Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,409 rules
Malicious Keylogger DLL Execution via Rundll32 klg.dll
This rule detects rundll32.exe loading a DLL named klg.dll which Interlock ransomware operators deploy as a keylogger to capture credentials and keystrokes. The specific module name executed through rundll32 is a reliable behavioral indicator of the keylogging component.
HuntRule TeamWindowsprocess_creationHigh113Premium2026-05-17Malicious DLL Side-Loading of vcl120.bpl From AppData via HijackLoader (via image_load)
This rule detects a vcl120.bpl Delphi runtime package being loaded from a user AppData Roaming directory, the side-loading step used by the IObit-abusing HijackLoader to stage AsyncRAT. The legitimate vcl120.bpl resides with its application, not under AppData.
HuntRule TeamWindowsimage_loadHigh131Premium2026-05-17Suspicious NTFS Symbolic Link Evaluation Enabled via fsutil for Remote Access (via process_creation)
This rule detects fsutil enabling remote-to-local or remote-to-remote symbolic link evaluation, an uncommon configuration change made in the RansomHub intrusion to let symlinks resolve across hosts during propagation and encryption. Adversaries flip these SymlinkEvaluation settings to reach files through crafted links that are normally blocked, so this fsutil behavior change is a distinctive attacker-preparation indicator.
HuntRule TeamWindowsprocess_creationMedium308Premium2026-05-16Suspicious Office VBA Security Downgrade via Registry (via registry_set)
This rule detects registry changes that enable programmatic access to the VBA object model and disable macro warnings which the OfflRouter virus sets to spread through Office documents without prompting. Weakening Office macro protections is a precursor to self-propagating macro malware and unattended code execution.
HuntRule TeamWindowsregistry_setMedium322Premium2026-05-16Malicious ServiceDll Hijack with QSC Loader DLL
This rule detects a service Parameters ServiceDll value being set to the QSC loader DLLs swprr.dll or rasautosvc.dll. The CloudComputating group hijacked a Windows service to load these DLLs from System32 and execute the QSC multi-plugin framework with service persistence.
HuntRule TeamWindowsregistry_setHigh441Premium2026-05-16Suspicious RevengeHotels JS Loader Spawning PowerShell (via process_creation)
This rule detects wscript executing a Fat named JavaScript file that then launches PowerShell as used in the RevengeHotels campaign to stage VenomRAT. The threat actor delivers phishing JS droppers whose PowerShell child fetches the remote access trojan. A script host running a Fat JS file with a PowerShell descendant is a strong sign of this loader chain.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-05-16Suspicious Guest Account Enablement via net user for Privilege Abuse
This rule detects the built in guest account being activated through net user which the Gh0stGambit dropper abused for elevation. Enabling and repurposing the guest account provides a low visibility foothold for continued access. Activation of this normally disabled account is a strong sign of account manipulation.
HuntRule TeamWindowsprocess_creationHigh163Premium2026-05-16Suspicious Ukraine-Themed LNK Lure Files Dropped (via file_event)
This rule detects creation of shortcut lure files with region and messaging themed names used by the STEADY#URSA campaign for removable-media replication and social engineering against Ukrainian military targets.
HuntRule TeamWindowsfile_eventHigh102Premium2026-05-16Suspicious Port Forwarding Configuration via netsh portproxy (via process_creation)
This rule detects configuration of an IPv4 or IPv6 port forwarding rule using netsh portproxy. Fire Ant used netsh portproxy on servers and workstations to pivot and relay traffic deeper into segmented networks, sometimes abusing IPv6 to bypass IPv4 filtering. Network administrators may occasionally use portproxy for legitimate forwarding.
HuntRule TeamWindowsprocess_creationMedium285Premium2026-05-16Suspicious FileFix TypedPaths Entry Containing PowerShell or URL
This rule detects an Explorer TypedPaths registry value that records a PowerShell command or HTTP URL, the forensic artifact left when a FileFix lure has the victim paste an obfuscated command into the File Explorer address bar. TypedPaths normally stores browsed folder locations, not scripts or web addresses. A command string or URL in this value indicates the FileFix address-bar execution technique.
HuntRule TeamWindowsregistry_setHigh303Premium2026-05-16Suspicious PowerShell Stager Download of Spf Script by Seedworm
This rule detects PowerShell referencing the Spf.ps1 stager under a remote install path used by the Seedworm MuddyWater actor. The script initiates the next stage of the intrusion against Middle East targets. PowerShell fetching a remote install script is a common first-stage execution technique.
HuntRule TeamWindowsps_scriptMedium122Premium2026-05-16Suspicious Mustang Panda Scheduled Task SolidPDFPcl2Bmp Creation (via process_creation)
This rule detects creation of the SolidPDFPcl2Bmp scheduled task that relaunches the pcl2bmp sideloading host every five minutes in the Mustang Panda ZOHOMURK campaign. Adversaries register a five-minute recurring task pointing at the sideloaded binary in Public Documents to maintain execution. The task name paired with the Public Documents target path is highly specific.
HuntRule TeamWindowsprocess_creationMedium326Premium2026-05-16Suspicious Secedit Security Policy Export for Reconnaissance (via process_creation)
This rule detects secedit.exe exporting the local security policy configuration to a temp file as observed during the SoftEther VPN intrusion reconnaissance. Attackers export the policy to understand password and account restrictions before creating backdoor users.
—Windowsprocess_creationMedium3210Premium2026-05-16Malicious Shadow Copy Deletion and Recovery Tampering by BabLock Ransomware
This rule detects deletion of volume shadow copies and disabling of Windows recovery, hallmarks of BabLock ransomware pre-encryption activity. The operators run vssadmin Delete Shadows and bcdedit recoveryenabled No to prevent victims restoring their data. This inhibits recovery and maximizes the impact of the encryption stage.
HuntRule TeamWindowsprocess_creationHigh72Premium2026-05-16Malicious Payload Decoding via Certutil
This rule detects certutil using its decode function against PDF-named files to reconstruct an executable payload from base64, a defense-evasion and deobfuscation step. This was observed in a Vietnamese threat actor chain delivering PureRAT. Abusing certutil to decode disguised files bypasses download controls and unpacks the next-stage loader.
HuntRule TeamWindowsprocess_creationHigh2710Premium2026-05-16