Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,363 rules
Windows svchost.exe Uncommon Command-Line Parameter Process Creation
Alerts on Windows process starts of svchost.exe that include an uncommon -k parameter format, after excluding common and benign patterns.
Liran Ravich, Huntrule TeamWindowsprocess_creationHigh163Free2025-11-14Windows Registry: Suspicious Space-Padded TypedPaths Details String
Alerts on registry writes to TypedPaths url1 where Details includes “#” plus unusual Unicode space padding.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh437Free2025-11-04Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
Alerts on RunMRU registry updates containing '#' plus excessive unusual Unicode spaces that may conceal command text.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh120Free2025-11-04Windows Process Creation: Explorer Command Lines with Unicode Whitespace Padding and '#'
Alerts when Explorer spawns a process with command lines containing long Unicode whitespace padding followed by '#'.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh348Free2025-11-04Windows Application Logs: Detect WSUS deserialization exploitation via InvalidCastException indicators
Flags WSUS (EventID 7053) application log errors matching invalid cast/object data provider strings indicative of CVE-2025-59287 exploitation.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsapplicationHigh268Free2025-10-31Windows Process Creation: Suspicious cmd.exe or PowerShell Child of WSUS (wsusservice.exe)
Alerts when WSUS/IIS service processes spawn cmd or PowerShell interpreters, indicating potential exploitation and post-exploitation activity.
Huntress Labs, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh216Free2025-10-31Windows SpeechRuntime.exe Child Process Creation
Alerts when SpeechRuntime.exe spawns a child process, highlighting potential abuse for lateral movement on Windows.
andrewdanis, Huntrule TeamWindowsprocess_creationHigh213Free2025-10-23Windows Winrs.exe Local Command Execution via localhost/loopback
Alerts on Winrs.exe processes running locally by targeting localhost/loopback in /r or /remote.
Liran Ravich, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationHigh307Free2025-10-22Windows Process Creation: Commvault qlogin Argument Injection Indicators for Auth Bypass
Alerts on Windows command lines running Commvault qlogin with -localadmin-related markers consistent with argument injection.
X__Junior (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2025-10-20Windows Process: Commvault qoperation.exe JSP Webroot Path Traversal Webshell Drop
Alerts on qoperation.exe commands that use -file to write a .jsp into a webroot path, consistent with a webshell drop.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2025-10-20AWS CloudTrail Detects EC2 DeleteFlowLogs API Calls
Flags successful EC2 DeleteFlowLogs API calls in CloudTrail indicating VPC Flow Logs were removed.
Ivan Saakov, Huntrule TeamAwscloudtrailHigh182Free2025-10-19Windows: Detect baaupdate.exe Spawning Scripting, Admin, or LOLBin Child Processes
Alerts when baaupdate.exe runs typical script/utility processes, an uncommon parent-child execution pattern on Windows.
andrewdanis, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh130Free2025-10-18Windows: Detect Suspicious DLL Loads by BaaUpdate.exe from Publicly Writable Paths
Alerts when BaaUpdate.exe loads DLLs from Temp/Public-type locations associated with DLL search hijacking risk.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsimage_loadHigh131Free2025-10-18Kaspersky Endpoint Security Service Stopped via Command Line on Linux
Flags Linux commands using systemctl/bash/sh to stop Kaspersky (kesl) services, suggesting defense impairment or manual service shutdown.
Milad Cheraghi, Huntrule TeamLinuxprocess_creationHigh219Free2025-10-18AWS KMS Imported Key Material Import or Deletion via CloudTrail
Detects AWS KMS imported key material events in CloudTrail, including import and deletion of imported key material.
toopricey, Huntrule TeamAwscloudtrailHigh143Free2025-10-18