Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,392 rules
Suspicious Payload Download to Temp Masquerading as System32 File (via process_creation)
This rule detects PowerShell using Invoke-WebRequest to save a payload into the temp directory under a system32 style filename. OneNote delivered malware wrote files such as system32.exe and system32.bat into the user temp path to blend in before launching them.
HuntRule TeamWindowsprocess_creationMedium141Premium2026-06-08Possible MuddyWater C2 Domain Resolution
This rule detects DNS resolution of the domain screenai.online, a command-and-control host observed in a MuddyWater APT campaign that combined WMI execution and remote management tool abuse against Middle East targets. It captures beaconing infrastructure lookups tied to the intrusion. Detecting this is important because resolution of this campaign-specific domain is a high-confidence indicator of an infected host reaching out to attacker infrastructure.
HuntRule TeamWindowsdns_queryHigh408Premium2026-06-08Suspicious npm Credential Scan via whoami and npmrc Access
This rule detects the npm whoami identity check combined with access to the .npmrc credential file, a credential-harvesting step in the Shai Hulud 2.0 worm. The malicious payload queries npm /-/whoami and reads .npmrc to steal publishing tokens for propagating to further packages. Automated npm authentication probing paired with npmrc token access is a strong indicator of supply-chain credential theft.
HuntRule TeamWindowsprocess_creationLow2410Premium2026-06-08Suspicious AdFind Active Directory Enumeration via OWASSRF Post-Exploitation (via process_creation)
This rule detects use of the AdFind reconnaissance utility by process name or by its characteristic query flags, a discovery step performed after OWASSRF exploitation of Exchange servers. Attackers enumerate domain accounts trusts and objects to plan lateral movement, so AdFind activity outside sanctioned administration is a hands-on-keyboard indicator.
HuntRule TeamWindowsprocess_creationMedium52Premium2026-06-08Suspicious node Execution of sync.js from NodeJS Masquerade Directory
This rule detects node running a sync.js payload from a NodeJS named directory used as a masquerade staging location in the AsyncAPI npm supply chain compromise. Executing a sync.js loader from a fake NodeJS folder is the import-time payload delivery step that pulls the second stage from the attacker C2.
HuntRule TeamWindowsprocess_creationMedium318Premium2026-06-08PipeShell Exfiltration Over Named Pipes (via powershell)
This rule detects establishes "PipeShell" connection(s) between a server and client(s) in order to move laterally or exfiltrate data. The server side will trigger "ServerStream" IOCs meanwhile the client side will trigger "ClientStream" IOCs. The rule works based on this condition, where at least 2 hosts need to trigger one of the condition.
HuntRule TeamWindowspowershellMedium273Premium2026-06-08Suspicious Certutil URL Download to Public Directory (Soco404 Cryptomining)
This rule detects certutil used with its urlcache flag to fetch a remote payload, the download technique of the Soco404 campaign that staged binaries under the Public user directory. It matters because certutil acting as a downloader is a living off the land pattern used to pull cryptomining payloads onto Windows hosts.
HuntRule TeamWindowsprocess_creationMedium142Premium2026-06-08Suspicious NTDS Database Extraction from System Volume
This rule detects command-line references to the NTDS.dit Active Directory database being copied or dumped, a credential-theft step seen in CitrixBleed post-exploitation. Attackers extract NTDS.dit to harvest domain credential hashes for offline cracking and further compromise. Because access to this file outside of backup or DC maintenance is rare, it is a strong indicator of domain credential theft.
HuntRule TeamWindowsprocess_creationMedium143Premium2026-06-08CMSTP UAC Bypass via Automatic Install Flag (via process_creation)
This rule detects cmstp.exe invoked with the /au automatic-install flag, the User Account Control bypass used by the Caminho loader in the PureRAT chain to run an INF-defined command with elevated privileges. Adversaries leverage CMSTP as a trusted binary to silently elevate and execute payloads, making detection of this rarely legitimate flag critical for catching privilege escalation before process hollowing.
HuntRule TeamWindowsprocess_creationHigh375Premium2026-06-08Suspicious Scheduled Task Masquerading as EdgeUpdateHelper via process_creation
This rule detects schtasks.exe creating a scheduled task named EdgeUpdateHelper. GhostSocks operators use this Edge-updater-themed task name to blend malicious persistence with legitimate Microsoft Edge update tasks, keeping the infostealer running while evading casual review of scheduled tasks.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-06-08Malicious C2 Configuration Stored in Registry via TitanPlus Key (via registry_set)
This rule detects the creation of the TitanPlus registry key used by the STAC5777 threat cluster to store a list of command and control IP addresses and ports read by a sideloaded malicious DLL. The activity followed Microsoft Teams vishing and Quick Assist abuse and provides resilient C2 configuration storage.
HuntRule TeamWindowsregistry_setHigh142Premium2026-06-08Malicious Member Added to DNSadmin Group (via security)
This rule detects scenarios where a suspicious change is done on DNSadmin group in order to abuse DNSadmin privileges for DLL load.
HuntRule TeamWindowssecurityHigh103Premium2026-06-08Suspicious Deletion of a Scheduled Task to Cover Tracks (via process_creation)
This rule detects schtasks being used to force-delete a scheduled task, a cleanup step attackers take to remove an execution or persistence artifact after it has served its purpose. Scheduled-task deletion is an indicator-removal technique noted in the Red Canary Threat Detection Report. Detecting the deletion surfaces anti-forensic activity around task-based execution.
HuntRule TeamWindowsprocess_creationMedium121Premium2026-06-08Suspicious Chained Host Reconnaissance One-Liner via DenoGate Backdoor
This rule detects a single cmd.exe command chaining ipconfig, route print, and tasklist to profile the network and running processes. The DenoGate backdoor runs this reconnaissance one-liner shortly after gaining access to map the victim environment. Bundling several enumeration commands into one line is uncommon for administrators and signals automated triage by an implant.
HuntRule TeamWindowsprocess_creationHigh193Premium2026-06-08Suspicious DNS Query to HTML Smuggling AiTM Phishing Domain
This rule detects DNS resolution of the rnsnno phishing infrastructure hosted under the .pro top-level domain that was used in an HTML smuggling adversary-in-the-middle campaign. Victims delivering credentials to these domains had their Microsoft 365 sessions relayed and stolen. Resolution of this infrastructure indicates a user has interacted with the phishing lure.
HuntRule TeamWindowsdns_queryMedium162Premium2026-06-08