Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,301 rules
Suspicious SoftEther VPN Hamcore Config Written to ProgramData (via file_event)
This rule detects the creation of the SoftEther VPN hamcore.se2 archive or vpn_server.config under ProgramData as used by the Larva-26010 campaign to install a covert VPN tunnel on compromised web servers. These SoftEther artifacts in ProgramData indicate unauthorized remote access setup.
—Windowsfile_eventMedium339Premium2026-08-21Suspicious TransferLoader Configuration Storage in Phone Config Registry Key (via registry_set)
This rule detects creation of registry values under the Windows Phone Config key that TransferLoader abuses to store its C2 server, sleep timeout, encryption key and in-memory PE payload. Legitimate software rarely writes rmi, to, id or md values under this path.
HuntRule TeamWindowsregistry_setHigh404Premium2026-08-21Suspicious Discovery Command Spawned by Java Process
This rule detects the Cleo Java runtime spawning Windows discovery utilities such as nltest, whoami, and ipconfig, the hands-on-keyboard reconnaissance seen after exploitation of Cleo file transfer software and the Malichus malware. A Java service process launching domain and host enumeration is not part of normal operation. This lineage indicates active post-exploitation of an internet-facing Cleo server.
HuntRule TeamWindowsprocess_creationHigh213Premium2026-08-20Suspicious Persistence via pcalua Launching rundll32 Control_RunDLL
This rule detects the Program Compatibility Assistant pcalua being abused to launch rundll32 with the Control_RunDLL export against a user profile DLL. RedCurl uses this scheduled task chain to persist its BrowserSpec loader while masking the parent process.
HuntRule TeamWindowsprocess_creationHigh74Premium2026-08-20Suspicious PowerShell Invoke-WebRequest Piped to Invoke-Expression via FakeBat Loader
This rule detects PowerShell downloading a remote payload with Invoke-WebRequest using a custom User-Agent and piping the response straight into Invoke-Expression. FakeBat, also tracked as EugenLoader, delivers this one liner through malvertising and fake software sites to stage its next component in memory. Fileless download and execute cradles like this bypass disk based controls and warrant investigation.
HuntRule TeamWindowsps_scriptMedium111Premium2026-08-20Malicious Lazarus SIGNBT DLL Side-Loading via PCHealthCheck Host (via image_load)
This rule detects the Microsoft PC Health Check binary PCHealthCheck.exe loading a PCHealthCheck.dll from outside standard program directories, the DLL side-loading technique the Lazarus SIGNBT cluster uses to execute malicious code under a signed utility. Restricting to non-program paths separates the abuse from the legitimately installed application.
HuntRule TeamWindowsimage_loadHigh188Premium2026-08-20Suspicious DLL Side-Loading from Non-Standard winsystem Directory
This rule detects a module being loaded from the non-standard C:\winsystem directory used by the STARKVEIL chain to stage side-loaded DLLs alongside a legitimate signed executable. Attackers rely on this masquerading path to run malicious code under a trusted process while evading directory-based allowlists.
HuntRule TeamWindowsimage_loadHigh379Premium2026-08-20ClickFix Pastejacking via Script Interpreter Command in Run Dialog MRU (via registry_set)
This rule detects ClickFix pastejacking where a clipboard-injected download-and-execute command is entered through the Windows Run dialog and recorded in the Explorer RunMRU key. Adversaries leverage the Run dialog to have the victim manually launch a script interpreter, so PowerShell or download utilities appearing in RunMRU history is a strong user-assisted execution indicator.
HuntRule TeamWindowsregistry_setHigh295Premium2026-08-20Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
This rule detects browsercore.exe launched by a process other than a known browser or task host, a pattern used to request a PRT cookie for cloud authentication abuse. The cloud lateral-movement research shows attackers invoke browsercore outside its normal browser context to obtain single sign-on artifacts. An unexpected parent for this binary is a heuristic sign of token theft.
HuntRule TeamWindowsprocess_creationMedium292Premium2026-08-20Malicious DLL Sideloading via WSPrint and BugSplatRc64 by UAT-9244
This rule detects the WSPrint executable loading BugSplatRc64.dll from its ProgramData directory. UAT-9244 sideloads this DLL to execute follow-on implants under a benign-looking process. Loading a payload DLL from ProgramData through a planted executable is a hallmark of DLL search-order hijacking.
HuntRule TeamWindowsimage_loadHigh91Premium2026-08-20OpenSSH Server Firewall Configuration on Windows - Firewall (via firewall-as)
This rule detects configure the Windows firewall to allow incoming connections to perform stealthy lateral movement.
HuntRule TeamWindowsfirewall-asHigh369Premium2026-08-20Malicious Stickey Key Called CMD via Command Execution (via process_creation)
This rule detects calls the stickey key and execute CMD.
HuntRule TeamWindowsprocess_creationHigh351Premium2026-08-20SIP or Trust Provider Registration (via registry_set)
This rule detects register a SIP or trust provider in order to mislead signature validation checks.
HuntRule TeamWindowsregistry_setHigh3310Premium2026-08-20Suspicious Caret Obfuscated Command Execution via Process Creation
This rule detects caret-escaped command strings such as caret-broken curl and mshta invocations used by Scarlet Goldfinch ClickFix lures inside cmd.exe. Attackers insert carets between characters to evade signature matching and casual inspection, so heavily caret-broken tokens on the command line indicate deliberate obfuscation of a malicious download.
HuntRule TeamWindowsprocess_creationHigh83Premium2026-08-20Malicious Tool Execution from inetpub Web Root Directory
This rule detects execution of binaries from the inetpub pub directory, where the DynoWiper actor staged scheduling and update tools such as schtask.exe and update executables after web-server compromise. Legitimate processes rarely execute from inside the IIS web root, so a running binary there points to post-exploitation tooling.
HuntRule TeamWindowsprocess_creationHigh92Premium2026-08-20