Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
macOS split Command Used to Divide Files into Parts
Flags macOS process execution of split, indicating file splitting activity that may support staging or exfiltration.
Igor Fits, Mikhail Larin, oscd.community, Huntrule TeamMacosprocess_creationLow141Free2020-10-15Linux split Command Used to Divide Files for Possible Exfiltration
Identifies use of the Linux split command to break files into parts, potentially for staging or exfiltration.
Igor Fits, oscd.community, Huntrule TeamLinuxauditdLow315Free2020-10-15Linux auditd: Shutdown, reboot, halt, poweroff or init-triggered system reboot
Identifies Linux shutdown/reboot command execution patterns using auditd execve telemetry.
Igor Fits, oscd.community, Huntrule TeamLinuxauditdInformational93Free2020-10-15Linux: Grep used to search for passwords in files (auditd EXECVE)
Flags Linux process executions running grep with “password” in the command line.
Igor Fits, oscd.community, Huntrule TeamLinuxauditdHigh161Free2020-10-15Linux: Detect touch commands used to alter file timestamps with -t/-a/-c/-m/-r flags
Alerts on touch executions with timestamp options that alter file access and modification times on Linux.
Igor Fits, oscd.community, Huntrule TeamLinuxauditdMedium417Free2020-10-15Windows: Malicious Child Process Execution via vsjitdebugger.exe Just-In-Time Debugger
Flags unusual executables launched by vsjitdebugger.exe on Windows, excluding common Visual Studio helper/debugger children.
Agro (@agro_sev), Ensar Şamil (@sblmsrsn), oscd.community, Huntrule TeamWindowsprocess_creationMedium363Free2020-10-14Windows Process Execution Proxy Using SyncInvoke in CL_Invocation.ps1
Alerts on Windows command lines containing "SyncInvoke" consistent with CL_Invocation.ps1 execution proxy behavior.
Nasreddine Bencherchali (Nextron Systems), oscd.community, Natalia Shornikova, Huntrule TeamWindowsprocess_creationMedium271Free2020-10-14Windows Script and LOLBins Loading .NET CLR DLLs via clr.dll, mscoree.dll, mscorlib.dll
Alerts when common scripting/execution binaries load .NET CLR DLLs like clr.dll and mscoree.dll on Windows.
omkar72, oscd.community, Huntrule TeamWindowsimage_loadHigh4310Free2020-10-14macOS Network Sniffing Tool Execution via tcpdump or tshark
Identifies macOS execution of tcpdump or tshark, indicating potential network traffic sniffing activity.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationInformational123Free2020-10-14macOS Startup Item Plist Created in StartupItems Folders
Alerts on creation of startup item .plist files in macOS StartupItems directories, potential boot persistence setup.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosfile_eventLow306Free2020-10-14Windows Registry-Based DLL Hijack via WAB.EXE Using WAB Registry DLLPath
Flags WAB.EXE DLLPath registry writes where the configured DLL path differs from the default.
oscd.community, Natalia Shornikova, Huntrule TeamWindowsregistry_setHigh82Free2020-10-13Windows Process Creation: accesschk.exe Permission Audit Execution
Flags AccessChk (accesschk.exe) permission/audit executions using common query flags in Windows process creation logs.
Teymur Kheirkhabarov (idea), Mangatas Tondang, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium2110Free2020-10-13Windows te.exe Execution of Test Components (TAEF) via Process Creation
Alerts on process activity involving te.exe, which may indicate TAEF-based execution of malicious test components.
Agro (@agro_sev) oscd.community, Huntrule TeamWindowsprocess_creationLow71Free2020-10-13Windows msiexec.exe Installer Process Spawning cmd.exe or PowerShell
Flags installer-initiated spawning of cmd.exe or PowerShell from Windows\Installer temporary msi-related processes.
Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community, Huntrule TeamWindowsprocess_creationMedium289Free2020-10-13Detect Elevated Windows Installer (msiexec) Running as SYSTEM
Flags msiexec.exe MSI activity from Windows Installer running with SYSTEM integrity, excluding known benign parent contexts.
Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community, Huntrule TeamWindowsprocess_creationMedium125Free2020-10-13