Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
330 rules
AWS Route 53 Domain Transfer Lock Disabled via CloudTrail
Alerts when Route 53 domain transfer protection is removed through DisableDomainTransferLock events in CloudTrail.
sigmaCloudlow2021-07-22Windows Security: Detect Scheduled Task Deletion (EventID 4699)
Flags Windows scheduled task deletions from Security EventID 4699 while excluding common MRT and Firefox-related tasks.
sigmalow2021-01-22Linux Remote System Discovery via arp and ping Process Execution
Flags Linux arp or ping commands with LAN/loopback/link-local IP range arguments consistent with remote host discovery.
sigmaLinuxlow2020-10-22macOS Network Service Enumeration via nc, netcat, nmap, or telnet
Flags macOS executions of nc/netcat, nmap, or telnet consistent with local or remote service enumeration.
sigmamacOSlow2020-10-21Linux: Process Execution of Network Scanning and Recon Tools
Flags Linux process executions of common network scanning/recon utilities based on executable name (and netcat listen flag filtering).
sigmaLinuxlow2020-10-21Linux auditd: Network service enumeration via telnet, nmap, or netcat
Alerts when telnet/nmap/netcat-style binaries are executed on Linux via auditd, consistent with service discovery scanning.
sigmaLinuxlow2020-10-21Windows Event Log Detects Volume Shadow Copy Mounts (HarddiskVolumeShadowCopy, EventID 98)
Alerts when NTFS logs indicate a VSS (HarddiskVolumeShadowCopy) mount using EventID 98.
sigmaWindowslow2020-10-20macOS Gatekeeper bypass attempt using xattr to remove com.apple.quarantine
Flags macOS xattr usage that deletes the com.apple.quarantine extended attribute, consistent with a Gatekeeper bypass attempt.
sigmamacOSlow2020-10-19macOS Base64 Utility Decoding Command Activity
Flags macOS base64 decoding by detecting /usr/bin/base64 runs with the -d argument.
sigmamacOSlow2020-10-19Linux System Network Connections Discovery via who, w, last, lsof, or netstat
Identifies Linux discovery activity using who/w/last/lsof/netstat for enumerating network connections and system state.
sigmaLinuxlow2020-10-19Linux process discovery via grep/egrep searching for security software strings
Alerts when grep/egrep on Linux searches command lines for indicators of security/monitoring tools.
sigmaLinuxlow2020-10-19Linux Base64 Utility Decoding with -d/--decode in Process Creation
Identifies Linux base64 decoding activity using base64 with the -d/--decode flag.
sigmaLinuxlow2020-10-19Windows RunOnce Execution via runonce.exe With AlternateShellStartup and /r
Alerts on runonce.exe executing with /AlternateShellStartup and /r, consistent with configured RunOnce persistence behavior.
sigmaWindowslow2020-10-18macOS split Command Used to Divide Files into Parts
Flags macOS process execution of split, indicating file splitting activity that may support staging or exfiltration.
sigmamacOSlow2020-10-15Linux split Command Used to Divide Files for Possible Exfiltration
Identifies use of the Linux split command to break files into parts, potentially for staging or exfiltration.
sigmaLinuxlow2020-10-15macOS Startup Item Plist Created in StartupItems Folders
Alerts on creation of startup item .plist files in macOS StartupItems directories, potential boot persistence setup.
sigmamacOSlow2020-10-14Windows te.exe Execution of Test Components (TAEF) via Process Creation
Alerts on process activity involving te.exe, which may indicate TAEF-based execution of malicious test components.
sigmaWindowslow2020-10-13macOS Screen Capture via /usr/sbin/screencapture Process Execution
Identifies macOS instances where /usr/sbin/screencapture is executed to collect screenshots.
sigmamacOSlow2020-10-13macOS GUI Credential Prompt Capture via osascript
Flags osascript command lines that script system dialogs referencing authentication and password-related terms.
sigmamacOSlow2020-10-13Windows Indirect Command Execution via Program Compatibility Assistant pcwrun.exe
Alerts on child processes spawned by pcwrun.exe, indicating indirect command execution via Program Compatibility Assistant.
sigmaWindowslow2020-10-12