Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,407 rules
Malicious Defender Real-Time Monitoring Disable via Registry
This rule detects the DisableRealtimeMonitoring registry value being enabled to turn off Microsoft Defender real-time scanning. This was observed during Cephalus ransomware deployment alongside service stops and exclusions. Disabling real-time monitoring removes on-access detection so the encryptor can run freely.
HuntRule TeamWindowsregistry_setHigh163Premium2026-05-19Suspicious MSHTA Remote HTML Application Execution via Amatera Stealer ClickFix
This rule detects mshta.exe launching an HTML application from a remote URL, the ClickFix delivery step for the Amatera Stealer 4.0.2 variant. The victim is lured into running a copied command that pulls an HTA from attacker infrastructure. Remote mshta execution is a common living-off-the-land loader technique and should be reviewed against expected administrative activity.
HuntRule TeamWindowsprocess_creationMedium394Premium2026-05-19Suspicious propsys.dll Sideload via ComputerDefaults UAC Bypass (via image_load)
This rule detects ComputerDefaults.exe loading propsys.dll from outside the Windows system directories, the DLL sideload and UAC bypass the 8220 Gang chains to elevate and continue its cryptomining deployment. The auto-elevating ComputerDefaults binary is abused to load an attacker propsys.dll placed in a writable path. Detecting this non-system load surfaces the UAC bypass and sideloading step.
HuntRule TeamWindowsimage_loadHigh259Premium2026-05-19Malicious Obsidian Spawning Command Interpreter via Shell Commands Plugin
This rule detects the Obsidian note taking application spawning PowerShell, cmd or a shell as abused by the PhantomPulse RAT delivery chain through the Shell Commands plugin in Elastic research. A document editor launching a command interpreter is anomalous and indicates weaponized vault content executing attacker code.
HuntRule TeamWindowsprocess_creationHigh328Premium2026-05-19Suspicious Mshta Execution Of Remote HTA
This rule detects mshta.exe executing an HTA hosted at a remote http or https URL. In the WithSecure Initial Access Lab 2 the Koadic stager is delivered as a remote HTA run directly by mshta. Attackers use mshta to fetch and run remote HTML applications as a proxy execution and download technique.
HuntRule TeamWindowsprocess_creationHigh159Premium2026-05-19Suspicious Atera Agent Silent Installation via Command Line (via process_creation)
This rule detects silent installation of the Atera RMM agent identified by its IntegratorLogin and CompanyId command-line parameters. Adversaries deploy Atera as an unsanctioned remote access channel using these silent-install arguments, so their presence outside an approved rollout indicates RMM misuse.
HuntRule TeamWindowsprocess_creationMedium111Premium2026-05-19Suspicious schtasks Persistence Spawned from PowerShell or Script Chain
This rule detects schtasks creating a scheduled task when launched from a PowerShell or command-shell parent, a persistence step observed in the Suky Castle ClickFix-style campaign where an obfuscated PowerShell to cmd to attrib to schtasks chain established persistence. It captures scheduled-task creation originating from an interactive scripting context rather than an installer. Detecting this is important because attacker-driven schtasks activity typically descends from a script host rather than a legitimate management tool.
HuntRule TeamWindowsprocess_creationMedium175Premium2026-05-19Suspicious Access To Chrome Credential Files
This rule detects read access to the Google Chrome Local State, Cookies and Login Data files by a process other than Chrome, captured via a SACL file audit and Security event 4663. In the WithSecure Windows Lab 4 tooling such as Chlonium or Mimikatz reads these files to steal the DPAPI master key and decrypt session cookies and stored passwords. Attackers harvest browser credentials and session tokens for account takeover.
HuntRule TeamWindowssecurityHigh335Premium2026-05-19Suspicious PowerShell Execution Referencing an AppData Path
This rule detects powershell.exe executing a command that references a user AppData path, a persistence pattern in which scheduled tasks or autoruns launch PowerShell payloads staged in AppData. This behavior helps hunt for script-based persistence that survives reboots.
HuntRule TeamWindowsprocess_creationMedium73Premium2026-05-19Suspicious OpenClaw AI Agent Spawning Command Shell via Process Creation
This rule detects the OpenClaw AI agent binaries openclaw, clawdbot, or moltbot spawning a Unix command shell, the execution pattern that follows a poisoned agent skill being loaded. Adversaries plant malicious skills so the agent runs attacker commands with the user privileges, so an AI agent process launching sh, bash, or zsh is a strong sign of skill-based code execution.
HuntRule TeamWindowsprocess_creationMedium418Premium2026-05-19Malicious more_eggs LOLBIN Scriptlet Execution via ie4uinit BaseSettings Abuse (via process_creation)
This rule detects the ie4uinit LOLBIN being run with the -basesettings flag from a user-writable location such as AppData, the first-stage technique in the more_eggs TA4557 resume-lure intrusion where a copied ie4uinit loaded a malicious SCT through a planted ieuinit.inf. Adversaries relocate this signed binary to abuse its inf-driven command execution while evading path-based controls, so an out-of-System32 ie4uinit with -basesettings indicates staged code execution.
HuntRule TeamWindowsprocess_creationHigh159Premium2026-05-18Malicious LSASS Memory Dump via comsvcs.dll MiniDump (via process_creation)
This rule detects credential theft where rundll32 invokes the MiniDump export of comsvcs.dll to dump the memory of the LSASS process to disk, a technique observed in Akira ransomware intrusions. The resulting dump is later parsed offline to recover plaintext credentials and hashes.
HuntRule TeamWindowsprocess_creationHigh62Premium2026-05-18Malicious Windows Defender Service Disable via sc.exe by Nova Ransomware
This rule detects sc.exe being used to disable the WinDefend service by setting its start type to disabled, a defense evasion step performed by Nova ransomware before encryption. Disabling the Defender service removes real-time protection from the host.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-05-18Coin Miner Masquerading as Misspelled svchost Process
This rule detects execution of processes named svhost.exe or svshost.exe, misspelled variants of the legitimate Windows svchost.exe. The GPU miner campaign ran its cryptomining payload under these typosquatted names to masquerade as a trusted system process. Any process using these near-identical names is almost certainly a masquerade attempt.
HuntRule TeamWindowsprocess_creationHigh113Premium2026-05-18Malicious Shai-Hulud Data Exfiltration Script Execution via Process Creation
This rule detects execution of the .dev-env/config.sh helper script through bash, the staging and exfiltration routine dropped by the Shai-Hulud worm. The script bundles harvested secrets and pushes them to attacker infrastructure, so its execution indicates active collection and exfiltration on a compromised developer or build host.
HuntRule TeamWindowsprocess_creationHigh144Premium2026-05-18