Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
69 rules
Possible WizardUpdate Malware Infection (via process_creation)
highThis rule detects the execution traces of the WizardUpdate malware. WizardUpdate is a macOS trojan that attempts to infiltrate macOS machines to steal data and it is linked with other types of hostile payloads, increasing the chances of multiple infections on a device.
sigmamacOSPaid2026-07-27Possible Remote Access Utility - Team Viewer Session Started On MacOS Host (via process_creation)
lowThis rule detects the command line executed when TeamViewer starts a session started by a remote host. Once a connection has been started, an investigator can verify the connection details by viewing the "incoming_connections.txt" log file in the TeamViewer folder.
sigmamacOS2026-07-22Possible GUI Input Capture - macOS (via process_creation)
lowThis rule detects attempts to use system dialog prompts to capture user credentials
sigmamacOS2026-07-18Possible Local System Accounts Enumeration - MacOs (via process_creation)
lowThis rule detects enumeration of local system accounts on MacOS systems. This can be used by adversaries to identify accounts for lateral movement or privilege escalation.
sigmamacOS2026-07-12Suspicious Clipboard Access Through OSAScript (via process_creation)
mediumThis rule detects access to clipboard content via osascript, which may be used for data collection but also occurs in legitimate clipboard utilities and automation scripts
sigmamacOS2026-07-12Possible System Network Connections Enumeration - MacOs (via process_creation)
informationalThis rule detects use of system utilities to discover system network connections
sigmamacOS2026-07-05Possible Guest Account Enabled Through Sysadminctl (via process_creation)
lowThis rule detects attempts to enable the guest account using the sysadminctl utility
sigmamacOS2026-07-05Suspicious Execution through macOS Script Editor (via process_creation)
mediumThis rule detects when the macOS Script Editor utility spawns an unusual child process.
sigmamacOS2026-07-02Possible Macos Remote System Enumeration (via process_creation)
informationalThis rule detects the enumeration of other remote systems.
sigmamacOS2026-07-02Suspicious Hidden Flag Set On File/Directory Through Chflags - MacOS (via process_creation)
mediumThis rule detects the execution of the "chflags" utility with the "hidden" flag, to hide files on MacOS. When a file or directory has this hidden flag set, it becomes invisible to the default file listing commands and in graphical file browsers.
sigmamacOS2026-07-02Possible System Integrity Protection (SIP) Enumeration (via process_creation)
lowThis rule detects the use of csrutil to view the Configure System Integrity Protection (SIP) status. This method is used in post-exploit scenarios.
sigmamacOS2026-06-25Suspicious JXA In-memory Execution Through OSAScript (via process_creation)
highThis rule detects possible hostile execution of JXA in-memory via OSAScript
sigmamacOSPaid2026-06-18Suspicious Root Account Enable Through Dsenableroot (via process_creation)
mediumThis rule detects attempts to enable the root account via "dsenableroot"
sigmamacOS2026-06-17Possible Screen Capture - macOS (via process_creation)
lowThis rule detects attempts to use screencapture to collect macOS screenshots
sigmamacOS2026-06-16Suspicious Payload Decoded and Decrypted through Built-in Utilities (via process_creation)
mediumThis rule detects when a built-in utility is leveraged to decode and decrypt a payload after a macOS disk image (DMG) is executed. Malware authors may attempt to evade detection and trick users into running hostile code by encoding and encrypting their payload and placing it in a disk image file. This behavior is consistent with adware or malware families such as Bundlore and Shlayer.
sigmamacOS2026-06-16Possible Execution of JAMF MDM (via process_creation)
lowThis rule detects execution of the "jamf" binary to create user accounts and run commands. For example, the binary can be misused by adversaries on the system to bypass security controls or remove application control polices.
sigmamacOS2026-06-08Osacompile Execution By Potentially Suspicious Applet/Osascript (via process_creation)
mediumThis rule detects potential anomalous applet or osascript running "osacompile".
sigmamacOS2026-06-07Suspicious Scheduled Cron Task/Job - MacOs (via process_creation)
mediumThis rule detects misuse of the cron utility to perform task scheduling for initial or recurring execution of hostile code. Detection will focus on crontab jobs uploaded from the tmp folder.
sigmamacOS2026-06-07Suspicious Indicator Removal on Host - Clear Mac System Logs (via process_creation)
mediumThis rule detects deletion of local audit logs
sigmamacOS2026-06-06Possible Creation Of A Local User Account (via process_creation)
lowThis rule detects the creation of a new user account. Such accounts may be used for persistence that do not require persistent remote access tools to be deployed on the system.
sigmamacOS2026-06-05