Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
766 rules
PowerShell Get-Clipboard Cmdlet Execution via CLI on Windows
Flags Windows command lines containing Get-Clipboard, indicating potential clipboard data collection via PowerShell.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2020-05-02Windows PowerShell Get-Clipboard Command Execution
Flags PowerShell activity that includes the Get-Clipboard command, which may be used to collect clipboard contents.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsps_moduleMedium289Free2020-05-02PowerShell Decompress via Expand-Archive
Alerts on PowerShell usage of Expand-Archive, a common decompression step attackers may use to unpack files.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsps_moduleInformational93Free2020-05-02PowerShell Local User Creation via New-LocalUser
Flags PowerShell usage of New-LocalUser, indicating creation of a Windows local user.
"@ROxPinTeddy, Huntrule Team"Windowsps_scriptMedium40Free2020-04-11Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Flags HH.exe spawning CertReq/CertUtil/CMD/PowerShell/cscript/regsvr32/mshta and other common Windows execution utilities.
Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2020-04-01Windows PowerShell ScriptBlock containing WMImplant tool parameters
Alerts on PowerShell Script Block content containing WMImplant-related command and system-manipulation parameters.
NVISO, Huntrule TeamWindowsps_scriptHigh132Free2020-03-26Windows PowerShell execution with uncommon/suspicious parent process
Alerts when PowerShell is started from certain unusual parent processes that commonly indicate abuse.
Teymur Kheirkhabarov, Harish Segar, Huntrule TeamWindowsprocess_creationHigh268Free2020-03-20PowerShell Downgrade Attempts via -Version 2 on Windows Process Creation
Alerts on PowerShell executions specifying a -Version 2 argument, consistent with potential downgrade attempts.
Harish Segar (rule), Huntrule TeamWindowsprocess_creationMedium281Free2020-03-20Windows: Suspicious Execution of CSharp Interactive Console via PowerShell
Alerts when PowerShell launches csi.exe, indicating possible interactive .NET code execution.
Michael R. (@nahamike01), Huntrule TeamWindowsprocess_creationHigh142Free2020-03-08PowerShell CommandLine Uses FromBase64String to Decode Base64 Content (Windows)
Detects PowerShell process creation where the command line includes ::FromBase64String(, indicating Base64 decoding.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh83Free2020-01-29Windows Image Load: System.Management.Automation DLL Loaded by Non-PowerShell Process
Alerts when a non-PowerShell executable loads System.Management.Automation.dll on Windows, indicating possible PowerShell execution in another process.
Tom Kern, oscd.community, Natalia Shornikova, Tim Shelton, Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium71Free2019-11-14Windows Process Creation: Detect Obfuscated PowerShell IEX Invocation from Invoke-Obfuscation
Detects PowerShell commands showing obfuscation markers consistent with Invoke-Obfuscation-powered IEX invocation.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowsprocess_creationHigh143Free2019-11-08PowerShell: Obfuscated IEX Invocation via Invoke-Obfuscation String/Variable Patterns
Alerts on obfuscated PowerShell IEX invocation strings built from Invoke-Obfuscation style concatenation patterns in ScriptBlockText.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowsps_scriptHigh124Free2019-11-08PowerShell Module Obfuscated IEX Invocation via Invoke-Obfuscation Payload Patterns
Alerts when PowerShell module payloads contain patterns consistent with obfuscated IEX generation via Invoke-Obfuscation.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowsps_moduleHigh71Free2019-11-08Windows System Service Creation of Obfuscated PowerShell IEX (Invoke-Obfuscation)
Flags Windows service creations whose ImagePath contains obfuscated PowerShell IEX invocation strings.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowssystemHigh3010Free2019-11-08