Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Suspicious autorun registry modification via WMI wmic spawning reg.exe on Windows
Flags WMIC-driven reg.exe commands that add Run key autorun entries, especially when pointing to suspicious temp/user locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2025-02-17Windows curl.exe SOCKS Proxy and .onion Command-Line Execution
Alerts on Windows curl.exe being run with Tor SOCKS proxy URIs and .onion targets in the command line.
Arda Buyukkaya (EclecticIQ), Huntrule TeamWindowsprocess_creationHigh142Free2025-02-11Windows File Events: Suspicious WDAC Policy File Creation by Non-Excluded Processes
Alerts on WDAC-related policy files created under CodeIntegrity, excluding known deployment tools and scripts.
X__Junior, Huntrule TeamWindowsfile_eventMedium145Free2025-02-07Windows Scheduled Task Creation Using System Process Names
Flags schtasks.exe /create commands whose arguments reference common Windows system process names.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh269Free2025-02-05Windows Scheduled Task Creation via schtasks.exe with curl and PowerShell Command Line Indicators
Alerts on schtasks.exe task creation commands that simultaneously include curl download indicators and PowerShell execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2025-02-05Windows Process Creation: NimScan.exe Execution via Known File Hashes
Alerts on Windows execution of NimScan.exe when process image and known IMPHASH values match.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium181Free2025-02-05Windows MMC Executes Files with RLO-Reversed Extensions in Process Command Line
Alerts when mmc.exe runs with command lines containing RLO-style reversed filename patterns ending in .msc.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh416Free2025-02-05Windows ConHost Spawning Suspicious Script and Command-Line Child Processes
Flags conhost.exe spawning command/scripting utilities like PowerShell, MSHTA, or regsvr32.exe.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh100Free2025-02-05Windows MMC Loads Script Engine DLLs (vbscript.dll, jscript.dll, jscript9.dll)
Alerts when mmc.exe loads vbscript/jscript script engine DLLs, which can indicate script execution in a trusted process.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsimage_loadMedium454Free2025-02-05Windows file creation of executable/script files in \Users\Public
Alerts on Windows file creation in \Users\Public\ with potentially malicious script/binary extensions.
The DFIR Report, Huntrule TeamWindowsfile_eventHigh143Free2025-01-23Windows: Clfs.sys Loaded from Suspicious Process Image Paths
Alerts when clfs.sys is loaded by a process running from user/temp/perflogs-style suspicious paths on Windows.
X__Junior, Huntrule TeamWindowsimage_loadMedium232Free2025-01-20Linux: Shell spawned by rsync without -e flag in command line
Flags rsync/rsyncd spawning a shell when rsync lacks the expected " -e " command-line flag.
Florian Roth, Huntrule TeamLinuxprocess_creationHigh414Free2025-01-18Windows Registry EventLog ChannelAccess SDDL Tampering Detection
Detects registry changes to Windows Event Log ChannelAccess SDDL, which can limit event log visibility or control.
X__Junior, Huntrule TeamWindowsregistry_setHigh111Free2025-01-16M365 Audit: Successful Intune Company Portal login via Cmsi
Flags successful Company Portal (Intune) logins via Cmsi audit events that may indicate Conditional Access bypass attempts.
Josh Nickels, Marius Rothenbücher, Huntrule TeamM365auditHigh422Free2025-01-08Windows Application Error 1000 with lsass.exe and WLDAP32.dll Indicating LDAP Nightmare Attempt (CVE-2024-49113)
Alerts on Windows Application Error (EventID 1000) showing lsass.exe crashing in WLDAP32.dll—potential CVE-2024-49113 exploitation attempt.
Samuel Monsempes, Huntrule TeamWindowsapplicationHigh123Free2025-01-08