Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
PowerShell Module: Obfuscated STDIN Execution via cmd /c or cmd /r
Alerts when an obfuscated cmd->PowerShell payload uses stdin-style input and noexit/no-execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_moduleHigh171Free2020-10-15Windows Service Control Manager: Obfuscated Environment Variable PowerShell via cmd /c set -f
Alerts on Service Control Manager event 7045 where a service ImagePath uses cmd /c|/r with "set" and -f formatting.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh172Free2020-10-15Windows System Service Control Manager spawning cmd with PowerShell and stdin input obfuscation
Flags SCM-created services whose ImagePath runs cmd to invoke PowerShell using stdin/input and -NoExit patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh90Free2020-10-15Windows Security 4697: cmd.exe Launching Obfuscated PowerShell via Environment Variable Expansion
Alerts on EID 4697 service installation command lines containing obfuscated cmd.exe SET patterns used to execute PowerShell via environment variables.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh133Free2020-10-15Windows Security Event 4697 PowerShell Launch via cmd/stdin Obfuscation
Alerts on service creation events that run PowerShell through cmd with stdin-style obfuscation markers.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh90Free2020-10-15Windows msiexec.exe Installer Process Spawning cmd.exe or PowerShell
Flags installer-initiated spawning of cmd.exe or PowerShell from Windows\Installer temporary msi-related processes.
Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community, Huntrule TeamWindowsprocess_creationMedium309Free2020-10-13Windows PowerShell via sqltoolsps.exe (sqltoolsps.exe child process exclusion)
Flags suspicious sqltoolsps.exe executions that may launch PowerShell, excluding cases where smss.exe spawned the utility.
Agro (@agro_sev) oscd.communitly, Huntrule TeamWindowsprocess_creationMedium342Free2020-10-13Windows Process Command Line: Detect VAR++ LAUNCHER Obfuscated PowerShell
Flags Windows command lines showing VAR++ launcher-style obfuscated PowerShell execution through Invoke-Expression patterns.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationHigh3910Free2020-10-13Windows Process Creation: Obfuscated Cmd Uses clip.exe to Execute PowerShell
Alerts when cmd.exe uses obfuscated Clip.exe/clipboard calls to launch PowerShell.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsprocess_creationHigh245Free2020-10-13Detect VAR++ LAUNCHER-Style Obfuscated PowerShell Command Block
Detects VAR++ LAUNCHER-like PowerShell obfuscation patterns in ScriptBlockText.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptHigh4210Free2020-10-13PowerShell Script Block Obfuscation via cmd/clipboard and clip.exe execution
Identifies obfuscated PowerShell script blocks launching clip.exe and chaining clipboard-related execution.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_scriptHigh163Free2020-10-13PowerShell Module: VAR++ LAUNCHER Obfuscation in Obfuscated Command Payload
Identifies obfuscated PowerShell module payloads matching a VAR++ LAUNCHER-style invocation pattern.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_moduleHigh92Free2020-10-13PowerShell Module: Obfuscated Clip.exe launcher using cmd with clipboard download payload
Detects obfuscated PowerShell module commands that run cmd with clip.exe/clipboard payload formatting.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_moduleHigh218Free2020-10-13Windows System: Detects Service Control Manager spawning obfuscated PowerShell via VAR++ LAUNCHER
Flags newly created Windows services whose ImagePath contains cmd chaining and obfuscated PowerShell launcher indicators.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssystemHigh414Free2020-10-13Windows System Service Control: Obfuscated cmd Launching clip.exe for PowerShell
Flags service creation (Event 7045) with obfuscated cmd ImagePath using clip.exe/clipboard PowerShell execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh60Free2020-10-13