Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows File Creation of wermgr.exe in Uncommon Directory (Potential CVE-2023-36874)
Alerts on wermgr.exe creation in atypical Windows directories that may indicate filename spoofing.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh161Free2023-08-23Windows: Report.wer File Created in Uncommon WER ReportArchive Subfolders
Alerts on Report.wer creation under WER ReportArchive paths that don’t match common subfolder patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium132Free2023-08-23Windows Process Watch: PythonFunctionWarnings Disabled via Excel Security Registry Setting
Flags Excel-related process command lines that disable Python function execution warnings via PythonFunctionWarnings=0.
"@Kostastsale, Huntrule Team"Windowsprocess_creationHigh411Free2023-08-22macOS: In-Memory Download and Compile via curl and osacompile in a Single Command
Alerts when macOS processes include both curl and osacompile, consistent with downloading and compiling payloads.
Sohan G (D4rkCiph3r), Red Canary (idea), Huntrule TeamMacosprocess_creationMedium253Free2023-08-22macOS: JAMF CLI (jamf) execution for account and MDM management
Flags macOS executions of the JAMF CLI with command-line actions tied to account, MDM, and framework changes.
Jay Pandit, Huntrule TeamMacosprocess_creationLow151Free2023-08-22macOS Jamf MDM Suspicious Child Process Execution
Alerts when jamf on macOS spawns bash or sh, which may indicate misuse for command execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamMacosprocess_creationMedium339Free2023-08-22macOS Root Account Enable Attempt via dsenableroot
Detects macOS attempts to enable the root account by running /dsenableroot.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationMedium396Free2023-08-22macOS dseditgroup Used to Add User to admin Group
Flags dseditgroup command lines that edit and add a user to the macOS admin group.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationMedium315Free2023-08-22Linux Process Creation: ESXi User Account Added via esxcli system account add
Alerts when esxcli is used to run an ESXi system account add command, indicating user account creation.
Cedric Maurugeon, Huntrule TeamLinuxprocess_creationMedium93Free2023-08-22Azure Entra ID Riskdetection: Anonymous IP Address sign-in risk events
Detects Azure sign-in risk events labeled as anonymized/anonymous IP addresses.
Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh82Free2023-08-22Windows Process Execution Triggered from WebDAV LNK Paths
Alerts on explorer.exe launching cmd/cscript/mshta/powershell/wscript/pwsh when the command line references a WebDAV \DavWWWRoot\ LNK path.
Micah Babinski, Huntrule TeamWindowsprocess_creationMedium103Free2023-08-21Windows WebDAV Temporary File Creation with Suspicious Extensions
Flags creation of WebDAV temporary files on Windows in a Tfs_DAV temp path with executable/archive-like extensions.
Micah Babinski, Huntrule TeamWindowsfile_eventMedium70Free2023-08-21Windows Registry: New BgInfo UserFields value enabling custom WMI query execution
Alerts on new BgInfo UserFields registry entries that appear to configure a custom WMI query.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium152Free2023-08-16Windows Registry: New BgInfo UserFields value enabling custom VBScript execution
Detects registry changes under BgInfo UserFields that can be configured to run custom VBScript via BgInfo.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium151Free2023-08-16Windows Registry Set: New BgInfo Database Path Value
Detects registry writes under BgInfo database configuration that set a new external database path.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium111Free2023-08-16