Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,528 rules
Windows File Creation in SharePoint Web Server Extensions Suggesting ToolShell Drop
Alerts on Windows file creations within SharePoint Web Server Extensions that match suspicious spinstall/debug artifacts linked to CVE-2025-53770.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventCritical391Free2025-07-21Windows: WinRAR/Rar.exe Writing Files to Startup Folder Locations
Alerts on WinRAR/Rar creating files under the Windows Startup folder, a common persistence attempt.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh341Free2025-07-16Windows Scheduled Task Creation via schtasks.exe Using sshd/ssh.exe for Tunnel Setup
Alerts when schtasks.exe creates scheduled tasks that invoke sshd.exe or ssh.exe with tunnel-related arguments.
Rory Duncan, Huntrule TeamWindowsprocess_creationHigh142Free2025-07-14Windows registry delete: remove ShellEx ContextMenuHandlers EPP key for "Scan with Defender"
Alerts when a registry key tied to the Defender “Scan with” context menu is deleted, excluding MsMpEng.exe activity.
Matt Anderson (Huntress), Huntrule TeamWindowsregistry_deleteMedium193Free2025-07-11Windows PowerShell sets Microsoft Defender threat severity default actions to Allow/NoAction
Alerts when PowerShell Set-MpPreference sets Defender threat-severity default actions to Allow or NoAction.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh267Free2025-07-11Windows reg.exe disables Defender WMI Autologger sessions by setting Start to 0
Flags reg.exe changing WMI Autologger Start for DefenderApiLogger/DefenderAuditLogger to 0, impairing ETW security logging.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh141Free2025-07-09Windows Process Execution: Remove Windows Defender Context Menu Registry Keys via reg.exe/PowerShell
Alerts on reg.exe/PowerShell deleting Defender context menu handler registry keys to remove right-click scanning.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh378Free2025-07-09Windows File Events: ADExplorer .dat Snapshot Written by ADExp.exe or ADExplorer.exe
Detects ADExplorer exporting an AD snapshot by writing .dat files on Windows.
Arnim Rupp (Nextron Systems), Thomas Patzke, Huntrule TeamWindowsfile_eventMedium171Free2025-07-09Windows Registry Set: FileFix-style Command Evidence in TypedPaths url1
Flags Windows registry TypedPaths url1 updates containing URL fragments and command/script keywords consistent with FileFix behavior.
Alfie Champion (delivr.to), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh120Free2025-07-05Windows Process Creation: HollowReaper.exe Execution for Process Hollowing
Flags execution of HollowReaper.exe, a process hollowing shellcode launcher associated with stealth payload execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh223Free2025-07-01Windows Doppelganger (Doppelanger.exe) LSASS Dump Tool Execution
Alerts on Windows execution of Doppelganger.exe with matching IMPHASH values associated with LSASS dumping.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh304Free2025-07-01Windows: Suspicious regsvr32 invocation by Notepad++ installer referencing NppShell.dll
Alerts when regsvr32 is run silently to register NppShell.dll but the regsvr32 image isn’t from standard Windows system locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2025-06-26Windows Process Creation: Command-Line Kerberos Coercion Signature via DNS SPN Spoofing
Alerts on Windows command lines containing 'UWhRCA' and 'BAAAA', a signature tied to Kerberos coercion via spoofed credential targeting.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh193Free2025-06-20Windows DNS Query with Kerberos Coercion Signature via DNS Object SPN Spoofing
Alerts on Windows DNS queries containing a base64-like credential target signature linked to Kerberos coercion via DNS spoofing.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryHigh465Free2025-06-20Windows AD DNS Record Modification Indicators for Kerberos Coercion via SPN DNS Spoofing
Alerts on AD MicrosoftDNS DNS node changes whose DN contains a CREDENTIAL_TARGET_INFORMATION base64 marker tied to Kerberos coercion.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowssecurityHigh539Free2025-06-20