huntrule
RulesBlogHow it worksPricingAboutContact

Every published rule

Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.

3 rules

Access
Domain
Severity
Sort
  • Suspicious ntdsutil.exe Use for AD Snapshot Mount or Activation (Windows Process Creation)

    Alerts on ntdsutil.exe command lines that include snapshot mount and activation/instance fragments, indicating potential AD snapshot manipulation.

    sigmaWindows
    medium2022-09-14
  • Windows ntdsutil Abuse Indicators via ESENT Events Containing ntds.dit

    Flags ESENT application events mentioning ntds.dit that may indicate ntdsutil attempts to access the AD database.

    sigmaWindows
    medium2022-08-14
  • Windows: Execution of ntdsutil.exe for NTDS database operations

    Flags execution of ntdsutil.exe, a utility that can be used to manipulate the NTDS database (NTDS.DIT).

    sigmaWindows
    medium2019-01-16

The threat is new.
Your detection should not be late.

The library is public and free to read. Every rule shows the reporting behind it, the telemetry it needs and where it falls short.

HuntRuleHuntRule

Detection rules built from the latest attacker techniques. Expert-reviewed, source-backed Sigma.

Library

  • All rules
  • Pricing

Project

  • How it works
  • About
  • Sign in

Resources

  • Blog
  • Rules API
  • llms.txt
  • Sitemap

Company

  • Contact
  • Terms of Service
  • Privacy Policy

© 2026 HuntRule

Validate every rule against your own telemetry before you alert on it.