Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,296 rules
Malicious aspnet_compiler.exe Injection Host Spawned by PowerShell via process_creation
This rule detects the .NET build utility aspnet_compiler.exe being launched by PowerShell, the process-injection host abused by the multi-stage Phantom Stealer campaign to run reflectively loaded payload code. Spawning the signed compiler from a scripting engine is a wrong-context indicator that the stealer is hollowing a trusted binary to evade detection, exposing the injection before credential theft and SMTP exfiltration.
HuntRule TeamWindowsprocess_creationHigh365Premium2026-08-27Suspicious Windows Subsystem for Linux (WSL) Package Turned on - Native (via setup)
This rule detects enables the WSL to cary out malicious activities in a virtual instance to avoid detection.
HuntRule TeamWindowssetupMedium73Premium2026-08-27Malicious Akira Ransomware Encrypted File Extension via File Event
This rule detects files being renamed with the .akira extension appended during encryption by Akira ransomware. Mass creation of .akira files indicates active encryption of the host.
HuntRule TeamWindowsfile_eventHigh72Premium2026-08-27Suspicious Contagious Interview Disk Enumeration via Node Spawning Wmic
This rule detects a Node.js or npm process spawning wmic to enumerate logical disks which the North Korean Contagious Interview malware runs for host reconnaissance after a fake coding challenge executes. Developer-tooling parents launching WMI discovery is anomalous and marks the malicious interview package. It reveals early victim profiling before credential theft.
HuntRule TeamWindowsprocess_creationMedium354Premium2026-08-27Malicious Regsvr32 Executing DLL From Windows Temp
This rule detects regsvr32.exe registering or executing a DLL located in the Windows Temp directory which the ALPHV intrusion used after a VBS dropper wrote a payload there and this matters because regsvr32 loading a DLL from Temp is a common proxy execution and squiblydoo style evasion pattern that legitimate software does not exhibit.
HuntRule TeamWindowsprocess_creationHigh112Premium2026-08-27Suspicious Process Memory Read from Proc Mem for Secret Extraction
This rule detects a command that reads another process memory through the proc mem pseudo-file, a technique malicious npm packages use to scrape OIDC tokens and other in-memory secrets from CI runners. This vector appears in the npm supply chain attacks tracked by Unit 42. Detecting direct proc mem reads exposes runtime credential theft that never touches disk.
HuntRule TeamWindowsprocess_creationMedium51Premium2026-08-27Masquerading Exchange Server Impersonation via PrivExchange Relay Attack (via security)
This rule detects relays Exchange server authentication to abuse Exchange servers permissions and escalate privileges.
HuntRule TeamWindowssecurityHigh153Premium2026-08-27Suspicious Inline node.exe Command Executing Network and Process Spawning Code
This rule detects node.exe invoked with inline evaluated code that references network, command execution, and filesystem modules such as http, execSync, spawn, fs, and zlib. Microsoft attributed this pattern to Node.js malware that downloads and runs additional payloads directly from the command line. Inline module chaining lets the attacker fetch and execute code without dropping a script file, making it a strong indicator of malicious activity.
HuntRule TeamWindowsprocess_creationMedium142Premium2026-08-27Malicious Remote Shell Execution via SMB Admin Share (via security)
This rule detects execute a remote shell via the admin share.
HuntRule TeamWindowssecurityHigh162Premium2026-08-27Suspicious DUser DLL Sideloading by credwiz via Image Load
This rule detects the Credential Wizard binary or its renamed variants loading DUser.dll from outside the System32 directory, the DLL side-loading technique Secret Blizzard used to launch its TwoDash and related backdoors. A signed host binary loading a same-named DLL from a non-system path is a hallmark of side-loading based execution.
HuntRule TeamWindowsimage_loadHigh161Premium2026-08-26Suspicious Denied RDP Login with Valid Credentials (via security)
This rule detects tries to move laterally using RDP and access attempt is blocked due to restricted logon policies.
HuntRule TeamWindowssecurityMedium287Premium2026-08-26Malicious BitLocker Abuse for Ransomware via PowerShell (via ps_script)
This rule detects PowerShell that enables BitLocker while removing the key protectors which the ShrinkLocker ransomware does to encrypt drives and lock out the legitimate owner without leaving a recovery key.
HuntRule TeamWindowsps_scriptMedium143Premium2026-08-26Malicious WinGUP Updater Sideloading libcurl via gup.exe (via image_load)
This rule detects the WinGUP updater gup.exe loading a libcurl.dll from outside its normal install directories. The BoryptGrab-lineage infostealer distributed through fake GitHub repositories abused this signed updater to sideload its malicious loader DLL from user-writable paths.
HuntRule TeamWindowsimage_loadHigh245Premium2026-08-26Suspicious Masqueraded Windows Update Python Script Execution
This rule detects the Python interpreter executing a script masquerading as a Windows update named Windows Update Script.pyw, as dropped by the DeceptiveDevelopment ClickFix chain alongside drvUpdate.exe. The naming disguises attacker code as a benign system task, so catching the interpreter launching this file exposes the initial foothold.
HuntRule TeamWindowsprocess_creationHigh258Premium2026-08-26Suspicious GoGRPC Screen Capture Log File Creation (via file_event)
This rule detects creation of the appscreen.log artifact under the ProgramData appscreen directory that the GoGRPC backdoor writes while capturing screen data. This specific path and filename combination is unique to the malware.
HuntRule TeamWindowsfile_eventMedium103Premium2026-08-26