Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Detect rclone CLI Activity via Proxy User-Agent Prefix
Flags proxy traffic with a user agent beginning with rclone/v, indicating rclone usage through the proxy.
Janantha Marasinghe, Huntrule TeamWebproxyMedium194Free2022-10-18Windows PowerShell Set-Service SDDL Usage to Hide Services
Flags pwsh Set-Service commands that set a SecurityDescriptorSddl to hide a Windows service from other tools.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-10-17PowerShell Set-Service SecurityDescriptor (DCLCWPDTSD) to Hide Services
Flags PowerShell Set-Service calls that set a SecurityDescriptor SDDL (DCLCWPDTSD) to hide services from other utilities.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh132Free2022-10-17Uncommon Applications Access Windows DPAPI Master Key Files
Alerts on unusual process access to Windows DPAPI master key files under Microsoft\Protect.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_accessMedium141Free2022-10-17Windows Credential History File Access by Uncommon Applications
Alerts on CREDHIST file access from unexpected application images, indicating potential credential history theft.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_accessMedium295Free2022-10-17Windows Security Event 5136: msDS-KeyCredentialLink Shadow Credential Added to AD Object
Alerts on AD attribute changes adding to msDS-KeyCredentialLink via Windows Security EventID 5136, consistent with shadow credential additions.
Nasreddine Bencherchali (Nextron Systems), Elastic (idea), Huntrule TeamWindowssecurityHigh246Free2022-10-17macOS XCSSET Execution Indicators via bash-launched curl, osacompile, plutil, or zip
Flags macOS process chains involving bash-driven curl plus osacompile/plutil/zip operations targeting user and Group Containers paths.
Tim Rauch (rule), Elastic (idea), Huntrule TeamMacosprocess_creationMedium482Free2022-10-17macOS Process Execution Traces Indicating WizardUpdate Downloader/C2 Staging
Flags macOS process creations showing curl+eval execution and intermediate agent indicators associated with WizardUpdate activity.
Tim Rauch (rule), Elastic (idea), Huntrule TeamMacosprocess_creationHigh223Free2022-10-17macOS: Built-in openssl used to base64-decode and decrypt payload from mounted DMG volume
Alerts on OpenSSL base64-decode/decrypt commands using DMG-mounted '/Volumes/' paths on macOS.
Tim Rauch (rule), Elastic (idea), Huntrule TeamMacosprocess_creationMedium427Free2022-10-17Windows process execution: wermgr.exe running outside standard system directories
Alerts when wermgr.exe is launched from a non-standard directory on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh424Free2022-10-14Windows Process Creation: Suspicious Child Process Spawned by Wermgr.EXE
Alerts on suspicious children spawned by wermgr.exe using common execution utilities, with a rundll32 WerConCpl exclusion.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2022-10-14Windows Security Logoff Events (Event ID 4634/4647)
Identifies Windows user logoff using Security Event IDs 4634 and 4647.
frack113, Huntrule TeamWindowssecurityInformational204Free2022-10-14Windows Kerberos Replay Attack Likely Activity on Domain Controllers (Event ID 4649)
Alerts on Windows Security Event 4649 indicating a Kerberos replay error (KRB_AP_ERR_REPEAT).
frack113, Huntrule TeamWindowssecurityHigh429Free2022-10-14Windows Security Event 6423: Device Installation Blocked by Policy
Alerts when Windows blocks a device installation due to enforced system policy (Event ID 6423).
frack113, Huntrule TeamWindowssecurityMedium102Free2022-10-14Windows Security Event Add/Remove Computer Account (4741/4743)
Alerts on Windows domain computer account create/delete activity via Security event 4741 and 4743.
frack113, Huntrule TeamWindowssecurityLow80Free2022-10-14