Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows SFTP.exe Indirect Command Execution via ProxyCommand
Flags SFTP.exe executions that include ProxyCommand=, indicating potential indirect command execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium211Free2026-04-27Windows PUA: MemProcFS memory dump mounting via -device
Detects MemProcFS.exe execution with -device on Windows, consistent with mounting memory dumps for potential credential access.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh394Free2026-04-27Windows Defender windefend Event 1119 flags RedSun TieringEngineService.exe EICAR test file
Alerts on WinDefend 1119 remediation failures involving TieringEngineService.exe marked with EICAR content or triggered by RedSun.exe.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowswindefendCritical206Free2026-04-17Windows Named Pipe Created with Name "REDSUN"
Flags creation of the named pipe \REDSUN on Windows, consistent with RedSun-style IPC used during exploitation.
Swachchhanda Shrawan Poudel (Nextron Systems), @unresolvedhost, Huntrule TeamWindowspipe_createdCritical101Free2026-04-17Windows File Creation: TieringEngineService.exe in RS- prefixed Temp Directory
Detects creation of TieringEngineService.exe under an RS-{GUID}-prefixed directory in %TEMP% on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), @unresolvedhost, Huntrule TeamWindowsfile_eventCritical143Free2026-04-17Windows HackTool Indicators: NetExec (nxc.exe) PyInstaller Extraction Artifacts
Flags Windows file creation under Temp\_MEI* where NetExec nxc data files are dropped, indicating likely NetExec execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh171Free2026-04-08Windows Process Tree for Axios npm Supply-Chain RAT Droppers (cscript, curl, PowerShell)
Alerts on the Windows process/command-line pattern consistent with the Axios npm compromise execution and C2 fetch.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh323Free2026-04-01macOS: Detect Axios malicious npm execution chain using osascript, curl download, and cleanup
Flags macOS command-line patterns showing osascript execution plus npm package download and staged file cleanup.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamMacosprocess_creationHigh309Free2026-04-01Linux process chain for Axios NPM compromise: curl download with nohup and python3
Flags Linux executions where curl downloads /tmp/ld.py and the payload is run via nohup python3 from an Axios-related node process.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh91Free2026-04-01DNS queries to known malicious C2 domains from axios/plain-crypto-js npm compromise indicators
Alerts on DNS queries to known malicious C2 domains tied to an Axios npm supply-chain compromise.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—dnsHigh465Free2026-04-01Windows File Creation Indicators Linked to Malicious Axios npm Supply-Chain Components
Flags Windows file creation of wt.exe/system.bat and temp .vbs/.ps1 payloads when created by node.exe or powershell.exe.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh81Free2026-04-01macOS: Axios NPM compromise file creation via curl and node indicators
Alerts on macOS file events matching curl and node staging paths linked to an Axios npm compromise pattern.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamMacosfile_eventHigh131Free2026-04-01Linux file creation via curl to /tmp/ld.py (Axios NPM compromise indicators)
Alerts on Linux file creation of /tmp/ld.py by a /curl process, consistent with automated payload staging.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxfile_eventHigh418Free2026-04-01Linux Process Creation Indicators for LiteLLM Backdoored Package Activity (v1.82.7/v1.82.8)
Identifies Linux process executions matching indicators tied to backdoored LiteLLM v1.82.7/v1.82.8 credential-stealer and persistence activity.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh2010Free2026-03-30Linux Persistence File Creation Targeting sysmon.py and systemd user service
Alerts on creation of user persistence files under sysmon.py or systemd user service paths by a process running from /python3.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxfile_eventHigh122Free2026-03-30