Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,304 rules
SIP or Trust Provider Registration (via registry_set)
This rule detects register a SIP or trust provider in order to mislead signature validation checks.
HuntRule TeamWindowsregistry_setHigh3310Premium2026-08-20Suspicious Caret Obfuscated Command Execution via Process Creation
This rule detects caret-escaped command strings such as caret-broken curl and mshta invocations used by Scarlet Goldfinch ClickFix lures inside cmd.exe. Attackers insert carets between characters to evade signature matching and casual inspection, so heavily caret-broken tokens on the command line indicate deliberate obfuscation of a malicious download.
HuntRule TeamWindowsprocess_creationHigh83Premium2026-08-20Malicious Tool Execution from inetpub Web Root Directory
This rule detects execution of binaries from the inetpub pub directory, where the DynoWiper actor staged scheduling and update tools such as schtask.exe and update executables after web-server compromise. Legitimate processes rarely execute from inside the IIS web root, so a running binary there points to post-exploitation tooling.
HuntRule TeamWindowsprocess_creationHigh92Premium2026-08-20Malicious regsvcs LOLBin Loading Ransomware DLL from UNC Path
This rule detects the regsvcs.exe living-off-the-land binary being used to load and install a DLL from a UNC network path, matching SafePay ransomware deployment via regsvcs proxy execution. Attackers abuse regsvcs to run their encryptor DLL while bypassing application controls. Loading a DLL over UNC through regsvcs is not a legitimate developer workflow.
HuntRule TeamWindowsprocess_creationHigh155Premium2026-08-20Suspicious Active Directory Subnet Enumeration via ADFind Subnets Query (via process_creation)
This rule detects ADFind querying the configuration Subnets container with the subnets switch, the network-topology reconnaissance run in this multi-gang intrusion to map site subnets before lateral movement. Adversaries use ADFind to enumerate the directory Subnets object and understand the network layout for targeting, so this specific subnets query is a strong discovery indicator.
HuntRule TeamWindowsprocess_creationMedium151Premium2026-08-20Suspicious Rundll32 Executing DLL Start Export With Control Flags
This rule detects rundll32.exe calling a DLL Start export together with WarmCookie control flags such as /p /u or /update. WarmCookie also known as BadSpace was launched through rundll32 invoking its Start export with these command switches. The Start export paired with these operational flags is a distinctive WarmCookie loader signature for proxied malicious DLL execution.
HuntRule TeamWindowsprocess_creationHigh173Premium2026-08-20Malicious NetSupport RAT Execution From Public Folder via Process Creation
This rule detects the NetSupport client32.exe running with its client32.ini configuration from the Users Public directory, a placement pattern characteristic of NetSupport Manager abused as a remote access trojan. Attackers deploy the legitimate remote control tool from world-writable locations to gain hands-on-keyboard access while blending in with sanctioned software, so this path is a strong indicator of RAT abuse.
HuntRule TeamWindowsprocess_creationHigh113Premium2026-08-19Suspicious Firewall Rule Added Using PowerShell or CMD (via firewall-as)
This rule detects scenarios where a firewall rule is added using PowerShell or CMD.
HuntRule TeamWindowsfirewall-asMedium406Premium2026-08-19Suspicious Firewall Rule Masquerading as CloudExperienceHost via netsh
This rule detects creation of a Windows firewall rule via netsh whose name impersonates Microsoft.Windows.CloudExperienceHost, a defense evasion step used by the GigaWiper backdoor. Naming a malicious firewall rule after a trusted Windows component hides attacker network allowances from casual review.
HuntRule TeamWindowsprocess_creationMedium63Premium2026-08-19Masquerading Konni Registry Run Key Launching Wscript JavaScript from ProgramData (via registry_set)
This rule detects a CurrentVersion Run autorun value whose command runs wscript with the JavaScript engine against a script staged in ProgramData, the persistence behavior of a Konni AsyncRAT chain registered as GUpdate2 or SUpdate. Adversaries leverage the run key with the scripting host to relaunch their JavaScript loader at logon while masquerading as an updater, making early detection critical for surfacing persistence before AsyncRAT reconnects.
HuntRule TeamWindowsregistry_setHigh361Premium2026-08-19Suspicious GAM OAuth Token Enumeration via Process Creation
This rule detects use of the GAM command line tool to print or delete OAuth tokens across a Google Workspace tenant, activity observed both during attacker reconnaissance of consented apps and legitimate administrative cleanup. Because token enumeration reveals which third-party apps hold access, unexpected GAM token operations outside change windows can indicate an attacker mapping or pruning OAuth grants.
HuntRule TeamWindowsprocess_creationLow2910Premium2026-08-19Obfuscated XE Group Reflective Loader via PowerShell Spawned by IIS Worker Process (via process_creation)
This rule detects the IIS worker process w3wp.exe spawning a hidden PowerShell that runs a base64-encoded reflective loader, the in-memory execution step XE Group used after webshell access to launch Meterpreter. A web server process launching an obfuscated hidden PowerShell is a strong indicator of post-exploitation code execution.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-08-19Malicious XMRig Cryptominer Execution with NiceHash Pool Arguments
This rule detects launch of the XMRig cryptocurrency miner with its characteristic pool and NiceHash command-line flags. The BeatBanker dual-mode Android trojan runs XMRig against an attacker pool over TLS to abuse device resources for Monero mining as reported by Kaspersky. This flag combination is specific to covert mining and indicates resource hijacking on the host.
HuntRule TeamWindowsprocess_creationMedium234Premium2026-08-19Malicious Sticky Key Sethc Command for Replacement by CMD (via process_creation)
This rule detects replace the original sethc.exe file by cmd.exe.
HuntRule TeamWindowsprocess_creationHigh438Premium2026-08-19Malicious Lynx Ransomware Encrypted File Extension Creation (via file_event)
This rule detects creation of files carrying the .LYNX extension appended by the Lynx ransomware encryptor as reported by Group-IB. Adversaries rename encrypted files with this extension during impact, so a burst of these writes indicates active ransomware encryption on the host.
HuntRule TeamWindowsfile_eventHigh153Premium2026-08-19