Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
Nullsoft Scriptable Installer Script (NSIS) file creation
Detects the creation of the NSIS System plugin library, indicative of an NSIS script execution.
HuntRule TeamWindowsfile_eventLow91Premium2026-05-03Possible PowerShell Empire Default User-Agent In HTTP Traffic
This rule detects outbound HTTP traffic carrying the default user-agent string shipped with the PowerShell Empire C2 framework. In the WithSecure C2 and Exfiltration Lab 1 the Empire agent beacons out with an unmodified Mozilla compatible MSIE user-agent that is characteristic of the framework default profile. Attackers rely on this static header for their staging and command channel unless an operator customizes it.
HuntRule TeamWebproxyLow61Premium2026-05-02Suspicious Cron Persistence File Created in System Cron Directories
This rule detects creation of a file named 0anacron inside the system cron directories which the DripDropper Linux malware uses to masquerade as a trusted periodic job and establish scheduled task persistence. Placing a script among legitimate cron jobs lets the malware re execute and survive reboots. Detecting this file write surfaces persistence establishment on compromised Linux hosts.
HuntRule TeamLinuxfile_eventLow311Premium2026-04-30Azure Entra ID Sign-ins with User-Agent Containing "axios"
Flags Azure Entra ID sign-ins with a user agent containing "axios", indicating potential automated sign-in activity.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamAzuresigninlogsLow190Free2026-04-28Proxy requests to EvilTokens PhaaS phishing domains (Cloudflare Workers, Railway.app)
Alerts on proxy requests to Cloudflare Workers or Railway.app URLs associated with EvilTokens phishing PhaaS kit infrastructure.
uniqu3-us3r, Huntrule Team—proxyLow141Free2026-04-28Linux setcap sets cap_setuid on a binary via setcap utility
Alerts on Linux executions of setcap configuring cap_setuid on a binary, indicating potential identity-manipulation and persistence risk.
Luc Génaux, Huntrule TeamLinuxprocess_creationLow122Free2026-01-24Linux setcap sets cap_setgid on binaries (Setgid capability assignment)
Flags Linux setcap commands that set cap_setgid on binaries via process creation logs.
Luc Génaux, Huntrule TeamLinuxprocess_creationLow131Free2026-01-24Web Browser Opens .HTM/.HTML from Downloads Folder on Windows
Flags browser processes opening .htm files from a user’s Downloads folder on Windows, a pattern consistent with HTML attachment activity.
Joseph Kamau, Huntrule TeamWindowsprocess_creationLow130Free2025-12-05Linux File Creation with Unusually Long Filenames (100+ Characters)
Flags Linux file creations with filenames 100+ characters long, excluding specific known benign system paths, to support threat hunting.
"@kostastsale, Huntrule Team"Linuxfile_eventLow120Free2025-11-22Windows: Detect Advanced Installer PSF AI_STUBS Executables with OriginalFileName popupwrapper.exe
Flags Windows execution of Advanced Installer PSF AI_STUBS stubs where OriginalFileName equals popupwrapper.exe.
Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationLow265Free2025-11-03GitHub Audit Events: Repository Archived/Unarchived Status Change
Alerts on GitHub audit events indicating a repository was archived or unarchived.
Ivan Saakov, Huntrule TeamGithubauditLow385Free2025-10-18GitHub Pages repository site changed to public (repo.pages_public audit event)
Flags when a GitHub repository’s Pages site visibility is changed to public in the audit log.
Ivan Saakov, Huntrule TeamGithubauditLow483Free2025-10-18Windows Process Creation: Executable Launches Identical Self Instance (Sacrificial Process)
Alerts on Windows process creation where a targeted parent context suggests an executable spawns an identical instance, potentially as a sacrificial process.
frack113, Huntrule TeamWindowsprocess_creationLow90Free2025-10-17Linux sudo --chroot Command Execution
Identifies Linux executions of sudo with chroot-related options ("--chroot" or "-R") via process creation command-line telemetry.
Swachchhanda Shrawn Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationLow255Free2025-10-02Windows Process Information Discovery via Registry Queries (reg.exe/powershell)
Flags reg.exe and PowerShell registry queries used to enumerate OS, Defender, installed apps, timezone, and services.
lazarg, Huntrule TeamWindowsprocess_creationLow111Free2025-06-12