huntrule
RulesPricingHow it works

Every published rule

Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.

45 rules

Access
Domain
Severity
  • Suspicious Telegram API Access (via proxy)

    medium

    This rule detects anomalous requests to Telegram API without the usual Telegram User-Agent

    sigmaWeb
    2026-01-18
  • Suspicious Successful IIS Shortname Fuzzing Scan (via webserver)

    medium

    This rule detects when IIS uses an old .Net Framework it's possible to enumerate folders with the symbol "~"

    sigmaWeb
    2026-01-10
  • Download from Suspicious Dyndns Hosts (via proxy)

    medium

    This rule detects download of certain file types from hosts with dynamic DNS names (selected list)

    sigmaWeb
    2026-01-08
  • Suspicious Apache Threading Error (via apache)

    medium

    This rule detects an issue in apache logs that reports threading related errors

    sigmaWeb
    2026-01-05
  • Suspicious Crypto Miner User Agent (via proxy)

    high

    This rule detects anomalous user agent strings used by crypto miners in proxy logs

    sigmaWebPaid
    2026-01-01
  • Previous
  • 1
  • 2
  • 3
  • Next

The threat is new.
Your detection should not be late.

The library is public and free to read. Every rule shows the reporting behind it, the telemetry it needs and where it falls short.

HuntRuleHuntRule

Detection rules built from the latest attacker techniques. Expert-reviewed, source-backed Sigma.

Library

  • All rules
  • Pricing

Project

  • How it works
  • Sign in

Resources

  • Rules API
  • llms.txt
  • Sitemap

Company

  • Contact

© 2026 HuntRule

Validate every rule against your own telemetry before you alert on it.