Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
450 rules
Linux Process Execution of bpftrace with the --unsafe Option
Alerts when bpftrace is executed with the --unsafe option on Linux.
Andreas Hunkeler (@Karneades), Huntrule TeamLinuxprocess_creationMedium124Free2022-02-11Linux auditd: systemd service file creation under systemd directories
Identifies new systemd unit file creation events under common systemd directories using auditd PATH create logs.
Pawel Mazur, Huntrule TeamLinuxauditdMedium133Free2022-02-03Linux Auditd: Stop Firewalld, iptables, or UFW Services
Detects stopping firewall services (firewalld/iptables/ufw) on Linux via auditd service-stop events.
Pawel Mazur, Huntrule TeamLinuxauditdHigh163Free2022-01-22Linux doas Command Execution Identified
Flags Linux executions of the doas utility based on process image path ending with /doas.
Sittikorn S, Teoderick Contreras, Huntrule TeamLinuxprocess_creationLow71Free2022-01-20Linux doas.conf Creation via /etc/doas.conf File Events
Alerts when /etc/doas.conf is created on a Linux host.
Sittikorn S, Teoderick Contreras, Huntrule TeamLinuxfile_eventMedium133Free2022-01-20Suspicious /dev/tcp Usage in Linux Shell Commands
Flags Linux shell commands containing suspicious /dev/tcp redirection and file descriptor constructs.
frack113, Huntrule TeamLinux—Medium405Free2021-12-10Linux auditd: getcap scanning for setuid/setgid-capable files under root
Flags getcap command-line usage scanning / for Linux capability-bearing files via auditd.
Pawel Mazur, Huntrule TeamLinuxauditdLow153Free2021-11-28Linux wget POST-file Usage Indicating Data Exfiltration
Alerts on Linux wget commands using --post-file= to upload local files, indicating potential data exfiltration.
Pawel Mazur, Huntrule TeamLinuxauditdMedium266Free2021-11-18Linux: Kernel Module Loading via insmod (kmod)
Flags Linux auditd syscalls where insmod is executed via /usr/bin/kmod to load a kernel module.
Pawel Mazur, Huntrule TeamLinuxauditdHigh112Free2021-11-02Linux Process Creation Crypto Miner Command-Line Indicators
Alerts on Linux process executions with command-line strings typical of crypto mining pools, stratum endpoints, and miner options.
Florian Roth (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh147Free2021-10-26Linux Process Network Connections to Crypto Mining Pool Hosts
Flags Linux outbound connections to known Monero mining pool domains.
Florian Roth (Nextron Systems), Huntrule TeamLinuxnetwork_connectionHigh371Free2021-10-26Linux Network Connection to /bin/bash via Reverse Shell Pattern
Alerts on /bin/bash network connections to non-local destination IPs, consistent with reverse shell behavior.
Florian Roth (Nextron Systems), Huntrule TeamLinuxnetwork_connectionCritical131Free2021-10-16Linux Process Creation Webshell Tooling: Web Server Child Processes Running System Commands
Detects web server processes spawning Linux command-line tools commonly used for host discovery or persistence.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh183Free2021-10-15Linux dd Command Overwrite or Deletion via of= and input redirection
Flags Linux dd executions that use of= with /dev/zero or /dev/null, consistent with file overwrite or deletion attempts.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamLinuxprocess_creationLow142Free2021-10-15Linux Clipboard Data Collection via xclip -sel clip -o
Alerts on Linux processes running xclip to output clipboard content using -sel clip -o.
Pawel Mazur, Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamLinuxprocess_creationLow3710Free2021-10-15