Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,528 rules
Windows PowerShell Uninstall-WindowsFeature/Remove-WindowsFeature Removing Windows-Defender GUI
Detects PowerShell uninstall/removal commands targeting the Windows-Defender GUI feature.
yxinmiracle, Huntrule TeamWindowsprocess_creationHigh196Free2025-08-22VBScript Registry Write Attempt via Wscript.shell RegWrite on Windows
Flags command lines containing Wscript.shell CreateObject and RegWrite, indicating VBScript-driven registry modification attempts.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2025-08-13PowerShell VBScript RegWrite Registry Modification Attempts
Identifies PowerShell commands embedding VBScript Wscript.shell .RegWrite to modify Windows registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptMedium401Free2025-08-13Windows File Creation of .funksec Ransom Note Extension
Flags Windows file creations where the new filename ends with .funksec, consistent with FunkLocker-encrypted file naming.
Saiprashanth Pulisetti ( @Prashanthblogs), Huntrule TeamWindowsfile_eventHigh3310Free2025-08-08DNS Queries to Low-Reputation Effective TLDs (eTLD) via Known Bad TLD List
Alerts on DNS queries targeting domains under known low-reputation eTLD suffixes from an external threat-intel list.
Norbert Jaśniewicz (AlphaSOC), Huntrule Team—dnsMedium120Free2025-08-04Proxy HTTP GET traffic using Hello-World/1.0 user-agent (possible scraper botnet)
Flags proxy GET requests using the Hello-World/1.0 user-agent, which may indicate automated scraping.
Joseph A. M., Huntrule TeamWebproxyMedium224Free2025-08-02Windows Process Creation: CrushFTP spawning PowerShell, CMD, and scripting tool execution
Detects CrushFTP launching PowerShell/CMD and related LOLBins with command patterns consistent with RCE exploitation behavior.
Nisarg Suthar, Huntrule TeamWindowsprocess_creationHigh249Free2025-08-01Windows Reagentc.exe WinRE Disabled via /disable Command-Line Switch
Flags Reagentc.exe executions using /disable to disable Windows Recovery Environment (WinRE).
Daniel Koifman (KoifSec), Michael Vilshin, Huntrule TeamWindowsprocess_creationMedium323Free2025-07-31Windows WMIC Registry Changes via WMI StdRegProv Write Methods
Flags wmic.exe commands invoking WMI StdRegProv to create/delete keys or set registry values.
Daniel Koifman (KoifSec), Huntrule TeamWindowsprocess_creationMedium263Free2025-07-30Windows WMI StdRegProv Registry Enumeration via wmic.exe
Flags wmic.exe usage invoking WMI StdRegProv registry read/enumeration methods for discovery.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium432Free2025-07-30Windows WMI (wmic.exe) Sets User Password to Never Expire
Detects wmic.exe commands that set a Windows account password to never expire via WMI.
Daniel Koifman (KoifSec), Huntrule TeamWindowsprocess_creationMedium111Free2025-07-30Windows Suspicious File Writes to SharePoint Web Server Extensions Layouts Directory
Alerts on cmd/powershell/w3wp writes of script or web asset files into SharePoint layouts (15/16 TEMPLATE/ LAYOUTS).
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh397Free2025-07-24Windows: Suspicious Attachment File Created in Outlook Temp Directories
Alerts on creation of risky file types in Outlook attachment temporary folders used during email attachment handling.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh153Free2025-07-22IIS Web Logs: SharePoint ToolPane and spinstall0.aspx CVE-2025-53770 Exploitation Indicators
Alerts on IIS log traffic to SharePoint ToolPane/spinstall0 endpoints with a SignOut referer, matching indicators for CVE-2025-53770 exploitation.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverMedium162Free2025-07-21Windows Process Creation: Indicators of SharePoint spinstall0.aspx Encoded Command Exploitation (CVE-2025-53770)
Alerts on w3wp.exe command lines containing encoded spinstall0.aspx and SharePoint template layout path indicators consistent with CVE-2025-53770 exploitation.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2025-07-21