Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,364 rules
Windows AMSI Disabled by Registry Value Modification (AmsiEnable)
Alerts when Windows Script Settings AmsiEnable is set to 0x00000000 to disable AMSI.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh393Free2025-12-25Windows Process Creation: Registry Modification to Disable ETW AutoLogger via reg.exe or PowerShell
Flags reg.exe or PowerShell registry changes aimed at disabling WMI AutoLogger EventLog session components.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh247Free2025-12-25Windows Process Command-Line Tampering of AMSI Registry Values via reg.exe or PowerShell
Alerts on reg.exe or PowerShell command lines attempting to add/set AMSI enable registry settings.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh140Free2025-12-25Windows File Events: Legitimate Applications Writing Executables to Uncommon Locations
Alerts when selected Windows binaries write files to typically uncommon directories such as Temp, ProgramData, AppData, or system areas.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh193Free2025-12-10Linux process creation: suspicious child processes launched by Node.js server command execution
Flags Linux processes where a Node.js server child-process pattern launches suspicious shell/command tooling.
Swachchhanda Shrawan Poudel (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamLinuxprocess_creationHigh151Free2025-12-05Windows Process Creation: npm install for Shai-Hulud 2.0 Malicious Package Names and Versions
Alert on Windows node.exe running npm install with command-line package/version strings known from the Shai-Hulud 2.0 npm campaign.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2025-11-28Linux Process Creation: npm install of Shai-Hulud 2.0 malicious packages by name and version
Alerts on Linux npm install commands referencing known Shai-Hulud 2.0 malicious package versions.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh192Free2025-11-28Windows Schtasks Execution with Renamed schtasks.exe Binary
Alerts on scheduled task management commands that use a renamed schtasks.exe binary on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh489Free2025-11-27Windows Process Access: WerFaultSecure accessing MsMpEng with dbgcore.dll/dbghelp.dll call traces
Alerts on WerFaultSecure.exe accessing MsMpEng.exe with dbgcore/dbghelp DLLs in the call trace.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh471Free2025-11-27Windows suspicious access to LSASS.exe with dbgcore.dll/dbghelp.dll call trace from uncommon paths
Alerts on suspicious LSASS access from unusual locations when dbgcore.dll or dbghelp.dll appears in the call trace.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh193Free2025-11-27Windows Image Load: dbgcore.dll/dbghelp.dll Loaded from Uncommon User and System Paths
Alerts when dbgcore.dll or dbghelp.dll is loaded from user or other uncommon directories on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsimage_loadHigh142Free2025-11-27AWS CloudTrail GuardDuty Detector Deleted or Disabled via UpdateDetector
Identifies successful GuardDuty detector deletion or disablement from CloudTrail, reducing GuardDuty monitoring coverage.
suktech24, Huntrule TeamAwscloudtrailHigh2010Free2025-11-27Windows Process Creation: Grixba Reconnaissance Tool Command-Line Parameter Combination
Alerts on Windows command lines containing Grixba-like mode/input/scan parameter combinations during reconnaissance.
yxinmiracle, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2025-11-26Windows Script Interpreter Launching trufflehog or gitleaks Credential Scanner
Flags node.exe or bun.exe spawning trufflehog/gitleaks to perform secret or credential scanning.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh502Free2025-11-25Windows: Suspicious Script/Command Child Processes Spawned by ArcSOC.exe
Alerts when ArcSOC.exe launches cmd/cscript/mshta/powershell/wscript and similar interpreters, indicating potential remote code execution.
Micah Babinski, Huntrule TeamWindowsprocess_creationHigh130Free2025-11-25