Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,299 rules
Malicious PPL Abuse via ClipUp Protected Process Launch
This rule detects the ClipUp.exe utility launched with a protected process light argument, the technique RONINGLOADER uses to spawn a signed binary as a PPL and disable Microsoft Defender. Abusing ClipUp to obtain a protected process lets the loader tamper with security services that normally block it.
HuntRule TeamWindowsprocess_creationHigh82Premium2026-08-25Suspicious Host.exe In Windows Directory Running As Service
This rule detects execution of host.exe from the Windows directory with a service-style command line switch. BlackByte ransomware operators deployed C:\Windows\host.exe run with an -s flag and an eight-digit token to register itself as a service. A generically named binary placed in the Windows root and launched as a service is a masquerading and persistence pattern used to blend malicious execution into the OS.
HuntRule TeamWindowsprocess_creationHigh123Premium2026-08-25Malicious Command Execution Spawned by Apache Tomcat
This rule detects the Tomcat service process spawning command interpreters or administrative utilities, indicating web application remote code execution such as the Samsung MagicINFO exploitation observed by eSentire. A Java web server launching cmd, PowerShell, or account management binaries is a strong sign of server-side exploitation leading to cryptomining deployment.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-08-25Malicious In-Memory Payload Execution via PowerShell DownloadString (via process_creation)
This rule detects PowerShell downloading a script from a remote host and immediately executing it in memory using DownloadString together with Invoke-Expression, a fileless technique used by a ransomware actor after ColdFusion exploitation to run Cobalt Strike beacons and reverse shells. Combining a web download with immediate expression evaluation is a common malicious loader pattern.
HuntRule TeamWindowsprocess_creationHigh267Premium2026-08-24Suspicious DNS Zone Export via dnscmd for Reconnaissance
This rule detects use of dnscmd with the zone export option to dump an Active Directory DNS zone to a file, a reconnaissance technique used by the Karakurt extortion actor to enumerate internal hosts and services. A full zone export gives an attacker a map of the environment to plan lateral movement and target high-value systems.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-08-24Suspicious DLL Sideloading via Renamed fixmapi Swom.exe Loading Mapistub.dll via Confucius (via image_load)
This rule detects Confucius persistence in which the legitimate fixmapi.exe is copied to Swom.exe in AppData and side loads a malicious Mapistub.dll from LocalAppData. The genuine Mapistub.dll is a system component so loading it beside a renamed fixmapi binary indicates the loader. This chain establishes the backdoor.
HuntRule TeamWindowsimage_loadHigh122Premium2026-08-24Suspicious Network Scanning Tool Execution
This rule detects execution of network and port scanning utilities such as SoftPerfect Netscan and Advanced Port or IP Scanner that were used for internal reconnaissance as described in NCC Group Fivehands ransomware research. Adversaries run these scanners after initial access to map reachable hosts and services before lateral movement so their presence on servers or non administrator hosts is suspicious.
HuntRule TeamWindowsprocess_creationMedium101Premium2026-08-24Malicious User Account Control Bypass via Auto-Elevating Binary Hijack (via process_creation)
This rule detects a known auto-elevating Windows binary such as fodhelper, computerdefaults, eventvwr or sdclt spawning a command shell or script interpreter, the tell-tale child-process pattern of a User Account Control bypass. UAC bypasses are a recurring privilege-escalation and defense-evasion technique in the Red Canary Threat Detection Report, letting adversaries obtain a high-integrity process without a prompt. Detecting these parent-child pairs surfaces the elevation attempt.
HuntRule TeamWindowsprocess_creationHigh2010Premium2026-08-24Suspicious Execution of agent.exe From WinSyncDefender AppData Directory (via process_creation)
This rule detects execution of agent.exe from the Microsoft WinSyncDefender folder under AppData Roaming, the staging path used by Operation ShadowRecruit to host its SheetAgent RAT payload. Running a generically named binary from a fake Microsoft directory in a user-writable location is a wrong-context indicator of the recruitment-themed campaign against Indian job seekers, exposing the malware between delivery and Google Sheets C2.
HuntRule TeamWindowsprocess_creationHigh163Premium2026-08-24Suspicious Hidden PowerShell Downloading Payload via ClickFix (via process_creation)
This rule detects PowerShell launched with a hidden window that immediately downloads and executes remote content. The ClearFake ClickFix lure tricks users into pasting a mixed-case PowerShell command that runs with a suppressed window to fetch its next stage. A hidden PowerShell window combined with download and execution cmdlets is characteristic of ClickFix social engineering.
HuntRule TeamWindowsprocess_creationMedium219Premium2026-08-24Suspicious Double Extension docx Executable Execution (via process_creation)
This rule detects execution of a binary whose filename carries a double extension combining a document extension and padded spaces before .exe, the lure delivery technique used by Kimsuky against Japanese organizations. The masqueraded filename is designed to trick users into launching an executable they believe is a Word document.
HuntRule TeamWindowsprocess_creationMedium375Premium2026-08-24Malicious DLL Side-Loading of vcomp100 via converter.exe
This rule detects the ImageMagick converter.exe loading vcomp100.dll from outside the Windows system directories. The IDAT loader chain delivering Vidar and ACR stealers abused this signed binary to side-load a malicious vcomp100.dll and execute stager code under a trusted process.
HuntRule TeamWindowsimage_loadHigh201Premium2026-08-24In-Memory Remcos RAT Keylog Store Created Under ProgramData rema (via file_event)
This rule detects creation of the logs.dat file inside the ProgramData rema directory, the local store used by this Remcos RAT variant to buffer keystroke and clipboard capture before exfiltration. Adversaries leverage this staging file to accumulate stolen input on disk, making detection of the fixed path a useful indicator of active collection.
HuntRule TeamWindowsfile_eventMedium388Premium2026-08-24DLL Side-Loading of NvSmartMax via NvSmart Host Process
This rule detects the nvSmartEx.exe host loading NvSmartMax.dll from outside the legitimate NVIDIA program directory, the DLL side-loading pair used by DeadRinger actors to run implant code. A trusted NVIDIA binary loading its companion DLL from an unexpected path indicates search-order hijacking.
HuntRule TeamWindowsimage_loadHigh393Premium2026-08-24Malicious Microsoft Defender Default Action Changed to Allow Any Threat - Command (via process_creation)
This rule detects change Defender default action to allow any threats.
HuntRule TeamWindowsprocess_creationHigh91Premium2026-08-24