Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,286 rules
Malicious Wdigest Authentication Enabled - Reg via Command (via process_creation)
This rule detects enable Wdgiest authention so passwords are stored in clear text and can be dumped.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-03Malicious Boot Recovery Tampering via Bcdedit (via process_creation)
This rule detects bcdedit disabling automatic recovery or forcing the boot status policy to ignore failures, an inhibit-system-recovery step ransomware runs so victims cannot restore Windows after encryption. Boot-configuration tampering is an impact technique tracked in the Red Canary Threat Detection Report. Detecting these commands surfaces recovery being sabotaged ahead of encryption.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-03Malicious Task Manager Used for LSASS Dump - Kernel (via security)
This rule detects attempt to dump the LSASS process via the Task Manager.
HuntRule TeamWindowssecurityHigh00Premium2026-09-03Malicious Compiled HTML Help Process Spawning a Script Interpreter (via process_creation)
This rule detects the Windows help viewer hh.exe spawning a command shell or script interpreter, which happens when a weaponized compiled HTML help (.chm) file executes embedded script for proxy execution. Compiled HTML File abuse is a System Binary Proxy Execution technique in the Red Canary Threat Detection Report used to run code under a trusted binary and evade allowlisting. Detecting interpreter children of hh.exe surfaces malicious CHM execution.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-03Suspicious Data Staging via Password-Protected Archive Utility (via process_creation)
This rule detects command-line archive tools (rar, 7z, WinRAR) creating password-protected or split archives, a collection-and-staging step attackers use to bundle stolen data before exfiltration. Archiving collected data is a technique tracked in the Red Canary Threat Detection Report. Detecting these invocations surfaces data being packaged for theft.
HuntRule TeamWindowsprocess_creationMedium50Premium2026-09-03Malicious Winlogon Process Contact to C2 - Blacklotus - Sysmon (via process_creation)
This rule detects blacklotus HTTP downloader injection into winlogon.exe process.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-03Malicious Event Log Clear Attempt - Wmi (via process_creation)
This rule detects clear the event logs.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-03Suspicious File Permission Grant to Everyone via Icacls (via process_creation)
This rule detects icacls granting the Everyone principal full control of files or directories, a file-permission-modification step attackers use to make payloads world-writable or to weaken protected paths. Broad permission grants are tracked in the Red Canary Threat Detection Report. Detecting these commands surfaces tampering with access controls.
HuntRule TeamWindowsprocess_creationMedium40Premium2026-09-03Malicious Interactive Privileged Shell Triggered by Schedule Task - Deprecated (via process_creation)
This rule detects abuse the at command to elevate privilages. Note that at command is deprecated since Windows 8 and replaced by schtask.
HuntRule TeamWindowsprocess_creationHigh100Premium2026-09-03Malicious Brutforce Enumeration with Non Existing Users - Login (via security)
This rule detects enumerate potential existing users, resulting in failed logins with unexisting or invalid accounts.
HuntRule TeamWindowssecurityHigh80Premium2026-09-03Malicious Host Constrained Delegation Settings Changed for Potential Abuse (Rubeus) - Any Protocol (via security)
This rule detects modifies host delegation settings for privilege escalation.
HuntRule TeamWindowssecurityHigh80Premium2026-09-03Malicious Webserver IIS Configuration Edited - SYSMON (via file_event)
This rule detects edit IIS configuration file in order to load a module.
HuntRule TeamWindowsfile_eventHigh80Premium2026-09-03USN Change Journal Deletion via Fsutil (via process_creation)
This rule detects fsutil deleting the NTFS USN change journal, an indicator-removal technique that erases the record of file creations and modifications to frustrate forensic timeline reconstruction. USN journal deletion is tracked in the Red Canary Threat Detection Report. Detecting this command surfaces anti-forensic activity on the host.
HuntRule TeamWindowsprocess_creationMedium50Premium2026-09-03Obfuscated Massive Service Failures - Tchopper (via system)
This rule detects uses the Tchopper tool by abusing the display name of a service as a placeholder to upload an obfuscated payload. Service name may come with very high entropy.
HuntRule TeamWindowssystemHigh120Premium2026-09-02Malicious DLL Execution via Wuauclt Update Handler (via process_creation)
This rule detects wuauclt.exe invoked with UpdateDeploymentProvider and RunHandlerComServer arguments, which loads an attacker DLL through the Windows Update client, a signed-binary proxy technique. Wuauclt abuse is a defense-evasion technique tracked in the Red Canary Threat Detection Report. Detecting this invocation surfaces trusted-binary DLL loading.
HuntRule TeamWindowsprocess_creationHigh90Premium2026-09-02