Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,512 rules
macOS tmutil Time Machine Backup Deletion Attempts
Flags tmutil executions with delete in the command line that attempt to remove Time Machine backups.
Pratinav Chandra, Huntrule TeamMacosprocess_creationMedium3510Free2024-05-29Suspicious Web Browser Launch from PDF/Office Reader on Windows over HTTP(S)
Alerts when Acrobat/Office/PDF readers launch common browsers with HTTP(S) URLs, excluding known Microsoft and Foxit redirect patterns.
Joseph Kamau, Huntrule TeamWindowsprocess_creationMedium385Free2024-05-27Windows Process Access to Uncommon Target Images Using PROCESS_ALL_ACCESS
Alerts on Windows events granting PROCESS_ALL_ACCESS to processes with uncommon target image filenames.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_accessLow514Free2024-05-27Windows Network Connections to Cloudflared Tunnel Domains
Alerts when a Windows process initiates outbound connections to Cloudflared tunnel domain hostnames.
Kamran Saifullah, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium446Free2024-05-27Windows: File Creation by mysqld.exe With Script/Executable Extensions
Alerts on file creation by mysqld.exe producing .bat/.exe/.ps1/.vbs and other executable or script file types on Windows.
Joseph Kamau, Huntrule TeamWindowsfile_eventHigh223Free2024-05-27MacOS Sysctl Usage for System Discovery (hw., kern., machdep.)
Flags macOS sysctl commands querying hw., kern., or machdep. values for system discovery.
Pratinav Chandra, Huntrule TeamMacosprocess_creationMedium329Free2024-05-27Suspicious Child Process of KeyScrambler.exe on Windows
Alerts on KeyScrambler.exe launching cmd.exe, PowerShell, script hosts, regsvr32, or rundll32 as child processes.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium130Free2024-05-13macOS launchctl Execution of Launch Agent/Daemon
Flags launchctl usage on macOS to submit, load, or start Launch Agents/Daemons, a common persistence mechanism.
Pratinav Chandra, Huntrule TeamMacosprocess_creationMedium338Free2024-05-13PowerShell Start-NetEventSession Script Block Execution Indicating Potential Network Capture (Windows)
Alerts when PowerShell ScriptBlocks reference Start-NetEventSession, indicating potential network packet or event capture.
frack113, Huntrule TeamWindowsps_scriptMedium131Free2024-05-12Windows Registry: UAC PromptOnSecureDesktop Disabled
Detects setting UAC PromptOnSecureDesktop to 0 via Windows registry policy, disabling secure desktop for UAC prompts.
frack113, Huntrule TeamWindowsregistry_setMedium182Free2024-05-10Windows Registry: UAC notification disabled via UACDisableNotify set to DWORD 0x00000001
Alerts on registry changes that disable UAC notifications by setting UACDisableNotify to 0x00000001 on Windows.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium181Free2024-05-10Windows: wbadmin.exe Used to Recover/Dump Sensitive Registry Hives and NTDS.dit
Alert on wbadmin.exe recovery commands targeting SAM/SECURITY/SYSTEM hives and NTDS.dit.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh100Free2024-05-10Windows Process: File Recovery from Backup via wbadmin.exe
Flags wbadmin.exe executions that perform file recovery from backups based on recoveryTarget and itemtype:File arguments.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium120Free2024-05-10Windows Process Creation: wbadmin.exe Triggered for Backup of Sensitive Registry and NTDS Files
Alerts on wbadmin.exe backup commands that reference SAM/SECURITY/SYSTEM hives or NTDS.DIT.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh288Free2024-05-10Windows Firewall Allow Rule Added via WmiPrvSE.exe
Flags Windows firewall allow-rule additions where WmiPrvSE.exe is the modifying application.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfirewall-asMedium442Free2024-05-10