Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
69 rules
Suspicious Launch Agent/Daemon Execution Through Launchctl (via process_creation)
mediumThis rule detects the execution of programs as Launch Agents or Launch Daemons using launchctl on macOS.
sigmamacOS2026-05-29Possible Enumeration Behavior Via Find - MacOS (via process_creation)
mediumThis rule detects use of "find" binary in an anomalous manner to perform discovery
sigmamacOS2026-05-25Suspicious File Time Attribute Change (via process_creation)
mediumThis rule detects file time attribute change to hide new or changes to existing files
sigmamacOS2026-05-24Suspicious File Download Through Nscurl - MacOS (via process_creation)
mediumThis rule detects the execution of the nscurl utility to download files.
sigmamacOS2026-05-23Suspicious New File Exclusion Added To Time Machine Through Tmutil - MacOS (via process_creation)
mediumThis rule detects the addition of a new file or path exclusion to MacOS Time Machine via the "tmutil" utility. An adversary could exclude a path from Time Machine backups to prevent certain files from being backed up.
sigmamacOS2026-05-20Suspicious Execution of OSACompile Run-Only (via process_creation)
highThis rule detects potential anomalous run-only executions compiled using OSACompile
sigmamacOSPaid2026-05-15Possible Decode Base64 Encoded Text -MacOs (via process_creation)
lowThis rule detects use of base64 utility to decode arbitrary base64-encoded text
sigmamacOS2026-05-12Possible System Information Enumeration Via sw_vers (via process_creation)
mediumThis rule detects the use of "sw_vers" for system information discovery
sigmamacOS2026-05-08Possible In-Memory Download And Compile Of Payloads (via process_creation)
mediumThis rule detects potential in-memory downloading and compiling of applets using curl and osacompile as seen used by XCSSET malware
sigmamacOS2026-05-05Suspicious Time Machine Backup Disabled Through Tmutil - MacOS (via process_creation)
mediumThis rule detects disabling of Time Machine (Apple's automated backup utility software) via the native macOS backup utility "tmutil". An adversary can use this to prevent backups from occurring.
sigmamacOS2026-05-03Possible System Network Enumeration - macOS (via process_creation)
informationalThis rule detects enumeration of local network configuration
sigmamacOS2026-05-01Suspicious User Added To Admin Group Through DseditGroup (via process_creation)
mediumThis rule detects attempts to create and/or add an account to the admin group, thus granting admin privileges.
sigmamacOS2026-04-24Suspicious History File Operations (via process_creation)
mediumThis rule detects commandline operations on shell history files
sigmamacOS2026-04-23Possible MacOS Network Service Scanning (via process_creation)
lowThis rule detects enumeration of local or remote network services.
sigmamacOS2026-04-22Suspicious Time Machine Backup Removal Attempt Through Tmutil - MacOS (via process_creation)
mediumThis rule detects deletion attempts of MacOS Time Machine backups via the native backup utility "tmutil". An adversary may perform this action before launching a ransonware attack to prevent the victim from restoring their files.
sigmamacOS2026-04-18Suspicious Disabling of System Integrity Protection (SIP) (via process_creation)
mediumThis rule detects the use of csrutil to disable the Configure System Integrity Protection (SIP). This method is used in post-exploit scenarios.
sigmamacOS2026-04-14Suspicious Credentials from Password Stores - Keychain (via process_creation)
mediumThis rule detects passwords dumps from Keychain
sigmamacOS2026-04-14Suspicious User Added To Admin Group Through Dscl (via process_creation)
mediumThis rule detects attempts to create and add an account to the admin group via "dscl"
sigmamacOS2026-04-10Possible XCSSET Malware Infection (via process_creation)
mediumThis rule detects the execution traces of the XCSSET malware. XCSSET is a macOS trojan that primarily spreads via Xcode projects and maliciously modifies applications. Infected users are also vulnerable to having their credentials, accounts, and other vital data stolen.
sigmamacOS2026-04-09Suspicious MacOS Firmware Behavior (via process_creation)
mediumThis rule detects when a user manipulates with Firmward Password on MacOS. NOTE - this command has been disabled on silicon-based apple computers.
sigmamacOS2026-04-05