Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
PowerShell command line containing powercat invocation on Windows
Alerts when classic PowerShell starts with Powercat-related command-line strings ('powercat ' or 'powercat.ps1').
frack113, Huntrule TeamWindowsps_classic_startMedium3310Free2021-07-21Windows Private Key File Recon via cmd.exe, PowerShell, or findstr.exe
Flags Windows command-line searches for key/certificate file extensions using cmd.exe, PowerShell, or findstr.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium193Free2021-07-20PowerShell Compress-Archive Creates Archive in Temp or System Temp Paths
Flags PowerShell Compress-Archive usage writing archives to %TEMP%, AppData Local Temp, or Windows Temp.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium191Free2021-07-20PowerShell: Compress-Archive to TEMP/AppData/Windows Temp for Staging
Flags PowerShell scripts compressing data with Compress-Archive into $env:TEMP or Temp folders.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_scriptMedium203Free2021-07-20Windows PowerShell module usage: Compress-Archive to store archives in Temp locations
Alerts on PowerShell Compress-Archive output written to common temp staging directories.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_moduleMedium111Free2021-07-20PowerShell Classic Compress-Archive staging in TEMP or Temp directories
Alerts on PowerShell Compress-Archive output targeting common Temp directories for data staging.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowspowershell-classicMedium5410Free2021-07-20Windows Process Execution of SyncAppvPublishingServer.vbs with Inline PowerShell Commands
Flags Windows executions of SyncAppvPublishingServer.vbs with a semicolon-augmented command line consistent with embedded PowerShell.
frack113, Huntrule TeamWindowsprocess_creationMedium171Free2021-07-16PowerShell executes ADRecon.ps1 AD reconnaissance functions and writes ADRecon-Report.xlsx
Detects PowerShell ADRecon reconnaissance script content by matching AD discovery functions and the default ADRecon report output name.
Bhabesh Raj, Huntrule TeamWindowsps_scriptHigh325Free2021-07-16Suspicious PowerShell Execution From Windows Temporary Folders on Windows
Alerts when PowerShell runs with command-line paths pointing to Windows temp directories, excluding some common benign installers.
Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationMedium327Free2021-07-14Windows PowerShell: AtomicTestHarness Invoke-ATHRemoteFXvGPUDisablementCommand Abuse
Alerts on Windows process command lines invoking AtomicTestHarnesses RemoteFXvGPUDisablement PowerShell execution.
frack113, Huntrule TeamWindowsprocess_creationHigh173Free2021-07-13Windows PowerShell Module Creation With RemoteFXvGPUDisablement ModuleContents
Flags PowerShell module creation where ModuleContents includes Get-VMRemoteFXPhysicalVideoAdapter.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_moduleHigh527Free2021-07-13Windows PowerShell ModuleContents Set to Get-VMRemoteFXPhysicalVideoAdapter
Alerts on PowerShell module creation embedding Get-VMRemoteFXPhysicalVideoAdapter, a potential precursor to RemoteFXvGPUDisablement.exe abuse.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspowershell-classicHigh452Free2021-07-13Windows Process: SyncAppvPublishingServer.exe Executes PowerShell via PowerShell-encoded command
Alerts when SyncAppvPublishingServer.exe is launched with a command-line pattern indicative of PowerShell code execution.
frack113, Huntrule TeamWindowsprocess_creationMedium226Free2021-07-12Windows Registry Service Install Indicators for Cobalt Strike Staging
Identifies suspicious Windows service installation registry writes tied to ADMIN$/.exe and %COMSPEC% start powershell patterns.
Wojciech Lesicki, Huntrule TeamWindowsregistry_setHigh233Free2021-06-29PowerShell Tamper: Set-MpPreference disables Windows Defender scanning and protections
Flags PowerShell attempts to alter Windows Defender preferences using Set-MpPreference with Allow-style disable/default-action parameters.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_classic_provider_startHigh403Free2021-06-07