Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
AWS CloudTrail Detects STS GetCallerIdentity Calls with TruffleHog User-Agent
Identifies TruffleHog-labeled STS GetCallerIdentity calls in AWS CloudTrail, indicating possible AWS key validation or enumeration.
Adan Alvarez @adanalvarez, Huntrule TeamAwscloudtrailMedium271Free2025-10-12Windows: WinSCP Execution from Non-Standard Directory
Flags WinSCP started from a non-default directory on Windows to surface potential portable execution.
frack113, Huntrule TeamWindowsprocess_creationMedium70Free2025-10-12Windows: Winscp CLI FTP/SFTP Open via -command
Detects WinSCP executions with -command and an open request to ftp:// on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium60Free2025-10-12WSL Process Execution of Kali Linux on Windows
Flags Kali Linux running under WSL on Windows using process creation image and command-line indicators.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh444Free2025-10-10Windows WSL Kali Linux installation via wsl.exe --install -i
Flags wsl.exe commands that install a distribution specified as Kali Linux using --install -i.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2025-10-10Windows Process Creation: GoAnywhere child command execution indicating possible MFT exploitation
Flags Windows process trees where GoAnywhere Tomcat spawns suspicious cmd/PowerShell command lines consistent with exploitation activity.
MSFT (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh161Free2025-10-07Linux sudo --chroot Command Execution
Identifies Linux executions of sudo with chroot-related options ("--chroot" or "-R") via process creation command-line telemetry.
Swachchhanda Shrawn Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationLow215Free2025-10-02Linux File Creation of /etc/nsswitch.conf in Non-Standard Paths
Flags creation of /etc/nsswitch.conf in non-standard locations that could support privilege escalation.
Swachchhanda Shrawn Poudel (Nextron Systems), Huntrule TeamLinuxfile_eventHigh142Free2025-10-02Windows Registry RunMRU Key Deletion
Alerts on deletion of the Windows Run dialog command history (RunMRU) registry key.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh458Free2025-09-25Windows: Detect reg.exe Deletion of RunMRU Registry Key
Alerts on reg.exe commands that delete the RunMRU registry key, clearing Run dialog command history.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh345Free2025-09-25PUA: TruffleHog Execution on Windows via trufflehog.exe Process Launch
Flags Windows execution of trufflehog.exe, especially when targeting common code and collaboration platforms and using --results=verified.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium408Free2025-09-24Windows Process Execution of EDR-Freeze Tool
Flags execution of EDR-Freeze on Windows using image-name and IMPhash matches associated with the tool.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2025-09-24Linux Process Execution of TruffleHog with Secret-Scanning Platforms
Flags Linux execution of TruffleHog when command lines reference common source platforms and cloud targets.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium391Free2025-09-24Linux Process Creation: curl Exfiltration from Malicious NPM Package Webhook.site
Alerts on Linux curl command lines using -d to send data to a specific webhook.site endpoint, consistent with exfiltration.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh141Free2025-09-24Linux File Events: Malicious GitHub Workflow File Creation (shai-hulud-workflow*.yml/yaml)
Alerts on new .github/workflows YAML files named for Shai-Hulud, indicating potential malicious GitHub Actions persistence.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxfile_eventHigh437Free2025-09-24