Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,287 rules
TerraStealerV2 Data Staging in Bay0NsQIzx Package Directory (via file_event)
This rule detects TerraStealerV2 staging collected browser and wallet data inside the hardcoded Bay0NsQIzx package directory under LocalAppData before archiving it for exfiltration. Adversaries leverage a fixed staging folder to consolidate stolen artifacts, making file writes into this named directory a high-confidence collection indicator.
HuntRule TeamWindowsfile_eventHigh40Premium2026-09-01Malicious XWorm Persistence via Minute-Interval Scheduled Task Named XClient (via process_creation)
This rule detects creation of a highly privileged scheduled task named XClient that runs every minute, the persistence mechanism used by recent XWorm infection chains to relaunch the RAT payload continuously. Adversaries leverage minute-interval tasks to survive reboots and process termination, making early detection of the XClient task critical for removing the implant before further tasking.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-08-31APT28 Scheduled Task Named OneDriveHealth (via process_creation)
This rule detects creation of a scheduled task named OneDriveHealth via schtasks, the transient persistence APT28 registers and later deletes to establish its foothold while masquerading as a legitimate OneDrive maintenance job. Adversaries leverage benign-sounding task names to evade review, making detection of this specific task name useful for surfacing the intrusion.
HuntRule TeamWindowsprocess_creationMedium10Premium2026-08-31Malicious Wdigest Authentication Enabled - Registry (via registry_set)
This rule detects enable Wdgiest authention so passwords are stored in clear text and can be dumped.
HuntRule TeamWindowsregistry_setHigh30Premium2026-08-31RedDelta PlugX DLL Sideloading via Legitimate Utilities Loading Planted DLLs (via image_load)
This rule detects RedDelta PlugX DLL search-order hijacking in which signed utilities such as ONENOTEM.exe, inkform.exe, and LDeviceDetectionHelper.exe load attacker-planted DLLs from outside the Windows system directories. Adversaries leverage sideloading against trusted binaries to run the PlugX loader under a legitimate process, making these host-and-module pairings a strong defense-evasion indicator.
HuntRule TeamWindowsimage_loadHigh30Premium2026-08-31ClickFix Paste-Jacking Execution of mshta Retrieving Remote Payload (via process_creation)
This rule detects mshta.exe launched from the Windows Explorer Run dialog to fetch a remote payload over HTTP, the paste-jacking or ClickFix execution pattern in which a user is tricked into pasting a clipboard-injected command. Adversaries use this to run remote HTA or XLL content and stage stealer malware, making detection of Explorer-spawned mshta with a URL a strong signal of social-engineering-driven execution.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-31Malicious RDP Shadow Session Configuration Enabled - Registry (via registry_event)
This rule detects would enable shadow configuratin via registry. Note that this alert does not report the created Key and that further verification on hosts will be required to confirm the behavior.
HuntRule TeamWindowsregistry_eventHigh50Premium2026-08-31IFM Creation Detected from Commandline - Installation from Media (via process_creation)
This rule detects create an IFM image (usually used for deploying domain controllers to reduce replication traffic) for dumping credentials.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Suspicious Lateral Movement by Mounting a Network Share - Net Use - Command (via security)
This rule detects move laterally by mounting a network share using compromised user credentials.
HuntRule TeamWindowssecurityMedium30Premium2026-08-31Malicious Impacket DCOMexec Privilege Abuse via MMC (via security)
This rule detects execute the Impacket DCOMexec tool in order to abuse DCOM services.
HuntRule TeamWindowssecurityHigh60Premium2026-08-31Obfuscated Encoded PowerShell Payload Deployed via Process Execution (via process_creation)
This rule detects deployed an encoded PowerShell payload via a process execution. Some parameters are commented in case you would like to reduce false positives or make the rule more precise.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Suspicious Windows Native Pktmon Sniffer Abuse (via process_creation)
This rule detects use the Windows sniffer Pktmon in order to capture sensitive information or credentials.
HuntRule TeamWindowsprocess_creationMedium00Premium2026-08-31OpenSSH Server Listening on Socket (via openssh)
This rule detects enables the OpenSSH server and server starts to listening on SSH socket.
HuntRule TeamWindowsopensshMedium10Premium2026-08-31BITS Payload Downloaded via PowerShell (via powershell)
This rule detects downloads a payload by abusing BITS software. For more precise information, inspect "Bits-client" event log and search for ID 59 and 60.
HuntRule TeamWindowspowershellMedium10Premium2026-08-31Malicious WMI Spwaning PowerShell Process - WMImplant (via process_creation)
This rule detects wMIimplant.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31