Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Potential StyleSmuggler (CVE-2026-75650) Exploitation Attempt - Magento GraphQL Styles Parameter (via webserver)
Detects POST requests to the Magento GraphQL endpoint carrying a styles[...] query parameter, the pattern reported for exploitation of StyleSmuggler (CVE-2026-75650), an unauthenticated remote code execution vulnerability in Magento Open Source and Adobe Commerce 2.4.4 through 2.4.9. A match indicates an exploitation attempt, not confirmed compromise; correlate with implant process and file indicators on the host.
HuntRule TeamWindowswebserverCritical820Free2026-09-10Windows Process: SystemSettingsAdminFlows.exe Used to Disable Windows Defender
Alerts when SystemSettingsAdminFlows.exe is launched with command-line arguments consistent with disabling Windows Defender.
Chirag Damani (KPMG India), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh311Free2026-07-01Failed WMI NTEventLogFile ClearEventLog attempts (Windows WMI Event 5858)
Alerts on WMI errors (Event 5858) tied to attempted NTEventLogFile ClearEventLog calls on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowswmiMedium173Free2026-07-01Windows Process Creation: curl.exe Using NTLM with Empty Username (-u :)
Alerts when curl is run on Windows with --ntlm and empty -u : credentials, a pattern that may leak the current user's NTLMv2 response.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3610Free2026-06-04Windows Print.EXE Sensitive File Dump for Credential Access
Alerts when Print.EXE is executed with arguments targeting ntds.dit, SAM, SECURITY, and SYSTEM files for credential access.
Ayush Anand (Securityinbits), Huntrule TeamWindowsprocess_creationHigh111Free2026-04-28Windows: WMIC service ChangeStartMode sets Manual or Disabled startup type
Detects wmic.exe commands changing a Windows service startup type to Manual or Disabled via ChangeStartMode.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium438Free2026-04-27Windows SFTP.exe Indirect Command Execution via ProxyCommand
Flags SFTP.exe executions that include ProxyCommand=, indicating potential indirect command execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium261Free2026-04-27Windows PUA: MemProcFS memory dump mounting via -device
Detects MemProcFS.exe execution with -device on Windows, consistent with mounting memory dumps for potential credential access.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh414Free2026-04-27Windows HackTool Indicators: NetExec (nxc.exe) PyInstaller Extraction Artifacts
Flags Windows file creation under Temp\_MEI* where NetExec nxc data files are dropped, indicating likely NetExec execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh191Free2026-04-08Windows: Detect NetExec (nxc.exe) Process Execution with Network Service Commands
Flags Windows execution of NetExec (nxc.exe) when command lines include SMB/RDP/SSH/WinRM/WMI and other protocol keywords.
Chirag Damani, Huntrule TeamWindowsprocess_creationHigh175Free2026-03-29Windows Process Creation: curl Uploads to File-Sharing Domains
Detects curl commands on Windows uploading files to common file sharing/upload domains.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2026-03-29Windows AppLocker Audit-Mode Events Indicate Files Would Have Been Blocked
Alerts on AppLocker audit-only reports that specific apps would have been blocked if enforcement rules were enabled.
heyyanu, Huntrule TeamWindowsapplockerMedium162Free2026-03-26Windows System Restore Registry Modification via PowerShell or reg.exe Command Line
Flags PowerShell/reg.exe command lines modifying Windows System Restore registry keys to disable or restrict recovery.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh315Free2026-03-11Windows Process Creation: Python One-Liners Decoding Base64 via Command Line
Alerts on Windows Python command-line one-liners that import base64 and call decode functions.
Hugh Ryan (HueCodes), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh169Free2026-03-09OpenEDR ssh-shellhost Spawning Cmd or PowerShell With PTY on Windows
Alerts when OpenEDR ssh-shellhost.exe starts cmd.exe or PowerShell with --pty from under ITSMService.exe.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium152Free2026-02-19