Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,158 rules
macOS Emond Launch Daemon Rule Install Monitoring via plist and emondClients Paths
Alerts on macOS Emond rule plist or emond client database changes that may indicate persistence setup.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosfile_eventMedium141Free2020-10-23macOS Remote System Discovery via arp or ping enumeration
Identifies macOS arp -a or ping to private/local IP ranges used for remote system enumeration.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationInformational112Free2020-10-22Linux Remote System Discovery via arp and ping Process Execution
Flags Linux arp or ping commands with LAN/loopback/link-local IP range arguments consistent with remote host discovery.
Alejandro Ortuno, oscd.community, Huntrule TeamLinuxprocess_creationLow163Free2020-10-22macOS Network Service Enumeration via nc, netcat, nmap, or telnet
Flags macOS executions of nc/netcat, nmap, or telnet consistent with local or remote service enumeration.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationLow142Free2020-10-21macOS AppleScript Execution via osascript with -e, .scpt, or .js
Flags osascript usage on macOS with -e and script indicators consistent with executing AppleScript.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationMedium80Free2020-10-21Linux: Process Execution of Network Scanning and Recon Tools
Flags Linux process executions of common network scanning/recon utilities based on executable name (and netcat listen flag filtering).
Alejandro Ortuno, oscd.community, Georg Lauenstein (sure[secure]), Huntrule TeamLinuxprocess_creationLow124Free2020-10-21Linux auditd: Network service enumeration via telnet, nmap, or netcat
Alerts when telnet/nmap/netcat-style binaries are executed on Linux via auditd, consistent with service discovery scanning.
Alejandro Ortuno, oscd.community, Huntrule TeamLinuxauditdLow429Free2020-10-21Windows Registry: Detect esentutl.exe activity under VSS service keys
Flags registry changes under VSS service keys when initiated by esentutl.exe, consistent with VSS-related abuse.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_eventHigh132Free2020-10-20Windows: rundll32 Triggering comsvcs.dll MiniDump Against lsass.exe
Detects rundll32 invoking comsvcs.dll to dump lsass.exe via a MiniDump export.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_accessHigh131Free2020-10-20Windows DLL image load: credui.dll loaded by an uncommon process
Detects credui.dll or wincredui.dll being loaded by a process other than common system binaries.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium274Free2020-10-20Windows Event Log Detects Volume Shadow Copy Mounts (HarddiskVolumeShadowCopy, EventID 98)
Alerts when NTFS logs indicate a VSS (HarddiskVolumeShadowCopy) mount using EventID 98.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssystemLow458Free2020-10-20Windows Security: VSSAudit Event Source Registration (Event ID 4904/4905)
Alerts on VSSAudit security event source registration in Windows Security logs using Event IDs 4904/4905.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssecurityInformational3410Free2020-10-20macOS Gatekeeper bypass attempt using xattr to remove com.apple.quarantine
Flags macOS xattr usage that deletes the com.apple.quarantine extended attribute, consistent with a Gatekeeper bypass attempt.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamMacosprocess_creationLow408Free2020-10-19macOS Shutdown/Reboot Command Execution via /shutdown, /reboot, or /halt Paths
Flags macOS process executions ending with shutdown, reboot, or halt indicating possible host power disruption.
Igor Fits, Mikhail Larin, oscd.community, Huntrule TeamMacosprocess_creationInformational235Free2020-10-19macOS System Network Connection Discovery via who, w, last, lsof, or netstat
Flags macOS process executions of who/w/last/lsof/netstat used to discover network or session information.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamMacosprocess_creationInformational171Free2020-10-19