Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
141 rules
Suspicious autorun registry modification via WMI wmic spawning reg.exe on Windows
Flags WMIC-driven reg.exe commands that add Run key autorun entries, especially when pointing to suspicious temp/user locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2025-02-17Windows Registry RunMRU PowerShell or WMIC Execution Command Indicators
Alerts on RunMRU registry entries showing PowerShell (encoding/invocation) or WMIC shadowcopy/process call usage.
Ahmed Farouk, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setHigh191Free2024-11-01Windows Firewall Allow Rule Added via WmiPrvSE.exe
Flags Windows firewall allow-rule additions where WmiPrvSE.exe is the modifying application.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfirewall-asMedium442Free2024-05-10Windows WMI Disk and Volume Discovery via WMIC.exe
Flags WMIC.exe process executions that query Win32 logical disk and volume listing details.
Stephen Lincoln '@slincoln-aiq' (AttackIQ), Huntrule TeamWindowsprocess_creationMedium454Free2024-02-02Windows SharpMove (.NET) Execution via SharpMove.exe and Action Command-Line Flags
Alerts on SharpMove.exe process execution with command-line actions for DCOM, WMI VBS, and task scheduler.
Luca Di Bartolomeo (CrimpSec), Huntrule TeamWindowsprocess_creationHigh81Free2024-01-29Windows WMIC System Information Discovery via WMI Command-Line Queries
Flags WMIC command-line queries that pull OS, hardware, disk, memory, BIOS, and GPU details while excluding VMware Tools discovery scripts.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationLow120Free2023-12-19Windows Process Creation: Detect Event Log Query via wmic.exe, wevtutil.exe, or PowerShell
Detects command-line attempts to query Windows Event Logs using wevtutil, wmic, or Get-WinEvent/Get-EventLog.
Ali Alwashali, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2023-11-20Windows Process Creation: wmic.exe call terminate Attempt
Alerts on wmic.exe being executed with “call terminate”, indicating an attempt to terminate a process on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium122Free2023-09-11Windows Registry: New BgInfo UserFields value enabling custom WMI query execution
Alerts on new BgInfo UserFields registry entries that appear to configure a custom WMI query.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium152Free2023-08-16Windows PowerShell WMI Win32_NTEventlogFile Calls with Event Log Tampering Methods
Flags PowerShell calling Win32_NTEventlogFile WMI methods commonly used to clear, delete, backup, or alter Windows event logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2023-07-13Suspicious PowerShell WMI Win32_NTEventlogFile Usage (Event Log Tampering)
Detects PowerShell scripts calling Win32_NTEventlogFile methods associated with event log deletion, backup, renaming, or permission changes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium163Free2023-07-13Windows Process Creation: mshta/VBScript Launching PowerShell and Embedded Backdoor Logic
Alerts on Windows command lines combining mshta VBScript execution bypass, system survey WMI queries, and PowerShell HTTP/Base64 patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2023-03-10Windows PowerShell Execution with Encoded Hidden Execution Flags (Wmiexec)
Flags PowerShell process launches containing the Wmiexec default hidden/no-profile/execution-bypass flag sequence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh197Free2023-03-08Windows WMIC Remote Query Execution via /node
Identifies remote WMIC queries on Windows by matching WMIC execution with /node: in the command line.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2023-02-14Windows WMIC.exe Service Reconnaissance via Remote Service Queries
Flags WMIC.exe commands containing service-related reconnaissance strings while excluding stop/start service manipulation.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium355Free2023-02-14