Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,525 rules
Windows Process Creation: Possible CVE-2025-33053 WebDAV RCE via utility search-order manipulation
Flags suspicious child execution from WebDAV/UNC paths initiated by iediagcmd.exe or CustomShellHost.exe, consistent with CVE-2025-33053 exploitation.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh235Free2025-06-13Windows Process Access: Suspicious WebDAV target execution via iediagcmd.exe or CustomShellHost.exe (CVE-2025-33053)
Alerts when iediagcmd.exe or CustomShellHost.exe access WebDAV-hosted executables consistent with a potential RCE attempt.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh338Free2025-06-13Windows Process Information Discovery via Registry Queries (reg.exe/powershell)
Flags reg.exe and PowerShell registry queries used to enumerate OS, Defender, installed apps, timezone, and services.
lazarg, Huntrule TeamWindowsprocess_creationLow111Free2025-06-12Windows Process Creation: SharpSuccessor.exe Execution with Impersonation Parameters
Alerts on SharpSuccessor.exe command-line patterns indicative of Windows privilege escalation attempts.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh342Free2025-06-06RegAsm.exe Process Execution Missing Command-Line and Assembly Path (Windows)
Alert on RegAsm.exe process creation when the command line lacks typical Regasm flags or file parameters.
frack113, Huntrule TeamWindowsprocess_creationLow181Free2025-06-04Windows Event Log: MSSQLSERVER$AUDIT alerts on DROP/ TRUNCATE destructive SQL statements
Flags audited MSSQL transactions that include DROP TABLE, DROP DATABASE, or TRUNCATE TABLE.
Daniel Degasperi '@d4ns4n_', Huntrule TeamWindowsapplicationMedium275Free2025-06-04Windows Process Loaded BitsProxy.dll via Uncommon Image
Alert on image loads of BitsProxy.dll by processes outside an allowlist of common Windows BITS-related executables.
UnicornOfHunt, Huntrule TeamWindowsimage_loadLow130Free2025-06-04Windows DNS Queries to Malware Hosting and URL Shortener Domains
Alert on Windows DNS queries to domains tied to URL shorteners and malware hosting services.
Ahmed Nosir (@egycondor), Huntrule TeamWindowsdns_queryMedium249Free2025-06-02Linux mknod Syscall Used to Create Special Files
Flags mknod syscall activity in Linux auditd, indicating special file/device node creation.
Milad Cheraghi, Huntrule TeamLinuxauditdLow131Free2025-05-31Linux sysinfo Syscall for System Information Discovery
Detects auditd-reported sysinfo syscalls on Linux that can indicate system fingerprinting or reconnaissance.
Milad Cheraghi, Huntrule TeamLinuxauditdLow213Free2025-05-30Windows: TacticalRMM Agent Installed with API/Auth Flags Pointing to Remote RMM Server
Alerts when TacticalRMM agent starts with --api/--auth and identity flags consistent with connecting to a configured remote RMM server.
Ahmed Nosir (@egycondor), Huntrule TeamWindowsprocess_creationMedium446Free2025-05-29Windows PowerShell Obfuscated COM MSI Installation via WindowsInstaller.Installer
PowerShell spawning that uses WindowsInstaller.Installer COM with obfuscated strings to call InstallProduct and suppress UI.
Meroujan Antonyan (vx3r), Huntrule TeamWindowsprocess_creationHigh181Free2025-05-27Linux auditd: Clear kernel ring buffer via syslog syscall (action 5/4/6)
Flags auditd syslog syscall actions that clear or suppress kernel ring buffer (dmesg) logs.
Milad Cheraghi, Huntrule TeamLinuxauditdMedium153Free2025-05-27Windows vshadow.exe Proxy Execution via -exec Script/Command
Alerts when vshadow.exe is run with -exec, which can proxy execution of a script or command after shadow copy creation.
David Faiss, Huntrule TeamWindowsprocess_creationMedium4810Free2025-05-26Linux: Disable ASLR via personality syscall or sysctl/randomize_va_space changes
Flags Linux events where ASLR is disabled using the personality syscall or sysctl setting kernel.randomize_va_space=0.
Milad Cheraghi, Huntrule TeamLinuxauditdHigh162Free2025-05-26