Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows: Suspicious Attachment File Created in Outlook Temp Directories
Alerts on creation of risky file types in Outlook attachment temporary folders used during email attachment handling.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh153Free2025-07-22IIS Web Logs: SharePoint ToolPane and spinstall0.aspx CVE-2025-53770 Exploitation Indicators
Alerts on IIS log traffic to SharePoint ToolPane/spinstall0 endpoints with a SignOut referer, matching indicators for CVE-2025-53770 exploitation.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverMedium152Free2025-07-21Windows Process Creation: Indicators of SharePoint spinstall0.aspx Encoded Command Exploitation (CVE-2025-53770)
Alerts on w3wp.exe command lines containing encoded spinstall0.aspx and SharePoint template layout path indicators consistent with CVE-2025-53770 exploitation.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2025-07-21Windows File Creation in SharePoint Web Server Extensions Suggesting ToolShell Drop
Alerts on Windows file creations within SharePoint Web Server Extensions that match suspicious spinstall/debug artifacts linked to CVE-2025-53770.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventCritical341Free2025-07-21Windows: WinRAR/Rar.exe Writing Files to Startup Folder Locations
Alerts on WinRAR/Rar creating files under the Windows Startup folder, a common persistence attempt.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh311Free2025-07-16Windows Scheduled Task Creation via schtasks.exe Using sshd/ssh.exe for Tunnel Setup
Alerts when schtasks.exe creates scheduled tasks that invoke sshd.exe or ssh.exe with tunnel-related arguments.
Rory Duncan, Huntrule TeamWindowsprocess_creationHigh112Free2025-07-14Windows registry delete: remove ShellEx ContextMenuHandlers EPP key for "Scan with Defender"
Alerts when a registry key tied to the Defender “Scan with” context menu is deleted, excluding MsMpEng.exe activity.
Matt Anderson (Huntress), Huntrule TeamWindowsregistry_deleteMedium163Free2025-07-11Windows PowerShell sets Microsoft Defender threat severity default actions to Allow/NoAction
Alerts when PowerShell Set-MpPreference sets Defender threat-severity default actions to Allow or NoAction.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh237Free2025-07-11Windows reg.exe disables Defender WMI Autologger sessions by setting Start to 0
Flags reg.exe changing WMI Autologger Start for DefenderApiLogger/DefenderAuditLogger to 0, impairing ETW security logging.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh111Free2025-07-09Windows Process Execution: Remove Windows Defender Context Menu Registry Keys via reg.exe/PowerShell
Alerts on reg.exe/PowerShell deleting Defender context menu handler registry keys to remove right-click scanning.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh358Free2025-07-09Windows File Events: ADExplorer .dat Snapshot Written by ADExp.exe or ADExplorer.exe
Detects ADExplorer exporting an AD snapshot by writing .dat files on Windows.
Arnim Rupp (Nextron Systems), Thomas Patzke, Huntrule TeamWindowsfile_eventMedium151Free2025-07-09Windows Registry Set: FileFix-style Command Evidence in TypedPaths url1
Flags Windows registry TypedPaths url1 updates containing URL fragments and command/script keywords consistent with FileFix behavior.
Alfie Champion (delivr.to), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh90Free2025-07-05Windows Process Creation: HollowReaper.exe Execution for Process Hollowing
Flags execution of HollowReaper.exe, a process hollowing shellcode launcher associated with stealth payload execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2025-07-01Windows Doppelganger (Doppelanger.exe) LSASS Dump Tool Execution
Alerts on Windows execution of Doppelganger.exe with matching IMPHASH values associated with LSASS dumping.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh254Free2025-07-01Windows: Suspicious regsvr32 invocation by Notepad++ installer referencing NppShell.dll
Alerts when regsvr32 is run silently to register NppShell.dll but the regsvr32 image isn’t from standard Windows system locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2025-06-26