Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,293 rules
Malicious RDP Tunneling (via rdp)
This rule detects uses RDP tunneling to redirect traffic to a C&C target.
HuntRule TeamWindowsrdpHigh40Premium2026-08-31Malicious Service Permissions Hijacked for Privileges Abuse - Reg via PowerShell (via powershell)
This rule detects modify the permissions of a service using native PowerShell commands in order to abuse its privileges. Note that it requires PowerShell 7 or higher.
HuntRule TeamWindowspowershellHigh30Premium2026-08-31Malicious Windows Native Backup Deletion (via process_creation)
This rule detects delete existing Windows native backup (only available on Windows Server).
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Malicious Credentials (protected by DPAPI) Dump via Network Share (via security)
This rule detects attempt to dump DPAPI credentials (Windows Vault, Chrome, RDP, WiFi, Emails, ...) or registry hives via network share via tools like DonPAPI.
HuntRule TeamWindowssecurityHigh30Premium2026-08-30Malicious Stickey Key IFEO Registry Changed - Reg via Sysmon (via registry_event)
This rule detects changed the IFEO settings related to sethc.
HuntRule TeamWindowsregistry_eventHigh50Premium2026-08-30Malicious Mimispool Printer Driver Installation - PrintNightmare Vulnerability - CVE-2021-36958 (via printservice)
This rule detects help to detect scenarios where an attacker exploit the Mimispool print driver to escalate privileges.
HuntRule TeamWindowsprintserviceHigh70Premium2026-08-30Malicious Kerberos TGS Ticket Request Related to a Potential Golden Ticket (via security)
This rule detects request a potential Golden ticket. Findings returned by this rule may not confirm at 100% that a Golden ticket was generated and further investigations would be required to confirm it. Another indicator (in case of a lazy Golden ticket) to check would be to check if the TargetUserName refers to an existing user in the domain.
HuntRule TeamWindowssecurityHigh80Premium2026-08-30SynkLoader Python Stager Execution from AppData via pythonw (via process_creation)
This rule detects the SynkLoader Python stager launched by pythonw.exe from a randomly named AppData subdirectory using the fl\ang\ss.py path layout observed after a Microsoft Teams phishing lure. Adversaries run the loader silently to decrypt and inject follow-on modules while evading command-line script inspection, making early detection critical for stopping module deployment before credential theft.
HuntRule TeamWindowsprocess_creationMedium70Premium2026-08-30Malicious Command Injection via SyncAppvPublishingServer VBS LOLBin (via process_creation)
This rule detects abuse of the SyncAppvPublishingServer.vbs living-off-the-land script to inject PowerShell after a semicolon separator, the ClickFix delivery behavior ClearFake uses to launch a hidden PowerShell downloader from a clipboard-pasted Run command. Adversaries proxy execution through this signed script to evade script-host controls, making early detection critical for catching the infection at the first execution stage.
HuntRule TeamWindowsprocess_creationHigh100Premium2026-08-30FortiClient Binary Executed from LocalAppData Compliance Directory (via process_creation)
This rule detects a FortiClientCompliance.exe process running from a LocalAppData FortiClient compliance directory, an unusual user-writable location for endpoint software that in this intrusion was a renamed Greenshot binary used as a signed malware loader. Adversaries place trusted-looking binaries in AppData to masquerade legitimate software while executing sideloaded payloads, making early detection critical for catching the loader before shellcode execution.
HuntRule TeamWindowsprocess_creationHigh120Premium2026-08-30Operator Bloopers Cobalt Strike Modules
Detects use of Cobalt Strike module commands accidentally entered in the CMD shell
HuntRule TeamWindowsprocess_creationHigh80Premium2026-08-30Malicious Scheduled Task ForceNetbirdRestart for Remote Access Persistence (via process_creation)
This rule detects creation of a scheduled task named ForceNetbirdRestart that restarts the NetBird agent after boot, a persistence behavior used by MuddyWater to keep its remote-access tunnel available. Adversaries leverage the task to guarantee the covert NetBird channel reconnects on every reboot.
HuntRule TeamWindowsprocess_creationHigh110Premium2026-08-30TinyLoader USB Propagation via Double-Extension Executables (via file_event)
This rule detects creation of double-extension executables such as Photo.jpg.exe and Document.pdf.exe used by TinyLoader to spread across removable media. Adversaries leverage deceptive filenames that appear to be images or documents so users execute the loader from infected USB drives.
HuntRule TeamWindowsfile_eventMedium30Premium2026-08-30ESET Security Service Disabling via sc.exe (via process_creation)
This rule detects sc.exe being used to stop or disable ESET endpoint protection services such as ekrn and EraAgentSvc, a defense-evasion behavior performed by the EtherRAT deployment script before payload execution. Adversaries leverage service control to blind endpoint protection ahead of credential theft and lateral movement.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-08-30ToneShell Backdoor Persistence via dokanctl Scheduled Task (via process_creation)
This rule detects creation of the dokanctl scheduled task that the Frankenstein ToneShell variant registers to re-launch its AppData-based svchosts.exe payload every minute. The distinctive task name combined with schtasks creation reflects the backdoor installing minute-interval persistence on the host.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-08-30