Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,455 rules
Windows PowerShell sets Microsoft Defender threat severity default actions to Allow/NoAction
Alerts when PowerShell Set-MpPreference sets Defender threat-severity default actions to Allow or NoAction.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh267Free2025-07-11Windows reg.exe disables Defender WMI Autologger sessions by setting Start to 0
Flags reg.exe changing WMI Autologger Start for DefenderApiLogger/DefenderAuditLogger to 0, impairing ETW security logging.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh141Free2025-07-09Windows Process Execution: Remove Windows Defender Context Menu Registry Keys via reg.exe/PowerShell
Alerts on reg.exe/PowerShell deleting Defender context menu handler registry keys to remove right-click scanning.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh378Free2025-07-09Windows File Events: ADExplorer .dat Snapshot Written by ADExp.exe or ADExplorer.exe
Detects ADExplorer exporting an AD snapshot by writing .dat files on Windows.
Arnim Rupp (Nextron Systems), Thomas Patzke, Huntrule TeamWindowsfile_eventMedium171Free2025-07-09Windows Registry Set: FileFix-style Command Evidence in TypedPaths url1
Flags Windows registry TypedPaths url1 updates containing URL fragments and command/script keywords consistent with FileFix behavior.
Alfie Champion (delivr.to), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh120Free2025-07-05Windows Process Creation: HollowReaper.exe Execution for Process Hollowing
Flags execution of HollowReaper.exe, a process hollowing shellcode launcher associated with stealth payload execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh223Free2025-07-01Windows Doppelganger (Doppelanger.exe) LSASS Dump Tool Execution
Alerts on Windows execution of Doppelganger.exe with matching IMPHASH values associated with LSASS dumping.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh304Free2025-07-01Windows Process Creation: Command-Line Kerberos Coercion Signature via DNS SPN Spoofing
Alerts on Windows command lines containing 'UWhRCA' and 'BAAAA', a signature tied to Kerberos coercion via spoofed credential targeting.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh193Free2025-06-20Windows DNS Query with Kerberos Coercion Signature via DNS Object SPN Spoofing
Alerts on Windows DNS queries containing a base64-like credential target signature linked to Kerberos coercion via DNS spoofing.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryHigh465Free2025-06-20Windows AD DNS Record Modification Indicators for Kerberos Coercion via SPN DNS Spoofing
Alerts on AD MicrosoftDNS DNS node changes whose DN contains a CREDENTIAL_TARGET_INFORMATION base64 marker tied to Kerberos coercion.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowssecurityHigh539Free2025-06-20Windows DLL Load Trusted Path Bypass via Spoofed Directory Paths with Extra Space
Flags Windows DLL loads from spoofed "C:\Windows \\System32"-style paths with an extra space to indicate trusted-path bypass attempts.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsimage_loadHigh346Free2025-06-17Windows Process Information Discovery via Registry Queries (reg.exe/powershell)
Flags reg.exe and PowerShell registry queries used to enumerate OS, Defender, installed apps, timezone, and services.
lazarg, Huntrule TeamWindowsprocess_creationLow111Free2025-06-12Windows Process Creation: SharpSuccessor.exe Execution with Impersonation Parameters
Alerts on SharpSuccessor.exe command-line patterns indicative of Windows privilege escalation attempts.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh342Free2025-06-06RegAsm.exe Process Execution Missing Command-Line and Assembly Path (Windows)
Alert on RegAsm.exe process creation when the command line lacks typical Regasm flags or file parameters.
frack113, Huntrule TeamWindowsprocess_creationLow181Free2025-06-04Windows Event Log: MSSQLSERVER$AUDIT alerts on DROP/ TRUNCATE destructive SQL statements
Flags audited MSSQL transactions that include DROP TABLE, DROP DATABASE, or TRUNCATE TABLE.
Daniel Degasperi '@d4ns4n_', Huntrule TeamWindowsapplicationMedium275Free2025-06-04