Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,449 rules
Suspicious Foxit PDF Reader Spawning Command Interpreter
This rule detects Foxit PDF Reader spawning a command interpreter, the exploitation behavior triggered by a crafted PDF using OpenAction and Launch. Foxit should not normally launch cmd or PowerShell so this parent child pair signals abuse of the flawed design. Detecting it catches the initial code execution from the malicious document.
HuntRule TeamWindowsprocess_creationHigh308Premium2026-05-01Malicious Safe Mode Boot Configuration via bcdedit for Defense Evasion via Process Creation
This rule detects bcdedit.exe forcing a minimal safe-mode boot, a technique the Embargo ransomware uses to restart the host into an environment where most security products do not run before encrypting files. Legitimate administrative use of this exact command is rare on endpoints. This indicates preparation for defense evasion and ransomware detonation.
HuntRule TeamWindowsprocess_creationHigh406Premium2026-05-01Malicious LOLBin Download Saved as Windows Utility ping.exe via certutil or curl
This rule detects use of certutil or curl to download a remote file and save it under the name of a legitimate Windows utility such as ping.exe. The Mysterious Elephant APT used this masquerading technique to stage payloads disguised as trusted system binaries. Writing downloaded content to a well-known utility name in a non-System32 location is a strong indicator of ingress tool transfer combined with defense evasion.
HuntRule TeamWindowsprocess_creationHigh294Premium2026-05-01Malicious PowerShell DownloadFile to AppData Executable
This rule detects PowerShell using the WebClient DownloadFile method to fetch an executable into the AppData directory. Warzone RAT runs obfuscated PowerShell that downloads gm.exe into %appdata% before establishing persistence and UAC bypass. Downloading executables into AppData via PowerShell DownloadFile is a common malware retrieval and staging behavior.
HuntRule TeamWindowsprocess_creationHigh101Premium2026-05-01Malicious LOLBin Spawned by Outlook via MonikerLink CVE-2024-21413
This rule detects Microsoft Outlook spawning script interpreters or living off the land binaries such as mshta which is a hallmark of the MonikerLink CVE-2024-21413 exploitation chain. Successful exploitation lets an attacker bypass the Protected View warning and achieve code execution from a crafted email which makes any such child process highly suspicious.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-05-01Malicious CRYPTBASE.dll Side-Loading Outside System32
This rule detects CRYPTBASE.dll being loaded from a directory outside the Windows System32 folder. The CPU-Z and HWMonitor watering-hole campaign side-loaded a malicious CRYPTBASE.dll next to a trusted binary to hijack execution as reported by Kaspersky. Because the genuine CRYPTBASE.dll ships only in System32, loading it from any other path is a reliable DLL search-order hijack indicator.
HuntRule TeamWindowsimage_loadHigh173Premium2026-05-01Suspicious BitLocker FVE Policy Modification via Registry (via registry_set)
This rule detects writes to the HKLM SOFTWARE Policies Microsoft FVE registry policy keys which the ShrinkLocker ransomware sets to force BitLocker encryption behavior and enable drive locking against the victim.
HuntRule TeamWindowsregistry_setMedium241Premium2026-05-01Possible Shadow Credentials Abuse via msDS-KeyCredentialLink Modification
This rule detects modification of the msDS-KeyCredentialLink attribute on a directory object. Adversaries write key credentials to this attribute to perform certificate-based authentication as the target account, a technique known as Shadow Credentials used for persistence and credential theft.
HuntRule TeamWindowssecurityHigh299Premium2026-05-01Malicious Interlock Ransomware Ransom Note File Creation
This rule detects creation of ransom note files named README that Interlock ransomware writes across encrypted directories using the distinctive filename bang README bang txt. The unique note filename indicates active ransomware deployment and data encryption on the host.
HuntRule TeamWindowsfile_eventHigh83Premium2026-04-30Malicious Backup Catalog Deletion via Wbadmin (via process_creation)
This rule detects wbadmin being used to delete the backup catalog or system state backups. Ransomware destroys Windows Backup data so that administrators cannot restore files or system state after encryption. Deletion of backup catalogs is a deliberate recovery-inhibition step and rarely part of legitimate maintenance.
HuntRule TeamWindowsprocess_creationHigh82Premium2026-04-30Windows Print.EXE Sensitive File Dump for Credential Access
Alerts when Print.EXE is executed with arguments targeting ntds.dit, SAM, SECURITY, and SYSTEM files for credential access.
Ayush Anand (Securityinbits), Huntrule TeamWindowsprocess_creationHigh121Free2026-04-28Windows: WMIC service ChangeStartMode sets Manual or Disabled startup type
Detects wmic.exe commands changing a Windows service startup type to Manual or Disabled via ChangeStartMode.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium468Free2026-04-27Windows SFTP.exe Indirect Command Execution via ProxyCommand
Flags SFTP.exe executions that include ProxyCommand=, indicating potential indirect command execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium271Free2026-04-27Windows PUA: MemProcFS memory dump mounting via -device
Detects MemProcFS.exe execution with -device on Windows, consistent with mounting memory dumps for potential credential access.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh424Free2026-04-27Windows HackTool Indicators: NetExec (nxc.exe) PyInstaller Extraction Artifacts
Flags Windows file creation under Temp\_MEI* where NetExec nxc data files are dropped, indicating likely NetExec execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh201Free2026-04-08