicy to Unrestricted or Bypass
Alerts when PowerShell sets execution policy to Unrestricted or bypass, indicating weakened script execution controls.
frack113, Huntrule TeamWindowsps_scriptMedium163Free2021-10-20Windows PowerShell: Disable Windows Firewall Profile via Set-NetFirewallProfile
Flags PowerShell commands that disable one or more Windows Firewall profiles via Set-NetFirewallProfile -Enabled $false.
Austin Songer @austinsonger, Huntrule TeamWindowsps_scriptMedium132Free2021-10-12Windows vmtoolsd.exe Child Process Spawn via Scripting/Utility Binaries
Alert on vmtoolsd.exe spawning cmd/powershell/mshta/regsvr32/rundll32/wscript child processes with VM Tools batch-script command lines.
bohops, Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh153Free2021-10-08PowerShell Live Memory Dump via Get-StorageDiagnosticInfo with -IncludeLiveDump (Windows)
Identifies PowerShell use of Get-StorageDiagnosticInfo with -IncludeLiveDump to trigger a live memory dump on Windows.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsps_scriptHigh163Free2021-09-21PowerShell Add-DnsClientNrptRule Modifies NRPT Namespaces
Flags PowerShell scripts that add DNS Name Resolution Policy Table rules for a specified namespace.
Borna Talebi, Huntrule TeamWindowsps_scriptHigh192Free2021-09-14