Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
766 rules
PowerShell module obfuscation using clip.exe with echo and clipboard invocation
Flags obfuscated PowerShell module scripts that echo “clip” and invoke clipboard-related behavior.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh161Free2020-10-09Windows PowerShell: Detect Suspicious Opsec Artifacts in Script Module Content
Identifies PowerShell module content containing frequent offensive payload string markers associated with poor operational security.
ok @securonix invrep_de, oscd.community, Huntrule TeamWindowsps_moduleCritical445Free2020-10-09Windows Service Control Manager Rundll32 Obfuscation via Command-Line Encoded PowerShell
Detects service creation where ImagePath invokes rundll32 (shell32) with command-chain tokens indicative of obfuscated PowerShell.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh100Free2020-10-09Windows Security EID 4697: mshta Used to Run Obfuscated VBScript PowerShell
Detects service creation where the binary path includes mshta plus VBS/automation indicators consistent with script-based obfuscation.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh143Free2020-10-09Windows Security 4697: Obfuscated PowerShell via use of Clip.exe from scripts
Alerts on EID 4697 service installations where the service file name matches Clip/clipboard indicators tied to obfuscated PowerShell.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh182Free2020-10-09Windows: Code Execution via Pester.bat Using PowerShell Help or cmd.exe
Flags Windows process executions that invoke Pester-related help/commands via PowerShell or cmd, consistent with Pester.bat usage.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium100Free2020-10-08Windows Process Execution: Obfuscated PowerShell Invocation Using mshta with VBScript CreateObject
Flags Windows process command lines containing an obfuscated PowerShell+MSHTA VBScript execution pattern.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh226Free2020-10-08PowerShell share removal via Remove-SmbShare or Remove-FileShare on Windows
Flags PowerShell commands that remove SMB or file shares through Remove-SmbShare/Remove-FileShare.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsps_scriptMedium215Free2020-10-08PowerShell ScriptBlock Obfuscation via MSHTA VBScript CreateObject Execution
Alerts on PowerShell script blocks containing mshta and VBScript createobject/.run/window.close patterns consistent with obfuscated execution.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh153Free2020-10-08PowerShell Module: Obfuscated MSHTA Invocation via VBS CreateObject
Alerts when PowerShell module payload text includes an obfuscated MSHTA/VBScript invocation sequence.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh351Free2020-10-08PowerShell Service Persistence via Registry ImagePath on Windows
Flags Windows registry service ImagePath entries that reference PowerShell (powershell/pwsh).
oscd.community, Natalia Shornikova, Huntrule TeamWindowsregistry_setHigh202Free2020-10-06PowerShell Script Block WinAPI Calls Indicative of Injection or Token Abuse (Windows)
Detects PowerShell ScriptBlocks containing WinAPI function-name combinations consistent with injection and token manipulation.
Nasreddine Bencherchali (Nextron Systems), Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh173Free2020-10-06Windows PowerShell Remote Thread Into lsass.exe Suggesting Credential Dumping
Alerts when PowerShell creates a remote thread into lsass.exe, indicating possible credential dumping on Windows.
oscd.community, Natalia Shornikova, Huntrule TeamWindowscreate_remote_threadHigh215Free2020-10-06PowerShell Script Execution via Windows Service Creation (Service Control Manager)
Flags service creation/start events where the service ImagePath references PowerShell (powershell/pwsh).
oscd.community, Natalia Shornikova, Huntrule TeamWindowssystemHigh463Free2020-10-06Windows Service Creation of PowerShell/Pwsh Scripts (Security EID 4697)
Alerts on service creation events where the service executable name includes powershell or pwsh.
oscd.community, Natalia Shornikova, Huntrule TeamWindowssecurityHigh182Free2020-10-06