Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,279 rules
Malicious Xctdoor XcLoader Execution via Regsvr32 AppX Path Abuse (via process_creation)
This rule detects regsvr32.exe loading a DLL named settings.lock from the Microsoft MicrosoftOffice365Hub AppX package settings directory. This loader technique is used by the Xctdoor and XcLoader backdoors to execute encrypted payloads from a user AppX path where legitimate COM registration is not expected.
—Windowsprocess_creationHigh30Premium2026-09-05Suspicious Hidden Backdoor Account Creation Ending With Dollar Sign (via process_creation)
This rule detects creation of hidden local accounts whose names end with a dollar sign such as mssql or adminweb1 as used by the MS-SQL intruder for stealthy persistence. Accounts ending in a dollar sign are hidden from the standard net user listing.
—Windowsprocess_creationMedium60Premium2026-09-05Malicious Potato Family Privilege Escalation Tool Execution (via process_creation)
This rule detects execution of Potato family token impersonation tools including JuicyPotatoNG, RasManPotato, SigmaPotato, BadPotato, and RustPotato used for local privilege escalation in the MS-SQL intrusion. These utilities abuse SeImpersonate privileges to elevate to SYSTEM.
—Windowsprocess_creationHigh20Premium2026-09-05Malicious Certutil Decode of Encoded Web Shell to ASPX (via process_creation)
This rule detects certutil.exe decoding a text file into an ASPX web shell within a web server images directory as seen in the targeted MS-SQL server intrusion. Certutil decoding output directly into a web accessible aspx file is a common web shell deployment technique.
—Windowsprocess_creationHigh30Premium2026-09-05Suspicious MSBuild Execution From Office or Archive Extraction Context (via process_creation)
This rule detects MSBuild.exe being launched by Office applications, mail clients, or archive tools which is a strong sign of a phishing driven LOLBin attack. In a normal development environment MSBuild is invoked by build tooling rather than by document or extraction processes.
—Windowsprocess_creationMedium20Premium2026-09-05Suspicious Kimsuky Scheduled Task Impersonating Google Update CGI (via process_creation)
This rule detects schtasks creation of persistence tasks named GoogleUpdateTaskMachineCGI or GoogleExtension that launch wscript or the Python backdoor beauty.py as used by the Kimsuky LNK campaign. These task names impersonate Google update jobs to hide short interval persistence.
—Windowsprocess_creationMedium30Premium2026-09-05Malicious Ladon PowerShell Attack Framework Import (via process_creation)
This rule detects PowerShell importing the Ladon attack framework module and invoking its modules such as SweetPotato, Runas, or MssqlCmd as observed in the MeshAgent and SuperShell intrusion. Ladon provides scanning, privilege escalation, and lateral movement capabilities.
—Windowsprocess_creationHigh50Premium2026-09-05Suspicious Fscan Internal Network Scanner Execution (via process_creation)
This rule detects execution of the fscan network scanner with host file and silent output options as observed in the MeshAgent and SuperShell intrusion. Fscan is used by the actor to enumerate internal hosts and open ports for lateral movement.
—Windowsprocess_creationMedium20Premium2026-09-05Suspicious Browser History Wipe via Rundll32 ClearMyTracksByProcess (via process_creation)
This rule detects rundll32.exe invoking InetCpl.cpl ClearMyTracksByProcess to clear browser history and cache as used by the HiddenGh0st malware to remove traces. This indicator flag combination erases stored browsing artifacts on the host.
—Windowsprocess_creationMedium40Premium2026-09-05Suspicious CRAT Injection Named Pipe ChromeUpdatePipe (via pipe_created)
This rule detects the creation of the named pipe ChromeUpdatePipe used by the CRAT payload to transmit injected code between processes. The pipe masquerades as a Chrome update channel and is a stable indicator of this backdoor family.
—Windowspipe_createdHigh20Premium2026-09-05Suspicious Xctdoor Script Dropper Staging in Public Videos Folder (via file_event)
This rule detects the creation of VBS, BAT, or PS1 launcher and downloader scripts inside the Public Videos directory, a staging location used by the Xctdoor infection chain. Script files in this path are highly unusual for normal user activity.
—Windowsfile_eventMedium20Premium2026-09-05Suspicious Larva-24009 Keylogger Log Staging in OneDrive Path (via file_event)
This rule detects the creation of keylogger output files named log.log or logv.log under the ProgramData Microsoft OneDrive directory as observed in the Larva-24009 campaign. The use of an OneDrive named folder under ProgramData for keystroke capture is a strong indicator of this actor.
—Windowsfile_eventMedium20Premium2026-09-05Suspicious AtlasRAT Loader Artifacts in Public Documents (via file_event)
This rule detects the creation of AtlasRAT loader components such as Wxfun.dll, offline.ini, and MODIf.html in the Public Documents directory. These filenames and location are used by the AtlasRAT in-memory loader chain to stage and inject the RAT.
—Windowsfile_eventMedium40Premium2026-09-05Suspicious Kimsuky Python Backdoor Staging in Winii Directory (via file_event)
This rule detects the creation of the Python backdoor beauty.py or its norton.db scheduler definition inside the C winii directory as used by the Kimsuky LNK campaign. This hidden staging path and filename set are distinctive to the backdoor deployment.
—Windowsfile_eventMedium60Premium2026-09-05Suspicious T-Rex CoinMiner Binaries in Windows NT Program Files Folder (via file_event)
This rule detects the creation of T-Rex CoinMiner executables such as mmc.exe, mtn.exe, syc.exe, syn.exe, or tnt.exe inside a Windows NT folder under Program Files x86 as used in the internet cafe mining campaign. Placing miner binaries under a fake Windows NT directory is a masquerading technique.
—Windowsfile_eventMedium90Premium2026-09-05