Detection Rule Index
Sigma and Splunk detection rules, mirrored as metadata plus IntelFusions original rules published in full — each linked to the ATT&CK techniques it covers and the malware it detects.
- Linux Crontab Enumeration SPLUNK
- LOLBAS Network Connection On Uncommon Port SPLUNK
- LOLBAS Rare Network Connection SPLUNK
- Windows AppX Deployment Unsigned Package Installation SIGMA · medium
- Successful MSIX/AppX Package Installation SIGMA · low
- Windows AppX Deployment Full Trust Package Installation SIGMA · medium
- Windows EDRSilencer Custom Outbound Filter Added SPLUNK
- Windows Filtering Platform Filter Added To Block EDR Process SPLUNK
- Python Site Hooks Creation During Package Installation SPLUNK
- Python Network Traffic During Package Build SPLUNK
- Python PYTHONPATH Modification During Package Installation SPLUNK
- Python PTH File Creation During Package Installation SPLUNK
- Windows Wermgr Spawning System Integrity Process SPLUNK
- Windows Phantom DLL Created on Disk SPLUNK
- Windows Defender MpClient.dll Loaded by Non-Defender Process SPLUNK
- Windows Error Report Created in ReportQueue Manually SPLUNK
- Windows Defender Threat Detected on Kernel Object Path SPLUNK
- Windows Alternate Data Stream Created Over Local Share SPLUNK
- Windows Cloud Sensitive File Read Access By Uncommon Process SPLUNK
- New User Account Creation Attempt Via ADSI in CommandLine SIGMA · medium
- PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy SIGMA · low
- New User Account Creation Attempt Via ADSI SIGMA · medium
- Linux Binary Executed from Shared Memory Directory SPLUNK
- Linux Suspicious Staging of Alternate System Files SPLUNK
- Linux Suspicious XDG Autostart SPLUNK
- Linux EFI Bootloader File Deletion SPLUNK
- Windows Network Sniffing Tool Executed SPLUNK
- Linux Shell Pseudo Device Reverse Shell SPLUNK
- Linux Suspicious GCC Invocation Building Init Shared Object SPLUNK
- Windows Dir Piped to Findstr Activity SPLUNK
- Windows Suspicious Child Process of Consent.EXE SPLUNK
- Linux MOTD Script Added SPLUNK
- Linux Possible Nimbuspwn Privilege Escalation SPLUNK
- Linux Possible System Binary Backdoor SPLUNK
- Linux Usermod Root UID Set SPLUNK
- Linux Root Execution of id SPLUNK
- Linux Suspicious Child Process of PostgreSQL SPLUNK
- Linux Ghostscript Exploitation SPLUNK
- Linux Suspicious Privileged Container Execution SPLUNK
- Linux Possible GSM Privilege Escalation SPLUNK
- Linux Suspicious Docker Build Command Execution SPLUNK
- Linux Netcat Outbound Connection SPLUNK
- Linux Possible Bootloader Modification SPLUNK
- Windows Powershell Commands from DNS TXT SPLUNK
- Linux UDEV Rule Created SPLUNK
- Linux Possible Privilege Escalation via PYTHONPATH SPLUNK
- Linux File Creation In System Generator Directory SPLUNK
- Linux Shell History Access Via Command Line Utility SPLUNK
- Linux Suspicious Redis Activity SPLUNK
- Certificate Services Outbound SMB or LDAP Connection SIGMA · high