Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,519 rules
Windows Cmd.exe: SET /p file append/override pattern via set /p=
Alerts on Cmd.exe command lines containing SET /p= syntax that may be used with redirection to modify file contents.
Nasreddine Bencherchali (Nextron Systems), MahirAli Khan (in/mahiralikhan), Huntrule TeamWindowsprocess_creationLow100Free2024-08-22macOS chflags Hidden Flag Set via chflags hidden parameter
Alerts when chflags is run with the hidden flag on macOS to make files or directories less visible.
Omar Khaled (@beacon_exe), Huntrule TeamMacosprocess_creationMedium331Free2024-08-21Azure AD: StrongAuthenticationRequirement Set to Disabled/State=0
Alerts on Azure Entra user updates that change StrongAuthenticationRequirement to a disabled State ("State":0).
Harjot Singh (@cyb3rjy0t), Huntrule TeamAzureauditlogsMedium239Free2024-08-21Windows Process Creation: BCP.EXE Used to Export SQL Data
Flags Windows executions of bcp.exe where command-line options indicate MSSQL data export via out/queryout.
Omar Khaled (@beacon_exe), MahirAli Khan (in/mahiralikhan), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium183Free2024-08-20Azure AD Audit: Update User Risk and MFA Registration Policy
Flags Azure AD audit events showing updates to user risk and MFA registration policy.
Harjot Singh (@cyb3rjy0t), Huntrule TeamAzureauditlogsHigh162Free2024-08-13macOS Process Creation: hdiutil Used to Attach or Mount Disk Images
Flags hdiutil usage on macOS when command lines indicate disk image attachment or mounting.
Omar Khaled (@beacon_exe), Huntrule TeamMacosprocess_creationMedium151Free2024-08-10macOS hdiutil Disk Image Creation via Process Execution
Flags macOS executions of hdiutil with the 'create' option, consistent with disk image creation.
Omar Khaled (@beacon_exe), Huntrule TeamMacosprocess_creationMedium142Free2024-08-10Windows Process Masquerading as svchost.exe via Binary Name and Location
Alerts on svchost.exe-named processes launched from non-standard paths with OriginalFileName svchost.exe.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh511Free2024-08-07Windows Rundll32 Execution of Ammy Admin Agent DLL
Identifies rundll32 executions that invoke the Ammy Admin agent DLL with a run parameter on Windows.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium150Free2024-08-05Windows: cmd.exe Launched by AnyViewer Agent (AVCore.exe)
Alerts when AnyViewer’s AVCore.exe launches cmd.exe with -d in a remote management context.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium110Free2024-08-03Windows Registry Set Internet Settings ZoneMap Proxy and Intranet Values
Alerts on Windows ZoneMap registry changes that set proxy/intranet bypass values, using registry set-value telemetry and process image context.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsregistry_setLow398Free2024-07-31Windows DLL Side-Loading: OleView loading aclui.dll
Alerts on OleView.exe loading aclui.dll on Windows, excluding common benign paths to highlight potential DLL side-loading.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadHigh292Free2024-07-31macOS pbpaste Clipboard Read via Process Execution
Flags macOS executions of pbpaste that can expose clipboard contents to stdout for potential data collection.
Daniel Cortez, Huntrule TeamMacosprocess_creationMedium130Free2024-07-30Windows Security: Changes to "ESX Admins" Domain Group Membership
Alerts on domain group management events involving the "ESX Admins" group name, which may grant privileged access.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh413Free2024-07-30Windows File Access to Cryptocurrency Wallet Keystores by Uncommon Processes
Alerts on access to Ethereum/Bitcoin-style wallet files from non-standard processes on Windows.
X__Junior (Nextron Systems), Huntrule TeamWindowsfile_accessMedium419Free2024-07-29