Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,442 rules
Suspicious Toshiba Binary Sideloading toshdpapi.dll
This rule detects the legitimate Toshiba toshdpdb.exe loading a malicious toshdpapi.dll from its directory, a DLL sideloading chain used to run a PlugX variant in China-linked espionage intrusions that also deployed RA World ransomware.
HuntRule TeamWindowsimage_loadHigh408Premium2026-05-05Possible DLL Search Order Hijack of httpapi.dll Outside System32 (via image_load)
This rule detects the Windows httpapi.dll being loaded from a directory other than System32 or SysWOW64 which indicates DLL search order hijacking. Abuse of a writable agent directory to plant httpapi.dll was used to escalate privileges to SYSTEM against the Delinea Privilege Manager agent.
HuntRule TeamWindowsimage_loadHigh3410Premium2026-05-05Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)
This rule detects the SimpleHelp Remote Access client spawning a command shell that runs account and domain enumeration utilities. Following exploitation of SimpleHelp RMM for initial access, operators used the persisted client to run net and nltest reconnaissance.
HuntRule TeamWindowsprocess_creationMedium141Premium2026-05-04Suspicious Headless Browser Automation with Anti-Detection Flags via Astaroth (via process_creation)
This rule detects a browser launched in headless automation mode with flags that suppress automation indicators. The Astaroth spambot drives Chrome or Edge with headless, disable-infobars, and excludeSwitches settings to abuse authenticated web sessions without user awareness. This flag combination is unusual on endpoint hosts.
HuntRule TeamWindowsprocess_creationMedium258Premium2026-05-04Suspicious Permissions Changed on a Group Policy - GPO (via security)
This rule detects will attempt to take control over a group policy.
HuntRule TeamWindowssecurityMedium392Premium2026-05-04Suspicious Browser Launch With Remote Debugging for Cookie Theft (via process_creation)
This rule detects a Chromium-based browser launched with both a remote debugging port and a custom user data directory. Phantom Goblin abuses this to extract cookies and session data directly from the browser.
HuntRule TeamWindowsprocess_creationMedium221Premium2026-05-04Suspicious Service DLL Registration via regsvr32 Silent
This rule detects regsvr32.exe silently registering a DLL as part of the RONINGLOADER service installation chain that loads goldendays.dll. Adversaries use the silent flag to register malicious DLLs without user-visible prompts while establishing service-based persistence.
HuntRule TeamWindowsprocess_creationMedium458Premium2026-05-04Suspicious COLDRIVER Logon Script Persistence via UserInitMprLogonScript (via process_creation)
This rule detects a reg add command creating the UserInitMprLogonScript value under HKCU Environment to run a hidden PowerShell stager at logon as performed by the COLDRIVER SIMPLEFIX chain. This logon script value is a well known but rarely legitimate persistence location.
HuntRule TeamWindowsprocess_creationHigh294Premium2026-05-04Uncommon Print Spooler Exploitation Spawning a Child Process (via process_creation)
This rule detects the print spooler service (spoolsv.exe) spawning a command shell, script interpreter or a process from a user-writable path, behavior consistent with PrintNightmare-style spooler exploitation for code execution or privilege escalation. Print spooler abuse is a privilege-escalation technique noted in the Red Canary Threat Detection Report. Detecting anomalous spooler children surfaces exploitation of the service.
HuntRule TeamWindowsprocess_creationHigh133Premium2026-05-04Suspicious SystemSettings DLL Sideload from Non-System Path via image_load
This rule detects SystemSettings.exe loading a SystemSettings.dll from a path outside the System32 directory, the DLL sideloading technique used to launch SharkLoader in the StrikeShark campaign. The genuine binary only loads its companion DLL from System32. A matching name loaded from elsewhere indicates a sideloading proxy execution.
HuntRule TeamWindowsimage_loadHigh2910Premium2026-05-04Malicious Zhong Stealer Loader and Log Artifacts
This rule detects creation of TASLoginBase.dll or TASLogin.log, host artifacts written by the Zhong Stealer during execution and inventory logging. These filenames are unique to the Zhong Stealer toolkit targeting fintech support channels.
HuntRule TeamWindowsfile_eventHigh222Premium2026-05-04Suspicious PowerShell Download to AppData Intel Path
This rule detects PowerShell using DownloadFile to stage a payload into an AppData Intel directory as seen in the Foxit PDF exploitation chain. The attacker hides downloaded miner and RAT payloads under an Intel named folder in the user profile. Detecting the download cradle exposes remote payload retrieval.
HuntRule TeamWindowsprocess_creationHigh244Premium2026-05-04Suspicious Domain Trust Discovery via Nltest
This rule detects the nltest utility enumerating domain trusts, a reconnaissance step performed after GoldMelody gained code execution through ASP.NET ViewState deserialization. Adversaries map domain trust relationships to plan lateral movement. While administrators occasionally use nltest, its execution from web-facing hosts is suspicious.
HuntRule TeamWindowsprocess_creationMedium197Premium2026-05-04Suspicious Executable Launched from Domain Netlogon Share (via process_creation)
This rule detects execution of a binary located under a domain controller Netlogon share, a propagation method where RansomHub places scheduled tasks and payloads in the Netlogon folder to run on member logon per Group-IB. Adversaries abuse Group Policy and the Netlogon share to spread ransomware across domain hosts, so process execution from this path warrants investigation.
HuntRule TeamWindowsprocess_creationMedium333Premium2026-05-04Suspicious Payload Drop to Public User Directory by Gladinet Exploit
This rule detects the files d3d11.dll or Centre.exe being written under the Public user directory, a payload staging behavior observed by Huntress following CVE-2025-30406 exploitation of Gladinet CentreStack. Attackers drop a DLL sideloading component and secondary executable into a world-writable directory to establish execution and persistence. Placement of these named binaries in the Public directory is anomalous and indicates post-exploitation staging.
HuntRule TeamWindowsfile_eventMedium113Premium2026-05-04