Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
macOS Persistence Attempt Using PlistBuddy to Modify LaunchAgents/LaunchDaemons
Identifies PlistBuddy commands that enable RunAtLoad for LaunchAgents or LaunchDaemons persistence on macOS.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationHigh161Free2023-02-18macOS Installer Scripts Spawning Suspicious Interpreter Child Processes
Alerts when macOS installer scripts (preinstall/postinstall) spawn shell, scripting, osascript, curl, or wget processes.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationMedium112Free2023-02-18Windows Registry Persistence Indicators in Event Viewer Events.asp Links
Flags Windows registry entries that reference Event Viewer Events.asp redirection URLs, excluding known benign svchost/GPO templates.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium151Free2023-02-17Windows suspicious vsstrace.dll image load by uncommon executables
Alert on vsstrace.dll module loads from processes outside common Windows/system paths.
frack113, Huntrule TeamWindowsimage_loadMedium60Free2023-02-17Windows Tomcat Log File Deletion Indicating Possible Forensic Evidence Destruction
Flags Windows file deletions matching Tomcat log paths and common Catalina/localhost access log filename patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteMedium453Free2023-02-16Windows Process Command-Line Containing Unicode Right-to-Left Override (U+202E)
Alerts on Windows process launches with command lines containing Unicode U+202E to support right-to-left text obfuscation.
Micah Babinski, @micahbabinski, Swachchhanda Shrawan Poudel (Nextron Systems), Luc Génaux, Huntrule TeamWindowsprocess_creationHigh82Free2023-02-15Windows: certutil.exe ExportPFX certificate export via -exportPFX flag
Flags certutil.exe executions on Windows that include the -exportPFX argument to export certificate material.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium354Free2023-02-15Windows: certutil.EXE Downloading Files from File-Sharing Domains via Suspicious Flags
Alert when certutil.exe is run with URL/download flags targeting common file-sharing domains.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh120Free2023-02-15Windows certutil.exe Download from Direct IP Using URL/IP-Related Flags
Alerts when certutil.exe is launched with direct-IP download indicators and download-capable certutil flags.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2023-02-15Windows certutil.exe Used to Download Files via Suspicious Command-Line Flags
Alerts on certutil.exe runs with URL/HTTP-related flags indicative of remote file download.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2023-02-15Windows certutil.exe Base64/Hex Decode via -decode or -decodehex Flags
Flags certutil.exe use for decoding base64 or hex data via -decode or -decodehex on Windows.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh122Free2023-02-15Windows: CertOC.exe Loading a DLL from User-Writable Paths via -LoadDLL
Alerts on CertOC.exe using -LoadDLL with DLLs from temp/user-writable directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2023-02-15Windows PowerShell Console History File Deleted (PSReadLine)
Flags deletion of the PowerShell PSReadLine ConsoleHost_history.txt file, which can remove command history evidence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteMedium102Free2023-02-15Windows Event Log EVTX File Deletion in winevt\Logs
Flags deletion of Windows Event Log .evtx files under System32\winevt\Logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteMedium313Free2023-02-15Windows Process Execution of Script Interpreters After Extraction from Compressed Files
Flags parent 7zip/WinRAR/Explorer temp extraction leading to execution of script interpreters such as PowerShell or HTA.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium90Free2023-02-15