Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
146 rules
PowerShell Script Block Logging: PowerView cmdlet names match
Alerts when PowerShell ScriptBlockText includes PowerView/PowerSploit reconnaissance cmdlet names tied to domain and access discovery.
Bhabesh Raj, Huntrule TeamWindowsps_scriptHigh2310Free2021-05-18Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns
Alerts on Exchange-focused suspicious Windows command-line activity involving dumping, temp file creation, and compression utilities.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical192Free2021-03-09macOS Remote System Discovery via arp or ping enumeration
Identifies macOS arp -a or ping to private/local IP ranges used for remote system enumeration.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationInformational142Free2020-10-22Linux Remote System Discovery via arp and ping Process Execution
Flags Linux arp or ping commands with LAN/loopback/link-local IP range arguments consistent with remote host discovery.
Alejandro Ortuno, oscd.community, Huntrule TeamLinuxprocess_creationLow163Free2020-10-22Linux auditd: Network service enumeration via telnet, nmap, or netcat
Alerts when telnet/nmap/netcat-style binaries are executed on Linux via auditd, consistent with service discovery scanning.
Alejandro Ortuno, oscd.community, Huntrule TeamLinuxauditdLow479Free2020-10-21macOS System Network Connection Discovery via who, w, last, lsof, or netstat
Flags macOS process executions of who/w/last/lsof/netstat used to discover network or session information.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamMacosprocess_creationInformational211Free2020-10-19macOS Security Software Discovery via grep of Known Security Software Names
Flags /usr/bin/grep on macOS when command lines include identifiers associated with security tools and agents.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamMacosprocess_creationMedium356Free2020-10-19macOS File and Directory Discovery via System Utilities
Detects macOS usage of file, ls -R, find, mdfind, or tree for file/directory enumeration.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamMacosprocess_creationInformational203Free2020-10-19Linux System Network Connections Discovery via who, w, last, lsof, or netstat
Identifies Linux discovery activity using who/w/last/lsof/netstat for enumerating network connections and system state.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamLinuxprocess_creationLow121Free2020-10-19Linux process discovery via grep/egrep searching for security software strings
Alerts when grep/egrep on Linux searches command lines for indicators of security/monitoring tools.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamLinuxprocess_creationLow182Free2020-10-19Linux Process Discovery: find, ls -R, tree, findmnt, and locate executed
Alerts on Linux execution of file/directory discovery utilities like find, tree, findmnt, recursive ls, and mlocate.
Daniil Yugoslavskiy, oscd.community, CheraghiMilad, Huntrule TeamLinuxprocess_creationInformational90Free2020-10-19Windows Process: reg.exe Software Version Discovery via svcVersion Query
Alerts when reg.exe is used to query \Software\ for svcVersion, indicating Windows software version discovery.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationMedium112Free2020-10-16Linux Local Groups Discovery via /groups or /etc/group File Enumeration
Detects Linux commands and utilities used to enumerate local groups and read /etc/group.
Ömer Günal, Alejandro Ortuno, oscd.community, Huntrule TeamLinuxprocess_creationLow379Free2020-10-11Linux System Information Discovery via Common Command-Line Utilities
Flags Linux executions of uname, hostname, uptime, lspci, dmidecode, lscpu, and lsmod for system discovery behavior.
Ömer Günal, oscd.community, Huntrule TeamLinuxprocess_creationInformational243Free2020-10-08Linux System & Hardware Information Discovery via File and Version Reads
Detects Linux file access to BIOS/DMI, hardware model, kernel, and OS release/issue identifiers used for system profiling.
Ömer Günal, oscd.community, Huntrule TeamLinuxauditdInformational2710Free2020-10-08