Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,411 rules
Suspicious GoGRPC Persistence via Realtek HD Audio Run Key (via process_creation)
This rule detects a PowerShell command that sets a CurrentVersion Run value named Realtek HD Audio pointing to an executable in the roaming AppData folder as used by the GoGRPC backdoor. Legitimate Realtek audio software does not persist from AppData.
HuntRule TeamWindowsprocess_creationHigh134Premium2026-05-12Suspicious VMware Tools Binary Executing from Non-Standard Path
This rule detects a process named vmtools.exe or vmwared.exe running from a directory outside the legitimate VMware installation tree. CL-STA-1062 masquerades its loader as VMware guest tooling to evade analyst scrutiny on virtualized targets. Spotting the trusted filename in the wrong path exposes a masqueraded implant rather than genuine VMware software.
HuntRule TeamWindowsprocess_creationHigh162Premium2026-05-12Suspicious Batch Execution From Hidden __MACOSX Archive Path (via process_creation)
This rule detects a command shell executing a batch file from a hidden __MACOSX directory extracted from a delivery archive, the initial execution step of this Cobalt Strike infection chain. Legitimate workflows do not run scripts from __MACOSX archive residue.
HuntRule TeamWindowsprocess_creationHigh125Premium2026-05-12Suspicious Excel Outbound Network Connection
This rule detects Excel.exe initiating an outbound network connection, which is unusual for a spreadsheet application that has no child process. In the WithSecure Initial Access Lab 4 an Excel 4.0 SLK macro injects meterpreter shellcode into Excel itself which then beacons over HTTPS to a non-Microsoft address. Attackers keep the malicious code inside the Office host to avoid spawning a suspicious child process.
HuntRule TeamWindowsnetwork_connectionMedium365Premium2026-05-11Suspicious Windows Event Log Clearing via wevtutil (via process_creation)
This rule detects wevtutil being used to clear Windows event logs. This behavior was observed in Cyber Partisans activity aimed at espionage and disruption to destroy forensic evidence after intrusion. Because administrators occasionally clear logs during maintenance, matches should be correlated with the surrounding activity and account context.
HuntRule TeamWindowsprocess_creationMedium152Premium2026-05-11Suspicious Microsoft Defender Security Components Disabled - Command (via process_creation)
This rule detects disable Defender security features.
HuntRule TeamWindowsprocess_creationMedium1610Premium2026-05-11Suspicious UAC Bypass via Fodhelper Child Process
This rule detects fodhelper.exe spawning a child process, the hallmark of the ms-settings protocol handler UAC bypass used by BQTLock to elevate before injecting Remcos into explorer.exe. Fodhelper does not normally launch child processes outside of Settings interactions.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-05-11ArmouryLoader Persistence via Scheduled Task AsusUpdateServiceUA (via process_creation)
This rule detects creation of a scheduled task named AsusUpdateServiceUA, the persistence artifact ArmouryLoader registers to relaunch its shellcode payload at logon or on a short recurring interval while masquerading as an Asus update service. Adversaries use a plausible vendor task name to survive reboots and blend into legitimate software, making early detection critical for exposing the loader before CoffeeLoader delivery.
HuntRule TeamWindowsprocess_creationMedium158Premium2026-05-11Suspicious WindowsCodecs DLL Sideload from Non System Path by Fighting Ursa
This rule detects WindowsCodecs.dll being loaded from a location outside the Windows system directories, the DLL search order hijack Fighting Ursa uses when a renamed calc.exe sideloads a malicious copy to run its batch payload. Loading a system DLL name from a user path indicates sideloading rather than legitimate use. Detecting this exposes the sideload stage of the infection.
HuntRule TeamWindowsimage_loadMedium262Premium2026-05-11Malicious Citrix WFShell Spawning Command Interpreter via Command Line
This rule detects the Citrix wfshell.exe or cmstart.exe process spawning a command interpreter, a post-exploitation chain observed after abuse of the Citrix Bleed vulnerability CVE-2023-4966 leading to LockBit ransomware. These Citrix components should not launch shells. Detecting the chain exposes hands-on-keyboard activity following gateway compromise.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-05-11Malicious Office Application Spawning a Command Shell or Script Interpreter (via process_creation)
This rule detects a Microsoft Office application such as Word, Excel, PowerPoint or Outlook launching a command shell or script interpreter, the classic child-process signature of a malicious macro or exploited document. Phishing-driven Windows Command Shell and script execution rank among the most prevalent techniques in the Red Canary Threat Detection Report, marking the transition from initial access to code execution. Detecting interpreter children of Office processes surfaces the intrusion at that hand-off.
HuntRule TeamWindowsprocess_creationHigh151Premium2026-05-11Malicious Bring-Your-Own-Vulnerable-Driver Load By BlackByte
This rule detects loading of vulnerable kernel drivers abused by BlackByte to disable endpoint protection. BlackByte deployed the RtCore64 DBUtil_2_3 zamguard64 and gdrv vulnerable drivers to gain kernel-level code execution. Loading a known-vulnerable signed driver is a BYOVD technique that lets attackers terminate security products and tamper with the kernel.
HuntRule TeamWindowsimage_loadHigh133Premium2026-05-11Suspicious Microsoft Defender Exclusion Added via PowerShell
This rule detects PowerShell adding a Microsoft Defender exclusion path, a defense-evasion step performed by Pure Crypter before deploying its payload. Attackers exclude their staging directories from antivirus scanning so subsequent malicious files execute undetected, making unexpected Add-MpPreference exclusions a reliable evasion indicator.
HuntRule TeamWindowsprocess_creationMedium133Premium2026-05-11Cleo File Transfer Software Spawning Command Interpreter
This rule detects a Cleo managed file transfer process spawning a command interpreter such as cmd, PowerShell or Bash, the post-exploitation behavior of CVE-2024-55956 autorun abuse leading to Cobalt Strike by CL0P. A Cleo product launching a shell indicates exploitation of the Cleo Harmony VLTrader or LexiCom software.
HuntRule TeamWindowsprocess_creationHigh122Premium2026-05-11Suspicious Subprocess Spawned by LiteLLM Proxy Process (via process_creation)
This rule detects a LiteLLM proxy Python process spawning a shell or network utility. Such a child process is consistent with the subprocess execution abused in CVE-2026-42271. A LiteLLM proxy does not normally launch shells or download tools.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-05-11