Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
141 rules
Windows WMIC.exe Product Class Reconnaissance via Security Product Queries
Detects wmic.exe being used to enumerate firewall, antivirus, and antispyware product classes.
Michael Haag, Florian Roth (Nextron Systems), juju4, oscd.community, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium1910Free2023-02-14Windows WMIC Product Reconnaissance via Firewall/AV Enumeration
Alerts on wmic.exe executions with command lines consistent with Windows product enumeration for reconnaissance.
Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium154Free2023-02-14Windows wmic.exe Hardware Model Reconnaissance Using csproduct
Flags wmic.exe executions that include "csproduct" to query hardware model/vendor details.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium359Free2023-02-14Windows PowerShell Base64-Encoded WMI Class Invocation
Flags PowerShell command lines containing Base64 fragments indicative of WMI class usage (e.g., ShadowCopy, ScheduledJob) on Windows.
Christian Burkard (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2023-01-30Windows WMIC System Information Discovery via WMIC.EXE Recon
Flags WMIC.EXE executions running system info queries for OS and disk details.
TropChaud, Huntrule TeamWindowsprocess_creationMedium262Free2023-01-26Windows: Suspicious child processes spawned by ManageEngine ServiceDesk Plus (java.exe parent)
Alerts when ManageEngine ServiceDesk Java spawns common attacker tools like PowerShell, certutil, mshta, or wmic.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh103Free2023-01-18Windows DLL Sideloading: WmiApSrv Loads VMGuestLib.dll
Flags WmiApSrv.exe loading VMGuestLib.dll from VMware Tools vmStatsProvider on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium327Free2022-12-01Windows PowerShell WMI Volume Shadow Copy Deletion
Flags PowerShell WMI/CIM commands that query Win32_ShadowCopy and attempt deletion.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationHigh81Free2022-09-20PowerShell WMI Script Deletes Windows Volume Shadow Copies
Flags PowerShell WMI/CIM scripts that enumerate Win32_ShadowCopy and attempt to delete it.
Tim Rauch, frack113, Huntrule TeamWindowsps_scriptHigh204Free2022-09-20Windows WMIC System Reconnaissance Using "computersystem" Flag
Flags wmic.exe runs that include the "computersystem" argument for Windows host information discovery.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium92Free2022-09-08Windows Process Creation: Suspicious Service Stop/Pause/Delete/Disable via net, sc, PowerShell
Alerts on net/sc/wmic/PowerShell commands that stop, pause, delete, or disable Windows services, especially security/backup services.
Nasreddine Bencherchali (Nextron Systems), frack113 , X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-09-01Windows: Detect Suspicious mofcomp.exe Execution from Scripts or Temp Paths
Flags mofcomp.exe runs spawned by script interpreters or using temp/AppData paths, with exclusions for WmiPrvSE .mof-related activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-07-12Windows wmic.exe Used to Start or Stop Services
Alerts on wmic.exe command lines invoking startservice or stopservice via service calls.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2022-06-20Windows WMIC Process Creation Recon for Unquoted Service Paths
Flags wmic.exe service queries requesting name/displayname/pathname/startmode to support unquoted service path reconnaissance.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium161Free2022-06-20Windows Hotfix Inventory Recon via wmic.exe qfe
Detects wmic.exe executions with "qfe" used to enumerate installed Windows hotfixes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium147Free2022-06-20