Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
141 rules
PowerShell WMI Service Enumeration for Unquoted Service Path Recon
Flags PowerShell WMI queries for Win32_Service fields to enumerate potential unquoted service path issues.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium82Free2022-06-20Windows File Events: wmiexec Default Output File Creation (__1<9 digits>.<1-7 digits>)
Detects Windows file creation matching wmiexec default output filename patterns in admin share and drive paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventCritical287Free2022-06-02Suspicious Child Process Spawning by PowerShell on Windows
Alerts when PowerShell spawns potentially suspicious child binaries (e.g., certutil, mshta, wmic, rundll32), with exclusions for known benign patterns.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationMedium100Free2022-04-26PowerShell WMI Win32_Product MSI Installation via Invoke-CimMethod
Flags PowerShell using WMI Win32_Product via Invoke-CimMethod to invoke an MSI install.
frack113, Huntrule TeamWindowsps_scriptMedium91Free2022-04-24Windows process access indicating potential shellcode injection to lsass.exe
Alerts on high-privilege process access from wmiprvse.exe to lsass.exe consistent with potential shellcode injection behavior.
Bhabesh Raj, Huntrule TeamWindowsprocess_accessMedium90Free2022-03-11Windows: Application Uninstall via WMIC.exe (WMIC call uninstall)
Flags WMIC.exe commands that include "call" and "uninstall," indicating potential application removal on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium151Free2022-01-28Windows WMIC Process Flag Execution Indicating Process Reconnaissance
Alerts on wm ic.exe executions using the 'process' flag, consistent with attempting to enumerate running processes.
frack113, Huntrule TeamWindowsprocess_creationMedium101Free2022-01-01RPC Firewall detects remote DCOM/WMI-related RPC operations via specified interface UUIDs
Alerts on RPC Firewall RPC events indicating remote DCOM/WMI interface activity that can support lateral movement.
Sagie Dulce, Dekel Paz, Huntrule TeamRpc_firewallapplicationHigh3010Free2022-01-01PowerShell Scheduled Task Creation via ScriptBlock Logging
Identifies PowerShell script blocks that create and register scheduled tasks using TaskScheduler cmdlets or CIM WMI method calls.
frack113, Huntrule TeamWindowsps_scriptMedium92Free2021-12-28Windows Process Discovery via wmic.exe "group" Flag
Flags wmic.exe process executions querying local group information via a "group" command-line argument.
frack113, Huntrule TeamWindowsprocess_creationLow298Free2021-12-12PowerShell Suspicious Discovery of Local Groups via Get-LocalGroup Cmdlets
Flags PowerShell commands that enumerate local groups and group membership, including WMI/CIM queries for Win32 group data.
frack113, Huntrule TeamWindowsps_scriptLow319Free2021-12-12Windows WMI Event Consumer with Encoded Payload Containing Suspicious Strings
Detects WMI event consumer encoded payloads containing suspicious execution-related strings on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowswmi_eventHigh364Free2021-09-01Windows WMI Event Consumer (scrcons.exe) Creates Named Pipe
Flags scrcons.exe creating a Windows named pipe, using named pipe creation event telemetry.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdMedium187Free2021-09-01Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
Flags WmiPrvSE.exe spawning script/utility executables like mshta or regsvr32, with command-line keywords where applicable.
Vadim Khrykov (ThreatIntel), Cyb3rEng, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh396Free2021-08-23Windows Process Creation: Office-Launched WMIC with LOLBIN-Style Command Arguments
Alerts on Office spawning WMIC.exe with process/create/call arguments and LOLBIN-like tool references.
Vadim Khrykov, Cyb3rEng, Huntrule TeamWindowsprocess_creationHigh162Free2021-08-23