Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,286 rules
SocGholish Fake Browser Update Script Execution (via process_creation)
This rule detects the Windows Script Host running a JavaScript file whose name impersonates a browser update, the delivery-and-execution behavior behind SocGholish drive-by fake-update lures. SocGholish is a prevalent initial-access threat profiled in the Red Canary Threat Detection Report that uses malicious JScript to stage follow-on payloads. Detecting the fake-update script surfaces the intrusion at the execution stage before hands-on-keyboard activity.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-03Malicious Sticky Key File Created from CMD Copy (via file_event)
This rule detects replace the original sethc.exe file by cmd.exe.
HuntRule TeamWindowsfile_eventHigh40Premium2026-09-03Suspicious PSexec Execution Over SMB Share (via security)
This rule detects execute PSexec on a remote host via SMB.
HuntRule TeamWindowssecurityMedium40Premium2026-09-03Obfuscated Paste-and-Run Execution From the Windows Run Dialog (via process_creation)
This rule detects explorer.exe directly spawning PowerShell, mshta or curl with a remote URL or encoded payload, the signature of a ClickFix/paste-and-run lure that tricks a user into pasting an attacker command into the Run dialog. Paste-and-run social engineering is one of the fastest-rising initial-access techniques in the Red Canary Threat Detection Report, delivering stealers and loaders. Detecting interpreter children of explorer carrying remote or encoded commands surfaces the intrusion at first execution.
HuntRule TeamWindowsprocess_creationHigh80Premium2026-09-03Malicious LSASS Credential Dump with LSASSY - Admin Share (via security)
This rule detects remotely dump LSASS credentials using the LSASSY tool.
HuntRule TeamWindowssecurityHigh70Premium2026-09-03Suspicious Impact of 'SMOKEDHAM Backdoor' with MSDTC Service Privilege Escalation via Command Line (via process_creation)
This rule detects activity related to 'SMOKEDHAM backdoor' which manipulate the default running service accounf of the MSDTC service in order to DLL side-load a malicious binary.
HuntRule TeamWindowsprocess_creationMedium00Premium2026-09-03Malicious Shell Spawned by Mshta Delivery (via process_creation)
This rule detects mshta.exe spawning PowerShell, cmd or another script host, the delivery-to-execution handoff seen in ClickFix, Lumma Stealer and SmartApeSG fake-update chains. Mshta launching a shell is an execution technique tracked in the Red Canary Threat Detection Report. Detecting this parent-child pair surfaces HTA-driven payload execution.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-03Suspicious Silent Installation of Remote Management Software (via process_creation)
This rule detects silent or unattended command-line installation of remote monitoring and management tools such as AnyDesk, ScreenConnect, Atera or ConnectWise, which adversaries deploy for stealthy remote access that blends into legitimate IT tooling. Abuse of RMM software for remote access is a technique repeatedly profiled in the Red Canary Threat Detection Report. Detecting unattended installs surfaces attacker-controlled remote access being established.
HuntRule TeamWindowsprocess_creationMedium30Premium2026-09-03DSRM Password Changed - Native (via security)
This rule detects reset or synchronize with another domain account the DSRM (Directory Services Restore Mode) password in order to escalate privileges.
HuntRule TeamWindowssecurityHigh30Premium2026-09-03PowerShell Storing an Encoded Payload in the Registry (via process_creation)
This rule detects PowerShell writing a base64 or byte-array value into an HKCU registry key, the fileless persistence and staging behavior seen in Solarmarker and Yellow Cockatoo intrusions. Storing an encoded payload in the registry is a defense-evasion and persistence technique tracked in the Red Canary Threat Detection Report. Detecting this write surfaces a fileless payload being cached for later execution.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-03Malicious DCSync Domain Replication Credential Theft (via process_creation)
This rule detects command lines invoking DCSync-style directory replication (lsadump::dcsync or a /dcsync switch), which abuses replication rights to pull password hashes for any account directly from a domain controller. DCSync is a high-impact credential-access technique in the Red Canary Threat Detection Report and a route to domain dominance. Detecting the replication request surfaces theft of privileged credentials without touching LSASS.
HuntRule TeamWindowsprocess_creationCritical10Premium2026-09-03Suspicious Security Software Discovery via WMI or Defender Query (via process_creation)
This rule detects command lines that enumerate installed antivirus or EDR products through the SecurityCenter2 WMI namespace or Get-MpComputerStatus, a security-software-discovery step taken to plan defense evasion. Security software discovery is tracked in the Red Canary Threat Detection Report. Detecting these queries surfaces an attacker profiling defenses before acting.
HuntRule TeamWindowsprocess_creationMedium30Premium2026-09-03Malicious DLL ServerLevelPluginDll Command Installation (via process_creation)
This rule detects scenarios where a DLL is loaded by the DNS server in order to escalate privileges or initiate a remote shell.
HuntRule TeamWindowsprocess_creationCritical10Premium2026-09-03Malicious Scheduled Persistent Task with SYSTEM Privileges Creation (via process_creation)
This rule detects creates a privileged task to establish persistence.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-03VSS Backup Deletion or Resize (via process_creation)
This rule detects delete or resize existing VSS backup.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-03