Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,363 rules
Linux Script Interpreters Spawning Credential Scanners (trufflehog, gitleaks)
Flags Linux cases where node or bun processes launch trufflehog or gitleaks to search for secrets.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh112Free2025-11-25Windows Process Creation: Bun executes bun_environment.js via node.exe
Flags node.exe spawning bun.exe with a command line containing bun_environment.js and a GitHub runner release download.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh458Free2025-11-25Windows Process Creation: Shai-Hulud String Indicators in Command Line
Alerts on Windows process executions whose command line includes Shai-Hulud indicator strings.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh182Free2025-11-25Linux Bun Runtime Execution: bun_environment.js via node-parent process
Flags /node-launched /bun executions running bun_environment.js with an external runner release download URL.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh228Free2025-11-25Linux Process Creation: Shai-Hulud String Indicators in Command Line
Alerts on Linux process command lines containing Shai-Hulud or SHA1HULUD indicator strings.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh153Free2025-11-25Windows Process Creation: File Upload Clickfix Lure via Browser to Command Execution
Alerts when browser-launched processes include clickfix-style command markers plus tool and captcha-related terms on Windows.
0xFustang, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh495Free2025-11-24Windows WSASS Process Execution via WerFaultSecure.EXE
Alerts on Windows process creation showing wsass.exe running with WerFaultSecure.exe and a PID-like argument.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh211Free2025-11-23Linux File Creation: Filename Contains Embedded Base64 Bash Fragments
Alerts on Linux file events for filenames that appear to embed Base64-decoding bash command patterns.
"@kostastsale, Huntrule Team"Linuxfile_eventHigh131Free2025-11-22macOS Atomic Stealer FileGrabber and curl POST to exfiltrate /tmp/out.zip
Alert on macOS command lines showing FileGrabber from /tmp or curl POST exfiltration with /tmp/out.zip.
Jason Phang Vern - Onn, Robbin Ooi Zhen Heng (Gen Digital), Huntrule TeamMacosprocess_creationHigh387Free2025-11-22macOS File Persistence from Atomic MacOS Stealer (helper file and LaunchDaemon plist)
Flags macOS file creations used as persistence artifacts: per-user .helper files and a specific LaunchDaemon plist.
Jason Phang Vern - Onn, Robbin Ooi Zhen Heng (Gen Digital), Huntrule TeamMacosfile_eventHigh323Free2025-11-22Cisco ASA WebVPN Proxy GET Requests to MacTunnel and csvrloader Paths
Alerts on proxy-observed HTTP GET requests to specific Cisco ASA WebVPN exploit-related URI stems.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—proxyHigh383Free2025-11-20Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Alerts on explorer.exe child process launches with clipboard markers and anti-bot/CAPTCHA-related wording indicating ClickFix/FileFix execution.
montysecurity, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2025-11-19Windows Network Connection Initiated by finger.exe
Alerts on Windows network connections started by finger.exe, an unusual utility that can support remote command retrieval.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh414Free2025-11-19Windows DNS Queries Triggered by finger.exe
Alerts on Windows DNS queries made by finger.exe, a rarely used utility that can be abused to fetch remote commands.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryHigh335Free2025-11-19Windows: Suspicious Kerberos Ticket Requests from PowerShell Using KerberosRequestorSecurityToken
Flags PowerShell command lines that reference KerberosRequestorSecurityToken and .GetRequest() for suspicious Kerberos ticket requests.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2025-11-18