Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,286 rules
Suspicious File Timestamp Manipulation via PowerShell (via process_creation)
This rule detects PowerShell setting both CreationTime and LastWriteTime on a file, the hallmark of timestomping used to blend a dropped payload in with legitimate files and defeat timeline analysis. Timestomping is an indicator-removal technique tracked in the Red Canary Threat Detection Report. Detecting these property assignments surfaces anti-forensic tampering with file metadata.
HuntRule TeamWindowsprocess_creationMedium50Premium2026-09-02Malicious DLL ServerLevelPluginDll Registration - Reg via Sysmon (via registry_set)
This rule detects scenarios where a DLL is loaded by the DNS server in order to escalate privileges or initiate a remote shell.
HuntRule TeamWindowsregistry_setCritical40Premium2026-09-02Registry Query for WDigest
Rule to detect discovery activity for WDigest registry settings
HuntRule TeamWindowsprocess_creationMedium40Premium2026-09-02Malicious Registry Hive Dump of SAM or SYSTEM via Reg Save (via process_creation)
This rule detects reg.exe saving the SAM, SYSTEM or SECURITY registry hive to disk, which lets an attacker extract local credential material and boot keys for offline hash recovery. Registry hive dumping is a credential-access technique documented in the Red Canary Threat Detection Report. Detecting these save commands surfaces local credential theft in progress.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-02Suspicious Code Execution via InstallUtil LOLBIN (via process_creation)
This rule detects InstallUtil.exe run with uninstall or log-suppression flags used to trigger attacker code in a .NET assembly's Uninstall method while avoiding console output, a signed-binary proxy technique. InstallUtil abuse is a defense-evasion technique tracked in the Red Canary Threat Detection Report. Detecting these command lines surfaces code execution under a trusted Microsoft utility.
HuntRule TeamWindowsprocess_creationMedium40Premium2026-09-02Malicious UAC Bypass via sdclt Handler Hijack (via registry_set)
This rule detects modification of the HKCU exefile runas isolatedCommand or Folder shell open command keys that sdclt.exe consults, a registry hijack used to auto-elevate an attacker command without a UAC prompt. This sdclt handler hijack is a privilege-escalation technique tracked in the Red Canary Threat Detection Report. Detecting the key change surfaces a UAC-bypass being staged.
HuntRule TeamWindowsregistry_setHigh60Premium2026-09-02Malicious Winlogon Shell or Userinit Persistence Modification (via registry_set)
This rule detects modification of the Winlogon Shell or Userinit values, which are executed at every interactive logon and are abused to launch a payload persistently with the user's session. Winlogon helper persistence is a technique tracked in the Red Canary Threat Detection Report. Detecting changes to these keys surfaces a logon-triggered persistence foothold.
HuntRule TeamWindowsregistry_setHigh80Premium2026-09-02Malicious Bulk Data Exfiltration via Rclone (via process_creation)
This rule detects rclone being run with copy, sync or move operations to a cloud remote, the staging-and-exfiltration tool ransomware crews use to bulk-transfer stolen data before encryption. Data exfiltration over cloud storage is documented in the Red Canary Threat Detection Report as a hallmark of double-extortion intrusions. Detecting rclone transfer commands surfaces exfiltration during the critical window before impact.
HuntRule TeamWindowsprocess_creationHigh80Premium2026-09-02Malicious Diskshadow Command Abuse to Expose VSS Backup (via process_creation)
This rule detects attemps to create an IFM for dumping credentials.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-02Suspicious RDP Shadow Session Started - Native (via rdp)
This rule detects has initiated a RDP shadow session.
HuntRule TeamWindowsrdpMedium40Premium2026-09-02Malicious Tampering With Windows Defender Protection (via process_creation)
This rule detects command-line attempts to disable core Microsoft Defender protections, such as turning off real-time monitoring through Set-MpPreference or adding broad exclusions, or stopping and disabling the WinDefend service. Impairing endpoint defenses is a common defense-evasion step in the Red Canary Threat Detection Report, clearing the way for follow-on tooling to run undetected. Detecting these tamper commands surfaces the adversary weakening the host before further action.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-02Suspicious LSASS Credential Dump with LSASSY - PowerShell (via powershell)
This rule detects remotely dump LSASS credentials using the LSASSY tool.
HuntRule TeamWindowspowershellMedium80Premium2026-09-02Malicious Medium Risk Local/domain Local Group Membership Change (via security)
This rule detects scenarios where a suspicious group membership is changed.
HuntRule TeamWindowssecurityHigh60Premium2026-09-02Suspicious Brutforce with Denied Access Due to Account Restrictions Policies (via security)
This rule detects attemps to use a comprimised account but failed to login due to account restrictions policies (permissions, time restrictions, workstation, logon type, ...).
HuntRule TeamWindowssecurityMedium30Premium2026-09-02Suspicious Scheduled Task Creation with Command Line (via process_creation)
This rule detects creates a scheduled task via commmand line.
HuntRule TeamWindowsprocess_creationMedium40Premium2026-09-02