Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,443 rules
Suspicious Payload Drop to Public User Directory by Gladinet Exploit
This rule detects the files d3d11.dll or Centre.exe being written under the Public user directory, a payload staging behavior observed by Huntress following CVE-2025-30406 exploitation of Gladinet CentreStack. Attackers drop a DLL sideloading component and secondary executable into a world-writable directory to establish execution and persistence. Placement of these named binaries in the Public directory is anomalous and indicates post-exploitation staging.
HuntRule TeamWindowsfile_eventMedium113Premium2026-05-04Malicious Equation Editor Child Process Execution via process_creation
This rule detects the Microsoft Equation Editor EQNEDT32.EXE spawning any child process which almost always indicates exploitation of the CVE-2017-11882 memory corruption vulnerability. SideWinder delivered RTF documents that exploited Equation Editor to launch mshta.exe and fetch a remote HTA payload against maritime and nuclear targets. Equation Editor never legitimately creates child processes so this is a high confidence exploitation signal.
HuntRule TeamWindowsprocess_creationHigh112Premium2026-05-03Suspicious Defender Exclusion Added via Set-MpPreference
This rule detects use of Set-MpPreference with an exclusion path parameter to exempt a directory from Windows Defender scanning, a defense-evasion step performed by the PureCrypter loader. Adding broad exclusions is rarely a legitimate interactive action.
HuntRule TeamWindowsprocess_creationMedium173Premium2026-05-03Suspicious Subtitle File Parsing for Staged Command Execution
This rule detects a command that reads a subtitle srt file and pipes selected lines through findstr and more to extract and run embedded script code. This is the first stage of a fake movie torrent that delivers Agent Tesla through a layered PowerShell chain.
HuntRule TeamWindowsprocess_creationMedium71Premium2026-05-03Suspicious Shared Printer Creation - PrintNightmare Vulnerability - CVE-2021-36958 (via security)
This rule detects exploit the PrintNightmare vulnerability by exposing a vulnerable shared printer. At any case, any new printer share creation should be carefully monitored.
HuntRule TeamWindowssecurityMedium122Premium2026-05-03Suspicious Quick Format of Drive with Auto-Confirmation
This rule detects the format command running a quick format with automatic yes confirmation, matching the SyncFuture helpformat routine that wiped a drive. The batch tooling formatted a non-system volume with /Q and /Y to destroy data without user interaction. Unattended quick formatting of a drive is a destructive action that can indicate data-destruction or anti-forensic intent.
HuntRule TeamWindowsprocess_creationMedium41Premium2026-05-03Malicious secur32.dll Sideload From Color Profile Directory (via image_load)
This rule detects a secur32.dll being loaded from the printer spool color drivers directory rather than System32. ShadowPad was deployed via DLL sideloading using signed hosts such as WindowsUpdate.exe loading a malicious secur32.dll from spool drivers color. A trusted system DLL name loaded from an unexpected writable path indicates search-order hijacking and stealthy backdoor execution.
HuntRule TeamWindowsimage_loadHigh142Premium2026-05-03Suspicious CoinMiner KillProc Termination of Competing Miners (via process_creation)
This rule detects termination of competing mining processes such as phoenixminer, ethdcrminer64, or geekminer which the T-Rex CoinMiner campaign performs to monopolize GPU resources. Killing rival miner executables is a distinctive impact stage behavior.
—Windowsprocess_creationMedium91Premium2026-05-03Suspicious DynamicWrapperX Registration via regsvr32 (via process_creation)
This rule detects regsvr32.exe silently registering libeay32.dll, the loading vector for the DynamicWrapperX component used by the SugarGh0st RAT. Abusing regsvr32 to register a renamed helper DLL provides script-driven Windows API access while evading application controls.
HuntRule TeamWindowsprocess_creationMedium185Premium2026-05-03Nullsoft Scriptable Installer Script (NSIS) file creation
Detects the creation of the NSIS System plugin library, indicative of an NSIS script execution.
HuntRule TeamWindowsfile_eventLow91Premium2026-05-03Malicious Microsoft Defender Tampering via PowerShell MpPreference
This rule detects PowerShell disabling Microsoft Defender real-time monitoring or adding scan exclusions, the defense-evasion step performed by The Gentlemen ransomware before deploying its payload. Tampering with Defender protection settings is a high-confidence indicator of an adversary preparing to run malware unhindered.
HuntRule TeamWindowsprocess_creationHigh113Premium2026-05-03Suspicious Lazarus SIGNBT Loader Configuration Artifacts wpd Files (via file_event)
This rule detects creation of the external configuration and payload container files wpd.ini, wpd.mmf and wpd.bin that the Lazarus SIGNBT loader drops beside its side-loaded DLLs to hold AES-encrypted C2 proxy lists and payloads. These distinctively named artifacts accompany the loader on disk, making their appearance a useful indicator of a SIGNBT deployment.
HuntRule TeamWindowsfile_eventMedium72Premium2026-05-03Malicious DLL Sideloading via SmadavProtect and SolidPDFCreator by Stately Taurus
This rule detects legitimate signed executables SmadavProtect32.exe and SolidPDFCreator.exe loading the malicious sideloaded DLLs Smadhook32c.dll and SolidPDFCreator.dll used by Stately Taurus to run the errordetails payload described by Unit 42. DLL search-order hijacking of trusted binaries lets the actor execute espionage code under a benign process which evades signature-based defenses.
HuntRule TeamWindowsimage_loadMedium3010Premium2026-05-03Suspicious Kernel Mode Service Creation via SC
This rule detects creation of a kernel-mode service using sc with a kernel type flag, the mechanism used to load a driver during the ReadText34 ransomware incident as part of a bring-your-own-vulnerable-driver attack. Registering a kernel service outside of software installation is anomalous. Attackers exploit this to load vulnerable drivers that disable endpoint protection.
HuntRule TeamWindowsprocess_creationMedium101Premium2026-05-03Suspicious Execution of PIF File as AutoIt Loader
This rule detects execution of a process image with the .pif extension, an abuse observed in a Lumma infostealer campaign where a renamed AutoIt3 interpreter named Riding.pif performed process hollowing to inject the stealer. It captures the use of an uncommon executable extension to disguise a script interpreter. Detecting this is important because .pif files launching as active processes are almost never legitimate on modern systems and frequently indicate masqueraded loader activity.
HuntRule TeamWindowsprocess_creationMedium367Premium2026-05-03