Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,304 rules
Suspicious winrm.vbs LOLBAS Script Execution for Code Proxying
This rule detects cscript or wscript executing the built in winrm.vbs script, a living-off-the-land binary abused in the OnlyDcRatFans campaign to proxy execution of a DcRat payload retrieved from paste.ee. winrm.vbs is normally used interactively by administrators, so its invocation by a script host to run additional code indicates abuse.
HuntRule TeamWindowsprocess_creationMedium72Premium2026-08-19Suspicious DLL Sideloading via Fake ApowerREC.exe Loading lastbld2Base.dll via Winos (via image_load)
This rule detects the Winos 4.0 loader using a fake ApowerREC.exe to side load the malicious lastbld2Base.dll through its DllMain during initial execution. The pairing of this screen recorder binary with that DLL name is specific to the campaign. It launches the in memory implant.
HuntRule TeamWindowsimage_loadHigh309Premium2026-08-19Suspicious PowerShell Download to Disk Then Execute (via process_creation)
This rule detects PowerShell downloading a remote file and saving it to disk with an output path, a common precursor to executing a staged payload. AresLoader retrieves its DLL over HTTP with an OutFile parameter before starting the process. Download-to-disk followed by local execution is a recurring ingress-tool-transfer behavior.
HuntRule TeamWindowsprocess_creationMedium299Premium2026-08-19Suspicious mstsc Launch of RDP File From User Download or Temp Path (via process_creation)
This rule detects the Remote Desktop client mstsc.exe opening a .rdp configuration file from a Downloads, Temp or AppData location, the delivery pattern of the rogue RDP campaign that phished malicious .rdp files enabling remote application mode and drive redirection. Executing an attacker-supplied RDP file connects victims to actor-controlled servers with resource redirection.
HuntRule TeamWindowsprocess_creationMedium211Premium2026-08-19KrbRelayUp Service Installation - Native (via system)
This rule detects escalate privileges while abusing KrbRelayUp attack.
HuntRule TeamWindowssystemHigh398Premium2026-08-19Suspicious DarkVNC vncdll64.dll Hidden VNC Module Load
This rule detects loading of vncdll64.dll, the hidden VNC module used by DarkVNC to create a covert desktop session inside explorer.exe for interactive remote control. This named module is specific to the DarkVNC toolset and its load indicates hands on keyboard access hidden from the victim.
HuntRule TeamWindowsimage_loadMedium112Premium2026-08-19Suspicious Service Installation Masquerading as winupd
This rule detects installation of a Windows service named winupd, a masquerade used by the INC Ransom group to run a renamed PsExec binary under a plausible Windows-update name. Service creation with this deceptive name is not expected from legitimate software and indicates hands-on-keyboard execution and lateral movement.
HuntRule TeamWindowssystemHigh435Premium2026-08-19Suspicious NSPX30 DLL Side-Loading of comx3 via RsStub (via image_load)
This rule detects the RsStub.exe binary loading comx3.dll, the DLL side-loading chain that launches the NSPX30 implant by abusing a legitimate executable. Loading this attacker-supplied DLL into a trusted process delivers the AitM-enabled backdoor while evading signature checks.
HuntRule TeamWindowsimage_loadMedium102Premium2026-08-19Suspicious Security Software Discovery via PowerShell SecurityCenter2 AntivirusProduct Query (via process_creation)
This rule detects PowerShell querying the root/SecurityCenter2 AntivirusProduct WMI class, the security-software discovery step Troll Stealer runs while profiling a victim before credential theft. Adversaries enumerate installed antivirus to tailor evasion, so this query outside of administrative inventory tooling is a meaningful reconnaissance indicator.
HuntRule TeamWindowsprocess_creationMedium92Premium2026-08-19Malicious Credential Hive Copy from Volume Shadow Copy
This rule detects a copy command referencing a HarddiskVolumeShadowCopy path together with a credential store name such as SAM, SYSTEM, or ntds.dit, a technique Huntress observed for extracting locked hives from a shadow copy. Attackers duplicate credential databases from the snapshot to bypass file locks before offline cracking. Copying hive files out of a shadow copy is a strong credential-access indicator.
HuntRule TeamWindowsprocess_creationHigh141Premium2026-08-19Malicious Curl to Shell Dropper from Paste Site via Command Line
This rule detects a shell command that downloads a script from a public paste site such as rentry.co or glot.io and pipes it directly into a shell interpreter. This one-line fetch-and-execute pattern is used by the OpenClaw AI skill marketplace supply chain campaign to deliver macOS stealer payloads. Detecting it exposes ingress tool transfer that bypasses on-disk staging and gives the attacker immediate code execution.
HuntRule TeamWindowsprocess_creationHigh153Premium2026-08-19NitrogenLoader Sideloading via Renamed Setup Binary Loading python312.dll (via image_load)
This rule detects a setup.exe process loading python312.dll, the DLL sideloading pair used by the Nitrogen campaign where a renamed python.exe host loads a malicious NitrogenLoader DLL mirroring the exports of a genuine Python runtime. Adversaries leverage this trojanized installer bundle delivered through malvertising to stage Cobalt Strike, making detection valuable for catching the loader before beacon injection.
HuntRule TeamWindowsimage_loadMedium194Premium2026-08-18Suspicious Python or uv Execution Spawned by AI CLI Assistant
This rule detects the python or uv interpreter launched as a child of an AI command line assistant such as the Claude or Gemini CLI which reflects adversaries directing these agents to run local code during hands on abuse. Because AI CLI tools can execute arbitrary commands on behalf of a user they can be steered into running attacker supplied scripts. Detecting unexpected interpreter children of AI assistants supports hunting for this emerging abuse.
HuntRule TeamWindowsprocess_creationLow163Premium2026-08-18Suspicious RegSvcs Reflective .NET Load from Fake Update Chain
This rule detects PowerShell spawning RegSvcs.exe which is abused as an injection target for reflectively loaded .NET payloads decoded from disguised png files. This behavior was seen in fake browser update campaigns delivering BitRAT and Lumma Stealer. Attackers pick RegSvcs as a signed host to execute malicious code under a trusted image name.
HuntRule TeamWindowsprocess_creationHigh397Premium2026-08-18Suspicious HelloNet SSH Reverse Tunnel via frontpage.exe (via process_creation)
This rule detects execution of frontpage.exe with an SSH reverse port-forwarding argument, a renamed SSH client used by the HelloNet campaign to establish an outbound reverse tunnel on port 8443. Attackers use such tunnels to expose internal services and maintain covert remote access to compromised hosts.
HuntRule TeamWindowsprocess_creationHigh399Premium2026-08-18