Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,451 rules
Windows DNS Queries Triggered by finger.exe
Alerts on Windows DNS queries made by finger.exe, a rarely used utility that can be abused to fetch remote commands.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryHigh335Free2025-11-19Windows: Suspicious Kerberos Ticket Requests from PowerShell Using KerberosRequestorSecurityToken
Flags PowerShell command lines that reference KerberosRequestorSecurityToken and .GetRequest() for suspicious Kerberos ticket requests.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2025-11-18Windows RDP Enable/Disable via Win32_TerminalServiceSetting WMI Tool Commands
Flags WMIC/PowerShell command lines that reference Win32_TerminalServiceSetting SetAllowTSConnections to change RDP.
Daniel Koifman (KoifSec), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium482Free2025-11-15Windows svchost.exe Uncommon Command-Line Parameter Process Creation
Alerts on Windows process starts of svchost.exe that include an uncommon -k parameter format, after excluding common and benign patterns.
Liran Ravich, Huntrule TeamWindowsprocess_creationHigh163Free2025-11-14Windows CMD for /f Tokens= with Recursive Dir Listing
Flags cmd.exe for /f loops using tokens= with recursive dir enumeration in the command line and parent.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationMedium162Free2025-11-12Windows Registry: Suspicious Space-Padded TypedPaths Details String
Alerts on registry writes to TypedPaths url1 where Details includes “#” plus unusual Unicode space padding.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh437Free2025-11-04Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
Alerts on RunMRU registry updates containing '#' plus excessive unusual Unicode spaces that may conceal command text.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh120Free2025-11-04Windows Process Creation: Explorer Command Lines with Unicode Whitespace Padding and '#'
Alerts when Explorer spawns a process with command lines containing long Unicode whitespace padding followed by '#'.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh348Free2025-11-04Windows: Detect Advanced Installer PSF AI_STUBS Executables with OriginalFileName popupwrapper.exe
Flags Windows execution of Advanced Installer PSF AI_STUBS stubs where OriginalFileName equals popupwrapper.exe.
Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationLow275Free2025-11-03Windows Registry Add WFP Filter Rules via BFE Parameters Path
Alerts on registry changes adding persistent WFP filters under the BFE policy persistent filter path via svchost.exe.
Frack113, Huntrule TeamWindowsregistry_setMedium142Free2025-10-23Windows SpeechRuntime.exe Child Process Creation
Alerts when SpeechRuntime.exe spawns a child process, highlighting potential abuse for lateral movement on Windows.
andrewdanis, Huntrule TeamWindowsprocess_creationHigh213Free2025-10-23Windows process creation: child process spawned by winrshost.exe
Flags Windows process children of winrshost.exe that may indicate WinRS-driven remote command execution.
Liran Ravich, Huntrule TeamWindowsprocess_creationMedium161Free2025-10-22Windows Winrs.exe Local Command Execution via localhost/loopback
Alerts on Winrs.exe processes running locally by targeting localhost/loopback in /r or /remote.
Liran Ravich, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationHigh307Free2025-10-22Windows Suspicious File Write to Apache/Tomcat webapps ROOT (.jsp) by Web Server Processes
Alerts on .jsp writes into Apache/Tomcat webapps ROOT from dotnet/java/IIS worker processes on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventMedium306Free2025-10-20Windows: ISATAP Router Address Set via Iphlpsvc Event ID 4100
Alerts on Windows events where an ISATAP router address is set via Microsoft-Windows-Iphlpsvc, excluding localhost/null values.
hamid, Huntrule TeamWindowssystemMedium91Free2025-10-19