Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
146 rules
Linux Password Policy Discovery via chage and passwd Commands
Identifies Linux password policy discovery by running chage/waswo with status arguments and reading common password policy files.
Ömer Günal, oscd.community, Pawel Mazur, Huntrule TeamLinuxauditdLow173Free2020-10-08Windows Registry Key Export via regedit.exe (-E) to File
Flags regedit.exe registry exports to files using the -E option, indicating potential discovery or exfiltration prep.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationLow173Free2020-10-07macOS Local Network Configuration Discovery via ARP/ifconfig/netstat/networksetup/defaults
Finds macOS network discovery activity by spotting arp/ifconfig/netstat/networksetup/socketfilterfw and specific firewall preference reads.
remotephone, oscd.community, Huntrule TeamMacosprocess_creationInformational271Free2020-10-06Linux System Network Discovery via Firewall/Network Tools
Alerts on Linux process activity running common network/firewall tools and DNS discovery indicators.
Ömer Günal and remotephone, oscd.community, Huntrule TeamLinuxprocess_creationInformational143Free2020-10-06Linux process discovery via common process listing and monitoring tools
Flags Linux execution of common tools used to enumerate running processes.
Ömer Günal, oscd.community, CheraaghiMilad, Huntrule TeamLinuxprocess_creationLow110Free2020-10-06Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Alerts on SharpHound/Bloodhound-like processes launching with discovery-focused command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh174Free2019-12-20Windows System Time Discovery via net.exe or w32tm.exe
Flags Windows net.exe/net1.exe or w32tm.exe command lines used to query system time/time zone.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationLow71Free2019-10-24Windows Domain Trust Discovery Using dsquery.exe TrustedDomain Queries
Flags Windows executions of dsquery.exe with trustedDomain to discover Active Directory domain trusts.
E.M. Anhaus, Tony Lambert, oscd.community, omkar72, Huntrule TeamWindowsprocess_creationMedium251Free2019-10-24Windows Local Account Discovery via System Utilities Process Execution
Flags Windows processes that match utilities used to enumerate local user and account information.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow335Free2019-10-21Linux System Owner or User Discovery via Common Utility Execution
Flags execution of Linux user/system identification utilities such as whoami and id.
Timur Zinniatullin, oscd.community, Huntrule TeamLinuxauditdLow376Free2019-10-21Cisco AAA discovery via show/dir commands
Alerts on Cisco AAA log entries with discovery-oriented 'dir' and 'show' command keywords.
Austin Clark, Huntrule TeamCiscoaaaLow299Free2019-08-12