Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,461 rules
Windows Security: Detect NoFilter Tool Activity via RonPolicy Filtering Policy Indicators
Alerts on Windows Filtering Platform policy change events containing "RonPolicy" consistent with NoFilter abuse.
Stamatis Chatzimangou (st0pp3r), Huntrule TeamWindowssecurityHigh191Free2024-01-05Windows Process Creation: EDRSilencer Executed
Flags execution of EDRSilencer.exe on Windows based on process image and identifying metadata.
"@gott_cyber, Huntrule Team"Windowsprocess_creationHigh437Free2024-01-02Windows Process Execution of dotnet-trace.exe Child via '-- collect' Arguments
Alerts on dotnet-trace.exe executions with '-- ' and 'collect' command-line arguments that may proxy child process execution.
Jimmy Bayne (@bohops), Huntrule TeamWindowsprocess_creationMedium389Free2024-01-02macOS Process Execution of system_profiler for System Discovery via Specific Data Types
Flags macOS system_profiler runs that request application, hardware, network, and USB data via command-line data types.
Stephen Lincoln `@slincoln_aiq` (AttackIQ), Huntrule TeamMacosprocess_creationMedium474Free2024-01-02macOS SIP Status Enumeration via csrutil status
Flags execution of "csrutil status" on macOS to enumerate System Integrity Protection state.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamMacosprocess_creationLow92Free2024-01-02macOS csrutil Used to Disable System Integrity Protection (SIP)
Detects macOS processes running csrutil to disable SIP by matching /csrutil with a command line containing 'disable'.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamMacosprocess_creationMedium131Free2024-01-02Windows Process Execution: Suspicious cmd.exe Command-Line Combinations (Pikabot-like)
Alerts on cmd.exe /c command chains containing download/delay and rundll32 indicators consistent with Pikabot-like staging.
Alejandro Houspanossian ('@lekz86'), Huntrule TeamWindowsprocess_creationMedium102Free2024-01-02Windows Registry Persistence via AppCompatFlags Layers REGISTERAPPRESTART
Detects registry persistence settings that include the AppCompat layer "REGISTERAPPRESTART" on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium229Free2024-01-01Windows Registry Change to Desktop Wallpaper Policy or Settings
Detects Windows registry updates that enforce or change the desktop wallpaper and restrict user control.
Nasreddine Bencherchali (Nextron Systems), Stephen Lincoln @slincoln-aiq (AttackIQ), Huntrule TeamWindowsregistry_setMedium82Free2023-12-21Windows reg.exe Changes Desktop Background Policy Values
Alerts when reg.exe is used to modify Windows registry settings that control wallpaper or desktop background behavior.
Stephen Lincoln @slincoln-aiq (AttackIQ), Huntrule TeamWindowsprocess_creationMedium144Free2023-12-21Windows Process Execution of Renamed cloudflared.exe with Tunnel/Run Command Arguments
Alerts on Windows process executions of renamed cloudflared with tunnel run/cleanup command-line arguments or matching SHA-256 hashes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2023-12-20Windows Execution of cloudflared for Cloudflare Try/Quick Tunnel Ad-hoc Tunneling
Flags execution of cloudflared on Windows with -url arguments consistent with Cloudflare Quick Tunnel setup.
Sajid Nawaz Khan, Huntrule TeamWindowsprocess_creationMedium120Free2023-12-20Windows execution of cloudflared.exe from a non-default directory
Alerts on cloudflared.exe executions from unusual paths on Windows, excluding standard Program Files locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium466Free2023-12-20Windows DNS Queries for Cloudflared Tunnel Domains
Alerts on Windows DNS queries for domains ending with common Cloudflared tunnel hostnames.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns_queryMedium283Free2023-12-20macOS Bash Pipelines Extract Image Bytes and Base64-Decode Output to a File
Alerts on bash on macOS that tails image bytes, base64-decodes them, and writes decoded output to a new file.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamMacosprocess_creationHigh102Free2023-12-20