Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,360 rules
WSL Process Execution of Kali Linux on Windows
Flags Kali Linux running under WSL on Windows using process creation image and command-line indicators.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh474Free2025-10-10Windows WSL Kali Linux installation via wsl.exe --install -i
Flags wsl.exe commands that install a distribution specified as Kali Linux using --install -i.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh193Free2025-10-10Windows Process Creation: GoAnywhere child command execution indicating possible MFT exploitation
Flags Windows process trees where GoAnywhere Tomcat spawns suspicious cmd/PowerShell command lines consistent with exploitation activity.
MSFT (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh191Free2025-10-07Linux File Creation of /etc/nsswitch.conf in Non-Standard Paths
Flags creation of /etc/nsswitch.conf in non-standard locations that could support privilege escalation.
Swachchhanda Shrawn Poudel (Nextron Systems), Huntrule TeamLinuxfile_eventHigh182Free2025-10-02Windows Registry RunMRU Key Deletion
Alerts on deletion of the Windows Run dialog command history (RunMRU) registry key.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh488Free2025-09-25Windows: Detect reg.exe Deletion of RunMRU Registry Key
Alerts on reg.exe commands that delete the RunMRU registry key, clearing Run dialog command history.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh375Free2025-09-25Windows Process Execution of EDR-Freeze Tool
Flags execution of EDR-Freeze on Windows using image-name and IMPhash matches associated with the tool.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2025-09-24Linux Process Creation: curl Exfiltration from Malicious NPM Package Webhook.site
Alerts on Linux curl command lines using -d to send data to a specific webhook.site endpoint, consistent with exfiltration.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh181Free2025-09-24Linux File Events: Malicious GitHub Workflow File Creation (shai-hulud-workflow*.yml/yaml)
Alerts on new .github/workflows YAML files named for Shai-Hulud, indicating potential malicious GitHub Actions persistence.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxfile_eventHigh497Free2025-09-24Windows Process Creation: WerFaultSecure.exe PPL Tampering with Dump/Impair Parameters
Alerts on WerFaultSecure.exe executions with PPL-related dump/impair command-line parameters that may target sensitive security protections.
Jason (https://github.com/0xbcf), Huntrule TeamWindowsprocess_creationHigh183Free2025-09-23Windows: Suspicious Velociraptor Child Process Execution Indicators
Alerts when Velociraptor.exe spawns specific child processes tied to tunneling, msiexec web installs, or PowerShell download commands.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh334Free2025-08-29Windows PowerShell Uninstall-WindowsFeature/Remove-WindowsFeature Removing Windows-Defender GUI
Detects PowerShell uninstall/removal commands targeting the Windows-Defender GUI feature.
yxinmiracle, Huntrule TeamWindowsprocess_creationHigh196Free2025-08-22Windows File Creation of .funksec Ransom Note Extension
Flags Windows file creations where the new filename ends with .funksec, consistent with FunkLocker-encrypted file naming.
Saiprashanth Pulisetti ( @Prashanthblogs), Huntrule TeamWindowsfile_eventHigh3310Free2025-08-08Windows Process Creation: CrushFTP spawning PowerShell, CMD, and scripting tool execution
Detects CrushFTP launching PowerShell/CMD and related LOLBins with command patterns consistent with RCE exploitation behavior.
Nisarg Suthar, Huntrule TeamWindowsprocess_creationHigh249Free2025-08-01Windows Suspicious File Writes to SharePoint Web Server Extensions Layouts Directory
Alerts on cmd/powershell/w3wp writes of script or web asset files into SharePoint layouts (15/16 TEMPLATE/ LAYOUTS).
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh397Free2025-07-24