Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Microsoft 365 inbound suspicious email delivered to Inbox or Junk
Alerts when Defender-labeled suspicious inbound emails are delivered to user Inbox/Junk in Microsoft 365.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamM365auditMedium397Free2026-01-27Windows Vulnerable Driver Blocklist Disabled via Registry DWORD Setting
Flags registry changes that disable Windows Vulnerable Driver Blocklist (VulnerableDriverBlocklistEnable = 0).
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh561Free2026-01-26Windows Vulnerable Driver Blocklist Registry Tampering via PowerShell or REG.EXE
Flags PowerShell/REG.EXE command lines that change the VulnerableDriverBlocklistEnable registry setting under \Control\CI\Config.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh73Free2026-01-26Windows HVCI Registry Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/pwsh or reg.exe command lines modifying HVCI/Hypervisor-enforced code integrity registry values.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh431Free2026-01-26Windows Registry: Alert on Changes to \shell\open\command Targeting Common Malware Paths
Alerts on registry_set events modifying \shell\open\command to point to suspicious temp/user-writable locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setMedium454Free2026-01-24Windows Registry Modification: OracleOciLib/OracleOciLibPath Under MSDTC for oci.dll Redirection
Alerts on MSDTC MTxOCI registry changes to OracleOciLib/OracleOciLibPath that may redirect oci.dll loading to attacker-controlled locations.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh161Free2026-01-24Windows cmd.exe Executing start Utility with Hidden Window Flags (/b or /min)
Alerts on cmd.exe invoking start.exe with /b or /min, especially when directed at scripts or files in suspicious temp/public paths.
Vladan Sekulic, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium238Free2026-01-24Linux setcap sets cap_setuid on a binary via setcap utility
Alerts on Linux executions of setcap configuring cap_setuid on a binary, indicating potential identity-manipulation and persistence risk.
Luc Génaux, Huntrule TeamLinuxprocess_creationLow102Free2026-01-24Linux setcap sets cap_setgid on binaries (Setgid capability assignment)
Flags Linux setcap commands that set cap_setgid on binaries via process creation logs.
Luc Génaux, Huntrule TeamLinuxprocess_creationLow111Free2026-01-24Windows Registry Query for System Language Using reg.exe
Flags reg.exe registry queries to Control\Nls\Language, indicating system language discovery on Windows.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamWindowsprocess_creationMedium142Free2026-01-09Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
Flags M365 audit events where inbox rules are created/updated with parameters that can delete, mark, move, or keyword-match messages.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamM365auditMedium80Free2026-01-09OpenCanary RDP New Connection Attempt on Application Logtype 14001
Alerts on OpenCanary logging a new RDP connection attempt (logtype 14001), indicating remote access probing.
Marco Pedrinazzi (@pedrinazziM), Huntrule TeamOpencanaryapplicationHigh427Free2026-01-06OpenCanary Application Logs: Detect SYN Port Scan Targets on a Hosted Node
Flags OpenCanary events indicating the host was probed with a TCP SYN port scan.
Marco Pedrinazzi (@pedrinazziM), Huntrule TeamOpencanaryapplicationHigh103Free2026-01-06OpenCanary application logs: detect NMAP XMAS scans targeting an OpenCanary node
Detects OpenCanary log events showing an Nmap Xmas scan targeting the monitored node.
Marco Pedrinazzi (@pedrinazziM), Huntrule TeamOpencanaryapplicationHigh352Free2026-01-06OpenCanary: Detect NMAP OS Scan Targets via Application Logtype 5002
Alerts when OpenCanary records an NMAP OS scan event (logtype 5002), indicating host fingerprinting activity.
Marco Pedrinazzi (@pedrinazziM), Huntrule TeamOpencanaryapplicationHigh3910Free2026-01-06