Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,461 rules
macOS System Information Discovery via sw_vers with product/build flags
Detects sw_vers executions on macOS that request product name/version or build version details.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamMacosprocess_creationMedium143Free2023-12-20macOS Process Discovery via ioreg I/O Kit Registry Queries
Flags macOS executions of ioreg with discovery-oriented arguments and device/vendor strings from command-line telemetry.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamMacosprocess_creationMedium172Free2023-12-20Windows: tar.exe Archive Extraction Using -x Flag
Flags Windows process executions of tar.exe with -x to extract compressed archives.
AdmU3, Huntrule TeamWindowsprocess_creationLow339Free2023-12-19Windows tar.exe Used to Create Compressed Archives
Flags tar.exe (or bsdtar) command lines using -c/-r/-u to create or update compressed archives on Windows.
Nasreddine Bencherchali (Nextron Systems), AdmU3, Huntrule TeamWindowsprocess_creationLow103Free2023-12-19Windows WMIC System Information Discovery via WMI Command-Line Queries
Flags WMIC command-line queries that pull OS, hardware, disk, memory, BIOS, and GPU details while excluding VMware Tools discovery scripts.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationLow130Free2023-12-19Windows Task Scheduler: SVR Scheduled Task Names (GraphicalProton) Matching
Flags Windows scheduled task creation, update, or deletion when task names match known SVR GraphicalProton backdoor strings.
CISA, Huntrule TeamWindowstaskschedulerHigh141Free2023-12-18Windows Scheduled Task Creation Using SVR-Specific Task Names
Alerts on Windows scheduled task events with SVR-associated task names indicative of persistence.
CISA, Huntrule TeamWindowssecurityHigh112Free2023-12-18Windows ImageLoad of SVR GraphicalProton DLL Names
Flags Windows DLL loads matching known GraphicalProton/SVR DLL filename suffixes.
CISA, Huntrule TeamWindowsimage_loadMedium457Free2023-12-18Windows Registry: Set LSA NoLMHash to 0 to Enable LM Hash Storage
Flags changes to NoLMHash (DWORD 0) enabling Windows to store LM password hashes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh173Free2023-12-15Windows Process Creation: Enable LM Hash Storage via Lsa\NoLMHash=0 in Command Line
Flags process command lines that set Lsa\NoLMHash to 0 to enable LM hash storage.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh366Free2023-12-15Windows Registry: HVCI disallowed image list modified (HVCIDisallowedImages)
Alerts when Windows HVCI disallowed images registry value is modified, indicating potential driver load policy tampering.
Nasreddine Bencherchali (Nextron Systems), Omar Khaled (@beacon_exe), Huntrule TeamWindowsregistry_setHigh101Free2023-12-05Windows Process Creation: whoami.exe Executed With /all for Full Identity Enumeration
Detects Windows executions of whoami.exe using the /all flag to enumerate full identity details.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium2810Free2023-12-04Windows process command line matches WinPwn tool execution keywords
Alerts on Windows process executions with command-line keywords associated with WinPwn (WinPwn.exe/ps1/offline mode).
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh286Free2023-12-04Windows PowerShell ScriptBlock keyword match for WinPwn tool usage
Alerts when PowerShell ScriptBlock text contains WinPwn execution or script/file reference keywords.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsps_scriptHigh152Free2023-12-04Linux dd Process Memory Map Overwrite for Code Injection (proc/mem)
Alerts when dd is used to write to /proc/<pid>/mem, suggesting potential Linux process code injection.
Joseph Kamau, Huntrule TeamLinuxprocess_creationMedium131Free2023-12-01