Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,392 rules
Suspicious Edge Update Setup Spawning PowerShell via ClearFake
This rule detects a MicrosoftEdgeUpdateSetup lure executable spawning PowerShell. The ClearFake fake-update campaign delivers a spoofed Edge updater that launches PowerShell to fetch and run its next stage, an execution chain that legitimate browser updates do not produce.
HuntRule TeamWindowsprocess_creationHigh122Premium2026-06-12ToneShell Backdoor GUID Store SystemRuntimeLag.inc in ProgramData (via file_event)
This rule detects creation of the SystemRuntimeLag.inc file that the Frankenstein ToneShell variant writes under ProgramData to store its per-host victim GUID. This uniquely named artifact is not associated with legitimate software and marks the backdoor recording its infection state.
HuntRule TeamWindowsfile_eventMedium103Premium2026-06-12Suspicious Hidden Account Creation - With Fast Deletion (via security)
This rule detects creates a hidden local account. See also rule "User account creation disguised in a computer account".
HuntRule TeamWindowssecurityMedium112Premium2026-06-12Malicious PlugX DLL Side-Loading via LMIGuardianSvc from SamsungDriver Directory (via process_creation)
This rule detects the legitimate LMIGuardianSvc binary executing from a SamsungDriver directory created by Mustang Panda to side-load PlugX. The signed binary search-order loads a malicious LMIGuardianDll from this attacker-controlled path. Running this LogMeIn component from a non-standard user directory is anomalous.
HuntRule TeamWindowsprocess_creationHigh227Premium2026-06-12Suspicious PowerShell Execution of Script from Netlogon Share by Cyber Anarchy Squad
This rule detects PowerShell launched with an execution policy bypass to run a script hosted on the domain netlogon share. The Cyber Anarchy Squad uses this technique to distribute and execute tooling such as rm.ps1 across compromised environments. Bypassing execution policy to run a remote logon-share script indicates malicious lateral distribution.
HuntRule TeamWindowsprocess_creationHigh164Premium2026-06-12Suspicious Run Key Persistence via Masqueraded svhostss Value by Elpaco Ransomware
This rule detects creation of a Run key value named svhostss which masquerades as the legitimate Windows svchost process. Elpaco ransomware, a Mimic variant, uses this autorun entry to persist across reboots. The deceptive naming combined with an autorun context indicates persistence for a ransomware payload.
HuntRule TeamWindowsregistry_setHigh113Premium2026-06-12Suspicious Java Runtime Executing JAR from User Download or Temp Directory
This rule detects java.exe or javaw.exe running a JAR file from a user download, Temp or AppData path, the execution stage of the Java RAT delivered through HTML smuggling in tax themed phishing. A JRE launching a JAR from a download folder is a common cross platform RAT delivery pattern rather than normal application behavior.
HuntRule TeamWindowsprocess_creationMedium464Premium2026-06-12Suspicious Renamed Python Interpreter WinAeroModule via Process Creation
This rule detects execution of a binary named WinAeroModule.exe, a masquerading name GoldenJackal gives to a renamed Python interpreter used to run its collection and exfiltration scripts on air-gapped hosts. The name mimics a Windows Aero theme component to appear benign. This indicates masqueraded interpreter execution supporting espionage tooling.
HuntRule TeamWindowsprocess_creationMedium237Premium2026-06-11Suspicious EastWind Implant Execution from ProgramData DRM Directory
This rule detects execution of a process from the C\ProgramData\Microsoft\DRM directory, a staging path used by the EastWind campaign for DLL sideloading and implant hosting. Legitimate DRM components do not run from this location, so process execution here signals attacker payload deployment and warrants investigation.
HuntRule TeamWindowsprocess_creationHigh143Premium2026-06-11Suspicious CasPol Execution Spawned by PowerShell for Injection
This rule detects the .NET CasPol.exe utility being launched by PowerShell, a system binary proxy execution chain used by the XWorm LATAM campaign to hollow CasPol and host the RAT payload. CasPol is seldom executed interactively, and a PowerShell parent is highly suspicious.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-06-11Suspicious Massive Remote Schedule Task Creation via Named Pipes - CrackMapExec with ATexec (via security)
This rule detects remotely creates a scheduled task on multiple hosts over named pipes to execute commands or elevate privileges.
HuntRule TeamWindowssecurityMedium133Premium2026-06-11Malicious Named Pipe kesknq for Token Impersonation (via pipe_created)
This rule detects creation of the named pipe kesknq used for privilege escalation and token impersonation in an Apache ActiveMQ exploitation leading to LockBit. The specific pipe name was reused across the getsystem routine and a service of the same name. Named pipe impersonation lets the operator elevate from a service context to SYSTEM.
HuntRule TeamWindowspipe_createdHigh132Premium2026-06-11Suspicious Edgecution Malicious Extension Load via Headless Edge (via process_creation)
This rule detects Microsoft Edge being launched with a load-extension argument together with headless mode and a Recovery user data directory as used by Edgecution to run its malicious browser extension backdoor. Legitimate Edge sessions do not side load unpacked extensions in headless mode.
HuntRule TeamWindowsprocess_creationHigh111Premium2026-06-11Malicious BlackCat Boot Configuration Change to Safe Mode with Networking via bcdedit (via process_creation)
This rule detects bcdedit being used to force the system to boot into Safe Mode with networking, a pre-ransomware defense-evasion step observed in the Nitrogen campaign before BlackCat encryption. Adversaries reboot endpoints into Safe Mode so that most security agents do not load while the ransomware still reaches network shares, making this a high-value early indicator of imminent encryption.
HuntRule TeamWindowsprocess_creationHigh106Premium2026-06-11Suspicious WinRAR Silent Archive Staging
This rule detects WinRAR invoked with the specific silent recursion and monitoring flag combination used to stage data for exfiltration. This behavior matches Akira operators who archive victim files quietly prior to theft. This distinctive flag set is uncommon in normal usage and indicates automated collection of files before ransomware exfiltration.
HuntRule TeamWindowsprocess_creationMedium102Premium2026-06-11