Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,450 rules
Windows Schtasks Execution with Renamed schtasks.exe Binary
Alerts on scheduled task management commands that use a renamed schtasks.exe binary on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh489Free2025-11-27Windows Process Access: WerFaultSecure accessing MsMpEng with dbgcore.dll/dbghelp.dll call traces
Alerts on WerFaultSecure.exe accessing MsMpEng.exe with dbgcore/dbghelp DLLs in the call trace.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh471Free2025-11-27Windows suspicious access to LSASS.exe with dbgcore.dll/dbghelp.dll call trace from uncommon paths
Alerts on suspicious LSASS access from unusual locations when dbgcore.dll or dbghelp.dll appears in the call trace.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh193Free2025-11-27Windows Image Load: dbgcore.dll/dbghelp.dll Loaded from Uncommon User and System Paths
Alerts when dbgcore.dll or dbghelp.dll is loaded from user or other uncommon directories on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsimage_loadHigh142Free2025-11-27Windows Script Interpreter Launching trufflehog or gitleaks Credential Scanner
Flags node.exe or bun.exe spawning trufflehog/gitleaks to perform secret or credential scanning.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh502Free2025-11-25Windows: Suspicious Script/Command Child Processes Spawned by ArcSOC.exe
Alerts when ArcSOC.exe launches cmd/cscript/mshta/powershell/wscript and similar interpreters, indicating potential remote code execution.
Micah Babinski, Huntrule TeamWindowsprocess_creationHigh130Free2025-11-25ArcSOC.exe Creates Suspicious Script/Executable Files on Windows
Alerts when ArcSOC.exe creates files with script/executable extensions such as .exe, .ps1, .aspx, or .bat.
Micah Babinski, Huntrule TeamWindowsfile_eventHigh173Free2025-11-25Windows Process Creation: File Upload Clickfix Lure via Browser to Command Execution
Alerts when browser-launched processes include clickfix-style command markers plus tool and captcha-related terms on Windows.
0xFustang, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh495Free2025-11-24Windows WSASS Process Execution via WerFaultSecure.EXE
Alerts on Windows process creation showing wsass.exe running with WerFaultSecure.exe and a PID-like argument.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh211Free2025-11-23Windows Process: GPME Used to Modify Default Domain and Default Domain Controllers GPOs
Flags MMC launching GPME to target Default Domain/Default Domain Controllers GPO objects by GUID via gpobject.
TropChaud, Huntrule TeamWindowsprocess_creationMedium476Free2025-11-22Windows ImageLoad of Unsigned .node Native Add-on Files
Alerts on Windows loading of unsigned or unverifiable .node files, indicating potential native code execution in Electron-based apps.
Jonathan Beierle (@hullabrian), Huntrule TeamWindowsimage_loadMedium152Free2025-11-22Windows Security Event 5136 for Changes to Default Domain and Default Domain Controllers GPOs
Flags EventID 5136 modifications to Default Domain or Default Domain Controllers GPO containers in Windows AD.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowssecurityMedium4910Free2025-11-22Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Alerts on explorer.exe child process launches with clipboard markers and anti-bot/CAPTCHA-related wording indicating ClickFix/FileFix execution.
montysecurity, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2025-11-19Windows Network Connection Initiated by finger.exe
Alerts on Windows network connections started by finger.exe, an unusual utility that can support remote command retrieval.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh414Free2025-11-19Windows DNS Queries Triggered by finger.exe
Alerts on Windows DNS queries made by finger.exe, a rarely used utility that can be abused to fetch remote commands.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryHigh335Free2025-11-19