Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows WMI Shadow Copy Deletion via PowerShell
Identifies PowerShell commands that use WMI Win32_ShadowCopy to delete or remove Volume Shadow Copies.
frack113, Huntrule TeamWindowsps_classic_startHigh369Free2021-06-03Windows Service Control Manager Events: Suspicious Service Install Paths used by Cobalt Strike
Alerts on Windows 7045 service installs with ImagePath patterns consistent with Cobalt Strike-style PowerShell and execution.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowssystemCritical245Free2021-05-26Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowssecurityHigh133Free2021-05-26Windows Process Creation: PsExec/PAExec Flags Indicating SYSTEM Execution
Flags indicating PsExec/PAExec-style execution as LOCAL SYSTEM using cmd/powershell/pwsh in process command lines.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh4110Free2021-05-22PowerShell Script Block Logging: PowerView cmdlet names match
Alerts when PowerShell ScriptBlockText includes PowerView/PowerSploit reconnaissance cmdlet names tied to domain and access discovery.
Bhabesh Raj, Huntrule TeamWindowsps_scriptHigh2310Free2021-05-18PowerShell Defender Exclusion via Set/Add-MpPreference Command-Line Flags (Windows)
Detects PowerShell commands that add or set Microsoft Defender exclusions using Add/Set-MpPreference parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium316Free2021-04-29Windows PowerShell Get-Process or aliases targeting LSASS (lsas)
Alerts on PowerShell Get-Process/alias commands referencing LSASS in Windows process creation events.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh447Free2021-04-23Windows PowerShell: Get-Process querying lsass within a ScriptBlock
Alerts when PowerShell ScriptBlock text runs Get-Process against lsass, a common credential-access precursor.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh142Free2021-04-23PowerShell ScriptBlock Certificate Export via Export-PfxCertificate or Export-Certificate
Detects PowerShell script blocks invoking certificate export cmdlets, which may be abused to steal sensitive certificate material.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptMedium111Free2021-04-23Windows Process Creation: Exchange PowerShell Snap-in Loading via Add-PSSnapin
Flags PowerShell executions that Add-PSSnapin Exchange snap-ins, consistent with Exchange mailbox/config data collection.
FPT.EagleEye, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh326Free2021-03-03Windows PowerShell TcpClient reverse-shell connection attempt via Net.Sockets
Alerts on PowerShell processes launching with .NET TcpClient stream/write patterns consistent with reverse TCP connectivity.
FPT.EagleEye, wagga, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2021-03-03Windows PowerShell Command Lines with WMI Process Creation and rundll32 Invocation
Flags Windows command lines where PowerShell/WMI is used to spawn rundll32 from c:\windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical173Free2021-01-20Windows: Abused Debug Privilege via Command-Line Route/Add Spawned by System Parents
Flags PowerShell/cmd spawned by system processes with command lines containing both 'route' and 'ADD'.
Semanur Guneysu @semanurtg, oscd.community, Huntrule TeamWindowsprocess_creationHigh131Free2020-10-28Windows PowerShell Process Creation: COMPRESS OBFUSCATION with ASCII Encoding and DeflateStream
Flags PowerShell process creation command lines that use ASCII encoding plus compression/stream-reading patterns associated with obfuscation.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationMedium426Free2020-10-18PowerShell ScriptBlock Logging: Obfuscated RUNDLL Launcher using rundll32.exe and shell32.dll
Identifies PowerShell script content invoking rundll32.exe/shell32.dll via shellexec_rundll and referencing PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptMedium152Free2020-10-18