Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
Windows Scheduled Task File Creation Activity (File Event)
Flags file creation under Windows scheduled task directories that may indicate new scheduled task persistence.
Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule TeamWindowsfile_eventLow80Free2023-09-27Windows File Access to .reg and .hive Backups by Uncommon Applications
Alerts on access to .hive/.reg files from less-common application paths on Windows.
frack113, Huntrule TeamWindowsfile_accessLow80Free2023-09-15Windows: Headless Chromium Browser Execution via --headless
Alerts on headless Chromium-based browser launches on Windows using the "--headless" command-line flag.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow80Free2023-09-12Windows File Creation of .dmp/.hdmp/ .dump Crash Memory Dumps
Identifies Windows file creations of .dmp/.dump/.hdmp files that may indicate memory dump generation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow120Free2023-09-07Windows File Deletion: Remove Zone.Identifier Alternate Data Stream
Alerts on Windows deletions of the Zone.Identifier ADS, which attackers may remove to evade zone-based security controls.
frack113, Huntrule TeamWindowsfile_deleteLow170Free2023-09-04Windows: Detect WinRAR Creating .rev Files Associated with CVE-2023-40477
Alert on .rev file creation tied to WinRAR/Explorer on Windows as an indicator of potential CVE-2023-40477 exploitation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow145Free2023-08-31Linux Process Discovery of Container Environment via ls -i on / Directory
Detects Linux commands that list inode information for '/' to probe whether execution is occurring inside a container.
Seth Hanford, Huntrule TeamLinuxprocess_creationLow336Free2023-08-23Linux Docker Container Discovery via .dockerenv File Listing or Reads
Detects Linux process executions using common utilities to read or list .dockerenv, indicating potential container environment discovery.
Seth Hanford, Huntrule TeamLinuxprocess_creationLow103Free2023-08-23Linux Container Discovery via /proc Virtual Filesystem Probing with CLI Text Tools
Flags Linux process executions using standard text tools to enumerate /proc for container-related discovery signals.
Seth Hanford, Huntrule TeamLinuxprocess_creationLow82Free2023-08-23macOS: JAMF CLI (jamf) execution for account and MDM management
Flags macOS executions of the JAMF CLI with command-line actions tied to account, MDM, and framework changes.
Jay Pandit, Huntrule TeamMacosprocess_creationLow151Free2023-08-22Windows PowerShell Script Modifies File Permissions with Set-Acl
Flags PowerShell scripts that call Set-Acl to change ACL permissions on a specified path.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptLow80Free2023-07-18PowerShell NetFirewallRule Cmdlet Enumeration of Local Windows Firewall Rules
Flags PowerShell attempts to enumerate local Windows firewall rules via Get-NetFirewallRule or Show-NetFirewallRule.
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule TeamWindowsps_moduleLow80Free2023-07-13Linux Named Pipe Creation via mkfifo Process Execution
Flags Linux process executions of /mkfifo that create named pipes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationLow90Free2023-06-16Windows DLL Sideloading Indicators: 7za.dll Loaded from Non-Program Files Paths
Alerts when a process loads 7za.dll from a non-Program Files path, indicating potential DLL sideloading.
X__Junior, Huntrule TeamWindowsimage_loadLow186Free2023-06-09Linux OS Architecture Discovery Using grep
Flags grep executions on Linux whose command line ends with known CPU/architecture identifiers.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationLow368Free2023-06-02