Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: WinRAR/Rar.exe Writing Files to Startup Folder Locations
Alerts on WinRAR/Rar creating files under the Windows Startup folder, a common persistence attempt.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh341Free2025-07-16Windows Scheduled Task Creation via schtasks.exe Using sshd/ssh.exe for Tunnel Setup
Alerts when schtasks.exe creates scheduled tasks that invoke sshd.exe or ssh.exe with tunnel-related arguments.
Rory Duncan, Huntrule TeamWindowsprocess_creationHigh142Free2025-07-14Windows registry delete: remove ShellEx ContextMenuHandlers EPP key for "Scan with Defender"
Alerts when a registry key tied to the Defender “Scan with” context menu is deleted, excluding MsMpEng.exe activity.
Matt Anderson (Huntress), Huntrule TeamWindowsregistry_deleteMedium193Free2025-07-11Windows PowerShell sets Microsoft Defender threat severity default actions to Allow/NoAction
Alerts when PowerShell Set-MpPreference sets Defender threat-severity default actions to Allow or NoAction.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh267Free2025-07-11Windows reg.exe disables Defender WMI Autologger sessions by setting Start to 0
Flags reg.exe changing WMI Autologger Start for DefenderApiLogger/DefenderAuditLogger to 0, impairing ETW security logging.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh141Free2025-07-09Windows Process Execution: Remove Windows Defender Context Menu Registry Keys via reg.exe/PowerShell
Alerts on reg.exe/PowerShell deleting Defender context menu handler registry keys to remove right-click scanning.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh368Free2025-07-09Windows File Events: ADExplorer .dat Snapshot Written by ADExp.exe or ADExplorer.exe
Detects ADExplorer exporting an AD snapshot by writing .dat files on Windows.
Arnim Rupp (Nextron Systems), Thomas Patzke, Huntrule TeamWindowsfile_eventMedium171Free2025-07-09Windows Registry Set: FileFix-style Command Evidence in TypedPaths url1
Flags Windows registry TypedPaths url1 updates containing URL fragments and command/script keywords consistent with FileFix behavior.
Alfie Champion (delivr.to), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh100Free2025-07-05Windows Process Creation: HollowReaper.exe Execution for Process Hollowing
Flags execution of HollowReaper.exe, a process hollowing shellcode launcher associated with stealth payload execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh203Free2025-07-01Windows Doppelganger (Doppelanger.exe) LSASS Dump Tool Execution
Alerts on Windows execution of Doppelganger.exe with matching IMPHASH values associated with LSASS dumping.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh304Free2025-07-01Windows Process Creation: Command-Line Kerberos Coercion Signature via DNS SPN Spoofing
Alerts on Windows command lines containing 'UWhRCA' and 'BAAAA', a signature tied to Kerberos coercion via spoofed credential targeting.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh183Free2025-06-20Windows DNS Query with Kerberos Coercion Signature via DNS Object SPN Spoofing
Alerts on Windows DNS queries containing a base64-like credential target signature linked to Kerberos coercion via DNS spoofing.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryHigh465Free2025-06-20Windows AD DNS Record Modification Indicators for Kerberos Coercion via SPN DNS Spoofing
Alerts on AD MicrosoftDNS DNS node changes whose DN contains a CREDENTIAL_TARGET_INFORMATION base64 marker tied to Kerberos coercion.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowssecurityHigh519Free2025-06-20Windows DLL Load Trusted Path Bypass via Spoofed Directory Paths with Extra Space
Flags Windows DLL loads from spoofed "C:\Windows \\System32"-style paths with an extra space to indicate trusted-path bypass attempts.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsimage_loadHigh316Free2025-06-17Windows Process Information Discovery via Registry Queries (reg.exe/powershell)
Flags reg.exe and PowerShell registry queries used to enumerate OS, Defender, installed apps, timezone, and services.
lazarg, Huntrule TeamWindowsprocess_creationLow111Free2025-06-12