Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
450 rules
Linux Syslog Alerts for Stopping Built-in Security Tools
Alerts on syslog text indicating security tools are being stopped: iptables, firewalld, cbdaemon, or falcon-sensor.
Ömer Günal, Alejandro Ortuno, oscd.community, Huntrule TeamLinuxsyslogMedium132Free2020-06-17Linux process activity: chown root and setuid/setgid chmod flags
Alerts on Linux command lines that set root ownership and enable setuid/setgid via chmod u+s or g+s.
Ömer Günal, Huntrule TeamLinuxprocess_creationLow111Free2020-06-16Linux auditd: New user account creation via useradd (ADD_USER/SYSCALL)
Flags Linux auditd evidence of new local user accounts created using useradd.
Marie Euler, Pawel Mazur, Huntrule TeamLinuxauditdMedium465Free2020-05-18Linux auditd: Alert on suspicious C2-related command executions
Alerts on auditd executions of common C2-adjacent tools when labeled with the "susp_activity" key.
Marie Euler, Huntrule TeamLinuxauditdMedium173Free2020-05-18Linux auditd alerts on syslog daemon configuration file changes
Alerts when syslog daemon configuration files are changed on a Linux host via auditd PATH events.
Mikhail Larin, oscd.community, Huntrule TeamLinuxauditdHigh132Free2019-10-25Linux auditd: Monitor changes to /etc/audit, /etc/libaudit.conf, and /etc/audisp files
Flags modifications to Linux auditd configuration files that can weaken host auditing.
Mikhail Larin, oscd.community, Huntrule TeamLinuxauditdHigh111Free2019-10-25Linux: Detect Modification of /etc/ld.so.preload for Shared Object Injection
Flags auditd activity where /etc/ld.so.preload is modified, indicating potential shared object injection.
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Huntrule TeamLinuxauditdHigh92Free2019-10-24Linux auditd: dd overwrites a file using /dev/null or /dev/zero
Flags dd command lines that overwrite files by sourcing data from /dev/null or /dev/zero.
Jakob Weinzettl, oscd.community, Huntrule TeamLinuxauditdLow92Free2019-10-23Linux System Owner or User Discovery via Common Utility Execution
Flags execution of Linux user/system identification utilities such as whoami and id.
Timur Zinniatullin, oscd.community, Huntrule TeamLinuxauditdLow376Free2019-10-21Linux: Detect execution of tcpdump or tshark with interface (-i) capture option
Alerts on tcpdump or tshark executions on Linux where an interface flag is present, consistent with network sniffing.
Timur Zinniatullin, oscd.community, Huntrule TeamLinuxauditdLow438Free2019-10-21Linux Masquerading via crond Path Using cp Launching /bin/sh
Alerts on Linux execve where cp runs through /bin/sh and the argument ends with /crond, indicating potential masquerading.
Timur Zinniatullin, oscd.community, Huntrule TeamLinuxauditdMedium60Free2019-10-21Linux Auditd: Command Execution of zip, gzip -k, or tar -c for Data Compression
Alerts on Linux execve events launching zip, gzip (-k), or tar create commands often used to compress data.
Timur Zinniatullin, oscd.community, Huntrule TeamLinuxauditdLow81Free2019-10-21Linux auditd: Webshell Remote Command Execution via execve/execveat (euid=33)
Alerts on execve/execveat executions by the web server user, consistent with potential webshell command execution.
Ilyas Ochkov, Beyu Denis, oscd.community, Huntrule TeamLinuxauditdCritical162Free2019-10-12Linux Service Reload/Start via systemctl or service Command Execution
Identifies Linux process executions invoking service control commands with start or reload keywords.
Jakob Weinzettl, oscd.community, CheraghiMilad, Huntrule TeamLinuxauditdLow185Free2019-09-23Linux auditd: chmod/chown process execution indicating file or folder permission changes
Flags Linux EXECVE events running chmod or chown, which commonly correspond to file/folder permission changes.
Jakob Weinzettl, oscd.community, Huntrule TeamLinuxauditdLow264Free2019-09-23