Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows: Suspicious Kerberos Ticket Requests from PowerShell Using KerberosRequestorSecurityToken
Flags PowerShell command lines that reference KerberosRequestorSecurityToken and .GetRequest() for suspicious Kerberos ticket requests.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2025-11-18Windows RDP Enable/Disable via Win32_TerminalServiceSetting WMI Tool Commands
Flags WMIC/PowerShell command lines that reference Win32_TerminalServiceSetting SetAllowTSConnections to change RDP.
Daniel Koifman (KoifSec), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium462Free2025-11-15Windows svchost.exe Uncommon Command-Line Parameter Process Creation
Alerts on Windows process starts of svchost.exe that include an uncommon -k parameter format, after excluding common and benign patterns.
Liran Ravich, Huntrule TeamWindowsprocess_creationHigh133Free2025-11-14Windows CMD for /f Tokens= with Recursive Dir Listing
Flags cmd.exe for /f loops using tokens= with recursive dir enumeration in the command line and parent.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationMedium122Free2025-11-12Windows Registry: Suspicious Space-Padded TypedPaths Details String
Alerts on registry writes to TypedPaths url1 where Details includes “#” plus unusual Unicode space padding.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh387Free2025-11-04Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
Alerts on RunMRU registry updates containing '#' plus excessive unusual Unicode spaces that may conceal command text.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh100Free2025-11-04Windows Process Creation: Explorer Command Lines with Unicode Whitespace Padding and '#'
Alerts when Explorer spawns a process with command lines containing long Unicode whitespace padding followed by '#'.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh318Free2025-11-04Windows: Detect Advanced Installer PSF AI_STUBS Executables with OriginalFileName popupwrapper.exe
Flags Windows execution of Advanced Installer PSF AI_STUBS stubs where OriginalFileName equals popupwrapper.exe.
Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationLow245Free2025-11-03FortiGate SSL VPN Settings Edited
Flags FortiGate VPN SSL settings being edited, which may indicate changes to SSL VPN access or authentication configuration.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium162Free2025-11-01FortiGate User Group Modified via Edit Event
Alerts on FortiGate user group edits that can change access permissions, including VPN-related group membership.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium143Free2025-11-01FortiGate: Addition of VPN SSL Web Portal via Event Logs
Detects FortiGate configuration events where a VPN SSL web portal is added.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium426Free2025-11-01FortiGate: Local User Added via CLI Event
Alerts on FortiGate events where a new local user is added under user.local.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium324Free2025-11-01FortiGate: Alert on Added Firewall Policy via Event Log
Flags FortiGate events where a firewall policy is added (action Add on firewall.policy).
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium206Free2025-11-01FortiGate Firewall Address Object Added (event action Add)
Alerts when a FortiGate firewall address object is added via configuration change events.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium61Free2025-11-01FortiGate: Administrator Account Added via system.admin Events
Alerts on FortiGate events that add a new administrator account in system.admin.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium383Free2025-11-01