Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Network Connections Initiated by Processes in C:\Users\Public
Flags outbound network connections initiated by a process whose image path is under C:\Users\Public on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium60Free2024-05-31DarkGate Loader Dropped in C:\Temp via AutoIT Script or autoit3.exe (Windows File Events)
Flags Windows file activity in C:\temp for DarkGate loader staging using .au3 and autoit3.exe artifacts.
Tomasz Dyduch, Josh Nickels, Huntrule TeamWindowsfile_eventMedium101Free2024-05-31macOS: Time Machine Exclusion Added via tmutil addexclusion
Alerts on tmutil commands that add new Time Machine exclusions to skip backing up selected files.
Pratinav Chandra, Huntrule TeamMacosprocess_creationMedium121Free2024-05-29macOS: Disable Time Machine via tmutil
Flags macOS tmutil commands that include disabling Time Machine to stop automated backups.
Pratinav Chandra, Huntrule TeamMacosprocess_creationMedium319Free2024-05-29macOS tmutil Time Machine Backup Deletion Attempts
Flags tmutil executions with delete in the command line that attempt to remove Time Machine backups.
Pratinav Chandra, Huntrule TeamMacosprocess_creationMedium3210Free2024-05-29Suspicious Web Browser Launch from PDF/Office Reader on Windows over HTTP(S)
Alerts when Acrobat/Office/PDF readers launch common browsers with HTTP(S) URLs, excluding known Microsoft and Foxit redirect patterns.
Joseph Kamau, Huntrule TeamWindowsprocess_creationMedium325Free2024-05-27Windows Process Access to Uncommon Target Images Using PROCESS_ALL_ACCESS
Alerts on Windows events granting PROCESS_ALL_ACCESS to processes with uncommon target image filenames.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_accessLow424Free2024-05-27Windows Network Connections to Cloudflared Tunnel Domains
Alerts when a Windows process initiates outbound connections to Cloudflared tunnel domain hostnames.
Kamran Saifullah, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium396Free2024-05-27Windows: File Creation by mysqld.exe With Script/Executable Extensions
Alerts on file creation by mysqld.exe producing .bat/.exe/.ps1/.vbs and other executable or script file types on Windows.
Joseph Kamau, Huntrule TeamWindowsfile_eventHigh153Free2024-05-27MacOS Sysctl Usage for System Discovery (hw., kern., machdep.)
Flags macOS sysctl commands querying hw., kern., or machdep. values for system discovery.
Pratinav Chandra, Huntrule TeamMacosprocess_creationMedium289Free2024-05-27Suspicious Child Process of KeyScrambler.exe on Windows
Alerts on KeyScrambler.exe launching cmd.exe, PowerShell, script hosts, regsvr32, or rundll32 as child processes.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium90Free2024-05-13macOS launchctl Execution of Launch Agent/Daemon
Flags launchctl usage on macOS to submit, load, or start Launch Agents/Daemons, a common persistence mechanism.
Pratinav Chandra, Huntrule TeamMacosprocess_creationMedium308Free2024-05-13PowerShell Start-NetEventSession Script Block Execution Indicating Potential Network Capture (Windows)
Alerts when PowerShell ScriptBlocks reference Start-NetEventSession, indicating potential network packet or event capture.
frack113, Huntrule TeamWindowsps_scriptMedium121Free2024-05-12Windows Registry: UAC PromptOnSecureDesktop Disabled
Detects setting UAC PromptOnSecureDesktop to 0 via Windows registry policy, disabling secure desktop for UAC prompts.
frack113, Huntrule TeamWindowsregistry_setMedium162Free2024-05-10Windows Registry: UAC notification disabled via UACDisableNotify set to DWORD 0x00000001
Alerts on registry changes that disable UAC notifications by setting UACDisableNotify to 0x00000001 on Windows.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium121Free2024-05-10