Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Diskshadow Script Mode Execution via /s Flag
Alerts when Diskshadow is executed in script mode using the /s flag.
Ivan Dyachkov, oscd.community, Huntrule TeamWindowsprocess_creationMedium60Free2020-10-07PowerShell Service Persistence via Registry ImagePath on Windows
Flags Windows registry service ImagePath entries that reference PowerShell (powershell/pwsh).
oscd.community, Natalia Shornikova, Huntrule TeamWindowsregistry_setHigh192Free2020-10-06Windows: Winrm.vbs AWL bypass using attacker WsmPty.xsl/WsmTxt.xsl
Detects WinRM vbs execution with suspicious XSL formatting arguments, especially when the binary is outside System32/SysWOW64.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium354Free2020-10-06Windows: VBoxDrvInst.exe Invoked with driver/executeinf Parameters
Flags VBoxDrvInst.exe launched with parameters indicative of INF processing (driver/executeinf).
Konstantin Grishchenko, oscd.community, Huntrule TeamWindowsprocess_creationMedium141Free2020-10-06Windows: Time Travel Debugging Utility (tttracer.exe) Process Execution
Alerts when tttracer.exe is the parent process of a spawned process on Windows.
Ensar Şamil, @sblmsrsn, @oscd_initiative, Huntrule TeamWindowsprocess_creationHigh388Free2020-10-06PowerShell Script Block WinAPI Calls Indicative of Injection or Token Abuse (Windows)
Detects PowerShell ScriptBlocks containing WinAPI function-name combinations consistent with injection and token manipulation.
Nasreddine Bencherchali (Nextron Systems), Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh143Free2020-10-06Windows UAC Bypass via dism.exe Loading Fake dismcore.dll
Alerts when dism.exe loads a dismcore.dll that is not the expected System32 Dism DLL.
oscd.community, Dmitry Uchakin, Huntrule TeamWindowsimage_loadHigh384Free2020-10-06Windows Time Travel Debugging DLL Loads (ttdrecord/ttdwriter/ttdloader)
Flags Windows image loads of Time Travel Debugging Utility DLLs (tdrecord/tdwriter/tdloader), often abused for stealthy credential dumping.
Ensar Şamil, @sblmsrsn, @oscd_initiative, Huntrule TeamWindowsimage_loadHigh406Free2020-10-06Windows file events: Winrm.vbs payload XSL execution artifacts WsmPty.xsl/WsmTxt.xsl outside system folders
Alert on WsmPty.xsl/WsmTxt.xsl files written outside System32 and SysWOW64, consistent with WinRM VBScript misuse.
Julia Fomina, oscd.community, Huntrule TeamWindowsfile_eventMedium469Free2020-10-06Windows PowerShell Remote Thread Into lsass.exe Suggesting Credential Dumping
Alerts when PowerShell creates a remote thread into lsass.exe, indicating possible credential dumping on Windows.
oscd.community, Natalia Shornikova, Huntrule TeamWindowscreate_remote_threadHigh205Free2020-10-06PowerShell Script Execution via Windows Service Creation (Service Control Manager)
Flags service creation/start events where the service ImagePath references PowerShell (powershell/pwsh).
oscd.community, Natalia Shornikova, Huntrule TeamWindowssystemHigh453Free2020-10-06Windows Service Creation of PowerShell/Pwsh Scripts (Security EID 4697)
Alerts on service creation events where the service executable name includes powershell or pwsh.
oscd.community, Natalia Shornikova, Huntrule TeamWindowssecurityHigh162Free2020-10-06macOS Local Network Configuration Discovery via ARP/ifconfig/netstat/networksetup/defaults
Finds macOS network discovery activity by spotting arp/ifconfig/netstat/networksetup/socketfilterfw and specific firewall preference reads.
remotephone, oscd.community, Huntrule TeamMacosprocess_creationInformational261Free2020-10-06macOS Cron Task Abuse via crontab Executed from /tmp
Detects macOS cron scheduling activity where crontab is run with /tmp in the command line.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationMedium446Free2020-10-06macOS Local User Account Creation via dscl or sysadminctl
Flags macOS commands (dscl create or sysadminctl addUser) that add local user accounts for persistence.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationLow80Free2020-10-06