Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,287 rules
Malicious Event Log Deactivation or Size Reduction - Command (via process_creation)
This rule detects disable or reduce the size of an event log.
HuntRule TeamWindowsprocess_creationHigh80Premium2026-09-02Malicious Kimsuky VBE Payload Download via Curl to AppData and Execution (via process_creation)
This rule detects a command shell chain that uses curl to download a remote payload into the user AppData Roaming directory as a VBScript encoded file and then executes it, the delivery behavior of a Kimsuky LNK campaign abusing remote control tools across Northeast Asia. Adversaries leverage curl as a trusted utility to stage a bot.vbe beacon while blending with normal traffic, making early detection critical for catching the intrusion at the delivery stage.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-02Uncommon Mustang Panda pcl2bmp Sideloading Host Executed from Public Documents (via process_creation)
This rule detects the legitimate pcl2bmp binary launched from the Public Documents directory, the DLL side-loading host used to load the malicious ctxmui.dll in the Mustang Panda ZOHOMURK operation against Indian government and energy sectors. Adversaries relocate a signed executable to a world-writable path so it sideloads their loader under a trusted process. Execution of this printer utility from Public Documents is highly anomalous.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-02Enabling restricted admin mode
Detects the registry modification to enable restricted admin mode using reg.exe
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-02Malicious Inhibition of System Recovery via Shadow Copy or Backup Deletion (via process_creation)
This rule detects command lines that delete volume shadow copies or backups or disable boot-time recovery, using vssadmin, wmic shadowcopy, wbadmin or bcdedit. Inhibiting system recovery is a high-impact technique in the Red Canary Threat Detection Report and a hallmark of ransomware preparing to prevent victims from restoring encrypted data. Detecting these destructive commands provides a critical, high-fidelity signal immediately before or during encryption.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-02Suspicious Scheduled Task Enumerated (via process_creation)
This rule detects enumerates scheduled task configuration.
HuntRule TeamWindowsprocess_creationMedium70Premium2026-09-02Malicious IIS Application Pool Credential Dumping (via process_creation)
This rule detects scenarios where an attacker.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-02ClickFix PowerShell In-Memory Execution via Invoke-RestMethod Piped to Invoke-Expression (via process_creation)
This rule detects the ClickFix golden pattern in which PowerShell retrieves a remote payload with Invoke-RestMethod and immediately runs it through Invoke-Expression, executing code entirely in memory. Adversaries leverage this download-and-run one-liner delivered through pastejacking overlays, making the paired cmdlets a reliable ClickFix execution indicator.
HuntRule TeamWindowsprocess_creationMedium90Premium2026-09-02Malicious RDP BlueeKeep Connection Closed - CVE-2019-0708 (via rdp)
This rule detects exploit the BlueKeep vulnerability.
HuntRule TeamWindowsrdpHigh70Premium2026-09-02OpenSSH Native Server Feature Installation (via powershell)
This rule detects enables the native OpenSSH server feature on Windows to perform stealthy lateral movement.
HuntRule TeamWindowspowershellMedium60Premium2026-09-02Malicious Impacket DCOMexec Process Abuse via MMC (via process_creation)
This rule detects execute the Impacket DCOMexec tool in order to abuse DCOM services.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-02Malicious Anonymous Login - Domain Specified (via security)
This rule detects scenarios where a suspicious anonymous login is performed during discovery phases.
HuntRule TeamWindowssecurityHigh30Premium2026-09-02BITS Payload Downloaded via Commandline (via process_creation)
This rule detects downloads a payload by abusing BITS software. For more precise information, inspect "Bits-client" event log and search for ID 59 and 60.
HuntRule TeamWindowsprocess_creationMedium40Premium2026-09-02Suspicious Group Discovery - Command (via process_creation)
This rule detects enumerate local or domain groups via commandline.
HuntRule TeamWindowsprocess_creationMedium50Premium2026-09-02Malicious Service Deactivation - Command (via process_creation)
This rule detects disable.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-02