Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,530 rules
Windows: WinSCP Execution from Non-Standard Directory
Flags WinSCP started from a non-default directory on Windows to surface potential portable execution.
frack113, Huntrule TeamWindowsprocess_creationMedium120Free2025-10-12Windows: Winscp CLI FTP/SFTP Open via -command
Detects WinSCP executions with -command and an open request to ftp:// on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium90Free2025-10-12WSL Process Execution of Kali Linux on Windows
Flags Kali Linux running under WSL on Windows using process creation image and command-line indicators.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh474Free2025-10-10Windows WSL Kali Linux installation via wsl.exe --install -i
Flags wsl.exe commands that install a distribution specified as Kali Linux using --install -i.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh193Free2025-10-10Windows Process Creation: GoAnywhere child command execution indicating possible MFT exploitation
Flags Windows process trees where GoAnywhere Tomcat spawns suspicious cmd/PowerShell command lines consistent with exploitation activity.
MSFT (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh191Free2025-10-07Linux sudo --chroot Command Execution
Identifies Linux executions of sudo with chroot-related options ("--chroot" or "-R") via process creation command-line telemetry.
Swachchhanda Shrawn Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationLow275Free2025-10-02Linux File Creation of /etc/nsswitch.conf in Non-Standard Paths
Flags creation of /etc/nsswitch.conf in non-standard locations that could support privilege escalation.
Swachchhanda Shrawn Poudel (Nextron Systems), Huntrule TeamLinuxfile_eventHigh182Free2025-10-02Windows Registry RunMRU Key Deletion
Alerts on deletion of the Windows Run dialog command history (RunMRU) registry key.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh488Free2025-09-25Windows: Detect reg.exe Deletion of RunMRU Registry Key
Alerts on reg.exe commands that delete the RunMRU registry key, clearing Run dialog command history.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh375Free2025-09-25PUA: TruffleHog Execution on Windows via trufflehog.exe Process Launch
Flags Windows execution of trufflehog.exe, especially when targeting common code and collaboration platforms and using --results=verified.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium448Free2025-09-24Windows Process Execution of EDR-Freeze Tool
Flags execution of EDR-Freeze on Windows using image-name and IMPhash matches associated with the tool.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2025-09-24Linux Process Execution of TruffleHog with Secret-Scanning Platforms
Flags Linux execution of TruffleHog when command lines reference common source platforms and cloud targets.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium411Free2025-09-24Linux Process Creation: curl Exfiltration from Malicious NPM Package Webhook.site
Alerts on Linux curl command lines using -d to send data to a specific webhook.site endpoint, consistent with exfiltration.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh181Free2025-09-24Linux File Events: Malicious GitHub Workflow File Creation (shai-hulud-workflow*.yml/yaml)
Alerts on new .github/workflows YAML files named for Shai-Hulud, indicating potential malicious GitHub Actions persistence.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxfile_eventHigh497Free2025-09-24Windows Process Creation: WerFaultSecure.exe PPL Tampering with Dump/Impair Parameters
Alerts on WerFaultSecure.exe executions with PPL-related dump/impair command-line parameters that may target sensitive security protections.
Jason (https://github.com/0xbcf), Huntrule TeamWindowsprocess_creationHigh183Free2025-09-23