Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,353 rules
Suspicious Fog Ransomware File Artifacts (via file_event)
This rule detects creation of the Fog ransomware DbgLog.sys operational log or files bearing the .fog and .flocked encrypted extensions. These artifacts are dropped during Fog ransomware encryption on compromised hosts.
HuntRule TeamWindowsfile_eventHigh239Premium2026-08-21SwimSnake Driver Execution Persistence via Session Manager PlatformExecute (via registry_set)
This rule detects writes to the Session Manager PlatformExecute registry value, an unusual boot-time execution key the fake FinalShell SwimSnake campaign abuses to trigger a released driver (BEB.exe) for security-software tampering. Adversaries plant execution entries under Session Manager to run code very early and outside common autostart monitoring, making early detection critical for catching driver-based defense evasion before shellcode injection into explorer.exe.
HuntRule TeamWindowsregistry_setHigh102Premium2026-08-21Suspicious Scheduled Task Creation for Efimer Controller (via process_creation)
This rule detects schtasks.exe registering a task that references controller.xml the scheduled-task definition used by the Efimer Trojan for persistence. Efimer establishes a recurring task to keep its clipboard clipper and Tor-based command channel running. A task built from an XML file named controller in user-writable space is an indicator of this infection.
HuntRule TeamWindowsprocess_creationHigh162Premium2026-08-21Malicious Windows Firewall Disable via Netsh
This rule detects netsh disabling the Windows firewall, removing host network restrictions to ease lateral movement and remote access. This was observed during KawaLocker ransomware deployment together with RDP enablement. Turning off the firewall exposes services and undermines network segmentation defenses.
HuntRule TeamWindowsprocess_creationMedium122Premium2026-08-21Obfuscated Certutil Payload Download - Command (via process_creation)
This rule detects abuse certutil command to download obfuscated malicious payload.
HuntRule TeamWindowsprocess_creationHigh3310Premium2026-08-21Suspicious OpenSSH Reverse Tunnel Establishment via ssh.exe
This rule detects ssh.exe launched with the -R remote-forwarding switch to establish a reverse tunnel. In Talos IR ransomware engagements operators used OpenSSH reverse tunnels to proxy traffic back into the victim network for persistent access, so this is a protocol-tunneling indicator that should be correlated with the tunnel destination.
HuntRule TeamWindowsprocess_creationMedium266Premium2026-08-21Suspicious TransferLoader Temporary File Creation in Windows Temp (via file_event)
This rule detects creation of the defender.user.tmp staging file in the Windows temporary directory that TransferLoader writes during execution. The masquerading filename mimics Microsoft Defender while residing in a temp path.
HuntRule TeamWindowsfile_eventMedium72Premium2026-08-21Suspicious SoftEther VPN Hamcore Config Written to ProgramData (via file_event)
This rule detects the creation of the SoftEther VPN hamcore.se2 archive or vpn_server.config under ProgramData as used by the Larva-26010 campaign to install a covert VPN tunnel on compromised web servers. These SoftEther artifacts in ProgramData indicate unauthorized remote access setup.
—Windowsfile_eventMedium339Premium2026-08-21Suspicious TransferLoader Configuration Storage in Phone Config Registry Key (via registry_set)
This rule detects creation of registry values under the Windows Phone Config key that TransferLoader abuses to store its C2 server, sleep timeout, encryption key and in-memory PE payload. Legitimate software rarely writes rmi, to, id or md values under this path.
HuntRule TeamWindowsregistry_setHigh404Premium2026-08-21Suspicious Discovery Command Spawned by Java Process
This rule detects the Cleo Java runtime spawning Windows discovery utilities such as nltest, whoami, and ipconfig, the hands-on-keyboard reconnaissance seen after exploitation of Cleo file transfer software and the Malichus malware. A Java service process launching domain and host enumeration is not part of normal operation. This lineage indicates active post-exploitation of an internet-facing Cleo server.
HuntRule TeamWindowsprocess_creationHigh213Premium2026-08-20Suspicious Persistence via pcalua Launching rundll32 Control_RunDLL
This rule detects the Program Compatibility Assistant pcalua being abused to launch rundll32 with the Control_RunDLL export against a user profile DLL. RedCurl uses this scheduled task chain to persist its BrowserSpec loader while masking the parent process.
HuntRule TeamWindowsprocess_creationHigh74Premium2026-08-20Suspicious PowerShell Invoke-WebRequest Piped to Invoke-Expression via FakeBat Loader
This rule detects PowerShell downloading a remote payload with Invoke-WebRequest using a custom User-Agent and piping the response straight into Invoke-Expression. FakeBat, also tracked as EugenLoader, delivers this one liner through malvertising and fake software sites to stage its next component in memory. Fileless download and execute cradles like this bypass disk based controls and warrant investigation.
HuntRule TeamWindowsps_scriptMedium111Premium2026-08-20Malicious Lazarus SIGNBT DLL Side-Loading via PCHealthCheck Host (via image_load)
This rule detects the Microsoft PC Health Check binary PCHealthCheck.exe loading a PCHealthCheck.dll from outside standard program directories, the DLL side-loading technique the Lazarus SIGNBT cluster uses to execute malicious code under a signed utility. Restricting to non-program paths separates the abuse from the legitimately installed application.
HuntRule TeamWindowsimage_loadHigh188Premium2026-08-20Suspicious DLL Side-Loading from Non-Standard winsystem Directory
This rule detects a module being loaded from the non-standard C:\winsystem directory used by the STARKVEIL chain to stage side-loaded DLLs alongside a legitimate signed executable. Attackers rely on this masquerading path to run malicious code under a trusted process while evading directory-based allowlists.
HuntRule TeamWindowsimage_loadHigh379Premium2026-08-20ClickFix Pastejacking via Script Interpreter Command in Run Dialog MRU (via registry_set)
This rule detects ClickFix pastejacking where a clipboard-injected download-and-execute command is entered through the Windows Run dialog and recorded in the Explorer RunMRU key. Adversaries leverage the Run dialog to have the victim manually launch a script interpreter, so PowerShell or download utilities appearing in RunMRU history is a strong user-assisted execution indicator.
HuntRule TeamWindowsregistry_setHigh295Premium2026-08-20