Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
450 rules
Linux groupdel Executed to Delete a User Group
Alerts when the Linux groupdel command is executed, indicating group deletion activity.
Tuan Le (NCSGroup), Huntrule TeamLinuxprocess_creationMedium162Free2022-12-26Linux: usermod used to add users to root or sudoers groups
Detects usermod commands that append a user to root or sudoers groups, indicating potential privilege escalation persistence.
TuanLe (GTSC), Huntrule TeamLinuxprocess_creationMedium395Free2022-12-21Linux: New user created with UID=0 or GID=0/10/27 indicating privileged group access
Alerts on Linux user creation events that assign privileged UID/GID values like root, wheel, or sudo.
Pawel Mazur, Huntrule TeamLinux—High103Free2022-12-21Linux network connections to ngrok tunneling endpoints
Alerts on Linux connections to ngrok tunnel domains, which may indicate tunneling-based C2 or exfiltration.
Florian Roth (Nextron Systems), Huntrule TeamLinuxnetwork_connectionHigh101Free2022-11-03Linux Suspicious curl Start with User-Agent Modification Flags
Flags Linux curl invocations that set a custom User-Agent using -A/--user-agent.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium247Free2022-09-15Linux: Suspicious curl upload via form or data flags
Alerts on Linux curl executions that include file upload or form submission flags in their command line, excluding localhost targets.
Nasreddine Bencherchali (Nextron Systems), Cedric MAURUGEON (Update), Huntrule TeamLinuxprocess_creationMedium151Free2022-09-15Linux Service Management Command Usage to Stop or Disable Services
Flags Linux service-control commands with stop/disable intent, while excluding selected benign upgrade and snap workflows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium168Free2022-09-15Process Creation: curl on Linux
Flags Linux process starts for the curl binary, indicating potential remote file download or web requests.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationLow90Free2022-09-15Linux crontab Removal via "crontab -r" Process Command Line
Identifies attempts to remove the current user crontab via "crontab -r" on Linux.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium104Free2022-09-15Linux: chattr Used to Remove Immutable File Attribute
Flags Linux process use of chattr with -i to remove the immutable file attribute.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium121Free2022-09-15Linux: Base64-Encoded Shebang Patterns in Command Line
Flags Linux command lines containing Base64-encoded shebang prefixes for common shells, indicating potential encoded script execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium163Free2022-09-15Linux auditd: BPFDoor .pid or .lock file access in /var/run
Alerts on auditd-monitored access to specific /var/run .pid and .lock files associated with BPFDoor-style behavior.
Rafal Piasecki, Huntrule TeamLinuxauditdHigh416Free2022-08-10Linux auditd: iptables NAT redirect execution to altered TCP destination ports
Flags iptables NAT REDIRECT commands with --to-ports values 42–43 observed via Linux auditd EXECVE.
Rafal Piasecki, Huntrule TeamLinuxauditdMedium141Free2022-08-10Linux Process Creation: Base64-Encoded Pipe to Bash/Sh Execution
Flags Linux command lines that use base64-encoded data piped into bash or sh for execution.
pH-T (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium80Free2022-07-26Linux Triple Cross eBPF rootkit install commands via sudo tc on enp0s3
Flags sudo tc commands using qdisc/filter syntax and enp0s3 consistent with eBPF rootkit installer behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh142Free2022-07-05