Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
PowerShell ScriptBlock launching redirected comspec to Alternate Data Stream via '>'
Flags PowerShell script blocks using Start-Process with comspec and " > " redirection consistent with ADS-style file hiding.
frack113, Huntrule TeamWindowsps_scriptMedium93Free2021-09-02PowerShell discovery of Win32_PnPEntity via ScriptBlockText
Alerts when PowerShell script blocks reference Win32_PnPEntity to enumerate attached Plug and Play devices.
frack113, Huntrule TeamWindowsps_scriptLow373Free2021-08-23PowerShell Write-Hijack HackTool Creates .bat for DLL Hijack Execution (Windows)
Flags PowerShell creating .bat files consistent with PowerUp Write-Hijack DLL abuse on Windows.
Subhash Popuri (@pbssubhash), Huntrule TeamWindowsfile_eventHigh101Free2021-08-21PowerShell WMI Event Subscription Persistence via New-CimInstance
Finds PowerShell creating WMI __EventFilter and CommandLineEventConsumer objects for event-triggered persistence.
frack113, Huntrule TeamWindowsps_scriptMedium383Free2021-08-19Windows PowerShell: Add-Content to $profile for Potential Persistence
Detects PowerShell Add-Content writing to $profile, especially when paired with common command-loading or execution payloads.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium143Free2021-08-18PowerShell ShellIntel Commandlet Abuse via ScriptBlock Logging
Flags PowerShell script blocks that reference known ShellIntel commandlets tied to exploitation activity.
Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems), Huntrule TeamWindowsps_scriptHigh121Free2021-08-09Successful ProxyShell-like Exchange exploitation via autodiscover.json and PowerShell/MAPI paths
Flags Exchange-targeted web requests with /autodiscover.json plus exploit URI fragments returning 200/301.
Florian Roth (Nextron Systems), Rich Warren, Huntrule Team—webserverCritical123Free2021-08-09Detects ProxyShell-Style Exchange Probing via /autodiscover.json and PowerShell URIs (HTTP 401)
Flags Exchange web requests with ProxyShell-like /autodiscover.json query patterns and PowerShell/EWS-related parameters, often returning HTTP 401.
Florian Roth (Nextron Systems), Rich Warren, Huntrule Team—webserverHigh248Free2021-08-07PowerShell timestomping via file timestamp property and setter usage (Windows)
Identifies PowerShell timestomping attempts by matching script text that sets file creation, access, and write timestamps.
frack113, Huntrule TeamWindowsps_scriptMedium192Free2021-08-03PowerShell Virtualization Environment Discovery via WMI in ScriptBlockLogging (Windows)
Identifies PowerShell WMI queries for Win32 computer system and ACPI thermal data used to check virtualization environments.
frack113, Duc.Le-GTSC, Huntrule TeamWindowsps_scriptMedium354Free2021-08-03Windows PowerShell Recon via Export-Oriented Commands in Script Block Logging
Detects PowerShell script blocks performing recon queries (services/processes) and writing output to TEMP.
frack113, Huntrule TeamWindowsps_scriptMedium356Free2021-07-30PowerShell Keylogging via Get-Keystrokes and Win32 API Calls (GetAsyncKeyState, GetForegroundWindow)
Flags PowerShell script blocks containing Get-Keystrokes with GetAsyncKeyState/GetForegroundWindow for potential keylogging.
frack113, Huntrule TeamWindowsps_scriptMedium445Free2021-07-30PowerShell SAM Hive Copy via Volume Shadow Copy Paths on Windows
Flags PowerShell commands that copy the SAM hive from Volume Shadow Copy locations using .NET or PowerShell copy semantics.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh339Free2021-07-29PowerShell Script Block Collection of Documents via Recursive Get-ChildItem
Alerts on PowerShell file enumeration that recursively searches and includes common document extensions via Get-ChildItem.
frack113, Huntrule TeamWindowsps_scriptMedium343Free2021-07-28Windows PowerShell Script Block Local Email Collection via Outlook COM Automation
Flags PowerShell script block text referencing Outlook COM automation used to collect locally stored email.
frack113, Huntrule TeamWindowsps_scriptMedium439Free2021-07-21