How it works

HuntRule turns current attacker techniques into expert-reviewed Sigma detection rules that security teams and security products can discover, understand and deploy.

01

Sources

Everything the library is built from arrives here first, continuously: vendor reporting, government advisories and independent research. None of it is a detection yet, and most of it will never need to become one.

Arrives from

  • Vendor reporting
  • Advisories
  • Technical research

What we commit to

A detection library is worth only the claims it is willing to be held to. These are ours.

  • Every published rule names the reporting it came from.
  • Telemetry requirements and known limitations are stated, not implied.
  • Reviewed and validated are distinct statuses and are never conflated.
  • Meaningful changes are versioned, and deprecations are announced.
  • No rule is claimed to catch every variant or to work without tuning.

Review catches a great deal. It is not a substitute for your own telemetry.

Treat every rule as a starting point: read the linked source, check that the log source exists in your estate, tune the thresholds, and run it in audit mode before it pages anyone.