Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,359 rules
SAP NetViewer Webshell Command Execution via JSP cmd Parameter
Alerts on SAP NetViewer JSP requests likely used as webshells to execute system commands via cmd-style query parameters.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverHigh317Free2025-05-14Suspicious cmd.exe execution from w3wp.exe tied to CentreStack portal.config (Windows process creation)
Alerts when w3wp.exe launches cmd.exe and its command line references \portal\portal.config, suggesting possible IIS app exploitation.
Jason Rathbun (Blackpoint Cyber), Huntrule TeamWindowsprocess_creationHigh3810Free2025-04-17Windows Registry: MiniNt Key Added to Disable Security Event Logging on Reboot
Flags registry set activity that adds the MiniNt key, which stops Windows Event Log from writing events after a reboot.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh121Free2025-04-09Windows Process Creation: Disabling Security Logging via MiniNt Registry Key Set
Flags reg.exe or PowerShell commands that create/modify the MiniNt registry key to impair Windows event logging.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2025-04-09Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators
Alerts on Windows RunMRU registry changes containing HTTP/HTTPS URLs plus captcha/automation or command execution indicators.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh471Free2025-03-25Windows Process Creation: Suspicious LNK Command-Line Whitespace Padding Beyond UI Limit
Alerts when explorer.exe launches a .lnk and the command line contains suspicious whitespace padding used to hide extended arguments.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2025-03-19Suspicious autorun registry modification via WMI wmic spawning reg.exe on Windows
Flags WMIC-driven reg.exe commands that add Run key autorun entries, especially when pointing to suspicious temp/user locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2025-02-17Windows curl.exe SOCKS Proxy and .onion Command-Line Execution
Alerts on Windows curl.exe being run with Tor SOCKS proxy URIs and .onion targets in the command line.
Arda Buyukkaya (EclecticIQ), Huntrule TeamWindowsprocess_creationHigh162Free2025-02-11Windows Scheduled Task Creation Using System Process Names
Flags schtasks.exe /create commands whose arguments reference common Windows system process names.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh319Free2025-02-05Windows MMC Executes Files with RLO-Reversed Extensions in Process Command Line
Alerts when mmc.exe runs with command lines containing RLO-style reversed filename patterns ending in .msc.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh446Free2025-02-05Windows ConHost Spawning Suspicious Script and Command-Line Child Processes
Flags conhost.exe spawning command/scripting utilities like PowerShell, MSHTA, or regsvr32.exe.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh130Free2025-02-05Windows file creation of executable/script files in \Users\Public
Alerts on Windows file creation in \Users\Public\ with potentially malicious script/binary extensions.
The DFIR Report, Huntrule TeamWindowsfile_eventHigh183Free2025-01-23Linux: Shell spawned by rsync without -e flag in command line
Flags rsync/rsyncd spawning a shell when rsync lacks the expected " -e " command-line flag.
Florian Roth, Huntrule TeamLinuxprocess_creationHigh424Free2025-01-18Windows Registry EventLog ChannelAccess SDDL Tampering Detection
Detects registry changes to Windows Event Log ChannelAccess SDDL, which can limit event log visibility or control.
X__Junior, Huntrule TeamWindowsregistry_setHigh181Free2025-01-16M365 Audit: Successful Intune Company Portal login via Cmsi
Flags successful Company Portal (Intune) logins via Cmsi audit events that may indicate Conditional Access bypass attempts.
Josh Nickels, Marius Rothenbücher, Huntrule TeamM365auditHigh472Free2025-01-08