Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
766 rules
Windows: Alert on suspicious parent process spawning csc.exe
Flags csc.exe execution when spawned by script/document hosts or PowerShell using encoded content, excluding common benign parent contexts.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh484Free2019-02-11Windows PowerShell Script Block Matches Common Reflection and Injection Keywords
Alerts on PowerShell script block text containing reflection, dynamic assembly loading, and injection-related keywords.
Florian Roth (Nextron Systems), Perez Diego (@darkquassar), Tuan Le (NCSGroup), Huntrule TeamWindowsps_scriptMedium73Free2019-02-11Windows Process Creation: Suspicious PowerShell Argument Obfuscation via Truncated Substrings
Alerts on PowerShell executions where the command line contains suspicious truncated parameter substrings (e.g., windowstyle, NoProfile, encoded/exec policy, bypass).
Florian Roth (Nextron Systems), Daniel Bohannon (idea), Roberto Rodriguez (Fix), Huntrule TeamWindowsprocess_creationHigh306Free2019-01-16PowerShell Spawned by wscript.exe or cscript.exe on Windows
Flags PowerShell launched by Windows script engines (wscript/cscript), excluding specific Health Service State activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium119Free2019-01-16Windows PowerShell execution with download-related command line patterns
Alerts when PowerShell is started with command-line fragments indicative of downloading remote content.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationMedium92Free2019-01-16Windows Process Creation: PowerShell Command Lines with Hidden Base64-Encoded Keywords
Alerts on PowerShell launching with 'hidden' and embedded base64-like strings in the command line.
John Lambert (rule), Huntrule TeamWindowsprocess_creationHigh121Free2019-01-16PowerShell Executed From AppData on Windows (Command Line Indicators)
Flags PowerShell command lines that include AppData paths (Local/Roaming), indicating possible user-profile script execution.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium82Free2019-01-09Windows PowerShell Base64-encoded shellcode in ScriptBlockText
Flags PowerShell script blocks containing Base64 strings matching known shellcode markers.
David Ledbetter (shellcode), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh113Free2018-11-17Suspicious XOR-Encoded PowerShell Command Line (Windows Process Creation)
Flags PowerShell (powershell.exe/pwsh) process executions with command-line indicators consistent with XOR/obfuscated scripting.
Sami Ruohonen, Harish Segar, Tim Shelton, Teymur Kheirkhabarov, Vasiliy Burov, oscd.community, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium257Free2018-09-05Windows PowerShell Suspicious Encoded Command-Line Execution
Alerts on PowerShell launched with encoded-command switches and embedded encoded content patterns in the command line.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, Anton Kutepov, oscd.community, Huntrule TeamWindowsprocess_creationHigh238Free2018-09-03Windows Process Creation: PowerShell Command Execution Hidden in DLL Invocation
Flags DLL-invoking Windows binaries whose command lines include PowerShell execution strings.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2018-08-25PowerShell NTFS Alternate Data Stream Writes via set-content/add-content
Alerts on PowerShell Set/Add-Content operations that specify -Stream, indicating potential NTFS Alternate Data Stream writes.
Sami Ruohonen, Huntrule TeamWindowsps_scriptHigh262Free2018-07-24Windows PowerShell Remote Thread Creation Into Uncommon Target Processes
Alerts on PowerShell creating remote threads in rundll32.exe or regsvr32.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_remote_threadMedium175Free2018-06-25Windows File Events: Known Offensive PowerShell Script File Creation
Alerts on creation of known offensive PowerShell/PowerShell module filenames on Windows.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Mustafa Kaan Demir, Georg Lauenstein, Huntrule TeamWindowsfile_eventHigh242Free2018-04-07Windows Process Creation: Suspicious Child Programs Spawned by mshta, PowerShell, wscript, rundll32
Alerts when mshta/PowerShell and similar script hosts spawn tasks, download/transfer, or utility tools on Windows.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh218Free2018-04-06