Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,390 rules
Malicious DLL Side-Loading of msimg32 via Silverlight.Configuration.exe
This rule detects Silverlight.Configuration.exe loading msimg32.dll from outside the Windows system directories. The Horns and Hooves campaign abused this signed binary to side-load a planted msimg32.dll and execute the NetSupport loader under a trusted process.
HuntRule TeamWindowsimage_loadHigh133Premium2026-06-20Suspicious Deletion of Explorer RunMRU Values
This rule detects deletion of values under the Explorer RunMRU key, an anti-forensic step in newer NetSupport RAT ClickFix loaders. The malware removed RunMRU entries to erase evidence that the victim had pasted the malicious command into the Windows Run dialog. Programmatic clearing of RunMRU history is an indicator of indicator-removal activity.
HuntRule TeamWindowsregistry_setMedium142Premium2026-06-20Malicious MicrosoftUpdate Run Key Persistence via Axios Compromise
This rule detects creation of a CurrentVersion Run value named MicrosoftUpdate that launches the renamed wt.exe interpreter as used by the Windows variant of the Axios supply chain RAT. The benign looking value name paired with a ProgramData interpreter path indicates masquerading persistence for the backdoor.
HuntRule TeamWindowsregistry_setHigh375Premium2026-06-20Suspicious New Member Added to an Exchange Administration Group - Medium Risk (via security)
This rule detects scenarios where a new member is added to a sensitive group related to Exchange server.
HuntRule TeamWindowssecurityMedium91Premium2026-06-20Suspicious CMSTP Execution With INF Payload via process_creation
This rule detects the Connection Manager Profile Installer cmstp.exe running with an INF file or silent flag, the LOLBin abused in the GST-phishing Remcos RAT chain to bypass UAC and execute attacker code. Adversaries leverage the trusted, auto-elevating cmstp binary to run malicious INF-defined commands while evading application controls, so its rare invocation is a strong signal of the multi-stage .NET infection.
HuntRule TeamWindowsprocess_creationHigh225Premium2026-06-20Malicious NTDS Database Dump via NTDSUtil in BlackSuit Ransomware
This rule detects ntdsutil being used to create an installation from media (IFM) copy of the Active Directory database, a credential-access technique observed in BlackSuit ransomware intrusions. Dumping NTDS.dit gives operators every domain hash for offline cracking and full domain compromise, making this a critical detection.
HuntRule TeamWindowsprocess_creationHigh403Premium2026-06-19Suspicious Scheduled Task Persistence Masquerading as OneDrive Update
This rule detects creation of a scheduled task named OneDrive Update via schtasks that runs at very short intervals and at startup, the persistence used by the GigaWiper destructive backdoor. Impersonating the OneDrive updater lets the wiper relaunch frequently while blending into expected update activity.
HuntRule TeamWindowsprocess_creationMedium111Premium2026-06-19Malicious Regsvr32 Loading a DLL From a Data Directory (via process_creation)
This rule detects regsvr32.exe registering a DLL located in ProgramData or a user AppData directory, the loader behavior Emotet and similar malware use to execute a dropped payload under a trusted binary. Regsvr32 execution of user-dropped DLLs is a defense-evasion technique tracked in the Red Canary Threat Detection Report. Detecting these invocations surfaces malware loading from a staging directory.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-06-19Uncommon Domain Trust Discovery via Nltest (via process_creation)
This rule detects nltest.exe being used to enumerate domain controllers and domain trust relationships, a discovery step that adversaries and loaders such as those profiled in the Red Canary Threat Detection Report run to understand the Active Directory environment before moving laterally. Because interactive nltest trust enumeration is uncommon on typical endpoints, it is a useful early indicator of hands-on-keyboard reconnaissance. Detecting these queries surfaces the adversary orienting inside the domain.
HuntRule TeamWindowsprocess_creationMedium93Premium2026-06-19Suspicious Shell Spawned by Langflow Python Process (via process_creation)
This rule detects a Langflow Python process spawning a command shell or network utility. Such a child process is consistent with the reverse shell payloads used against CVE-2025-3248. A Langflow worker does not normally launch interactive shells.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-06-19Suspicious bitsadmin Download to AppData Temp via ClickFix Revenge Chain
This rule detects bitsadmin.exe performing a transfer that downloads a remote http resource into the user AppData or Temp directory, the payload retrieval step of the ClickFix campaign following a Windows Run dialog paste. bitsadmin used interactively to fetch executables into user writable folders is a well known living off the land download technique. This catches the staging of the second stage binary.
HuntRule TeamWindowsprocess_creationHigh92Premium2026-06-19Suspicious File Download via certutil
This rule detects certutil.exe being used with URL-cache download arguments to retrieve remote files, a living-off-the-land technique used by RansomHub affiliates to stage tooling. certutil is not a general purpose downloader, so its use to fetch remote content commonly indicates ingress tool transfer by an adversary.
HuntRule TeamWindowsprocess_creationMedium367Premium2026-06-19Suspicious Boot Configuration Change to Safeboot Minimal via bcdedit
This rule detects use of bcdedit to set the boot configuration to safeboot minimal, forcing the host to reboot into Safe Mode where most endpoint security agents do not load. The ToyMaker intrusion used this to disable protections before hands-on-keyboard activity, so it is a high-confidence defense-evasion signal preceding credential theft or ransomware deployment.
HuntRule TeamWindowsprocess_creationHigh2010Premium2026-06-19Suspicious Active Directory Discovery via ADFind
This rule detects execution of the ADFind reconnaissance utility which Black Basta operators use to enumerate Active Directory users groups and computers during the discovery phase of an intrusion. While ADFind is a legitimate administrative tool its presence on endpoints is frequently associated with pre ransomware reconnaissance.
HuntRule TeamWindowsprocess_creationMedium453Premium2026-06-18Malicious UAT-8302 Hidden PowerShell Execution of whatpc.ps1
This rule detects PowerShell running the whatpc.ps1 script with an execution policy bypass and a hidden window, matching the UAT-8302 reconnaissance stager. The named script drives host profiling and follow-on tasking while the hidden bypass flags suppress user visibility and controls. Execution of this specific script under these flags indicates active UAT-8302 operations.
HuntRule TeamWindowsprocess_creationHigh166Premium2026-06-18