Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
766 rules
Windows Named Pipe Created for PowerShell PSHost Instance
Alerts on named pipe creation with a \PSHost prefix, indicating PowerShell host-related activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowspipe_createdInformational40Free2019-09-12Windows Named Pipe Creation: Alternate PowerShell Host via \PSHost
Alerts on creation of \PSHost named pipes to identify alternate PowerShell host usage via Windows pipe events.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowspipe_createdMedium62Free2019-09-12Windows: WinRM inbound network connections to ports 5985/5986 for PowerShell remoting
Alerts on WinRM inbound connections (ports 5985/5986) consistent with remote PowerShell remoting activity.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh383Free2019-09-12Windows Process Creation: Empire PowerShell UAC Bypass CommandLine Pattern
Flags Windows process creation events running Empire-style PowerShell UAC bypass command fragments.
Ecco, Huntrule TeamWindowsprocess_creationCritical61Free2019-08-30PowerShell FromBase64String CommandLine Base64 Encoded Usage (Windows)
Flags PowerShell command lines containing FromBase64String along with base64-encoded UTF-16 marker patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh72Free2019-08-24Windows PowerShell Base64 Command Line Executing IEX
Identifies Windows PowerShell processes with Base64-encoded command-line content that contains an IEX execution pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2310Free2019-08-23Uncommon PowerShell HostApplication Values in Windows PowerShell Start Logs
Detects PowerShell classic start events with unusual HostApplication values that may indicate evasion of powershell.exe-focused detections.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsps_classic_startMedium30Free2019-08-11Windows Remote PowerShell Session via PS Module ContextInfo and wsmprovhost.exe
Flags Windows PowerShell remote session module context involving wsmprovhost.exe while filtering out archive module references.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowsps_moduleHigh103Free2019-08-10Windows Remote PowerShell via PS Classic (wsmprovhost.exe, HostName=ServerRemoteHost)
Flags Windows telemetry indicating a remote PowerShell session startup using wsmprovhost.exe with a specified host parameter.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsps_classic_startLow62Free2019-08-10Windows: MMC spawning command-line executables
Flags cases where mmc.exe starts command-line tools like cmd, PowerShell, script hosts, or BITSADMIN.
Karneades, Swisscom CSIRT, Huntrule TeamWindowsprocess_creationHigh101Free2019-08-05Windows PowerShell Script Block Logging: Nishang Commandlet Names and Arguments
High-severity alert on PowerShell script blocks that reference known Nishang commandlets and exfil/execution helper names.
Alec Costello, Huntrule TeamWindowsps_scriptHigh248Free2019-05-16Windows PowerShell Process Creation With Empire-Style EncodedCommand Launch Parameters
Flags PowerShell command lines containing hidden/stealth and encoded Empire-style launch parameters on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh127Free2019-04-20Suspicious PowerShell/WScript Activity in WMI Event Consumer Commands
Identifies WMI event consumer commands containing PowerShell/WScript download-and-execute patterns like Net.WebClient and IEX.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule TeamWindowswmi_eventHigh113Free2019-04-15WmiPrvSE.exe Spawned PowerShell Child Process on Windows
Alerts on PowerShell spawning from WmiPrvSE.exe, a possible indicator of WMI-based remote execution.
Markus Neis @Karneades, Huntrule TeamWindowsprocess_creationMedium73Free2019-04-03Windows: PowerShell-triggered HTA retrieval and execution with registry and process disruption
Alerts on Windows process creation where PowerShell uses mshta over HTTP and includes .hta, registry query, and cmd.exe termination.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh411Free2019-02-24