Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows MeshAgent Remote Access Tool Command Line Execution Indicators
Flags Windows processes invoking MeshAgent with --meshServiceName, indicating potential remote access tool execution.
Norbert Jaśniewicz (AlphaSOC), Huntrule TeamWindowsprocess_creationMedium120Free2025-05-19Windows Impacket-Pattern File Creation: sessionresume_[a-zA-Z]{8} Indicator
Flags Windows file creations of filenames matching Impacket sessionresume pattern ('sessionresume_<8 letters>').
The DFIR Report, IrishDeath, Huntrule TeamWindowsfile_eventHigh172Free2025-05-19Windows WER BugCheck Crash Dump Reporting via Event ID 1001
Flags Windows WER SystemErrorReporting Event ID 1001 entries indicating a crash with bugcheck and dump/report details.
Jason Mull, Huntrule TeamWindowssystemMedium132Free2025-05-12Suspicious Inline JavaScript Execution by Node.js (node.exe) on Windows
Flags Windows command lines where node.exe is used with JavaScript execution indicators and module keywords consistent with malicious activity.
Microsoft (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium464Free2025-04-21Windows Process Execution of JavaScript via Node.exe
Alerts when node.exe starts a process with a .js argument on Windows, which may indicate suspicious script execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationLow205Free2025-04-21Windows Registry: MiniNt Key Added to Disable Security Event Logging on Reboot
Flags registry set activity that adds the MiniNt key, which stops Windows Event Log from writing events after a reboot.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh101Free2025-04-09Windows Process Creation: Disabling Security Logging via MiniNt Registry Key Set
Flags reg.exe or PowerShell commands that create/modify the MiniNt registry key to impair Windows event logging.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2025-04-09Windows PowerShell History File Access Attempt via ConsoleHost_history.txt
Alerts on Windows process executions whose command line references PowerShell console history files or HistorySavePath.
Luc Génaux, Huntrule TeamWindowsprocess_creationMedium142Free2025-04-03Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators
Alerts on Windows RunMRU registry changes containing HTTP/HTTPS URLs plus captcha/automation or command execution indicators.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh471Free2025-03-25Windows Process Creation: Suspicious LNK Command-Line Whitespace Padding Beyond UI Limit
Alerts when explorer.exe launches a .lnk and the command line contains suspicious whitespace padding used to hide extended arguments.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2025-03-19Windows PowerShell ScriptBlock: Get-ADComputer reconnaissance for unconstrained delegation properties
Flags PowerShell script blocks that query AD computer delegation-related properties using Get-ADComputer-style discovery.
frack113, Huntrule TeamWindowsps_scriptMedium299Free2025-03-05Windows Process Creation: AdFind.exe Execution for Active Directory Recon
Alerts on Windows execution of AdFind.exe based on image/name and known imphash values indicative of AD reconnaissance.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium102Free2025-02-26Windows: Notepad Password File Discovery via Process Creation
Flags explorer-launched Notepad opening files named like password*.{txt,csv,doc,xls} that may contain credentials.
The DFIR Report, Huntrule TeamWindowsprocess_creationLow122Free2025-02-21Suspicious autorun registry modification via WMI wmic spawning reg.exe on Windows
Flags WMIC-driven reg.exe commands that add Run key autorun entries, especially when pointing to suspicious temp/user locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2025-02-17Windows File Events: Suspicious WDAC Policy File Creation by Non-Excluded Processes
Alerts on WDAC-related policy files created under CodeIntegrity, excluding known deployment tools and scripts.
X__Junior, Huntrule TeamWindowsfile_eventMedium165Free2025-02-07