Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Linux sysinfo Syscall for System Information Discovery
Detects auditd-reported sysinfo syscalls on Linux that can indicate system fingerprinting or reconnaissance.
Milad Cheraghi, Huntrule TeamLinuxauditdLow193Free2025-05-30Windows: TacticalRMM Agent Installed with API/Auth Flags Pointing to Remote RMM Server
Alerts when TacticalRMM agent starts with --api/--auth and identity flags consistent with connecting to a configured remote RMM server.
Ahmed Nosir (@egycondor), Huntrule TeamWindowsprocess_creationMedium416Free2025-05-29Windows PowerShell Obfuscated COM MSI Installation via WindowsInstaller.Installer
PowerShell spawning that uses WindowsInstaller.Installer COM with obfuscated strings to call InstallProduct and suppress UI.
Meroujan Antonyan (vx3r), Huntrule TeamWindowsprocess_creationHigh161Free2025-05-27Linux auditd: Clear kernel ring buffer via syslog syscall (action 5/4/6)
Flags auditd syslog syscall actions that clear or suppress kernel ring buffer (dmesg) logs.
Milad Cheraghi, Huntrule TeamLinuxauditdMedium123Free2025-05-27Windows vshadow.exe Proxy Execution via -exec Script/Command
Alerts when vshadow.exe is run with -exec, which can proxy execution of a script or command after shadow copy creation.
David Faiss, Huntrule TeamWindowsprocess_creationMedium4510Free2025-05-26Linux: Disable ASLR via personality syscall or sysctl/randomize_va_space changes
Flags Linux events where ASLR is disabled using the personality syscall or sysctl setting kernel.randomize_va_space=0.
Milad Cheraghi, Huntrule TeamLinuxauditdHigh102Free2025-05-26Windows: New-ADServiceAccount Creates Delegated Service Account in Target OUs
Alerts on PowerShell runs of New-ADServiceAccount to create a delegated service account with -CreateDelegatedServiceAccount and -path.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium90Free2025-05-24Windows PowerShell Modifies dMSA msDS-ManagedAccountPrecededByLink Attributes
Flags PowerShell script content modifying msDS-ManagedAccountPrecededByLink (dMSA link attributes) via AD link changes.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptLow393Free2025-05-24PowerShell dMSA Service Account Creation in Target OUs via New-ADServiceAccount
Alerts on PowerShell creating a delegated service account via New-ADServiceAccount with -CreateDelegatedServiceAccount and -path.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptMedium152Free2025-05-24Linux auditd: Detect writes to /proc/sysrq-trigger or sysrq-related config for Magic SysRq abuse
Alerts on auditd PATH events referencing /sysrq or /sysrq-trigger, indicating possible Linux Magic SysRq abuse.
Milad Cheraghi, Huntrule TeamLinuxauditdMedium436Free2025-05-23Windows reg.exe Registry Save/Export of Third-Party Credential Paths
Alerts on reg.exe save/export commands targeting registry keys tied to third-party credential data.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh182Free2025-05-22Windows: Deno writes files from remote HTTPS content into AppData
Alerts when Deno writes to user AppData while using remote HTTPS download-style paths.
Josh Nickels, Michael Taggart, Huntrule TeamWindowsfile_eventLow429Free2025-05-22Windows File Access to Browser Credential Storage by Non-Browser Processes
Flags non-browser processes reading common browser credential storage files on Windows, indicating potential credential theft.
frack113, X__Junior (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Parth-FourCore, Huntrule TeamWindowsfile_accessLow214Free2025-05-22Windows Security: Kerberos TGT requests with PreAuthType=0 and RC4-HMAC (0x17) to krbtgt
Alerts on krbtgt TGT requests using RC4-HMAC with pre-authentication disabled (PreAuthType=0), consistent with AS-REP roasting attempts.
ANosir, Huntrule TeamWindowssecurityMedium421Free2025-05-22Zeek HTTP: Suspicious User-Agent Containing "katz-ontop"
Alerts on Zeek HTTP sessions whose User-Agent includes "katz-ontop", a potential malware indicator.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamZeekhttpHigh112Free2025-05-22