Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,450 rules
Windows Registry: Alert on Changes to \shell\open\command Targeting Common Malware Paths
Alerts on registry_set events modifying \shell\open\command to point to suspicious temp/user-writable locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setMedium454Free2026-01-24Windows Registry Modification: OracleOciLib/OracleOciLibPath Under MSDTC for oci.dll Redirection
Alerts on MSDTC MTxOCI registry changes to OracleOciLib/OracleOciLibPath that may redirect oci.dll loading to attacker-controlled locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh241Free2026-01-24Windows cmd.exe Executing start Utility with Hidden Window Flags (/b or /min)
Alerts on cmd.exe invoking start.exe with /b or /min, especially when directed at scripts or files in suspicious temp/public paths.
Vladan Sekulic, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium338Free2026-01-24Windows Registry Query for System Language Using reg.exe
Flags reg.exe registry queries to Control\Nls\Language, indicating system language discovery on Windows.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamWindowsprocess_creationMedium212Free2026-01-09Windows Registry: User Shell Folders Value Modification via reg.exe or PowerShell
Alerts when reg.exe or PowerShell modifies User Shell Folders/Shell Folders Startup-related registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh487Free2026-01-05Windows: Kernel Driver Utility (KDU) and hamakaze.exe Execution
Alerts on KDU/hamakaze.exe launches with command-line parameters associated with kernel driver loading.
Matt Anderson, Dray Agha, Anna Pham (Huntress), Huntrule TeamWindowsprocess_creationHigh463Free2026-01-02Windows devcon.exe Command Line Disabling VMware VMCI Device
Flags devcon.exe command lines that disable VMware VMCI using VMCI PCI ID or VMWVMCIHOSTDEV driver markers.
Matt Anderson, Dray Agha, Anna Pham (Huntress), Huntrule TeamWindowsprocess_creationHigh214Free2026-01-02Windows Registry Set: Disable Windows Credential Guard by Zeroing EnableVirtualizationBasedSecurity
Alerts on registry value changes that zero Credential Guard/LSA configuration flags to disable virtualization-based secret protection.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh3310Free2025-12-26Windows Registry Delete of Credential Guard EnableVirtualizationBasedSecurity or LsaCfgFlags
Flags deletion of Credential Guard/LSA-related registry values that may weaken virtualization-based secret protection.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh171Free2025-12-26Windows Credential Guard Registry Key Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/Reg.exe commands that add/modify/delete DeviceGuard/LSA registry values tied to Credential Guard.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh505Free2025-12-26Windows AMSI Disabled by Registry Value Modification (AmsiEnable)
Alerts when Windows Script Settings AmsiEnable is set to 0x00000000 to disable AMSI.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh393Free2025-12-25Windows Process Creation: Registry Modification to Disable ETW AutoLogger via reg.exe or PowerShell
Flags reg.exe or PowerShell registry changes aimed at disabling WMI AutoLogger EventLog session components.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh247Free2025-12-25Windows Process Command-Line Tampering of AMSI Registry Values via reg.exe or PowerShell
Alerts on reg.exe or PowerShell command lines attempting to add/set AMSI enable registry settings.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh140Free2025-12-25Windows File Events: Legitimate Applications Writing Executables to Uncommon Locations
Alerts when selected Windows binaries write files to typically uncommon directories such as Temp, ProgramData, AppData, or system areas.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh193Free2025-12-10Windows GitHub Self-Hosted Runner Execution via Runner.Worker and Runner.Listener
Alerts on Windows process activity from GitHub self-hosted runner Worker/Listener indicating spawnclient or run/configure operations.
Daniel Koifman (KoifSec), Huntrule TeamWindowsprocess_creationMedium202Free2025-11-29