Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
141 rules
Windows Defender Exploit Guard blocks PSExec/WMI process creations (PsExec service and WMI provider)
Flags ASR blocks (windefend 1121) of process creations tied to WMI (wmiprvse.exe) or PSExec (psexesvc.exe).
Bhabesh Raj, Huntrule TeamWindowswindefendHigh133Free2020-07-14Windows Persistence Attempt via sc config or wmic COR_PROFILER (Blue Mockingbird)
Flags sc.exe sc config and wmic.exe COR_PROFILER command lines tied to wercplsupporte.dll references.
Trent Liffick (@tliffick), Huntrule TeamWindowsprocess_creationHigh111Free2020-05-14Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Alerts on Word-to-temp execution followed by wmic shadowcopy deletion consistent with Maze-style ransomware droppers.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical169Free2020-05-08Windows PowerShell ScriptBlock containing WMImplant tool parameters
Alerts on PowerShell Script Block content containing WMImplant-related command and system-manipulation parameters.
NVISO, Huntrule TeamWindowsps_scriptHigh132Free2020-03-26Zeek DCE-RPC Execution Indicators: JobAdd, Task Scheduler RPC, WMI ExecMethod, and Service Creation/Start
Detects Zeek DCE-RPC calls that match execution-related JobAdd, Task Scheduler, WMI, or service create/start operations.
"@neu5ron, SOC Prime, Huntrule Team"Zeekdce_rpcMedium123Free2020-03-19Successful Windows Account Logon via WMI (4624 with WmiPrvSE.exe)
Flags successful 4624 logons tied to WmiPrvSE.exe, indicating WMI-driven authentication on Windows.
Thomas Patzke, Huntrule TeamWindowssecurityLow83Free2019-12-04Windows Shadow Copy Deletion via PowerShell, WMIC, vssadmin, diskshadow, or wbadmin
Flags Windows commands that use shadow-copy management utilities with deletion or shadowstorage removal parameters.
Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh91Free2019-10-22Windows Shadow Copy Creation via PowerShell/pwsh/wmic/vssadmin Commands
Detects Windows processes using PowerShell/pwsh/wmic/vssadmin with shadow copy creation parameters.
Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationMedium325Free2019-10-22Windows WMI Backdoor in Exchange Transport Agent via WMI Event Filter Execution
Alerts when WMI-backed execution is launched under EdgeTransport.exe, excluding common Exchange and conhost false positives.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical111Free2019-10-11Windows Process Activity Clearing or Modifying Event Logs via Wevtutil, PowerShell, or WMI
Flags suspicious Windows process command lines that clear or reconfigure Event Logs using wevtutil, PowerShell, or WMI, with an msiexec exception.
Ecco, Daniil Yugoslavskiy, oscd.community, D3F7A5105, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2019-09-26Windows: WmiPrvSE.exe Spawning a Child Process
Identifies child processes created by WmiPrvSE.exe on Windows, highlighting potential WMI-based execution attempts.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsprocess_creationMedium92Free2019-08-15Windows Image Load: WMI DLLs Loaded by Uncommon Process
Alert on loading of common WMI DLLs by processes outside typical system/.NET paths.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsimage_loadLow50Free2019-08-10Suspicious PowerShell/WScript Activity in WMI Event Consumer Commands
Identifies WMI event consumer commands containing PowerShell/WScript download-and-execute patterns like Net.WebClient and IEX.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule TeamWindowswmi_eventHigh113Free2019-04-15WmiPrvSE.exe Spawned PowerShell Child Process on Windows
Alerts on PowerShell spawning from WmiPrvSE.exe, a possible indicator of WMI-based remote execution.
Markus Neis @Karneades, Huntrule TeamWindowsprocess_creationMedium73Free2019-04-03Windows Process Creation Attempt Using wmic.exe process call create
Alerts on Windows process creation attempts invoking wmic.exe with “process call create”, a common pattern for WMI-based execution.
Michael Haag, Florian Roth (Nextron Systems), juju4, oscd.community, Huntrule TeamWindowsprocess_creationMedium30Free2019-01-16