Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,528 rules
Windows WSASS Process Execution via WerFaultSecure.EXE
Alerts on Windows process creation showing wsass.exe running with WerFaultSecure.exe and a PID-like argument.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh211Free2025-11-23Windows Process: GPME Used to Modify Default Domain and Default Domain Controllers GPOs
Flags MMC launching GPME to target Default Domain/Default Domain Controllers GPO objects by GUID via gpobject.
TropChaud, Huntrule TeamWindowsprocess_creationMedium476Free2025-11-22Windows ImageLoad of Unsigned .node Native Add-on Files
Alerts on Windows loading of unsigned or unverifiable .node files, indicating potential native code execution in Electron-based apps.
Jonathan Beierle (@hullabrian), Huntrule TeamWindowsimage_loadMedium152Free2025-11-22Windows Security Event 5136 for Changes to Default Domain and Default Domain Controllers GPOs
Flags EventID 5136 modifications to Default Domain or Default Domain Controllers GPO containers in Windows AD.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowssecurityMedium4910Free2025-11-22Linux File Creation: Filename Contains Embedded Base64 Bash Fragments
Alerts on Linux file events for filenames that appear to embed Base64-decoding bash command patterns.
"@kostastsale, Huntrule Team"Linuxfile_eventHigh131Free2025-11-22Linux File Creation with Unusually Long Filenames (100+ Characters)
Flags Linux file creations with filenames 100+ characters long, excluding specific known benign system paths, to support threat hunting.
"@kostastsale, Huntrule Team"Linuxfile_eventLow120Free2025-11-22macOS Atomic Stealer FileGrabber and curl POST to exfiltrate /tmp/out.zip
Alert on macOS command lines showing FileGrabber from /tmp or curl POST exfiltration with /tmp/out.zip.
Jason Phang Vern - Onn, Robbin Ooi Zhen Heng (Gen Digital), Huntrule TeamMacosprocess_creationHigh387Free2025-11-22macOS File Persistence from Atomic MacOS Stealer (helper file and LaunchDaemon plist)
Flags macOS file creations used as persistence artifacts: per-user .helper files and a specific LaunchDaemon plist.
Jason Phang Vern - Onn, Robbin Ooi Zhen Heng (Gen Digital), Huntrule TeamMacosfile_eventHigh323Free2025-11-22Cisco ASA WebVPN Proxy GET Requests to MacTunnel and csvrloader Paths
Alerts on proxy-observed HTTP GET requests to specific Cisco ASA WebVPN exploit-related URI stems.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—proxyHigh383Free2025-11-20Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Alerts on explorer.exe child process launches with clipboard markers and anti-bot/CAPTCHA-related wording indicating ClickFix/FileFix execution.
montysecurity, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2025-11-19Windows Network Connection Initiated by finger.exe
Alerts on Windows network connections started by finger.exe, an unusual utility that can support remote command retrieval.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh414Free2025-11-19Windows DNS Queries Triggered by finger.exe
Alerts on Windows DNS queries made by finger.exe, a rarely used utility that can be abused to fetch remote commands.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryHigh335Free2025-11-19Windows: Suspicious Kerberos Ticket Requests from PowerShell Using KerberosRequestorSecurityToken
Flags PowerShell command lines that reference KerberosRequestorSecurityToken and .GetRequest() for suspicious Kerberos ticket requests.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2025-11-18Windows RDP Enable/Disable via Win32_TerminalServiceSetting WMI Tool Commands
Flags WMIC/PowerShell command lines that reference Win32_TerminalServiceSetting SetAllowTSConnections to change RDP.
Daniel Koifman (KoifSec), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium482Free2025-11-15Windows svchost.exe Uncommon Command-Line Parameter Process Creation
Alerts on Windows process starts of svchost.exe that include an uncommon -k parameter format, after excluding common and benign patterns.
Liran Ravich, Huntrule TeamWindowsprocess_creationHigh163Free2025-11-14