Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,524 rules
Windows PowerShell Modifies dMSA msDS-ManagedAccountPrecededByLink Attributes
Flags PowerShell script content modifying msDS-ManagedAccountPrecededByLink (dMSA link attributes) via AD link changes.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptLow413Free2025-05-24PowerShell dMSA Service Account Creation in Target OUs via New-ADServiceAccount
Alerts on PowerShell creating a delegated service account via New-ADServiceAccount with -CreateDelegatedServiceAccount and -path.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptMedium202Free2025-05-24Linux auditd: Detect writes to /proc/sysrq-trigger or sysrq-related config for Magic SysRq abuse
Alerts on auditd PATH events referencing /sysrq or /sysrq-trigger, indicating possible Linux Magic SysRq abuse.
Milad Cheraghi, Huntrule TeamLinuxauditdMedium446Free2025-05-23Windows reg.exe Registry Save/Export of Third-Party Credential Paths
Alerts on reg.exe save/export commands targeting registry keys tied to third-party credential data.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh232Free2025-05-22Windows: Deno writes files from remote HTTPS content into AppData
Alerts when Deno writes to user AppData while using remote HTTPS download-style paths.
Josh Nickels, Michael Taggart, Huntrule TeamWindowsfile_eventLow479Free2025-05-22Windows File Access to Browser Credential Storage by Non-Browser Processes
Flags non-browser processes reading common browser credential storage files on Windows, indicating potential credential theft.
frack113, X__Junior (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Parth-FourCore, Huntrule TeamWindowsfile_accessLow254Free2025-05-22Windows Security: Kerberos TGT requests with PreAuthType=0 and RC4-HMAC (0x17) to krbtgt
Alerts on krbtgt TGT requests using RC4-HMAC with pre-authentication disabled (PreAuthType=0), consistent with AS-REP roasting attempts.
ANosir, Huntrule TeamWindowssecurityMedium481Free2025-05-22Zeek HTTP: Suspicious User-Agent Containing "katz-ontop"
Alerts on Zeek HTTP sessions whose User-Agent includes "katz-ontop", a potential malware indicator.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamZeekhttpHigh112Free2025-05-22DNS Queries to Katz Stealer–Associated Domains (Network)
Alerts on DNS queries for domains associated with Katz Stealer.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—dnsHigh374Free2025-05-22Windows DLL Load Indicators for Katz Stealer 2025 Variants
Alerts on Windows image loads of DLLs with Katz Stealer-associated names/paths.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsimage_loadHigh373Free2025-05-22Windows DNS Queries to Katz Stealer-Related Domains
Alerts on Windows DNS queries to domains associated with Katz Stealer malware infrastructure.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryHigh345Free2025-05-22Windows RMM Tool MeshAgent Execution with Renamed MeshServiceName
Identifies renamed MeshAgent executions on Windows by matching --meshServiceName with OriginalFileName containing meshagent.
Norbert Jaśniewicz (AlphaSOC), Huntrule TeamWindowsprocess_creationHigh171Free2025-05-19Windows MeshAgent Remote Access Tool Command Line Execution Indicators
Flags Windows processes invoking MeshAgent with --meshServiceName, indicating potential remote access tool execution.
Norbert Jaśniewicz (AlphaSOC), Huntrule TeamWindowsprocess_creationMedium140Free2025-05-19Windows Impacket-Pattern File Creation: sessionresume_[a-zA-Z]{8} Indicator
Flags Windows file creations of filenames matching Impacket sessionresume pattern ('sessionresume_<8 letters>').
The DFIR Report, IrishDeath, Huntrule TeamWindowsfile_eventHigh172Free2025-05-19macOS Process Creation: MeshAgent renamed execution via --meshServiceName
Identifies macOS executions of MeshAgent instances that include --meshServiceName, indicating potential renamed remote access tooling.
Norbert Jaśniewicz (AlphaSOC), Huntrule TeamMacosprocess_creationHigh214Free2025-05-19