Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,293 rules
Suspicious Remote Utilities RuRAT Host Deployment via Fake Crypto Wallet Installer (via process_creation)
This rule detects execution of Remote Utilities host and client binaries used as a remote access backdoor after a fake cryptocurrency wallet installer campaign attributed to a suspected Russian threat actor. Adversaries deploy the legitimate Remote Utilities RMM under attacker control to gain persistent hands-on access to victim hosts, so its execution outside sanctioned administration warrants investigation.
HuntRule TeamWindowsprocess_creationMedium10Premium2026-08-30Masquerading Edge Update Masquerade Executed From AppData (via process_creation)
This rule detects a process named MicrosoftEdgeUpdateCore.exe running from a user AppData path rather than a legitimate Microsoft Edge install location, the self-copy used by the LeakyStealer payload to run under a trusted-looking name. Adversaries name their loader after Edge update binaries to evade casual inspection while injecting into Explorer and harvesting wallet and browser data.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-30Suspicious Hardware Inventory Discovery via WMIC Device Class Queries (via process_creation)
This rule detects WMIC queries against keyboard, pointing device and monitor WMI classes used by the SHUYAL stealer to fingerprint the host and detect analysis environments before stealing credentials. Adversaries enumerate attached hardware to build a victim profile and to evade sandboxes that lack real peripherals.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-08-30Masquerading SSLoad PhantomLoader DLL Execution via Regsvr32 Silent Load from AppData (via process_creation)
This rule detects regsvr32.exe silently registering the MenuEx.dll PhantomLoader component that masquerades as a 360 Total Security module in the SSLoad infection chain launched from an MSI installer. Adversaries use regsvr32 as a trusted LOLBin to load the first-stage loader without a visible window, making this command pattern a strong indicator of the delivery stage.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-08-30Masquerading PNGPlug DLL Sideloading of libcef Into down.exe Host Binary (via image_load)
This rule detects the down.exe host binary loading a libcef.dll from the PNGPlug delivery archive, a DLL sideloading step that decrypts and injects the ValleyRAT payload hidden inside PNG-masqueraded files. Pairing this common legitimate application name with the CEF library load surfaces the sideloading behavior at the point of second-stage execution.
HuntRule TeamWindowsimage_loadMedium10Premium2026-08-30IMEEX Framework DLL Execution via Rundll32 Loading imaadp (via process_creation)
This rule detects rundll32.exe loading the imaadp.dll module used by the IMEEX framework to run its 64-bit backdoor while masquerading under a trusted host process. Invocation of this specific module name through rundll32 indicates the implant executing on the host.
HuntRule TeamWindowsprocess_creationMedium30Premium2026-08-30System Time Lookup
Detects use of time to look up the system time as part of host discovery
HuntRule TeamWindowsprocess_creationHigh30Premium2026-08-30Malicious Kimsuky AlphaSeed Payload Execution via Regsvr32 Loading edge dat (via process_creation)
This rule detects regsvr32 silently loading a .dat payload from the hidden .edge directory in the user profile, the proxy-execution behavior Kimsuky AlphaSeed uses to run its powermgmt.dat backdoor DLL. Regsvr32 registering a data-extension file from a hidden per-user folder is a strong signed-binary-proxy execution indicator for this loader.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-30DragonForce Ransomware Volume Shadow Copy Deletion via WMIC ShadowCopy Where Delete (via process_creation)
This rule detects abuse of WMIC to enumerate and delete a specific volume shadow copy by ID, the inhibit-recovery behavior DragonForce ransomware performs through cmd.exe before file encryption. Adversaries delete shadow copies so victims cannot restore encrypted files, making early detection critical for interrupting the intrusion before data becomes unrecoverable.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-30Renamed Mimikatz Credential Theft Command Indicators (via process_creation)
This rule detects command lines containing Mimikatz module and function names such as sekurlsa::logonpasswords, lsadump::sam or kerberos::golden, which reveal use of the credential-theft toolkit regardless of the executable's filename. Mimikatz is one of the most common credential-access tools in the Red Canary Threat Detection Report, harvesting plaintext passwords, hashes and Kerberos tickets to enable lateral movement and privilege escalation. Detecting its distinctive module syntax surfaces the tool even when it has been renamed or embedded in scripts.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-30Uncommon Executable Written to Startup Folder by WinRAR via CVE-2025-8088 Path Traversal (via file_event)
This rule detects WinRAR writing an executable into the user Startup folder, the persistence outcome of the CVE-2025-8088 alternate-data-stream path-traversal flaw abused in the Paper Werewolf campaign to auto-run its payload at logon. A decompression tool dropping a binary into a logon-autostart location is highly abnormal and indicates exploitation of the extractor.
HuntRule TeamWindowsfile_eventHigh80Premium2026-08-30Suspicious Local Account Creation and Privileged Group Addition via Net.EXE (via process_creation)
This rule detects creation of a local user account or addition of an account to a privileged local group through net.exe or net1.exe. Account manipulation for persistence and privilege escalation features in the Red Canary Threat Detection Report, letting adversaries establish durable, legitimate-looking access. Detecting local account and administrators-group changes at the command line surfaces backdoor-account activity.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-08-30Malicious Accessibility Feature Backdoor via Image File Execution Options Debugger (via registry_set)
This rule detects a Debugger value being set on an accessibility binary (sethc.exe, utilman.exe, osk.exe, magnify.exe, narrator.exe or displayswitch.exe) under Image File Execution Options, which lets an attacker launch a command shell from the logon screen without credentials. This accessibility-feature hijack is a persistence and privilege-escalation technique tracked in the Red Canary Threat Detection Report. Detecting the registry modification catches the backdoor before it is triggered at the lock screen.
HuntRule TeamWindowsregistry_setHigh30Premium2026-08-30Suspicious VERSION.dll Proxy Sideloading from User AppData Directory (via image_load)
This rule detects the Windows library VERSION.dll being loaded from a user AppData location rather than the system directories, the DLL proxying step of the browser cache smuggling technique that hijacks Microsoft Teams or OneDrive startup to run a beacon. Adversaries place a proxy VERSION.dll beside a trusted application so it loads ahead of the genuine system copy.
HuntRule TeamWindowsimage_loadMedium40Premium2026-08-30SilentMare Updater Execution from User AppData Directory (via process_creation)
This rule detects execution of the SilentMare updater binaries dropped into per-user AppData product folders by fake file-conversion and archive utilities delivered through malicious search ads. These updaters run on scheduled-task intervals to contact C2 and fetch in-memory .NET payloads, so their launch from a user profile directory is an early sign of the loader operating on the host.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-08-30