Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,523 rules
Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators
Alerts on Windows RunMRU registry changes containing HTTP/HTTPS URLs plus captcha/automation or command execution indicators.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh471Free2025-03-25Windows Process Creation: Suspicious LNK Command-Line Whitespace Padding Beyond UI Limit
Alerts when explorer.exe launches a .lnk and the command line contains suspicious whitespace padding used to hide extended arguments.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2025-03-19Windows PowerShell ScriptBlock: Get-ADComputer reconnaissance for unconstrained delegation properties
Flags PowerShell script blocks that query AD computer delegation-related properties using Get-ADComputer-style discovery.
frack113, Huntrule TeamWindowsps_scriptMedium299Free2025-03-05Windows Process Creation: AdFind.exe Execution for Active Directory Recon
Alerts on Windows execution of AdFind.exe based on image/name and known imphash values indicative of AD reconnaissance.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium102Free2025-02-26Zeek HTTP Requests to Low Reputation TLDs or Suspicious File Extensions
Alerts on Zeek HTTP requests to low-reputation TLDs or URIs/MIME types consistent with executable payload delivery.
"@signalblur, Corelight, Huntrule Team"ZeekhttpMedium211Free2025-02-26Windows: Notepad Password File Discovery via Process Creation
Flags explorer-launched Notepad opening files named like password*.{txt,csv,doc,xls} that may contain credentials.
The DFIR Report, Huntrule TeamWindowsprocess_creationLow152Free2025-02-21Windows Image Load: Suspicious ksproxy.ax Loading Suggesting CVE-2024-35250
Flags Windows module loads of ksproxy.ax, a potential indicator of CVE-2024-35250 exploitation attempt activity.
"@eyezuhk Isaac Fernandes, Huntrule Team"Windowsimage_loadMedium223Free2025-02-19Suspicious autorun registry modification via WMI wmic spawning reg.exe on Windows
Flags WMIC-driven reg.exe commands that add Run key autorun entries, especially when pointing to suspicious temp/user locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2025-02-17Windows curl.exe SOCKS Proxy and .onion Command-Line Execution
Alerts on Windows curl.exe being run with Tor SOCKS proxy URIs and .onion targets in the command line.
Arda Buyukkaya (EclecticIQ), Huntrule TeamWindowsprocess_creationHigh162Free2025-02-11Windows File Events: Suspicious WDAC Policy File Creation by Non-Excluded Processes
Alerts on WDAC-related policy files created under CodeIntegrity, excluding known deployment tools and scripts.
X__Junior, Huntrule TeamWindowsfile_eventMedium175Free2025-02-07Windows Scheduled Task Creation Using System Process Names
Flags schtasks.exe /create commands whose arguments reference common Windows system process names.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh319Free2025-02-05Windows Scheduled Task Creation via schtasks.exe with curl and PowerShell Command Line Indicators
Alerts on schtasks.exe task creation commands that simultaneously include curl download indicators and PowerShell execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium100Free2025-02-05Windows Process Creation: NimScan.exe Execution via Known File Hashes
Alerts on Windows execution of NimScan.exe when process image and known IMPHASH values match.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium211Free2025-02-05Windows MMC Executes Files with RLO-Reversed Extensions in Process Command Line
Alerts when mmc.exe runs with command lines containing RLO-style reversed filename patterns ending in .msc.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh446Free2025-02-05Windows ConHost Spawning Suspicious Script and Command-Line Child Processes
Flags conhost.exe spawning command/scripting utilities like PowerShell, MSHTA, or regsvr32.exe.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh130Free2025-02-05