Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
49 rules
Windows Process Creation: npm install for Shai-Hulud 2.0 Malicious Package Names and Versions
Alert on Windows node.exe running npm install with command-line package/version strings known from the Shai-Hulud 2.0 npm campaign.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2025-11-28Linux Process Creation: npm install of Shai-Hulud 2.0 malicious packages by name and version
Alerts on Linux npm install commands referencing known Shai-Hulud 2.0 malicious package versions.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh192Free2025-11-28Linux Process Creation: curl Exfiltration from Malicious NPM Package Webhook.site
Alerts on Linux curl command lines using -d to send data to a specific webhook.site endpoint, consistent with exfiltration.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh151Free2025-09-24Windows: .pth Python Path Configuration File Created in site-packages or venv
Detects creation of Windows Python .pth files in site-packages/venv directories, which can enable code execution or persistence via Python startup.
Andreas Braathen (mnemonic.io), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium110Free2024-04-25macOS Python Site-Packages .pth File Creation
Alerts on new .pth files created under macOS Python site-packages, a mechanism that can execute code at Python startup.
Andreas Braathen (mnemonic.io), Huntrule TeamMacosfile_eventMedium90Free2024-04-25Linux: Detect Python .pth Path Configuration File Creation in site-packages
Alerts on creation of Python .pth files in /lib/python3.X/site-packages on Linux, which can trigger code at Python startup.
Andreas Braathen (mnemonic.io), Huntrule TeamLinuxfile_eventMedium100Free2024-04-25Windows iexpress.exe Creates Self-Extracting Binaries Using SED Files From Suspicious Paths
Flags suspicious use of Windows iexpress.exe to create self-extracting packages via SED directives from uncommon/temp paths.
Joseliyo Sanchez, @Joseliyo_Jstnk, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh245Free2024-02-05Windows: Alerts on Creation of .sed Self-Extraction Directive File
Flags creation of newly created .sed directive files on Windows, which can be used for self-extracting package abuse.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsfile_executable_detectedMedium251Free2024-02-05Windows Process Creation: IExpress.exe Creating Self-Extracting Packages
Identifies IExpress.exe usage to generate self-extracting packages, including makecab.exe involvement and IExpress command-line patterns.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationMedium90Free2024-02-05Windows Process: winget adds new download source via 'source add' with IP/endpoint
Alerts on winget.exe being used to add a new package download source specified by an IP address.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2023-04-17Windows Winget adds HTTP package source
Alerts when winget is used to add a package source pointing to an http:// URL.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2023-04-17Windows: winget.exe adds new download sources via 'source add'
Alerts on winget.exe usage to add new package download sources using 'source add'.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2023-04-17Linux Package Removal via yum, apt, dpkg, or rpm Commands
Detects package uninstall activity on Linux via yum, apt/apt-get, dpkg, or rpm based on command-line removal flags.
Tuan Le (NCSGroup), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationLow2510Free2023-03-09Windows: PowerShell Add-AppxPackage Attempt With -AllowUnsigned for AppX Installation
Detects PowerShell Add-AppxPackage usage with -AllowUnsigned to install unsigned AppX packages.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium447Free2023-01-31Windows PowerShell: Add-AppxPackage with -AllowUnsigned for Unsigned AppX Installation
Flags PowerShell usage of Add-AppxPackage/Add-AppPackage with -AllowUnsigned to install unsigned AppX packages.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium123Free2023-01-31