Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,148 rules
Windows System Service Control: Obfuscated cmd Launching clip.exe for PowerShell
Flags service creation (Event 7045) with obfuscated cmd ImagePath using clip.exe/clipboard PowerShell execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh60Free2020-10-13Windows Zerologon Exploitation Attempts via Mimikatz or Tools from Kali Host
Identifies Windows Zerologon exploitation attempts tied to Kali-hosted activity and mimikatz-related keywords.
Demyan Sokolin @_drd0c, Teymur Kheirkhabarov @HeirhabarovT, oscd.community, Huntrule TeamWindowssystemCritical479Free2020-10-13Windows Security 4697 Alert for Obfuscated PowerShell Invoke via VAR++ LAUNCHER
Alerts on obfuscated PowerShell launcher patterns in Windows service creation events (EID 4697) consistent with VAR++ LAUNCHER.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssecurityHigh152Free2020-10-13Windows Security Log: Obfuscated cmd Execution of clip.exe via PowerShell Clipboard Patterns (EID 4697)
Alerts on service creation (Windows 4697) with CLIP.exe command-line patterns that indicate obfuscated PowerShell execution.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh143Free2020-10-13macOS Screen Capture via /usr/sbin/screencapture Process Execution
Identifies macOS instances where /usr/sbin/screencapture is executed to collect screenshots.
remotephone, oscd.community, Huntrule TeamMacosprocess_creationLow142Free2020-10-13macOS GUI Credential Prompt Capture via osascript
Flags osascript command lines that script system dialogs referencing authentication and password-related terms.
remotephone, oscd.community, Huntrule TeamMacosprocess_creationLow173Free2020-10-13Linux: Detect dd and truncate used to pad binaries and alter file contents
Flags Linux process executions of dd and truncate consistent with padding binaries to alter on-disk representation.
Igor Fits, oscd.community, Huntrule TeamLinuxauditdHigh101Free2020-10-13Windows Proxy Execution via wuauclt.exe (UpdateDeploymentProvider/RunHandlerComServer)
Alerts when wuauclt.exe is executed with UpdateDeploymentProvider/RunHandlerComServer-related parameters indicative of proxy execution.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Florian Roth (Nextron Systems), Sreeman, FPT.EagleEye Team, Huntrule TeamWindowsprocess_creationHigh238Free2020-10-12Windows WMIC process creation with suspicious command execution
Alerts on WMIC spawning new processes with command-line indicators of common execution/payload binaries on Windows.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2020-10-12Windows regini.exe Used to Modify Registry via Alternate Data Streams (ADS)
Alert on regini.exe process executions whose command line contains an ADS-style colon pattern used for registry modification.
Eli Salem, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh189Free2020-10-12Windows: regedit.exe imports .reg via an alternate data stream (ADS)
Alerts when regedit.exe is used to import a .reg file using an alternate data stream pattern in the command line.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh70Free2020-10-12Windows Regedit Exports Registry Hives to Files
Flags regedit.exe command lines exporting SYSTEM/SAM/SECURITY hives from HKLM to files.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh322Free2020-10-12Windows Process Creation: PowerShell or sc.exe Disabling Windows Defender Behavior Monitoring
Detects PowerShell flags or sc.exe service actions that disable WinDefend monitoring on Windows.
ok @securonix invrep-de, oscd.community, frack113, Huntrule TeamWindowsprocess_creationHigh144Free2020-10-12Windows Indirect Command Execution via Program Compatibility Assistant pcwrun.exe
Alerts on child processes spawned by pcwrun.exe, indicating indirect command execution via Program Compatibility Assistant.
A. Sungurov , oscd.community, Huntrule TeamWindowsprocess_creationLow151Free2020-10-12Detect Obfuscated PowerShell Command Invocation via Stdin on Windows
Flags PowerShell-like command-line patterns indicating obfuscated execution using stdin or input substitution.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh293Free2020-10-12