Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Linux Bun Runtime Execution: bun_environment.js via node-parent process
Flags /node-launched /bun executions running bun_environment.js with an external runner release download URL.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh158Free2025-11-25Linux Process Creation: Shai-Hulud String Indicators in Command Line
Alerts on Linux process command lines containing Shai-Hulud or SHA1HULUD indicator strings.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh143Free2025-11-25Windows Process Creation: File Upload Clickfix Lure via Browser to Command Execution
Alerts when browser-launched processes include clickfix-style command markers plus tool and captcha-related terms on Windows.
0xFustang, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh475Free2025-11-24Windows WSASS Process Execution via WerFaultSecure.EXE
Alerts on Windows process creation showing wsass.exe running with WerFaultSecure.exe and a PID-like argument.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh181Free2025-11-23Windows Process: GPME Used to Modify Default Domain and Default Domain Controllers GPOs
Flags MMC launching GPME to target Default Domain/Default Domain Controllers GPO objects by GUID via gpobject.
TropChaud, Huntrule TeamWindowsprocess_creationMedium466Free2025-11-22Windows ImageLoad of Unsigned .node Native Add-on Files
Alerts on Windows loading of unsigned or unverifiable .node files, indicating potential native code execution in Electron-based apps.
Jonathan Beierle (@hullabrian), Huntrule TeamWindowsimage_loadMedium132Free2025-11-22Windows Security Event 5136 for Changes to Default Domain and Default Domain Controllers GPOs
Flags EventID 5136 modifications to Default Domain or Default Domain Controllers GPO containers in Windows AD.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowssecurityMedium4610Free2025-11-22Linux File Creation: Filename Contains Embedded Base64 Bash Fragments
Alerts on Linux file events for filenames that appear to embed Base64-decoding bash command patterns.
"@kostastsale, Huntrule Team"Linuxfile_eventHigh101Free2025-11-22Linux File Creation with Unusually Long Filenames (100+ Characters)
Flags Linux file creations with filenames 100+ characters long, excluding specific known benign system paths, to support threat hunting.
"@kostastsale, Huntrule Team"Linuxfile_eventLow80Free2025-11-22macOS Atomic Stealer FileGrabber and curl POST to exfiltrate /tmp/out.zip
Alert on macOS command lines showing FileGrabber from /tmp or curl POST exfiltration with /tmp/out.zip.
Jason Phang Vern - Onn, Robbin Ooi Zhen Heng (Gen Digital), Huntrule TeamMacosprocess_creationHigh367Free2025-11-22macOS File Persistence from Atomic MacOS Stealer (helper file and LaunchDaemon plist)
Flags macOS file creations used as persistence artifacts: per-user .helper files and a specific LaunchDaemon plist.
Jason Phang Vern - Onn, Robbin Ooi Zhen Heng (Gen Digital), Huntrule TeamMacosfile_eventHigh293Free2025-11-22Cisco ASA WebVPN Proxy GET Requests to MacTunnel and csvrloader Paths
Alerts on proxy-observed HTTP GET requests to specific Cisco ASA WebVPN exploit-related URI stems.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—proxyHigh373Free2025-11-20Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Alerts on explorer.exe child process launches with clipboard markers and anti-bot/CAPTCHA-related wording indicating ClickFix/FileFix execution.
montysecurity, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2025-11-19Windows Network Connection Initiated by finger.exe
Alerts on Windows network connections started by finger.exe, an unusual utility that can support remote command retrieval.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh384Free2025-11-19Windows DNS Queries Triggered by finger.exe
Alerts on Windows DNS queries made by finger.exe, a rarely used utility that can be abused to fetch remote commands.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryHigh335Free2025-11-19