Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,443 rules
Suspicious PowerShell Download of updserc Archive to AppData via ClickFix
This rule detects PowerShell downloading an archive named updserc.zip into the local AppData directory. This activity is part of a ClickFix phishing chain abusing Booking.com themed lures to stage the PureRAT loader. Pulling a named archive into AppData through PowerShell is an early loader step that precedes DLL side-loading and in-memory execution.
HuntRule TeamWindowsprocess_creationHigh362Premium2026-05-03ClickFix Paste-Jacking Command Written to RunMRU History (via registry_set)
This rule detects download or script-execution commands recorded in the Explorer RunMRU history, the forensic residue left when a user pastes a clipboard-injected command into the Run dialog during a paste-jacking or ClickFix attack. Adversaries rely on this manual execution path to bypass download controls, making mshta or PowerShell cradle strings in RunMRU a useful post-execution indicator.
HuntRule TeamWindowsregistry_setMedium136Premium2026-05-03Malicious Data Exfiltration to Restic REST Server over HTTP (via process_creation)
This rule detects the restic backup utility being pointed at a remote REST endpoint over HTTP to back up file-share directories, the exfiltration channel used in the Nitrogen BlackCat intrusion to stage stolen data before ransomware. Adversaries repurpose restic as a fast deduplicating uploader to attacker-controlled REST servers, so restic writing to a rest http repository is a strong pre-encryption data-theft signal.
HuntRule TeamWindowsprocess_creationHigh123Premium2026-05-03Suspicious Vulnerable Driver googleapiutil64.sys Loaded for BYOVD
This rule detects loading of a driver named googleapiutil64.sys, a renamed vulnerable Baidu antivirus driver deployed by Warlock ransomware operators to disable security tooling via Bring Your Own Vulnerable Driver. The filename masquerades as a legitimate Google component.
HuntRule TeamWindowsdriver_loadHigh142Premium2026-05-02Obfuscated Encoded PowerShell Payload Deployed via Service (via security)
This rule detects deployed a service pointing to a hidden and encoded PowerShell payload. Some parameters are commented in case you would like to reduce false positives or make the rule more precise.
HuntRule TeamWindowssecurityHigh41Premium2026-05-02Malicious Axios NPM RAT Renamed PowerShell Execution via wt.exe
This rule detects a PowerShell binary copied to wt.exe under ProgramData and executed with a hidden window and execution policy bypass, matching the Axios NPM supply chain incident where a post-install hook drops a RAT. Renaming powershell.exe to wt.exe masquerades the interpreter as Windows Terminal to evade name-based detection. Execution of a masqueraded interpreter from ProgramData with bypass flags is a strong compromise indicator.
HuntRule TeamWindowsprocess_creationHigh338Premium2026-05-02Suspicious Fileless PowerShell Execution via Invoke-RestMethod Piped to IEX (via process_creation)
This rule detects PowerShell fetching remote content with Invoke-RestMethod and piping it straight into Invoke-Expression, the fileless delivery used by the SEO poisoning campaign impersonating Gemini and Claude Code installers. This pattern executes attacker-hosted script without touching disk. Some tooling uses irm iex legitimately, so review the target domain.
HuntRule TeamWindowsprocess_creationMedium377Premium2026-05-02Microsoft Defender SpyNet Reporting Disabled via Registry
This rule detects the Microsoft Defender SpyNetReporting registry value being set to 0, disabling cloud-delivered protection telemetry so malware runs with reduced detection. Huntress observed BlackCat affiliates degrading Defender before payload deployment. Turning off SpyNet reporting is a deliberate defense-evasion action rarely performed by legitimate administration.
HuntRule TeamWindowsregistry_setHigh3610Premium2026-05-02Suspicious New Rights Granted to an Account for Privilege Escalation (via security)
This rule detects grants new rights to an account in order to escalate privileges.
HuntRule TeamWindowssecurityMedium72Premium2026-05-02Malicious Mimikatz Driver Deployed via Service (via security)
This rule detects installs the Mimikatz driver to bypass the LSA protected mode (RunAsPPL) and dump LSASS process content.
HuntRule TeamWindowssecurityHigh1410Premium2026-05-02Malicious Impacket WMIexec Execution via SMB Admin Share (via security)
This rule detects remotely execute WMIexec via SMB admin share in order to escalate privileges.
HuntRule TeamWindowssecurityHigh73Premium2026-05-02Malicious Microsoft Defender Threat Exclusion Added - PowerShell (via powershell)
This rule detects scenarios where a threat exclusion is added to the antivirus in order to bypass its detection capacities.
HuntRule TeamWindowspowershellHigh173Premium2026-05-02Suspicious Windows Service ImagePath Pointing to AppData Directory
This rule detects creation or modification of a Windows service whose ImagePath references a user AppData directory. Legitimate services rarely execute from per-user AppData paths, so this pattern commonly indicates malware establishing persistence as a service. Reviewing such services helps surface service-based persistence.
HuntRule TeamWindowsregistry_setMedium102Premium2026-05-02Suspicious Daxin Backdoor Driver srt64.sys Loaded
This rule detects loading of a kernel driver named srt64.sys, associated with the Backdoor.Daxin espionage implant that hijacks legitimate network connections for covert command and control against hardened networks.
HuntRule TeamWindowsdriver_loadHigh121Premium2026-05-02Malicious Impacket wmiexec Output Redirection via ADMIN Share
This rule detects the characteristic Impacket wmiexec command line that redirects command output to a temporary file on the local admin share over the loopback address as described in the WithSecure WMI lab. This redirection pattern is highly specific to semi interactive Impacket WMI execution and is a strong indicator of remote lateral movement by an attacker toolkit.
HuntRule TeamWindowsprocess_creationHigh385Premium2026-05-02