Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: Detect reg.exe Deletion of RunMRU Registry Key
Alerts on reg.exe commands that delete the RunMRU registry key, clearing Run dialog command history.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh375Free2025-09-25PUA: TruffleHog Execution on Windows via trufflehog.exe Process Launch
Flags Windows execution of trufflehog.exe, especially when targeting common code and collaboration platforms and using --results=verified.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium428Free2025-09-24Windows Process Execution of EDR-Freeze Tool
Flags execution of EDR-Freeze on Windows using image-name and IMPhash matches associated with the tool.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2025-09-24Windows Process Creation: WerFaultSecure.exe PPL Tampering with Dump/Impair Parameters
Alerts on WerFaultSecure.exe executions with PPL-related dump/impair command-line parameters that may target sensitive security protections.
Jason (https://github.com/0xbcf), Huntrule TeamWindowsprocess_creationHigh183Free2025-09-23Windows Process Creation: Command-Line Deletion of IIS Logs
Flags command-line attempts on Windows to delete IIS logs using common deletion utilities and the \inetpub\logs\ path.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium446Free2025-09-02Windows: Suspicious Velociraptor Child Process Execution Indicators
Alerts when Velociraptor.exe spawns specific child processes tied to tunneling, msiexec web installs, or PowerShell download commands.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh334Free2025-08-29Windows PowerShell Uninstall-WindowsFeature/Remove-WindowsFeature Removing Windows-Defender GUI
Detects PowerShell uninstall/removal commands targeting the Windows-Defender GUI feature.
yxinmiracle, Huntrule TeamWindowsprocess_creationHigh196Free2025-08-22VBScript Registry Write Attempt via Wscript.shell RegWrite on Windows
Flags command lines containing Wscript.shell CreateObject and RegWrite, indicating VBScript-driven registry modification attempts.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2025-08-13PowerShell VBScript RegWrite Registry Modification Attempts
Identifies PowerShell commands embedding VBScript Wscript.shell .RegWrite to modify Windows registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptMedium341Free2025-08-13Windows Reagentc.exe WinRE Disabled via /disable Command-Line Switch
Flags Reagentc.exe executions using /disable to disable Windows Recovery Environment (WinRE).
Daniel Koifman (KoifSec), Michael Vilshin, Huntrule TeamWindowsprocess_creationMedium303Free2025-07-31Windows WMIC Registry Changes via WMI StdRegProv Write Methods
Flags wmic.exe commands invoking WMI StdRegProv to create/delete keys or set registry values.
Daniel Koifman (KoifSec), Huntrule TeamWindowsprocess_creationMedium263Free2025-07-30Windows WMI StdRegProv Registry Enumeration via wmic.exe
Flags wmic.exe usage invoking WMI StdRegProv registry read/enumeration methods for discovery.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium432Free2025-07-30Windows WMI (wmic.exe) Sets User Password to Never Expire
Detects wmic.exe commands that set a Windows account password to never expire via WMI.
Daniel Koifman (KoifSec), Huntrule TeamWindowsprocess_creationMedium101Free2025-07-30Windows Suspicious File Writes to SharePoint Web Server Extensions Layouts Directory
Alerts on cmd/powershell/w3wp writes of script or web asset files into SharePoint layouts (15/16 TEMPLATE/ LAYOUTS).
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh397Free2025-07-24Windows: Suspicious Attachment File Created in Outlook Temp Directories
Alerts on creation of risky file types in Outlook attachment temporary folders used during email attachment handling.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh153Free2025-07-22