huntrule
RulesPricingHow it worksAbout

Every published rule

Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.

4 rules

  • Potential Execution of DenoGate Backdoor via Microsoft Teams Delivery

    medium

    Detects suspicious execution of 'deno.exe' with indicators suggesting DenoGate backdoor, particularly when delivered through Microsoft Teams.

    sigmaWindowsPaid
    2026-07-28
  • Suspicious Use of Windows Quick Assist as Observed in UNC6692 Attacks

    medium

    Detects the execution of Quick Assist, as leveraged by UNC6692 for post-phishing IT impersonation and lateral movement.

    sigmaWindowsPaid
    2026-07-28
  • Potential Unauthorized Use of ATLAS AI SOC Customizations

    medium

    Detects when potentially unauthorized or risky customizations to ATLAS AI-driven SOC response workflows are made, which could indicate adversary abuse of automation.

    sigmaWindowsPaid
    2026-07-28
  • Microsoft Quick Assist Unsolicited Launch

    medium
    sigmaWindowsPaid
    2026-07-28

The threat is new.
Your detection should not be late.

The library is public and free to read. Every rule shows the reporting behind it, the telemetry it needs and where it falls short.

HuntRuleHuntRule

Detection rules built from the latest attacker techniques. Expert-reviewed, source-backed Sigma.

Library

  • All rules
  • Pricing

Project

  • How it works
  • Sign in

Resources

  • Rules API
  • llms.txt
  • Sitemap

Company

  • Contact

© 2026 HuntRule

Validate every rule against your own telemetry before you alert on it.