Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
macOS split Command Used to Divide Files into Parts
Flags macOS process execution of split, indicating file splitting activity that may support staging or exfiltration.
Igor Fits, Mikhail Larin, oscd.community, Huntrule TeamMacosprocess_creationLow141Free2020-10-15Linux split Command Used to Divide Files for Possible Exfiltration
Identifies use of the Linux split command to break files into parts, potentially for staging or exfiltration.
Igor Fits, oscd.community, Huntrule TeamLinuxauditdLow325Free2020-10-15macOS Startup Item Plist Created in StartupItems Folders
Alerts on creation of startup item .plist files in macOS StartupItems directories, potential boot persistence setup.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosfile_eventLow306Free2020-10-14Windows te.exe Execution of Test Components (TAEF) via Process Creation
Alerts on process activity involving te.exe, which may indicate TAEF-based execution of malicious test components.
Agro (@agro_sev) oscd.community, Huntrule TeamWindowsprocess_creationLow101Free2020-10-13macOS Screen Capture via /usr/sbin/screencapture Process Execution
Identifies macOS instances where /usr/sbin/screencapture is executed to collect screenshots.
remotephone, oscd.community, Huntrule TeamMacosprocess_creationLow142Free2020-10-13macOS GUI Credential Prompt Capture via osascript
Flags osascript command lines that script system dialogs referencing authentication and password-related terms.
remotephone, oscd.community, Huntrule TeamMacosprocess_creationLow173Free2020-10-13Windows Indirect Command Execution via Program Compatibility Assistant pcwrun.exe
Alerts on child processes spawned by pcwrun.exe, indicating indirect command execution via Program Compatibility Assistant.
A. Sungurov , oscd.community, Huntrule TeamWindowsprocess_creationLow171Free2020-10-12Windows PowerShell Command Line Encoded-Content Indicators via Type Conversion and String Building
Detects PowerShell command lines containing type-conversion and join/split character assembly indicators consistent with encoded content handling.
Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton, Huntrule TeamWindowsprocess_creationLow473Free2020-10-11Linux Local Groups Discovery via /groups or /etc/group File Enumeration
Detects Linux commands and utilities used to enumerate local groups and read /etc/group.
Ömer Günal, Alejandro Ortuno, oscd.community, Huntrule TeamLinuxprocess_creationLow379Free2020-10-11Windows regini.exe Execution Leading to Registry Key Changes
Alerts on Windows executions of regini.exe that can import registry changes from text files.
Eli Salem, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationLow181Free2020-10-08Windows net.exe Unmount Share (/delete) Execution
Alerts on net.exe/net1.exe commands that include "share" and "/delete", indicating share unmount/removal on Windows.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsprocess_creationLow152Free2020-10-08macOS Local System Account Enumeration via dscl, dscacheutil, and user listing commands
Detects macOS commands used to enumerate local system accounts via dscl, dscacheutil, id, lsof, who, and preference/query utilities.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationLow92Free2020-10-08Linux Local Account Enumeration via lastlog, /etc/* file reads, id, and lsof -u
Flags Linux process activity consistent with enumerating local system accounts using /etc account data and related tools.
Alejandro Ortuno, oscd.community, CheraghiMilad, Huntrule TeamLinuxprocess_creationLow495Free2020-10-08Linux Password Policy Discovery via chage and passwd Commands
Identifies Linux password policy discovery by running chage/waswo with status arguments and reading common password policy files.
Ömer Günal, oscd.community, Pawel Mazur, Huntrule TeamLinuxauditdLow173Free2020-10-08Windows Registry Key Export via regedit.exe (-E) to File
Flags regedit.exe registry exports to files using the -E option, indicating potential discovery or exfiltration prep.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationLow173Free2020-10-07