Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,416 rules
Windows: Mounting Internet Hosted WebDAV Shares via net.exe
Alerts on net.exe (net1.exe) commands that mount an HTTP/WebDAV network share.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2023-02-21Windows New Service Creation via sc.exe
Flags sc.exe service creation commands containing create and binPath on Windows, excluding Dropbox-launched cases.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow438Free2023-02-20PowerShell Creates Windows Service via New-Service and -BinaryPathName
Flags PowerShell command lines that use New-Service with -BinaryPathName to create a Windows service.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow372Free2023-02-20macOS: Guest account enabled via sysadminctl
Flags sysadminctl command lines that appear to activate the macOS guest account.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationLow323Free2023-02-18macOS Persistence Attempt Using PlistBuddy to Modify LaunchAgents/LaunchDaemons
Identifies PlistBuddy commands that enable RunAtLoad for LaunchAgents or LaunchDaemons persistence on macOS.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationHigh161Free2023-02-18macOS Installer Scripts Spawning Suspicious Interpreter Child Processes
Alerts when macOS installer scripts (preinstall/postinstall) spawn shell, scripting, osascript, curl, or wget processes.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationMedium112Free2023-02-18Windows Registry Persistence Indicators in Event Viewer Events.asp Links
Flags Windows registry entries that reference Event Viewer Events.asp redirection URLs, excluding known benign svchost/GPO templates.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium151Free2023-02-17Windows suspicious vsstrace.dll image load by uncommon executables
Alert on vsstrace.dll module loads from processes outside common Windows/system paths.
frack113, Huntrule TeamWindowsimage_loadMedium60Free2023-02-17Windows Tomcat Log File Deletion Indicating Possible Forensic Evidence Destruction
Flags Windows file deletions matching Tomcat log paths and common Catalina/localhost access log filename patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteMedium453Free2023-02-16Windows Process Command-Line Containing Unicode Right-to-Left Override (U+202E)
Alerts on Windows process launches with command lines containing Unicode U+202E to support right-to-left text obfuscation.
Micah Babinski, @micahbabinski, Swachchhanda Shrawan Poudel (Nextron Systems), Luc Génaux, Huntrule TeamWindowsprocess_creationHigh82Free2023-02-15Windows: certutil.exe ExportPFX certificate export via -exportPFX flag
Flags certutil.exe executions on Windows that include the -exportPFX argument to export certificate material.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium374Free2023-02-15Windows: certutil.EXE Downloading Files from File-Sharing Domains via Suspicious Flags
Alert when certutil.exe is run with URL/download flags targeting common file-sharing domains.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh140Free2023-02-15Windows certutil.exe Download from Direct IP Using URL/IP-Related Flags
Alerts when certutil.exe is launched with direct-IP download indicators and download-capable certutil flags.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2023-02-15Windows certutil.exe Used to Download Files via Suspicious Command-Line Flags
Alerts on certutil.exe runs with URL/HTTP-related flags indicative of remote file download.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2023-02-15Windows certutil.exe Base64/Hex Decode via -decode or -decodehex Flags
Flags certutil.exe use for decoding base64 or hex data via -decode or -decodehex on Windows.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh132Free2023-02-15