Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
macOS Remote System Discovery via arp or ping enumeration
Identifies macOS arp -a or ping to private/local IP ranges used for remote system enumeration.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationInformational112Free2020-10-22Linux Remote System Discovery via arp and ping Process Execution
Flags Linux arp or ping commands with LAN/loopback/link-local IP range arguments consistent with remote host discovery.
Alejandro Ortuno, oscd.community, Huntrule TeamLinuxprocess_creationLow163Free2020-10-22macOS Network Service Enumeration via nc, netcat, nmap, or telnet
Flags macOS executions of nc/netcat, nmap, or telnet consistent with local or remote service enumeration.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationLow142Free2020-10-21macOS AppleScript Execution via osascript with -e, .scpt, or .js
Flags osascript usage on macOS with -e and script indicators consistent with executing AppleScript.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationMedium80Free2020-10-21Linux: Process Execution of Network Scanning and Recon Tools
Flags Linux process executions of common network scanning/recon utilities based on executable name (and netcat listen flag filtering).
Alejandro Ortuno, oscd.community, Georg Lauenstein (sure[secure]), Huntrule TeamLinuxprocess_creationLow124Free2020-10-21Linux auditd: Network service enumeration via telnet, nmap, or netcat
Alerts when telnet/nmap/netcat-style binaries are executed on Linux via auditd, consistent with service discovery scanning.
Alejandro Ortuno, oscd.community, Huntrule TeamLinuxauditdLow449Free2020-10-21Windows Registry: Detect esentutl.exe activity under VSS service keys
Flags registry changes under VSS service keys when initiated by esentutl.exe, consistent with VSS-related abuse.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_eventHigh132Free2020-10-20Windows: rundll32 Triggering comsvcs.dll MiniDump Against lsass.exe
Detects rundll32 invoking comsvcs.dll to dump lsass.exe via a MiniDump export.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_accessHigh131Free2020-10-20Windows DLL image load: credui.dll loaded by an uncommon process
Detects credui.dll or wincredui.dll being loaded by a process other than common system binaries.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium274Free2020-10-20Windows Event Log Detects Volume Shadow Copy Mounts (HarddiskVolumeShadowCopy, EventID 98)
Alerts when NTFS logs indicate a VSS (HarddiskVolumeShadowCopy) mount using EventID 98.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssystemLow458Free2020-10-20Windows Security: VSSAudit Event Source Registration (Event ID 4904/4905)
Alerts on VSSAudit security event source registration in Windows Security logs using Event IDs 4904/4905.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssecurityInformational3610Free2020-10-20macOS Gatekeeper bypass attempt using xattr to remove com.apple.quarantine
Flags macOS xattr usage that deletes the com.apple.quarantine extended attribute, consistent with a Gatekeeper bypass attempt.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamMacosprocess_creationLow408Free2020-10-19macOS Shutdown/Reboot Command Execution via /shutdown, /reboot, or /halt Paths
Flags macOS process executions ending with shutdown, reboot, or halt indicating possible host power disruption.
Igor Fits, Mikhail Larin, oscd.community, Huntrule TeamMacosprocess_creationInformational235Free2020-10-19macOS System Network Connection Discovery via who, w, last, lsof, or netstat
Flags macOS process executions of who/w/last/lsof/netstat used to discover network or session information.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamMacosprocess_creationInformational191Free2020-10-19macOS Security Software Discovery via grep of Known Security Software Names
Flags /usr/bin/grep on macOS when command lines include identifiers associated with security tools and agents.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamMacosprocess_creationMedium316Free2020-10-19