Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
macOS dscl Adds User to Admin Group via -append /Groups/admin GroupMembership
Flags dscl commands on macOS that append a user into the local admin group membership.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationMedium2010Free2023-03-19Windows PowerShell File Dropper Activity: Creating Executables or Script Files
Alerts when PowerShell writes .exe/.dll or script-like files, consistent with binary/script staging or dropping.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium131Free2023-03-17Windows svchost.exe Spawning rundll32.exe with WebDav davclnt.dll DavSetCookie
Alerts on svchost.exe launching rundll32.exe to run davclnt.dll DavSetCookie for WebDav over a non-local IP.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2023-03-16Suspicious Proxy Requests to IPFS URLs Containing Email Address
Alerts when proxy request URIs target IPFS and include an email address.
Gavin Knapp, Huntrule TeamWebproxyLow173Free2023-03-16Linux process termination via kill, pkill, killall, or xkill command execution
Flags Linux process executions of kill/pkill/killall/xkill by matching executable image path suffixes.
Tuan Le (NCSGroup), Huntrule TeamLinuxprocess_creationMedium70Free2023-03-16Windows: Outlook querying WebClient/LanmanWorkstation registry network provider keys
Flags Outlook.exe querying HKLM\SYSTEM\Services WebClient/LanmanWorkstation NetworkProvider registry values.
Robert Lee @quantum_cookie, Huntrule TeamWindowssecurityCritical183Free2023-03-16Windows Registry: Hypervisor Enforced Code Integrity Enabled DWORD Set to 0
Alerts when HVCI-related registry values are set to 0, indicating Hypervisor Enforced Code Integrity has been disabled.
Nasreddine Bencherchali (Nextron Systems), Anish Bogati, Huntrule TeamWindowsregistry_setHigh141Free2023-03-14Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Flags Sysinternals ADExplorer running with -snapshot to export an Active Directory database to suspicious local directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2023-03-14Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot
Flags Sysinternals ADExplorer running with "snapshot" to create a local Active Directory database copy.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-03-14Windows AD Structure Export Using ldifde.exe with -f
Flags ldifde.exe executions using -f that indicate Active Directory structure export from a Windows host.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2023-03-14Windows Process Creation: dotnet-dump.exe collect Flag
Flags dotnet-dump.exe executions using the collect parameter, which may indicate memory dumping of sensitive processes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2023-03-14Windows: Detect csvde.exe Active Directory export to CSV
Flags csvde.exe executions on Windows that include -f, consistent with exporting Active Directory data for discovery.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium237Free2023-03-14Windows Registry Event for Potential Qakbot/IceID Persistence Key
Alerts on Windows registry events referencing a specific \\Software\\firm\\soft\\Name key suffix linked to Qakbot/IceID-like activity.
Hieu Tran, Huntrule TeamWindowsregistry_eventHigh132Free2023-03-13Windows Rundll32 Execution Masquerading as Image Files via Image Extensions
Flags rundll32.exe executions whose command line references image file extensions used for DLL masquerading.
Hieu Tran, Huntrule TeamWindowsprocess_creationHigh81Free2023-03-13Windows PowerShell Downloading DLLs via Invoke-WebRequest or Invoke-RestMethod
Alerts on PowerShell using web request cmdlets to download an HTTP DLL to disk.
Florian Roth (Nextron Systems), Hieu Tran, Huntrule TeamWindowsprocess_creationMedium70Free2023-03-13