Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,365 rules
Windows Vulnerable Driver Blocklist Disabled via Registry DWORD Setting
Flags registry changes that disable Windows Vulnerable Driver Blocklist (VulnerableDriverBlocklistEnable = 0).
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh901Free2026-01-26Windows Vulnerable Driver Blocklist Registry Tampering via PowerShell or REG.EXE
Flags PowerShell/REG.EXE command lines that change the VulnerableDriverBlocklistEnable registry setting under \Control\CI\Config.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2026-01-26Windows HVCI Registry Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/pwsh or reg.exe command lines modifying HVCI/Hypervisor-enforced code integrity registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh461Free2026-01-26Windows Registry Modification: OracleOciLib/OracleOciLibPath Under MSDTC for oci.dll Redirection
Alerts on MSDTC MTxOCI registry changes to OracleOciLib/OracleOciLibPath that may redirect oci.dll loading to attacker-controlled locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh241Free2026-01-24OpenCanary RDP New Connection Attempt on Application Logtype 14001
Alerts on OpenCanary logging a new RDP connection attempt (logtype 14001), indicating remote access probing.
Marco Pedrinazzi (@pedrinazziM), Huntrule TeamOpencanaryapplicationHigh447Free2026-01-06OpenCanary Application Logs: Detect SYN Port Scan Targets on a Hosted Node
Flags OpenCanary events indicating the host was probed with a TCP SYN port scan.
Marco Pedrinazzi (@pedrinazziM), Huntrule TeamOpencanaryapplicationHigh103Free2026-01-06OpenCanary application logs: detect NMAP XMAS scans targeting an OpenCanary node
Detects OpenCanary log events showing an Nmap Xmas scan targeting the monitored node.
Marco Pedrinazzi (@pedrinazziM), Huntrule TeamOpencanaryapplicationHigh382Free2026-01-06OpenCanary: Detect NMAP OS Scan Targets via Application Logtype 5002
Alerts when OpenCanary records an NMAP OS scan event (logtype 5002), indicating host fingerprinting activity.
Marco Pedrinazzi (@pedrinazziM), Huntrule TeamOpencanaryapplicationHigh4210Free2026-01-06OpenCanary - Nmap NULL Scan Targeting Detected
Detects OpenCanary logtype 5003 events consistent with NMAP NULL scan targeting.
Marco Pedrinazzi (@pedrinazziM), Huntrule TeamOpencanaryapplicationHigh172Free2026-01-06OpenCanary Application Logs: Nmap FIN Scan Targeting (Logtype 5005)
Detects Nmap FIN scan targeting against an OpenCanary node using application logs with logtype 5005.
Marco Pedrinazzi (@pedrinazziM), Huntrule TeamOpencanaryapplicationHigh124Free2026-01-06Windows Registry: User Shell Folders Value Modification via reg.exe or PowerShell
Alerts when reg.exe or PowerShell modifies User Shell Folders/Shell Folders Startup-related registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh487Free2026-01-05Windows: Kernel Driver Utility (KDU) and hamakaze.exe Execution
Alerts on KDU/hamakaze.exe launches with command-line parameters associated with kernel driver loading.
Matt Anderson, Dray Agha, Anna Pham (Huntress), Huntrule TeamWindowsprocess_creationHigh463Free2026-01-02Windows devcon.exe Command Line Disabling VMware VMCI Device
Flags devcon.exe command lines that disable VMware VMCI using VMCI PCI ID or VMWVMCIHOSTDEV driver markers.
Matt Anderson, Dray Agha, Anna Pham (Huntress), Huntrule TeamWindowsprocess_creationHigh214Free2026-01-02Windows Registry Set: Disable Windows Credential Guard by Zeroing EnableVirtualizationBasedSecurity
Alerts on registry value changes that zero Credential Guard/LSA configuration flags to disable virtualization-based secret protection.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh3310Free2025-12-26Windows Registry Delete of Credential Guard EnableVirtualizationBasedSecurity or LsaCfgFlags
Flags deletion of Credential Guard/LSA-related registry values that may weaken virtualization-based secret protection.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh171Free2025-12-26