Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
153 rules
Possible System and File Discovery via System_profiler or Mdfind (via process_creation)
This rule detects system_profiler or mdfind enumerating host details and indexed files, a system-information and file-discovery step attackers use to profile a macOS endpoint after initial access. Host discovery is tracked in the Red Canary Threat Detection Report macOS coverage. Detecting these queries surfaces reconnaissance of the system.
HuntRule TeamMacosprocess_creationLow81Premium2026-05-19Suspicious Self-Extracting Archive via tail Piped to funzip
This rule detects a shell piping the tail of a file into funzip, the self-extraction technique used by macOS Shlayer to unpack a password-protected archive appended to a dropper. This lets the adware carry and decompress its payload inline while hiding it from simple file inspection.
HuntRule TeamMacosprocess_creationHigh51Premium2026-05-17Malicious macOS.Gaslight Persistence via Apple-Namespace LaunchAgent (via file_event)
This rule detects creation of the LaunchAgent property list that the macOS.Gaslight Rust backdoor uses for persistence, masquerading inside the Apple com.apple namespace with the label com.apple.system.services.activity. Genuine Apple daemons are not installed as user LaunchAgents under this exact label. Its presence indicates the Gaslight implant is establishing persistence.
HuntRule TeamMacosfile_eventHigh259Premium2026-05-14LightSpy macOS Implant PID File Creation in Users Shared
This rule detects creation of the file irc.pid under the Users Shared directory, a fixed artifact written by the macOS variant of the LightSpy surveillance implant to track its running instance. Huntress recovered this PID file alongside plugin fetching and WebSocket command-and-control. The specific path and filename are a reliable host indicator of the implant executing on macOS.
HuntRule TeamMacosfile_eventMedium63Premium2026-05-14Suspicious LaunchDaemon Persistence via plist Relocation
This rule detects a property list being moved into a LaunchDaemons directory, the persistence step used by OSX/Dummy to ensure its payload runs at boot with system privileges. Installing a plist into LaunchDaemons registers the malware with launchd for automatic execution.
HuntRule TeamMacosprocess_creationMedium162Premium2026-05-12Suspicious COOKIE SPIDER macOS Data Exfiltration via curl Archive Upload (via process_creation)
This rule detects curl uploading an archive named out.zip on macOS. The SHAMOS stealer delivered by COOKIE SPIDER collects credentials and wallet files and exfiltrates them in an out.zip archive via curl. A curl invocation referencing this archive name is a high-fidelity exfiltration indicator.
HuntRule TeamMacosprocess_creationHigh71Premium2026-05-09Suspicious macOS Hardware Fingerprinting via ioreg IOPlatformUUID (via process_creation)
This rule detects use of ioreg to read the IOPlatformExpertDevice and IOPlatformUUID hardware identifiers, a host-fingerprinting step performed by the FlutterShell backdoor. The unique UUID is used to track infected macOS hosts and tailor follow-on backdoor commands.
HuntRule TeamMacosprocess_creationLow112Premium2026-05-04Suspicious WindowServer Binary Masquerade in Application Support (via file_event)
This rule detects creation of a file named WindowServer under ~/Library/Application Support/ on macOS. The Trojan-Proxy drops its main executable using the name of a legitimate system service in this user directory to blend in, so a WindowServer binary written to Application Support rather than the OS location indicates masquerading malware.
HuntRule TeamMacosfile_eventMedium169Premium2026-05-03Malicious Chrome Relaunch Hijack by FlutterShell Backdoor on macOS (via process_creation)
This rule detects Google Chrome being relaunched with restore-session arguments pointing at the sinterfumesco.com domain, a browser-hijack step of the FlutterShell backdoor from Operation FlutterBridge. The malware kills and restarts Chrome to redirect the victim to attacker-controlled search infrastructure.
HuntRule TeamMacosprocess_creationHigh51Premium2026-05-01macOS Process Creation: MeshAgent renamed execution via --meshServiceName
Identifies macOS executions of MeshAgent instances that include --meshServiceName, indicating potential renamed remote access tooling.
Norbert Jaśniewicz (AlphaSOC), Huntrule TeamMacosprocess_creationHigh194Free2025-05-19macOS Process Creation: MeshAgent Remote Access via --meshServiceName
Alerts on macOS process executions containing --meshServiceName, indicating potential MeshAgent remote access usage.
Norbert Jaśniewicz (AlphaSOC), Huntrule TeamMacosprocess_creationMedium120Free2025-05-19macOS chflags Hidden Flag Set via chflags hidden parameter
Alerts when chflags is run with the hidden flag on macOS to make files or directories less visible.
Omar Khaled (@beacon_exe), Huntrule TeamMacosprocess_creationMedium321Free2024-08-21macOS Process Creation: hdiutil Used to Attach or Mount Disk Images
Flags hdiutil usage on macOS when command lines indicate disk image attachment or mounting.
Omar Khaled (@beacon_exe), Huntrule TeamMacosprocess_creationMedium151Free2024-08-10macOS hdiutil Disk Image Creation via Process Execution
Flags macOS executions of hdiutil with the 'create' option, consistent with disk image creation.
Omar Khaled (@beacon_exe), Huntrule TeamMacosprocess_creationMedium112Free2024-08-10macOS Process Creation: nscurl File Download Arguments
Flags nscurl executions on macOS that include download-oriented command-line options, indicating potential remote file retrieval.
Daniel Cortez, Huntrule TeamMacosprocess_creationMedium123Free2024-06-04