Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: Detect Advanced Installer PSF AI_STUBS Executables with OriginalFileName popupwrapper.exe
Flags Windows execution of Advanced Installer PSF AI_STUBS stubs where OriginalFileName equals popupwrapper.exe.
Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationLow265Free2025-11-03Windows Registry Add WFP Filter Rules via BFE Parameters Path
Alerts on registry changes adding persistent WFP filters under the BFE policy persistent filter path via svchost.exe.
Frack113, Huntrule TeamWindowsregistry_setMedium142Free2025-10-23Windows SpeechRuntime.exe Child Process Creation
Alerts when SpeechRuntime.exe spawns a child process, highlighting potential abuse for lateral movement on Windows.
andrewdanis, Huntrule TeamWindowsprocess_creationHigh213Free2025-10-23Windows process creation: child process spawned by winrshost.exe
Flags Windows process children of winrshost.exe that may indicate WinRS-driven remote command execution.
Liran Ravich, Huntrule TeamWindowsprocess_creationMedium161Free2025-10-22Windows Winrs.exe Local Command Execution via localhost/loopback
Alerts on Winrs.exe processes running locally by targeting localhost/loopback in /r or /remote.
Liran Ravich, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationHigh307Free2025-10-22Windows Suspicious File Write to Apache/Tomcat webapps ROOT (.jsp) by Web Server Processes
Alerts on .jsp writes into Apache/Tomcat webapps ROOT from dotnet/java/IIS worker processes on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventMedium286Free2025-10-20Windows: ISATAP Router Address Set via Iphlpsvc Event ID 4100
Alerts on Windows events where an ISATAP router address is set via Microsoft-Windows-Iphlpsvc, excluding localhost/null values.
hamid, Huntrule TeamWindowssystemMedium91Free2025-10-19Windows SMB Server Share Connection Without Signing or Encryption
Alert on SMB share connections (IPC$/ADMIN$/C$) where signing and encryption are both reported as disabled.
Mohamed Abdelghani, Huntrule TeamWindowssmbserver-connectivityMedium456Free2025-10-19Windows: Monitor access to Signal Desktop config.json and db.sqlite in AppData\Roaming
Alerts on unauthorized access attempts to Signal Desktop’s config.json (key) and db.sqlite (messages) in the default Roaming path.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowssecurityMedium171Free2025-10-19Windows: Detect baaupdate.exe Spawning Scripting, Admin, or LOLBin Child Processes
Alerts when baaupdate.exe runs typical script/utility processes, an uncommon parent-child execution pattern on Windows.
andrewdanis, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh130Free2025-10-18Windows: Detect Suspicious DLL Loads by BaaUpdate.exe from Publicly Writable Paths
Alerts when BaaUpdate.exe loads DLLs from Temp/Public-type locations associated with DLL search hijacking risk.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsimage_loadHigh131Free2025-10-18Windows Process Execution: Restic Backup Tool Command-Line Indicators
Flags Windows executions where Restic is run with repo init/backup flags or remote storage targets.
Nounou Mbeiri, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2025-10-17WSL Process Execution of Kali Linux on Windows
Flags Kali Linux running under WSL on Windows using process creation image and command-line indicators.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh474Free2025-10-10Windows WSL Kali Linux installation via wsl.exe --install -i
Flags wsl.exe commands that install a distribution specified as Kali Linux using --install -i.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2025-10-10Windows Registry RunMRU Key Deletion
Alerts on deletion of the Windows Run dialog command history (RunMRU) registry key.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh488Free2025-09-25