Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,287 rules
BitLocker Feature Activation on Multiple Hosts - Native (via bitlocker)
This rule detects enable or reconfigure BitLocker on multiple hosts for ransomware purposes.
HuntRule TeamWindowsbitlockerHigh50Premium2026-09-02Malicious Brutforce Enumeration on Windows OpenSSH Server with Non Existing User (via security)
This rule detects sSH brutforce a Windows OpenSSH server with non existing users.
HuntRule TeamWindowssecurityHigh50Premium2026-09-02Malicious Massive Remote Service Creation via Named Pipes - Tchopper (via security)
This rule detects uses the Tchopper tool by remotely creating multiple services via named pipes.
HuntRule TeamWindowssecurityHigh30Premium2026-09-01Malicious Audit Policy Disabled by Command Line (via process_creation)
This rule detects disbale or clear the audit policy for defense evasion purposes.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-01Malicious Shared Folder Access with Forged Golden Ticket (via security)
This rule detects used a forged Golden ticket to login on a remote shared folder. Per default or if specified, the ticket will be forged using the builtin administrator account (SID *-500). However, and it frequent cases, a non suspicious user name will be specificied during the forge in order to evade security monitoring. The rule works based on this trick.
HuntRule TeamWindowssecurityHigh50Premium2026-09-01Malicious User Files Dump via Network Share - DonPapi, Lazagne (via security)
This rule detects attempt to dump user profile information via network share.
HuntRule TeamWindowssecurityHigh40Premium2026-09-01Malicious LSASS Credential Dump with LSASSY - Kernel Access (via security)
This rule detects remotely dump LSASS credentials using the LSASSY tool.
HuntRule TeamWindowssecurityHigh60Premium2026-09-01SystemNightmare by GentilKiwi - External Printer Mapped - CVE-2021-1675 / CVE-2021-34527 (via security)
This rule detects exploit the PrintNightmare vulnerability by abusing the Windows print spooler using the service exposed by Gentilkiwi.
HuntRule TeamWindowssecurityHigh60Premium2026-09-01Obfuscated RDP Tunneling Configuration Enabled for Port Forwarding (via process_creation)
This rule detects configure port forwarding on a host to redirect traffic to a C&C target.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-01Malicious Metasploit Reverse Shell Injection in SQL Server (via process_creation)
This rule detects inject a payload into SQL Server in order to obtain a remote shell.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-01Malicious Impacket WMIexec Process Execution (via process_creation)
This rule detects execute WMIexec in order to escalate privileges.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-01Malicious Fortinet APT Group Abuse on Windows - User (via security)
This rule detects scenarios where APT actors exploits Fortinet vulnerabilities to gain access into Windows infrastructure.
HuntRule TeamWindowssecurityHigh60Premium2026-09-01Malicious Service Abuse with Backdoored "command Failure" - Reg via PowerShell (via powershell)
This rule detects modify the configuration of a service to trigger an action when the service is crashed.
HuntRule TeamWindowspowershellHigh80Premium2026-09-01Malicious Rubeus Kerberos Unconstrained Delegation Abuse (via security)
This rule detects abuse Kerberos unconstrained delegation for domain persistence.
HuntRule TeamWindowssecurityHigh60Premium2026-09-01Malicious Stickey Key Called CMD via Command Execution - Hash Detection (via process_creation)
This rule detects calls the stickey key and execute CMD.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-01