Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,353 rules
Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
This rule detects browsercore.exe launched by a process other than a known browser or task host, a pattern used to request a PRT cookie for cloud authentication abuse. The cloud lateral-movement research shows attackers invoke browsercore outside its normal browser context to obtain single sign-on artifacts. An unexpected parent for this binary is a heuristic sign of token theft.
HuntRule TeamWindowsprocess_creationMedium292Premium2026-08-20Malicious DLL Sideloading via WSPrint and BugSplatRc64 by UAT-9244
This rule detects the WSPrint executable loading BugSplatRc64.dll from its ProgramData directory. UAT-9244 sideloads this DLL to execute follow-on implants under a benign-looking process. Loading a payload DLL from ProgramData through a planted executable is a hallmark of DLL search-order hijacking.
HuntRule TeamWindowsimage_loadHigh91Premium2026-08-20OpenSSH Server Firewall Configuration on Windows - Firewall (via firewall-as)
This rule detects configure the Windows firewall to allow incoming connections to perform stealthy lateral movement.
HuntRule TeamWindowsfirewall-asHigh369Premium2026-08-20Malicious Stickey Key Called CMD via Command Execution (via process_creation)
This rule detects calls the stickey key and execute CMD.
HuntRule TeamWindowsprocess_creationHigh351Premium2026-08-20SIP or Trust Provider Registration (via registry_set)
This rule detects register a SIP or trust provider in order to mislead signature validation checks.
HuntRule TeamWindowsregistry_setHigh3310Premium2026-08-20Suspicious Caret Obfuscated Command Execution via Process Creation
This rule detects caret-escaped command strings such as caret-broken curl and mshta invocations used by Scarlet Goldfinch ClickFix lures inside cmd.exe. Attackers insert carets between characters to evade signature matching and casual inspection, so heavily caret-broken tokens on the command line indicate deliberate obfuscation of a malicious download.
HuntRule TeamWindowsprocess_creationHigh93Premium2026-08-20Malicious Tool Execution from inetpub Web Root Directory
This rule detects execution of binaries from the inetpub pub directory, where the DynoWiper actor staged scheduling and update tools such as schtask.exe and update executables after web-server compromise. Legitimate processes rarely execute from inside the IIS web root, so a running binary there points to post-exploitation tooling.
HuntRule TeamWindowsprocess_creationHigh112Premium2026-08-20Malicious regsvcs LOLBin Loading Ransomware DLL from UNC Path
This rule detects the regsvcs.exe living-off-the-land binary being used to load and install a DLL from a UNC network path, matching SafePay ransomware deployment via regsvcs proxy execution. Attackers abuse regsvcs to run their encryptor DLL while bypassing application controls. Loading a DLL over UNC through regsvcs is not a legitimate developer workflow.
HuntRule TeamWindowsprocess_creationHigh165Premium2026-08-20Suspicious Active Directory Subnet Enumeration via ADFind Subnets Query (via process_creation)
This rule detects ADFind querying the configuration Subnets container with the subnets switch, the network-topology reconnaissance run in this multi-gang intrusion to map site subnets before lateral movement. Adversaries use ADFind to enumerate the directory Subnets object and understand the network layout for targeting, so this specific subnets query is a strong discovery indicator.
HuntRule TeamWindowsprocess_creationMedium151Premium2026-08-20Suspicious Rundll32 Executing DLL Start Export With Control Flags
This rule detects rundll32.exe calling a DLL Start export together with WarmCookie control flags such as /p /u or /update. WarmCookie also known as BadSpace was launched through rundll32 invoking its Start export with these command switches. The Start export paired with these operational flags is a distinctive WarmCookie loader signature for proxied malicious DLL execution.
HuntRule TeamWindowsprocess_creationHigh183Premium2026-08-20Malicious NetSupport RAT Execution From Public Folder via Process Creation
This rule detects the NetSupport client32.exe running with its client32.ini configuration from the Users Public directory, a placement pattern characteristic of NetSupport Manager abused as a remote access trojan. Attackers deploy the legitimate remote control tool from world-writable locations to gain hands-on-keyboard access while blending in with sanctioned software, so this path is a strong indicator of RAT abuse.
HuntRule TeamWindowsprocess_creationHigh123Premium2026-08-19Suspicious Firewall Rule Added Using PowerShell or CMD (via firewall-as)
This rule detects scenarios where a firewall rule is added using PowerShell or CMD.
HuntRule TeamWindowsfirewall-asMedium406Premium2026-08-19Suspicious Firewall Rule Masquerading as CloudExperienceHost via netsh
This rule detects creation of a Windows firewall rule via netsh whose name impersonates Microsoft.Windows.CloudExperienceHost, a defense evasion step used by the GigaWiper backdoor. Naming a malicious firewall rule after a trusted Windows component hides attacker network allowances from casual review.
HuntRule TeamWindowsprocess_creationMedium63Premium2026-08-19Masquerading Konni Registry Run Key Launching Wscript JavaScript from ProgramData (via registry_set)
This rule detects a CurrentVersion Run autorun value whose command runs wscript with the JavaScript engine against a script staged in ProgramData, the persistence behavior of a Konni AsyncRAT chain registered as GUpdate2 or SUpdate. Adversaries leverage the run key with the scripting host to relaunch their JavaScript loader at logon while masquerading as an updater, making early detection critical for surfacing persistence before AsyncRAT reconnects.
HuntRule TeamWindowsregistry_setHigh361Premium2026-08-19Suspicious GAM OAuth Token Enumeration via Process Creation
This rule detects use of the GAM command line tool to print or delete OAuth tokens across a Google Workspace tenant, activity observed both during attacker reconnaissance of consented apps and legitimate administrative cleanup. Because token enumeration reveals which third-party apps hold access, unexpected GAM token operations outside change windows can indicate an attacker mapping or pruning OAuth grants.
HuntRule TeamWindowsprocess_creationLow2910Premium2026-08-19