Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
766 rules
Windows PowerShell Process Creation with Unusually Long Command Lines (1000+ chars)
Flags PowerShell executions on Windows when the CommandLine is 1000+ characters long.
oscd.community, Natalia Shornikova, Huntrule TeamWindowsprocess_creationLow100Free2020-10-06PowerShell Access to LSASS on Windows Suggesting Credential Dumping
Alerts when PowerShell (powershell.exe/pwsh.exe) accesses lsass.exe, indicating potential credential dumping.
oscd.community, Natalia Shornikova, Huntrule TeamWindowsprocess_accessMedium90Free2020-10-06PowerShell Remote Thread Creation (Windows CreateRemoteThread)
Alerts when PowerShell creates a remote thread in another process, excluding CompatTelRunner.exe activity.
Nikita Nazarov, oscd.community, Huntrule TeamWindowscreate_remote_threadMedium60Free2020-10-06Non-privileged reg.exe or PowerShell registry service configuration changes on Windows
Flags non-admin reg.exe or PowerShell activity targeting service registry configuration paths on Windows.
Teymur Kheirkhabarov (idea), Ryan Plas (rule), oscd.community, Huntrule TeamWindowsprocess_creationHigh439Free2020-10-05Windows: SyncAppvPublishingServer.exe execution via PowerShell script block content
Flags PowerShell script blocks that reference SyncAppvPublishingServer.exe, indicating possible execution via a PowerShell-restricted workflow.
Ensar Şamil, @sblmsrsn, OSCD Community, Huntrule TeamWindowsps_scriptMedium141Free2020-10-05Windows SyncAppvPublishingServer Execution Triggering PowerShell Module Context
Alerts when SyncAppvPublishingServer.exe appears in PowerShell module ContextInfo on Windows.
Ensar Şamil, @sblmsrsn, OSCD Community, Huntrule TeamWindowsps_moduleMedium465Free2020-10-05Windows Security: Suspicious Remote Logon Using Explicit Credentials via Command-Line Tools
Flags EventID 4648 remote logons initiated by cmd/PowerShell/winrs/wmic/net/reg-style processes using explicit credentials.
oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Tim Shelton, Huntrule TeamWindowssecurityMedium81Free2020-10-05Windows Process Proxying: explorer.exe Spawned from cmd.exe or PowerShell
Flags cmd.exe/powershell.exe launching explorer.exe, indicating possible proxy-based execution on Windows.
Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Huntrule TeamWindowsprocess_creationLow110Free2020-10-05Windows PowerShell Command Lines Containing [char]0x or (WCHAR)0x Obfuscation Syntax
Identifies PowerShell execution command lines using suspicious [char]0x or (WCHAR)0x encoding patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2020-07-09Windows Process Execution: Copy From System Directories to Other Locations
Detects cmd.exe, PowerShell, and copy utilities copying files from System32/SysWOW64/WinSxS to other locations on disk.
Florian Roth (Nextron Systems), Markus Neis, Tim Shelton (HAWK.IO), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2020-07-03PowerShell Classic bXOR Operator Usage in Command Line
Identifies PowerShell classic executions from ConsoleHost using the -bxor operator in the command line.
Teymur Kheirkhabarov, Harish Segar, Huntrule TeamWindowsps_classic_startLow70Free2020-06-29Suspicious WSMAN COM Provider Usage Without PowerShell Host (Windows)
Alerts on WSMAN COM provider activity where the host application is not PowerShell.exe in PowerShell Classic logs.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowspowershell-classicMedium143Free2020-06-24Windows Process Creation: Detect Covenant PowerShell Launcher Command Lines
Identifies Windows PowerShell command lines commonly used by Covenant launchers, including hidden/encoded execution patterns.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh41Free2020-06-04Windows: CrackMapExec PowerShell obfuscation via join/split static patterns
Flags Windows PowerShell executions with command-line obfuscation strings associated with CrackMapExec behavior.
Thomas Patzke, Huntrule TeamWindowsprocess_creationHigh81Free2020-05-22Windows: Process executions matching Greenbug espionage tool indicators
Alerts on Windows process creation with command-line patterns matching PowerShell execution-policy bypass and reverse-shell related tooling.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical3410Free2020-05-20