Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
451 rules
Suspicious XMRig Cryptominer Execution on Linux
This rule detects execution of the XMRig Monero cryptominer identified by its characteristic mining pool and donate-level arguments which was deployed both UPX-packed and standard as post-exploitation payload following React2Shell CVE-2025-55182 compromises. Cryptominer execution on a workload host indicates resource hijacking for financial gain after successful exploitation.
HuntRule TeamLinuxprocess_creationMedium278Premium2026-06-19Suspicious PAN-OS GlobalProtect Portal Font Staging File Creation
This rule detects creation of the Latte-Regular.woff file under the GlobalProtect portal fonts directory which Wiz identified as a staging artifact used during exploitation of the PAN-OS vulnerabilities CVE-2024-0012 and CVE-2024-9474. This is important because attackers wrote this specific web font path to stage payloads on the appliance so its appearance signals that the firewall has been compromised and is being prepared for follow-on tooling.
HuntRule TeamLinuxfile_eventHigh465Premium2026-06-18Suspicious PolarEdge Implant Connect-Back Argument Pattern (via process_creation)
This rule detects the PolarEdge QNAP implant being launched with its distinctive connect-back argument set. The backdoor uses the cw mode flag together with the quiet foreground host and execute options to establish a reverse connection to its operator. This fixed argument combination is unique to the implant and reveals active backdoor invocation.
HuntRule TeamLinuxprocess_creationMedium83Premium2026-06-17Suspicious File Based C2 Relay via Python Web Panel via process_creation
This rule detects the file based command and control component of the AI assisted intrusions where python3 runs a relay.py or webpanel.py operator panel that dispatches commands through /tmp/cmd_ FIFO files. This lightweight Python relay brokers attacker instructions to the implant on the host. Running these operator scripts from a compromised server is a strong indicator of hands on keyboard control.
HuntRule TeamLinuxprocess_creationHigh121Premium2026-06-13Suspicious File Immutability Set via chattr for Anti-Removal on Linux
This rule detects chattr setting the immutable attribute on a file, an anti-removal technique used by the PeerBlight Linux backdoor to protect its sshd-agent persistence from deletion. Making backdoor files immutable prevents defenders and admins from removing them without first clearing the attribute. Interactive chattr immutability changes on service files are uncommon and suspicious.
HuntRule TeamLinuxprocess_creationMedium152Premium2026-06-13Malicious RCE Confirmation Markers from Offensive Agentic Tooling
This rule detects the VAPT confirmation markers and command placeholder that attackers wrap around executed commands when validating remote code execution with offensive agentic tooling built on stolen AI compute. The markers bracket command output so the automation can parse successful execution. Their appearance on hosts is a high-confidence sign of automated exploitation.
HuntRule TeamLinuxprocess_creationHigh72Premium2026-06-13Malicious UNC4841 FOXDOOR Shell Execution from Non-Standard Path (via process_creation)
This rule detects execution of the FOXDOOR shell component from the hardcoded /usr/share/foxdoor/ directory used by UNC4841 on compromised Barracuda ESG appliances. The path and binary name are attacker-controlled artifacts that provide interactive backdoor access. Detecting execution from this planted directory reveals active hands-on-keyboard operation on the appliance.
HuntRule TeamLinuxprocess_creationHigh231Premium2026-06-12Malicious Disabling of rsyslog or auditd Logging Services (via process_creation)
This rule detects commands that stop, disable, mask, or kill the rsyslog or auditd logging services on Linux. The Group-IB XMRig covert Linux PAM abuse campaign disables these services to blind host defenses before mining and persistence activity. Impairing logging is a strong pre-attack signal that an adversary is preparing to operate without leaving audit trails.
HuntRule TeamLinuxprocess_creationHigh83Premium2026-06-11Malicious Docker Client Targeting Remote Exposed 2375 API
This rule detects the docker client invoked with a remote host flag pointing at TCP port 2375 to run or exec against an exposed Docker Engine API. The Dero miner worm abuses this to deploy malicious containers onto unauthenticated hosts and spread its cryptojacking payload. Remote docker run or exec over 2375 is a clear container-takeover behavior.
HuntRule TeamLinuxprocess_creationHigh73Premium2026-06-11Suspicious Cron Persistence via etc cron.d tsar (via file_event)
This rule detects creation of a tsar cron job under etc cron.d as observed in the BrokenSesame research for host persistence. Dropping a system cron file lets an attacker run code as root on a schedule after escaping a container. The specific filename in the system cron directory is a strong persistence indicator.
HuntRule TeamLinuxfile_eventHigh226Premium2026-06-10Suspicious Webshell Written To F5 TMUI Web Directory
This rule detects creation of a PHP or JSP file within the F5 BIG-IP xui web directory tree which is where operators dropped webshells after TMUI exploitation as described in NCC Group RIFT F5 TMUI intelligence. Adversaries plant these webshells to maintain persistent remote command execution on the appliance so any script file appearing in these image and script paths is highly suspicious.
HuntRule TeamLinuxfile_eventHigh132Premium2026-06-09Suspicious SonicWall SMA init.d Persistence Launching deploy_new.py
This rule detects the workplace init script executing deploy_new.py which the actor used for persistence on a compromised SonicWall SMA appliance. The 0-day exploitation established a boot-time service under /etc/init.d/workplace to relaunch attacker tooling after reboots. Boot persistence on an internet-facing appliance provides durable access that survives restarts and patching attempts.
HuntRule TeamLinuxprocess_creationHigh353Premium2026-06-08Obfuscated ELF Magic-Byte Restoration via dd conv notrunc in Sindoor Dropper Chain (via process_creation)
This rule detects use of dd with conv=notrunc to overwrite the first bytes of a file, the ELF magic-byte restoration trick used by the Sindoor Dropper to reassemble a runnable Linux payload from a header-stripped file. Adversaries leverage this to defeat static detection of the staged binary, making detection useful for catching the deobfuscation step of the infection chain.
HuntRule TeamLinuxprocess_creationMedium111Premium2026-06-07Suspicious systemd User Service Persistence miasma-monitor (via file_event)
This rule detects creation of a miasma-monitor systemd user service unit used by the M-Red-Team AsyncAPI compromise for persistence. Writing a user-level systemd service lets an attacker relaunch a monitoring implant on login without root. The specific unit name combined with the user systemd path is a strong persistence signal.
HuntRule TeamLinuxfile_eventHigh183Premium2026-06-07Malicious Tunneling Tool Execution on Linux Host (via process_creation)
This rule detects execution of known network tunneling and proxy utilities used to pivot and exfiltrate from compromised Linux and container hosts. Observed in the Elastic Security Labs TeamPCP scenario where gost, frps, chisel, and socat establish covert channels for command and control and lateral movement.
HuntRule TeamLinuxprocess_creationMedium72Premium2026-06-07