Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,344 rules
Windows DLL Search Order Hijacking: Suspicious DLL Writes to App Dependency Folders
Alerts on suspicious .dll file creation by Office/cmd/scripting processes in AppData and OneDrive/Teams/Slack/VS Code directories.
Tim Rauch (rule), Elastic (idea), Huntrule TeamWindowsfile_eventMedium143Free2022-10-21macOS Script Editor Spawns Suspicious Command-Line Interpreters
Alerts when Script Editor launches command-line tools or interpreters like curl, shell binaries, python, or perl.
Tim Rauch (rule), Elastic (idea), Huntrule TeamMacosprocess_creationMedium162Free2022-10-21Windows Process Execution: SafetyKatz HackTool (SafetyKatz.exe)
Alerts when a process running SafetyKatz.exe is created, using image path and embedded file metadata.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical163Free2022-10-20Windows Process Creation: Seatbelt.exe PUA Discovery Command-Line Execution
Alerts on Windows process launches of Seatbelt.exe with discovery group arguments and outputfile usage.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh212Free2022-10-18PowerShell Set-Acl targeting Windows folder paths on Windows
Flags PowerShell Set-Acl commands that modify ACLs for Windows folder paths, often using FullControl/Allow.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2022-10-18PowerShell Set-Acl Script Execution Changes File or Folder Permissions on Windows
Flags PowerShell commands using Set-Acl (-AclObject and -Path) to alter Windows file or folder permissions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2022-10-18PowerShell Set-Service SecurityDescriptorSddl DACL Modification for Windows Services
Detects PowerShell Set-Service commands with SecurityDescriptorSddl SDDL patterns that modify Windows service DACLs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh373Free2022-10-18Detect rclone CLI Activity via Proxy User-Agent Prefix
Flags proxy traffic with a user agent beginning with rclone/v, indicating rclone usage through the proxy.
Janantha Marasinghe, Huntrule TeamWebproxyMedium194Free2022-10-18Windows PowerShell Set-Service SDDL Usage to Hide Services
Flags pwsh Set-Service commands that set a SecurityDescriptorSddl to hide a Windows service from other tools.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-10-17PowerShell Set-Service SecurityDescriptor (DCLCWPDTSD) to Hide Services
Flags PowerShell Set-Service calls that set a SecurityDescriptor SDDL (DCLCWPDTSD) to hide services from other utilities.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh132Free2022-10-17Uncommon Applications Access Windows DPAPI Master Key Files
Alerts on unusual process access to Windows DPAPI master key files under Microsoft\Protect.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_accessMedium141Free2022-10-17Windows Credential History File Access by Uncommon Applications
Alerts on CREDHIST file access from unexpected application images, indicating potential credential history theft.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_accessMedium295Free2022-10-17Windows Security Event 5136: msDS-KeyCredentialLink Shadow Credential Added to AD Object
Alerts on AD attribute changes adding to msDS-KeyCredentialLink via Windows Security EventID 5136, consistent with shadow credential additions.
Nasreddine Bencherchali (Nextron Systems), Elastic (idea), Huntrule TeamWindowssecurityHigh246Free2022-10-17macOS XCSSET Execution Indicators via bash-launched curl, osacompile, plutil, or zip
Flags macOS process chains involving bash-driven curl plus osacompile/plutil/zip operations targeting user and Group Containers paths.
Tim Rauch (rule), Elastic (idea), Huntrule TeamMacosprocess_creationMedium482Free2022-10-17macOS Process Execution Traces Indicating WizardUpdate Downloader/C2 Staging
Flags macOS process creations showing curl+eval execution and intermediate agent indicators associated with WizardUpdate activity.
Tim Rauch (rule), Elastic (idea), Huntrule TeamMacosprocess_creationHigh223Free2022-10-17