Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,449 rules
Windows: Detect NetExec (nxc.exe) Process Execution with Network Service Commands
Flags Windows execution of NetExec (nxc.exe) when command lines include SMB/RDP/SSH/WinRM/WMI and other protocol keywords.
Chirag Damani, Huntrule TeamWindowsprocess_creationHigh185Free2026-03-29Windows Process Creation: curl Uploads to File-Sharing Domains
Detects curl commands on Windows uploading files to common file sharing/upload domains.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2026-03-29Windows AppLocker Audit-Mode Events Indicate Files Would Have Been Blocked
Alerts on AppLocker audit-only reports that specific apps would have been blocked if enforcement rules were enabled.
heyyanu, Huntrule TeamWindowsapplockerMedium162Free2026-03-26Windows System Restore Registry Modification via PowerShell or reg.exe Command Line
Flags PowerShell/reg.exe command lines modifying Windows System Restore registry keys to disable or restrict recovery.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh315Free2026-03-11Windows Process Creation: Python One-Liners Decoding Base64 via Command Line
Alerts on Windows Python command-line one-liners that import base64 and call decode functions.
Hugh Ryan (HueCodes), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh189Free2026-03-09OpenEDR ssh-shellhost Spawning Cmd or PowerShell With PTY on Windows
Alerts when OpenEDR ssh-shellhost.exe starts cmd.exe or PowerShell with --pty from under ITSMService.exe.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium152Free2026-02-19Suspicious File Creation by OpenEDR ITSMService on Windows
Alerts on Windows file creations by OpenEDR ITSMService.exe when the target ends with common executable or script/archive extensions.
"@kostastsale, Huntrule Team"Windowsfile_eventMedium121Free2026-02-19Windows Process Creation: node.exe Running npx skills add New Agent Skills
Alerts when node.exe invokes the npx skills add flow to install new agent skills on Windows.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamWindowsprocess_creationMedium140Free2026-02-03Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)
Alerts when Notepad++ gup.exe spawns command/scripting or utility processes using suspicious tool keywords on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh477Free2026-02-03Windows File Creation by Notepad++ Updater gup.exe in Uncommon Locations
Alerts on file creations by Notepad++ updater gup.exe when the destination path is uncommon or not in allowed locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh399Free2026-02-03Windows DNS Monitoring: gup.exe Queries to Uncommon Domains
Alerts when Notepad++ gup.exe generates DNS queries to domains outside the approved set.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryMedium384Free2026-02-02Windows Vulnerable Driver Blocklist Disabled via Registry DWORD Setting
Flags registry changes that disable Windows Vulnerable Driver Blocklist (VulnerableDriverBlocklistEnable = 0).
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh901Free2026-01-26Windows Vulnerable Driver Blocklist Registry Tampering via PowerShell or REG.EXE
Flags PowerShell/REG.EXE command lines that change the VulnerableDriverBlocklistEnable registry setting under \Control\CI\Config.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2026-01-26Windows HVCI Registry Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/pwsh or reg.exe command lines modifying HVCI/Hypervisor-enforced code integrity registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh461Free2026-01-26Windows Registry: Alert on Changes to \shell\open\command Targeting Common Malware Paths
Alerts on registry_set events modifying \shell\open\command to point to suspicious temp/user-writable locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setMedium454Free2026-01-24