Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
766 rules
Windows Security: Detect Obfuscated PowerShell IEX Invocation via ServiceFileName Patterns (Event ID 4697)
Alerts on EventID 4697 instances where ServiceFileName matches obfuscated IEX-style PowerShell invocation patterns consistent with Invoke-Obfuscation.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowssecurityHigh141Free2019-11-08Windows PowerShell: Silence EmpireDNSAgent script matches DNS tunnel and remote shutdown/restart activity
Flags PowerShell ScriptBlockText that combines Empire process-control indicators with dnscat DNS tunneling commands.
Alina Stepchenkova, Group-IB, oscd.community, Huntrule TeamWindowsps_scriptCritical71Free2019-11-01Windows PowerShell Script Execution from Alternate Data Stream (ADS)
Flags PowerShell processes using Get-Content -Stream to execute or retrieve script content from an ADS.
Sergey Soldatov, Kaspersky Lab, oscd.community, Huntrule TeamWindowsprocess_creationHigh41Free2019-10-30Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice
Flags PowerShell command lines referencing audio device cmdlets used to get/toggle/set/write audio device settings.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium72Free2019-10-24Windows PowerShell ScriptBlock Web Request Cmdlets and Command-Line Tools
Alerts when PowerShell script blocks reference web request and download cmdlets/commands, excluding a specific guest configuration path.
James Pemberton / @4A616D6573, Huntrule TeamWindowsps_scriptMedium132Free2019-10-24Windows PowerShell Profile File Creation or Modification
Alerts on creation or modification of PowerShell profile.ps1 files in typical Windows and PowerShell 7 locations.
HieuTT35, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium153Free2019-10-24Windows Shadow Copy Deletion via PowerShell, WMIC, vssadmin, diskshadow, or wbadmin
Flags Windows commands that use shadow-copy management utilities with deletion or shadowstorage removal parameters.
Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh91Free2019-10-22Windows Shadow Copy Creation via PowerShell/pwsh/wmic/vssadmin Commands
Detects Windows processes using PowerShell/pwsh/wmic/vssadmin with shadow copy creation parameters.
Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationMedium325Free2019-10-22PowerShell ScriptBlock Winlogon Registry Modification via CurrentVersion\Winlogon
Detects PowerShell script blocks that modify Winlogon helper registry keys via Set-ItemProperty or New-Item on Windows.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptMedium102Free2019-10-21PowerShell Compress-Archive Cmdlet Execution for Data Compression
Flags PowerShell scripts using the Compress-Archive cmdlet, consistent with local data packaging before collection or exfiltration.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptLow50Free2019-10-21PowerShell ScriptBlock uses rundll32 with shell32.dll and obfuscated invoke/comspec/iex
Flags PowerShell script blocks containing rundll32/shell32.dll execution strings alongside invoke/iex/comspec patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh60Free2019-10-08PowerShell module: Obfuscated Invoke via rundll32/shell32.dll comspec iex patterns
Flags PowerShell module payloads containing obfuscated rundll32 shell32.dll shellexec_rundll invocation patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh297Free2019-10-08Windows Process Activity Clearing or Modifying Event Logs via Wevtutil, PowerShell, or WMI
Flags suspicious Windows process command lines that clear or reconfigure Event Logs using wevtutil, PowerShell, or WMI, with an msiexec exception.
Ecco, Daniil Yugoslavskiy, oscd.community, D3F7A5105, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2019-09-26Windows remote PowerShell session activity via wsmprovhost.exe process relationships
Alerts when wsmprovhost.exe is seen as a process or parent process, indicating remote PowerShell via WinRM.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsprocess_creationMedium60Free2019-09-12Windows: Non-interactive PowerShell (powershell.exe/pwsh.exe) spawned from GUI or updater parents
Alerts on non-interactive PowerShell spawned by atypical parent processes, excluding known update, VS Code, terminal, and defender-related parents.
Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements), Huntrule TeamWindowsprocess_creationLow91Free2019-09-12