Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Suspicious File Creation by OpenEDR ITSMService on Windows
Alerts on Windows file creations by OpenEDR ITSMService.exe when the target ends with common executable or script/archive extensions.
"@kostastsale, Huntrule Team"Windowsfile_eventMedium121Free2026-02-19Windows Process Creation: node.exe Running npx skills add New Agent Skills
Alerts when node.exe invokes the npx skills add flow to install new agent skills on Windows.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamWindowsprocess_creationMedium140Free2026-02-03Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)
Alerts when Notepad++ gup.exe spawns command/scripting or utility processes using suspicious tool keywords on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh477Free2026-02-03Windows File Creation by Notepad++ Updater gup.exe in Uncommon Locations
Alerts on file creations by Notepad++ updater gup.exe when the destination path is uncommon or not in allowed locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh399Free2026-02-03Windows DNS Monitoring: gup.exe Queries to Uncommon Domains
Alerts when Notepad++ gup.exe generates DNS queries to domains outside the approved set.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryMedium384Free2026-02-02Windows Vulnerable Driver Blocklist Disabled via Registry DWORD Setting
Flags registry changes that disable Windows Vulnerable Driver Blocklist (VulnerableDriverBlocklistEnable = 0).
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh781Free2026-01-26Windows Vulnerable Driver Blocklist Registry Tampering via PowerShell or REG.EXE
Flags PowerShell/REG.EXE command lines that change the VulnerableDriverBlocklistEnable registry setting under \Control\CI\Config.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2026-01-26Windows HVCI Registry Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/pwsh or reg.exe command lines modifying HVCI/Hypervisor-enforced code integrity registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh461Free2026-01-26Windows Registry: Alert on Changes to \shell\open\command Targeting Common Malware Paths
Alerts on registry_set events modifying \shell\open\command to point to suspicious temp/user-writable locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setMedium454Free2026-01-24Windows Registry Modification: OracleOciLib/OracleOciLibPath Under MSDTC for oci.dll Redirection
Alerts on MSDTC MTxOCI registry changes to OracleOciLib/OracleOciLibPath that may redirect oci.dll loading to attacker-controlled locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh171Free2026-01-24Windows cmd.exe Executing start Utility with Hidden Window Flags (/b or /min)
Alerts on cmd.exe invoking start.exe with /b or /min, especially when directed at scripts or files in suspicious temp/public paths.
Vladan Sekulic, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium338Free2026-01-24Windows Registry Query for System Language Using reg.exe
Flags reg.exe registry queries to Control\Nls\Language, indicating system language discovery on Windows.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamWindowsprocess_creationMedium212Free2026-01-09Windows Registry: User Shell Folders Value Modification via reg.exe or PowerShell
Alerts when reg.exe or PowerShell modifies User Shell Folders/Shell Folders Startup-related registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh487Free2026-01-05Windows: Kernel Driver Utility (KDU) and hamakaze.exe Execution
Alerts on KDU/hamakaze.exe launches with command-line parameters associated with kernel driver loading.
Matt Anderson, Dray Agha, Anna Pham (Huntress), Huntrule TeamWindowsprocess_creationHigh463Free2026-01-02Windows devcon.exe Command Line Disabling VMware VMCI Device
Flags devcon.exe command lines that disable VMware VMCI using VMCI PCI ID or VMWVMCIHOSTDEV driver markers.
Matt Anderson, Dray Agha, Anna Pham (Huntress), Huntrule TeamWindowsprocess_creationHigh214Free2026-01-02