Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,524 rules
OpenEDR ssh-shellhost Spawning Cmd or PowerShell With PTY on Windows
Alerts when OpenEDR ssh-shellhost.exe starts cmd.exe or PowerShell with --pty from under ITSMService.exe.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium152Free2026-02-19Suspicious File Creation by OpenEDR ITSMService on Windows
Alerts on Windows file creations by OpenEDR ITSMService.exe when the target ends with common executable or script/archive extensions.
"@kostastsale, Huntrule Team"Windowsfile_eventMedium121Free2026-02-19Windows: Suspicious Child Command Execution by SolarWinds WebHelpDesk (WHD)
Alerts on WebHelpDesk (bin) spawning tool-like child processes with download/execution command patterns on Windows.
Huntress Team, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh172Free2026-02-11Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Detects PowerShell script content using Exchange cmdlets to create or update inbox rules with message-manipulation actions.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamWindowsps_scriptMedium130Free2026-02-10Windows Process Creation: node.exe Running npx skills add New Agent Skills
Alerts when node.exe invokes the npx skills add flow to install new agent skills on Windows.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamWindowsprocess_creationMedium140Free2026-02-03Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)
Alerts when Notepad++ gup.exe spawns command/scripting or utility processes using suspicious tool keywords on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh477Free2026-02-03Windows File Creation by Notepad++ Updater gup.exe in Uncommon Locations
Alerts on file creations by Notepad++ updater gup.exe when the destination path is uncommon or not in allowed locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh399Free2026-02-03Windows DNS Monitoring: gup.exe Queries to Uncommon Domains
Alerts when Notepad++ gup.exe generates DNS queries to domains outside the approved set.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryMedium384Free2026-02-02Microsoft 365 inbound suspicious email delivered to Inbox or Junk
Alerts when Defender-labeled suspicious inbound emails are delivered to user Inbox/Junk in Microsoft 365.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamM365auditMedium437Free2026-01-27Windows Vulnerable Driver Blocklist Disabled via Registry DWORD Setting
Flags registry changes that disable Windows Vulnerable Driver Blocklist (VulnerableDriverBlocklistEnable = 0).
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh901Free2026-01-26Windows Vulnerable Driver Blocklist Registry Tampering via PowerShell or REG.EXE
Flags PowerShell/REG.EXE command lines that change the VulnerableDriverBlocklistEnable registry setting under \Control\CI\Config.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2026-01-26Windows HVCI Registry Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/pwsh or reg.exe command lines modifying HVCI/Hypervisor-enforced code integrity registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh461Free2026-01-26Windows Registry: Alert on Changes to \shell\open\command Targeting Common Malware Paths
Alerts on registry_set events modifying \shell\open\command to point to suspicious temp/user-writable locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setMedium454Free2026-01-24Windows Registry Modification: OracleOciLib/OracleOciLibPath Under MSDTC for oci.dll Redirection
Alerts on MSDTC MTxOCI registry changes to OracleOciLib/OracleOciLibPath that may redirect oci.dll loading to attacker-controlled locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh241Free2026-01-24Windows cmd.exe Executing start Utility with Hidden Window Flags (/b or /min)
Alerts on cmd.exe invoking start.exe with /b or /min, especially when directed at scripts or files in suspicious temp/public paths.
Vladan Sekulic, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium338Free2026-01-24