How it works
HuntRule turns current attacker techniques into expert-reviewed Sigma detection rules that security teams and security products can discover, understand and deploy.
01
Sources
Everything the library is built from arrives here first, continuously: vendor reporting, government advisories and independent research. None of it is a detection yet, and most of it will never need to become one.
Arrives from
- Vendor reporting
- Advisories
- Technical research
What we commit to
A detection library is worth only the claims it is willing to be held to. These are ours.
- Every published rule names the reporting it came from.
- Telemetry requirements and known limitations are stated, not implied.
- Reviewed and validated are distinct statuses and are never conflated.
- Meaningful changes are versioned, and deprecations are announced.
- No rule is claimed to catch every variant or to work without tuning.
Review catches a great deal. It is not a substitute for your own telemetry.
Treat every rule as a starting point: read the linked source, check that the log source exists in your estate, tune the thresholds, and run it in audit mode before it pages anyone.