Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,295 rules
Suspicious VERSION.dll Proxy Sideloading from User AppData Directory (via image_load)
This rule detects the Windows library VERSION.dll being loaded from a user AppData location rather than the system directories, the DLL proxying step of the browser cache smuggling technique that hijacks Microsoft Teams or OneDrive startup to run a beacon. Adversaries place a proxy VERSION.dll beside a trusted application so it loads ahead of the genuine system copy.
HuntRule TeamWindowsimage_loadMedium40Premium2026-08-30SilentMare Updater Execution from User AppData Directory (via process_creation)
This rule detects execution of the SilentMare updater binaries dropped into per-user AppData product folders by fake file-conversion and archive utilities delivered through malicious search ads. These updaters run on scheduled-task intervals to contact C2 and fetch in-memory .NET payloads, so their launch from a user profile directory is an early sign of the loader operating on the host.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-08-30SplashTop Network
Detects use of SplashTop
HuntRule TeamWindowsdns_queryHigh60Premium2026-08-30JavaScript Execution Using MSDOS 8.3 File Notation
Detects script execution using MSDOS 8.3 File names
HuntRule TeamWindowsprocess_creationMedium50Premium2026-08-30FlawedGrace spawning threat injection target
Detecting the command FlawedGrace is using for the purpose of injecting into it the spawned process, in this case the cmd.exe process.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-30Hiding local user accounts
Detects the use reg.exe to hide users from listed in the logon screen. This is possible by changing the registry key value to 0 for a specific user.
HuntRule TeamWindowsprocess_creationMedium50Premium2026-08-30Custom Cobalt Strike Command Execution
Detects the execution of a specific OneLiner to Invoke PowerShell commands.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-30Suspicious Khmer Shadow Scheduled Task VMwareNamespace Creation (via process_creation)
This rule detects creation of the VMwareNamespace scheduled task with a ten-minute repeat that maintains execution of the Khmer Shadow loader against Cambodian targets. Adversaries register this task to relaunch the sideloaded VMware binary from the local AppData persistence directory. The task name paired with the ten-minute interval is a distinctive persistence marker.
HuntRule TeamWindowsprocess_creationMedium70Premium2026-08-30SparkRAT Scheduled Task TaskHandler Running as SYSTEM from C Drivers (via process_creation)
This rule detects schtasks creating the TaskHandler task set to run at startup as SYSTEM with highest privileges from the C Drivers directory in the Cambodia-focused SparkRAT chain. Adversaries register a SYSTEM-level onstart task to relaunch their sideloading host under maximum privilege. The task name combined with the SYSTEM run context and C Drivers path is distinctive.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-08-30FileFix Browser Spawning Script Interpreter Child Process (via process_creation)
This rule detects a web browser spawning PowerShell, cmd, mshta or wscript, the highest-fidelity signal of the FileFix social-engineering attack that tricks users into pasting a command into the File Explorer address bar. Adversaries deliver a fragmented PowerShell one-liner through a fake upload dialog that then pulls a steganographic payload. Browsers do not normally launch script interpreters as children.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-30Untrusted Makop Ransomware Vulnerable Driver hlpdrv Drop for EDR Kill (via file_event)
This rule detects the Makop intrusion set dropping the hlpdrv vulnerable driver used to terminate endpoint protection at the kernel level before encryption. Adversaries deploy this abusable driver to disable defenses through bring-your-own-vulnerable-driver. Appearance of this specific driver filename on disk indicates staging for defense evasion.
HuntRule TeamWindowsfile_eventMedium90Premium2026-08-30INC Ransomware Ransom Note INC-README Written to Disk (via file_event)
This rule detects the INC ransomware dropping its INC-README ransom note across directories during encryption in the ransomware-as-a-service operation tracked by Acronis. Adversaries write the note to every touched folder alongside appending the .INC extension to encrypted files. The fixed note filename is a strong post-impact detection anchor.
HuntRule TeamWindowsfile_eventHigh70Premium2026-08-30PureHVNC Process Hollowing into RegAsm Spawned by PowerShell (via process_creation)
This rule detects RegAsm being spawned by PowerShell, the process-hollowing target used to run the PureHVNC RAT after a trojanized ScreenConnect installer downloads NvContainerRecovery.ps1. Adversaries inject PureHVNC into the .NET RegAsm host to hide under a trusted binary. RegAsm launched from PowerShell rather than build tooling is highly anomalous.
HuntRule TeamWindowsprocess_creationMedium70Premium2026-08-29Uncommon Browser Launched with Remote Debugging Port for Cookie Theft (via process_creation)
This rule detects a Chromium-based browser started with a remote debugging port flag, the technique Electron-based gaming stealers use to attach to the browser and dump cookies directly from a debugged instance. Adversaries launch the browser in debug mode to bypass cookie encryption and harvest session tokens. Debug-mode browser launches are rare outside developer tooling.
HuntRule TeamWindowsprocess_creationMedium140Premium2026-08-29Suspicious Shadow Vector Persistence via Schtasks OnLogon Highest from AppData (via process_creation)
This rule detects schtasks creating an onlogon task at highest run level pointing at an executable in AppData Roaming, the persistence used by the Shadow Vector campaign delivering AsyncRAT through court-themed SVG decoys to Colombian users. Adversaries register a high-privilege logon task that relaunches their payload from a user-writable path. An onlogon highest task targeting Roaming is a strong persistence indicator.
HuntRule TeamWindowsprocess_creationMedium90Premium2026-08-29