Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Process Creation: WerFaultSecure.exe PPL Tampering with Dump/Impair Parameters
Alerts on WerFaultSecure.exe executions with PPL-related dump/impair command-line parameters that may target sensitive security protections.
Jason (https://github.com/0xbcf), Huntrule TeamWindowsprocess_creationHigh163Free2025-09-23Windows Process Creation: Command-Line Deletion of IIS Logs
Flags command-line attempts on Windows to delete IIS logs using common deletion utilities and the \inetpub\logs\ path.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium406Free2025-09-02Windows: Suspicious Velociraptor Child Process Execution Indicators
Alerts when Velociraptor.exe spawns specific child processes tied to tunneling, msiexec web installs, or PowerShell download commands.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh304Free2025-08-29Windows PowerShell Uninstall-WindowsFeature/Remove-WindowsFeature Removing Windows-Defender GUI
Detects PowerShell uninstall/removal commands targeting the Windows-Defender GUI feature.
yxinmiracle, Huntrule TeamWindowsprocess_creationHigh166Free2025-08-22VBScript Registry Write Attempt via Wscript.shell RegWrite on Windows
Flags command lines containing Wscript.shell CreateObject and RegWrite, indicating VBScript-driven registry modification attempts.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium132Free2025-08-13PowerShell VBScript RegWrite Registry Modification Attempts
Identifies PowerShell commands embedding VBScript Wscript.shell .RegWrite to modify Windows registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptMedium301Free2025-08-13Windows File Creation of .funksec Ransom Note Extension
Flags Windows file creations where the new filename ends with .funksec, consistent with FunkLocker-encrypted file naming.
Saiprashanth Pulisetti ( @Prashanthblogs), Huntrule TeamWindowsfile_eventHigh2810Free2025-08-08DNS Queries to Low-Reputation Effective TLDs (eTLD) via Known Bad TLD List
Alerts on DNS queries targeting domains under known low-reputation eTLD suffixes from an external threat-intel list.
Norbert Jaśniewicz (AlphaSOC), Huntrule Team—dnsMedium60Free2025-08-04Proxy HTTP GET traffic using Hello-World/1.0 user-agent (possible scraper botnet)
Flags proxy GET requests using the Hello-World/1.0 user-agent, which may indicate automated scraping.
Joseph A. M., Huntrule TeamWebproxyMedium194Free2025-08-02Windows Process Creation: CrushFTP spawning PowerShell, CMD, and scripting tool execution
Detects CrushFTP launching PowerShell/CMD and related LOLBins with command patterns consistent with RCE exploitation behavior.
Nisarg Suthar, Huntrule TeamWindowsprocess_creationHigh239Free2025-08-01Windows Reagentc.exe WinRE Disabled via /disable Command-Line Switch
Flags Reagentc.exe executions using /disable to disable Windows Recovery Environment (WinRE).
Daniel Koifman (KoifSec), Michael Vilshin, Huntrule TeamWindowsprocess_creationMedium303Free2025-07-31Windows WMIC Registry Changes via WMI StdRegProv Write Methods
Flags wmic.exe commands invoking WMI StdRegProv to create/delete keys or set registry values.
Daniel Koifman (KoifSec), Huntrule TeamWindowsprocess_creationMedium223Free2025-07-30Windows WMI StdRegProv Registry Enumeration via wmic.exe
Flags wmic.exe usage invoking WMI StdRegProv registry read/enumeration methods for discovery.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium402Free2025-07-30Windows WMI (wmic.exe) Sets User Password to Never Expire
Detects wmic.exe commands that set a Windows account password to never expire via WMI.
Daniel Koifman (KoifSec), Huntrule TeamWindowsprocess_creationMedium81Free2025-07-30Windows Suspicious File Writes to SharePoint Web Server Extensions Layouts Directory
Alerts on cmd/powershell/w3wp writes of script or web asset files into SharePoint layouts (15/16 TEMPLATE/ LAYOUTS).
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh387Free2025-07-24