Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Suspicious Inline JavaScript Execution by Node.js (node.exe) on Windows
Flags Windows command lines where node.exe is used with JavaScript execution indicators and module keywords consistent with malicious activity.
Microsoft (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium434Free2025-04-21Windows Process Execution of JavaScript via Node.exe
Alerts when node.exe starts a process with a .js argument on Windows, which may indicate suspicious script execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationLow175Free2025-04-21Windows Suspicious .library-ms File Creation by 7z.exe, winrar.exe, or explorer.exe
Alerts on .library-ms file creation triggered by 7z.exe, winrar.exe, or explorer.exe, which may indicate forced-authentication style exploitation.
Gene Kazimiarovich, Huntrule TeamWindowsfile_eventMedium142Free2025-04-20Suspicious cmd.exe execution from w3wp.exe tied to CentreStack portal.config (Windows process creation)
Alerts when w3wp.exe launches cmd.exe and its command line references \portal\portal.config, suggesting possible IIS app exploitation.
Jason Rathbun (Blackpoint Cyber), Huntrule TeamWindowsprocess_creationHigh3610Free2025-04-17Windows: Suspicious child processes spawned by CrushFTP service
Alerts when CrushFTP service (crushftpservice.exe) launches shell/script executables like PowerShell, cmd, mshta, or bash.
Craig Sweeney, Matt Anderson, Jose Oregon, Tim Kasper, Faith Stratton, Samantha Shaw, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium103Free2025-04-10Windows Registry: MiniNt Key Added to Disable Security Event Logging on Reboot
Flags registry set activity that adds the MiniNt key, which stops Windows Event Log from writing events after a reboot.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh81Free2025-04-09Windows Process Creation: Disabling Security Logging via MiniNt Registry Key Set
Flags reg.exe or PowerShell commands that create/modify the MiniNt registry key to impair Windows event logging.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2025-04-09Windows PowerShell History File Access Attempt via ConsoleHost_history.txt
Alerts on Windows process executions whose command line references PowerShell console history files or HistorySavePath.
Luc Génaux, Huntrule TeamWindowsprocess_creationMedium122Free2025-04-03Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators
Alerts on Windows RunMRU registry changes containing HTTP/HTTPS URLs plus captcha/automation or command execution indicators.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh451Free2025-03-25Windows Process Creation: Suspicious LNK Command-Line Whitespace Padding Beyond UI Limit
Alerts when explorer.exe launches a .lnk and the command line contains suspicious whitespace padding used to hide extended arguments.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2025-03-19Windows PowerShell ScriptBlock: Get-ADComputer reconnaissance for unconstrained delegation properties
Flags PowerShell script blocks that query AD computer delegation-related properties using Get-ADComputer-style discovery.
frack113, Huntrule TeamWindowsps_scriptMedium269Free2025-03-05Windows Process Creation: AdFind.exe Execution for Active Directory Recon
Alerts on Windows execution of AdFind.exe based on image/name and known imphash values indicative of AD reconnaissance.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium82Free2025-02-26Zeek HTTP Requests to Low Reputation TLDs or Suspicious File Extensions
Alerts on Zeek HTTP requests to low-reputation TLDs or URIs/MIME types consistent with executable payload delivery.
"@signalblur, Corelight, Huntrule Team"ZeekhttpMedium141Free2025-02-26Windows: Notepad Password File Discovery via Process Creation
Flags explorer-launched Notepad opening files named like password*.{txt,csv,doc,xls} that may contain credentials.
The DFIR Report, Huntrule TeamWindowsprocess_creationLow92Free2025-02-21Windows Image Load: Suspicious ksproxy.ax Loading Suggesting CVE-2024-35250
Flags Windows module loads of ksproxy.ax, a potential indicator of CVE-2024-35250 exploitation attempt activity.
"@eyezuhk Isaac Fernandes, Huntrule Team"Windowsimage_loadMedium193Free2025-02-19