Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Process Creation: Command-Line Kerberos Coercion Signature via DNS SPN Spoofing
Alerts on Windows command lines containing 'UWhRCA' and 'BAAAA', a signature tied to Kerberos coercion via spoofed credential targeting.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2025-06-20Windows DNS Query with Kerberos Coercion Signature via DNS Object SPN Spoofing
Alerts on Windows DNS queries containing a base64-like credential target signature linked to Kerberos coercion via DNS spoofing.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryHigh435Free2025-06-20Windows AD DNS Record Modification Indicators for Kerberos Coercion via SPN DNS Spoofing
Alerts on AD MicrosoftDNS DNS node changes whose DN contains a CREDENTIAL_TARGET_INFORMATION base64 marker tied to Kerberos coercion.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowssecurityHigh499Free2025-06-20Zeek DNS detects base64 credential target pattern consistent with Kerberos DNS object spoofing
Alert on Zeek DNS queries containing the base64 Kerberos coercion signature pattern tied to CREDENTIAL_TARGET_INFORMATION.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamZeekdnsHigh272Free2025-06-20Windows DLL Load Trusted Path Bypass via Spoofed Directory Paths with Extra Space
Flags Windows DLL loads from spoofed "C:\Windows \\System32"-style paths with an extra space to indicate trusted-path bypass attempts.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsimage_loadHigh306Free2025-06-17Linux: Suspicious curl/wget Download to /tmp or /dev/shm Followed by sh -c Execution
Flags curl/wget retrieving content into /tmp or /dev/shm followed by immediate sh -c execution on Linux.
Aayush Gupta, Huntrule TeamLinuxprocess_creationHigh182Free2025-06-17Windows Process Creation: Possible CVE-2025-33053 WebDAV RCE via utility search-order manipulation
Flags suspicious child execution from WebDAV/UNC paths initiated by iediagcmd.exe or CustomShellHost.exe, consistent with CVE-2025-33053 exploitation.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh205Free2025-06-13Windows Process Access: Suspicious WebDAV target execution via iediagcmd.exe or CustomShellHost.exe (CVE-2025-33053)
Alerts when iediagcmd.exe or CustomShellHost.exe access WebDAV-hosted executables consistent with a potential RCE attempt.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh318Free2025-06-13Windows Process Information Discovery via Registry Queries (reg.exe/powershell)
Flags reg.exe and PowerShell registry queries used to enumerate OS, Defender, installed apps, timezone, and services.
lazarg, Huntrule TeamWindowsprocess_creationLow111Free2025-06-12Windows Process Creation: SharpSuccessor.exe Execution with Impersonation Parameters
Alerts on SharpSuccessor.exe command-line patterns indicative of Windows privilege escalation attempts.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh322Free2025-06-06RegAsm.exe Process Execution Missing Command-Line and Assembly Path (Windows)
Alert on RegAsm.exe process creation when the command line lacks typical Regasm flags or file parameters.
frack113, Huntrule TeamWindowsprocess_creationLow131Free2025-06-04Windows Event Log: MSSQLSERVER$AUDIT alerts on DROP/ TRUNCATE destructive SQL statements
Flags audited MSSQL transactions that include DROP TABLE, DROP DATABASE, or TRUNCATE TABLE.
Daniel Degasperi '@d4ns4n_', Huntrule TeamWindowsapplicationMedium255Free2025-06-04Windows Process Loaded BitsProxy.dll via Uncommon Image
Alert on image loads of BitsProxy.dll by processes outside an allowlist of common Windows BITS-related executables.
UnicornOfHunt, Huntrule TeamWindowsimage_loadLow80Free2025-06-04Windows DNS Queries to Malware Hosting and URL Shortener Domains
Alert on Windows DNS queries to domains tied to URL shorteners and malware hosting services.
Ahmed Nosir (@egycondor), Huntrule TeamWindowsdns_queryMedium219Free2025-06-02Linux mknod Syscall Used to Create Special Files
Flags mknod syscall activity in Linux auditd, indicating special file/device node creation.
Milad Cheraghi, Huntrule TeamLinuxauditdLow71Free2025-05-31