Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
PowerShell ScriptBlock COM CLSID GetTypeFromCLSID Download Cradle Indicators
Alerts on PowerShell script blocks using GetTypeFromCLSID with specific CLSIDs indicative of COM-based download cradles.
frack113, Huntrule TeamWindowsps_scriptMedium301Free2022-12-25Windows PowerShell: In-Memory Assembly Loading via Reflection.Assembly
Flags PowerShell script blocks that reference [Reflection.Assembly]::load for potential in-memory assembly loading.
frack113, Huntrule TeamWindowsps_scriptMedium112Free2022-12-25Windows Process Execution: Suspicious AgentExecutor.exe PowerShell Launch with ExecutionPolicy Bypass
Detects AgentExecutor.exe command lines that trigger PowerShell script execution, including remediations and potentially bypassed ExecutionPolicy.
Nasreddine Bencherchali (Nextron Systems), memory-shards, Huntrule TeamWindowsprocess_creationHigh70Free2022-12-24Windows AgentExecutor.exe PowerShell Execution (ExecutionPolicy Bypass) Process Creation
Alerts on AgentExecutor.exe launches that pass -powershell/-remediationScript to run PowerShell (including bypass execution policy).
Nasreddine Bencherchali (Nextron Systems), memory-shards, Huntrule TeamWindowsprocess_creationMedium70Free2022-12-24Windows Process Copy/Move of Browser Credential Stores
Identifies Windows commands copying or moving browser user data directories consistent with credential theft.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium226Free2022-12-23Windows Process Creation: Suspicious X509Enrollment.CBinaryConverter Execution
Alerts on Windows command lines referencing X509Enrollment.CBinaryConverter with a specific GUID.
frack113, Huntrule TeamWindowsprocess_creationMedium384Free2022-12-23PowerShell FromBase64String Decoding of Base64 Gzip Content in Process Creation on Windows
Windows process command lines using PowerShell FromBase64String with MemoryStream and Gzip-like Base64 markers (H4sI) are flagged.
frack113, Huntrule TeamWindowsprocess_creationMedium392Free2022-12-23Windows PowerShell Execution of AADInternals Cmdlets (process creation)
Flags PowerShell processes running AADInternals “-AADInt” cmdlets, indicating potential Azure AD/Office 365 administration or abuse.
Austin Songer (@austinsonger), Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-12-23Windows Chromium-Based Browsers Launched with Headless Debugging and User Profile Directory
Alerts on Windows launches of Chromium-based browsers in headless + remote debugging mode targeting a user data directory.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2022-12-23Suspicious X509Enrollment usage in Windows PowerShell scripts
Alerts on PowerShell script blocks containing X509Enrollment.CBinaryConverter and a specific enrollment GUID.
frack113, Huntrule TeamWindowsps_scriptMedium123Free2022-12-23PowerShell: FromBase64String Decoding of Gzip (H4sI) into MemoryStream
Identifies PowerShell script blocks that base64-decode and Gzip-unpack embedded content using in-memory streams.
frack113, Huntrule TeamWindowsps_scriptMedium161Free2022-12-23Windows PowerShell Script Block Logging: AADInternals Cmdlets (Add-AADInt to Update-AADInt) Execution
Flags PowerShell script block execution that contains AADInternals cmdlet names (AADInt), indicating potential admin or abuse activity.
Austin Songer (@austinsonger), Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptHigh103Free2022-12-23Windows System Service Installation of Remote Access Tool Services (Event 7045/7036)
Flags Windows service installation or updates for remote access tool services using Service Control Manager events.
Connor Martin, Nasreddine Bencherchali, Huntrule TeamWindowssystemMedium448Free2022-12-23Windows Security Event 4697 Service Install of Remote Access Tools
Alerts on Windows service creation (EID 4697) where the service name matches known remote access tool indicators.
Connor Martin, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityMedium123Free2022-12-23Windows: Explorer opened from cmd.exe/powershell using shell:MyComputerFolder shortcut
Flags explorer.exe opened for My Computer via shell:mycomputerfolder when started by cmd or PowerShell.
"@Kostastsale, Huntrule Team"Windowsprocess_creationHigh233Free2022-12-22