Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,452 rules
Windows PowerShell Uninstall-WindowsFeature/Remove-WindowsFeature Removing Windows-Defender GUI
Detects PowerShell uninstall/removal commands targeting the Windows-Defender GUI feature.
yxinmiracle, Huntrule TeamWindowsprocess_creationHigh196Free2025-08-22VBScript Registry Write Attempt via Wscript.shell RegWrite on Windows
Flags command lines containing Wscript.shell CreateObject and RegWrite, indicating VBScript-driven registry modification attempts.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2025-08-13PowerShell VBScript RegWrite Registry Modification Attempts
Identifies PowerShell commands embedding VBScript Wscript.shell .RegWrite to modify Windows registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptMedium401Free2025-08-13Windows Reagentc.exe WinRE Disabled via /disable Command-Line Switch
Flags Reagentc.exe executions using /disable to disable Windows Recovery Environment (WinRE).
Daniel Koifman (KoifSec), Michael Vilshin, Huntrule TeamWindowsprocess_creationMedium323Free2025-07-31Windows WMIC Registry Changes via WMI StdRegProv Write Methods
Flags wmic.exe commands invoking WMI StdRegProv to create/delete keys or set registry values.
Daniel Koifman (KoifSec), Huntrule TeamWindowsprocess_creationMedium263Free2025-07-30Windows WMI StdRegProv Registry Enumeration via wmic.exe
Flags wmic.exe usage invoking WMI StdRegProv registry read/enumeration methods for discovery.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium432Free2025-07-30Windows WMI (wmic.exe) Sets User Password to Never Expire
Detects wmic.exe commands that set a Windows account password to never expire via WMI.
Daniel Koifman (KoifSec), Huntrule TeamWindowsprocess_creationMedium111Free2025-07-30Windows Suspicious File Writes to SharePoint Web Server Extensions Layouts Directory
Alerts on cmd/powershell/w3wp writes of script or web asset files into SharePoint layouts (15/16 TEMPLATE/ LAYOUTS).
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh397Free2025-07-24Windows: Suspicious Attachment File Created in Outlook Temp Directories
Alerts on creation of risky file types in Outlook attachment temporary folders used during email attachment handling.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh153Free2025-07-22Windows: WinRAR/Rar.exe Writing Files to Startup Folder Locations
Alerts on WinRAR/Rar creating files under the Windows Startup folder, a common persistence attempt.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh341Free2025-07-16Windows Scheduled Task Creation via schtasks.exe Using sshd/ssh.exe for Tunnel Setup
Alerts when schtasks.exe creates scheduled tasks that invoke sshd.exe or ssh.exe with tunnel-related arguments.
Rory Duncan, Huntrule TeamWindowsprocess_creationHigh142Free2025-07-14Windows registry delete: remove ShellEx ContextMenuHandlers EPP key for "Scan with Defender"
Alerts when a registry key tied to the Defender “Scan with” context menu is deleted, excluding MsMpEng.exe activity.
Matt Anderson (Huntress), Huntrule TeamWindowsregistry_deleteMedium193Free2025-07-11Windows PowerShell sets Microsoft Defender threat severity default actions to Allow/NoAction
Alerts when PowerShell Set-MpPreference sets Defender threat-severity default actions to Allow or NoAction.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh267Free2025-07-11Windows reg.exe disables Defender WMI Autologger sessions by setting Start to 0
Flags reg.exe changing WMI Autologger Start for DefenderApiLogger/DefenderAuditLogger to 0, impairing ETW security logging.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh141Free2025-07-09Windows Process Execution: Remove Windows Defender Context Menu Registry Keys via reg.exe/PowerShell
Alerts on reg.exe/PowerShell deleting Defender context menu handler registry keys to remove right-click scanning.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh378Free2025-07-09