Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
macOS OSACompile Run-Only Script Execution
Flags osacompile commands on macOS using run-only (-x) with inline script (-e) execution.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationHigh511Free2023-01-31macOS Office Apps Spawning Shell or Scripting Processes
Alerts when Microsoft Office on macOS launches suspicious shell/script or download utilities as child processes.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationHigh289Free2023-01-31macOS JXA In-Memory Execution via osascript JavaScript eval and NSData URL loading
Detects osascript-launched in-memory JXA JavaScript execution patterns using eval and URL-based data loading.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationHigh153Free2023-01-31macOS osascript Clipboard Access via AppleScript Commands
Alerts on osascript commands that reference the system clipboard, which may indicate collection or automation misuse on macOS.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationMedium122Free2023-01-31Linux process copying passwd or shadow from /tmp
Alerts on Linux cp commands that copy /tmp-based passwd or shadow files.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationHigh351Free2023-01-31Windows PowerShell Base64-Encoded WMI Class Invocation
Flags PowerShell command lines containing Base64 fragments indicative of WMI class usage (e.g., ShadowCopy, ScheduledJob) on Windows.
Christian Burkard (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2023-01-30GitHub Audit Log: New Organization Member Added or Invited
Alerts on GitHub org audit events where a member is added or invited to a new or existing organization.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditInformational121Free2023-01-29GitHub Audit: High-Risk Security Controls Disabled
Alerts when GitHub audit logs show advanced security, OAuth restrictions, or 2FA requirements disabled for orgs or repos.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditHigh133Free2023-01-29Windows Registry: Monitor PendingFileRenameOperations changes from suspicious images
Alerts on registry tampering of PendingFileRenameOperations by processes running from suspicious image paths.
frack113, Huntrule TeamWindowsregistry_setMedium71Free2023-01-27GitHub Audit Log: Self-Hosted Runner Configuration Changes
Alerts on GitHub audit log events indicating self-hosted runner registration and runner group configuration changes.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditLow152Free2023-01-27GitHub Audit: Dependabot Alerts and Security Updates Disabled
Flags GitHub audit events where Dependabot alerts or security updates are disabled for an organization or repositories.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditHigh102Free2023-01-27Windows WMIC System Information Discovery via WMIC.EXE Recon
Flags WMIC.EXE executions running system info queries for OS and disk details.
TropChaud, Huntrule TeamWindowsprocess_creationMedium262Free2023-01-26Windows: Suspicious Child Process Spawned by VsCode code.exe
Alerts when code.exe spawns suspicious binaries, script hosts, or command-line activity that matches common execution patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium141Free2023-01-26Windows: Rundll32 Launching NSIS Module for Stealer Capability
Alerts on rundll32.exe execution tied to NSIS module loading indicators (nsis_uns and PrintUIEntry) in the command line.
TropChaud, Huntrule TeamWindowsprocess_creationMedium113Free2023-01-26Linux process: enabling BPF kprobes tracing via /sys/kernel/debug/tracing/events/kprobes
Flags Linux commands that enable BPF kprobes tracing through debugfs and probe enable endpoints in the command line.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium385Free2023-01-25