Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,530 rules
Windows RDP Enable/Disable via Win32_TerminalServiceSetting WMI Tool Commands
Flags WMIC/PowerShell command lines that reference Win32_TerminalServiceSetting SetAllowTSConnections to change RDP.
Daniel Koifman (KoifSec), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium482Free2025-11-15Windows svchost.exe Uncommon Command-Line Parameter Process Creation
Alerts on Windows process starts of svchost.exe that include an uncommon -k parameter format, after excluding common and benign patterns.
Liran Ravich, Huntrule TeamWindowsprocess_creationHigh163Free2025-11-14Windows CMD for /f Tokens= with Recursive Dir Listing
Flags cmd.exe for /f loops using tokens= with recursive dir enumeration in the command line and parent.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationMedium162Free2025-11-12Windows Registry: Suspicious Space-Padded TypedPaths Details String
Alerts on registry writes to TypedPaths url1 where Details includes “#” plus unusual Unicode space padding.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh437Free2025-11-04Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
Alerts on RunMRU registry updates containing '#' plus excessive unusual Unicode spaces that may conceal command text.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh120Free2025-11-04Windows Process Creation: Explorer Command Lines with Unicode Whitespace Padding and '#'
Alerts when Explorer spawns a process with command lines containing long Unicode whitespace padding followed by '#'.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh348Free2025-11-04Windows: Detect Advanced Installer PSF AI_STUBS Executables with OriginalFileName popupwrapper.exe
Flags Windows execution of Advanced Installer PSF AI_STUBS stubs where OriginalFileName equals popupwrapper.exe.
Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationLow275Free2025-11-03FortiGate SSL VPN Settings Edited
Flags FortiGate VPN SSL settings being edited, which may indicate changes to SSL VPN access or authentication configuration.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium212Free2025-11-01FortiGate User Group Modified via Edit Event
Alerts on FortiGate user group edits that can change access permissions, including VPN-related group membership.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium203Free2025-11-01FortiGate: Addition of VPN SSL Web Portal via Event Logs
Detects FortiGate configuration events where a VPN SSL web portal is added.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium496Free2025-11-01FortiGate: Local User Added via CLI Event
Alerts on FortiGate events where a new local user is added under user.local.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium344Free2025-11-01FortiGate: Alert on Added Firewall Policy via Event Log
Flags FortiGate events where a firewall policy is added (action Add on firewall.policy).
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium236Free2025-11-01FortiGate Firewall Address Object Added (event action Add)
Alerts when a FortiGate firewall address object is added via configuration change events.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium101Free2025-11-01FortiGate: Administrator Account Added via system.admin Events
Alerts on FortiGate events that add a new administrator account in system.admin.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium443Free2025-11-01Windows Application Logs: Detect WSUS deserialization exploitation via InvalidCastException indicators
Flags WSUS (EventID 7053) application log errors matching invalid cast/object data provider strings indicative of CVE-2025-59287 exploitation.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsapplicationHigh268Free2025-10-31