Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows Process Tree for Axios npm Supply-Chain RAT Droppers (cscript, curl, PowerShell)
Alerts on the Windows process/command-line pattern consistent with the Axios npm compromise execution and C2 fetch.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh363Free2026-04-01Windows File Creation Indicators Linked to Malicious Axios npm Supply-Chain Components
Flags Windows file creation of wt.exe/system.bat and temp .vbs/.ps1 payloads when created by node.exe or powershell.exe.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh81Free2026-04-01Windows System Restore Registry Modification via PowerShell or reg.exe Command Line
Flags PowerShell/reg.exe command lines modifying Windows System Restore registry keys to disable or restrict recovery.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh315Free2026-03-11Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Alerts when PowerShell script blocks reference Exchange inbox/rule cmdlets and forwarding/redirect parameters.
Nasreddine Bencherchali (Nextron Systems), Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamWindowsps_scriptMedium140Free2026-03-01OpenEDR ssh-shellhost Spawning Cmd or PowerShell With PTY on Windows
Alerts when OpenEDR ssh-shellhost.exe starts cmd.exe or PowerShell with --pty from under ITSMService.exe.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium152Free2026-02-19Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Detects PowerShell script content using Exchange cmdlets to create or update inbox rules with message-manipulation actions.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamWindowsps_scriptMedium130Free2026-02-10Windows Vulnerable Driver Blocklist Registry Tampering via PowerShell or REG.EXE
Flags PowerShell/REG.EXE command lines that change the VulnerableDriverBlocklistEnable registry setting under \Control\CI\Config.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2026-01-26Windows HVCI Registry Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/pwsh or reg.exe command lines modifying HVCI/Hypervisor-enforced code integrity registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh461Free2026-01-26Windows Registry: User Shell Folders Value Modification via reg.exe or PowerShell
Alerts when reg.exe or PowerShell modifies User Shell Folders/Shell Folders Startup-related registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh487Free2026-01-05Windows Credential Guard Registry Key Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/Reg.exe commands that add/modify/delete DeviceGuard/LSA registry values tied to Credential Guard.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh505Free2025-12-26Windows Process Creation: Registry Modification to Disable ETW AutoLogger via reg.exe or PowerShell
Flags reg.exe or PowerShell registry changes aimed at disabling WMI AutoLogger EventLog session components.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh247Free2025-12-25Windows Process Command-Line Tampering of AMSI Registry Values via reg.exe or PowerShell
Alerts on reg.exe or PowerShell command lines attempting to add/set AMSI enable registry settings.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh140Free2025-12-25Windows: Suspicious Script/Command Child Processes Spawned by ArcSOC.exe
Alerts when ArcSOC.exe launches cmd/cscript/mshta/powershell/wscript and similar interpreters, indicating potential remote code execution.
Micah Babinski, Huntrule TeamWindowsprocess_creationHigh130Free2025-11-25Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Alerts on explorer.exe child process launches with clipboard markers and anti-bot/CAPTCHA-related wording indicating ClickFix/FileFix execution.
montysecurity, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2025-11-19Windows: Suspicious Kerberos Ticket Requests from PowerShell Using KerberosRequestorSecurityToken
Flags PowerShell command lines that reference KerberosRequestorSecurityToken and .GetRequest() for suspicious Kerberos ticket requests.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2025-11-18