Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Process Creation: BCP.EXE Used to Export SQL Data
Flags Windows executions of bcp.exe where command-line options indicate MSSQL data export via out/queryout.
Omar Khaled (@beacon_exe), MahirAli Khan (in/mahiralikhan), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium103Free2024-08-20Azure AD Audit: Update User Risk and MFA Registration Policy
Flags Azure AD audit events showing updates to user risk and MFA registration policy.
Harjot Singh (@cyb3rjy0t), Huntrule TeamAzureauditlogsHigh152Free2024-08-13macOS Process Creation: hdiutil Used to Attach or Mount Disk Images
Flags hdiutil usage on macOS when command lines indicate disk image attachment or mounting.
Omar Khaled (@beacon_exe), Huntrule TeamMacosprocess_creationMedium131Free2024-08-10macOS hdiutil Disk Image Creation via Process Execution
Flags macOS executions of hdiutil with the 'create' option, consistent with disk image creation.
Omar Khaled (@beacon_exe), Huntrule TeamMacosprocess_creationMedium112Free2024-08-10Windows Process Masquerading as svchost.exe via Binary Name and Location
Alerts on svchost.exe-named processes launched from non-standard paths with OriginalFileName svchost.exe.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh441Free2024-08-07Windows Rundll32 Execution of Ammy Admin Agent DLL
Identifies rundll32 executions that invoke the Ammy Admin agent DLL with a run parameter on Windows.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium90Free2024-08-05Windows: cmd.exe Launched by AnyViewer Agent (AVCore.exe)
Alerts when AnyViewer’s AVCore.exe launches cmd.exe with -d in a remote management context.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium90Free2024-08-03Windows Registry Set Internet Settings ZoneMap Proxy and Intranet Values
Alerts on Windows ZoneMap registry changes that set proxy/intranet bypass values, using registry set-value telemetry and process image context.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsregistry_setLow368Free2024-07-31Windows DLL Side-Loading: OleView loading aclui.dll
Alerts on OleView.exe loading aclui.dll on Windows, excluding common benign paths to highlight potential DLL side-loading.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadHigh232Free2024-07-31macOS pbpaste Clipboard Read via Process Execution
Flags macOS executions of pbpaste that can expose clipboard contents to stdout for potential data collection.
Daniel Cortez, Huntrule TeamMacosprocess_creationMedium90Free2024-07-30Windows Security: Changes to "ESX Admins" Domain Group Membership
Alerts on domain group management events involving the "ESX Admins" group name, which may grant privileged access.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh373Free2024-07-30Windows File Access to Cryptocurrency Wallet Keystores by Uncommon Processes
Alerts on access to Ethereum/Bitcoin-style wallet files from non-standard processes on Windows.
X__Junior (Nextron Systems), Huntrule TeamWindowsfile_accessMedium369Free2024-07-29GitHub Audit: SSH Certificate Authority Created or SSH Certificate Requirement Disabled
Alerts on GitHub audit log events that create SSH certificate authorities or disable SSH certificate requirements.
Romain Gaillard (@romain-gaillard), Huntrule TeamGithubauditMedium91Free2024-07-29GitHub Audit Log: Repository or Organization Transfer Detected
Alerts on GitHub audit log events for repository or organization transfers between environments/accounts.
Romain Gaillard (@romain-gaillard), Huntrule TeamGithubauditMedium176Free2024-07-29GitHub Audit Logs: Private/Internal Forking Policy Enabled or Cleared
Alerts on GitHub audit log policy changes that enable or clear forking of private and internal repositories.
Romain Gaillard (@romain-gaillard), Huntrule TeamGithubauditMedium241Free2024-07-29