Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,353 rules
Obfuscated XE Group Reflective Loader via PowerShell Spawned by IIS Worker Process (via process_creation)
This rule detects the IIS worker process w3wp.exe spawning a hidden PowerShell that runs a base64-encoded reflective loader, the in-memory execution step XE Group used after webshell access to launch Meterpreter. A web server process launching an obfuscated hidden PowerShell is a strong indicator of post-exploitation code execution.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-08-19Malicious XMRig Cryptominer Execution with NiceHash Pool Arguments
This rule detects launch of the XMRig cryptocurrency miner with its characteristic pool and NiceHash command-line flags. The BeatBanker dual-mode Android trojan runs XMRig against an attacker pool over TLS to abuse device resources for Monero mining as reported by Kaspersky. This flag combination is specific to covert mining and indicates resource hijacking on the host.
HuntRule TeamWindowsprocess_creationMedium244Premium2026-08-19Malicious Sticky Key Sethc Command for Replacement by CMD (via process_creation)
This rule detects replace the original sethc.exe file by cmd.exe.
HuntRule TeamWindowsprocess_creationHigh438Premium2026-08-19Malicious Lynx Ransomware Encrypted File Extension Creation (via file_event)
This rule detects creation of files carrying the .LYNX extension appended by the Lynx ransomware encryptor as reported by Group-IB. Adversaries rename encrypted files with this extension during impact, so a burst of these writes indicates active ransomware encryption on the host.
HuntRule TeamWindowsfile_eventHigh153Premium2026-08-19Suspicious winrm.vbs LOLBAS Script Execution for Code Proxying
This rule detects cscript or wscript executing the built in winrm.vbs script, a living-off-the-land binary abused in the OnlyDcRatFans campaign to proxy execution of a DcRat payload retrieved from paste.ee. winrm.vbs is normally used interactively by administrators, so its invocation by a script host to run additional code indicates abuse.
HuntRule TeamWindowsprocess_creationMedium72Premium2026-08-19Suspicious DLL Sideloading via Fake ApowerREC.exe Loading lastbld2Base.dll via Winos (via image_load)
This rule detects the Winos 4.0 loader using a fake ApowerREC.exe to side load the malicious lastbld2Base.dll through its DllMain during initial execution. The pairing of this screen recorder binary with that DLL name is specific to the campaign. It launches the in memory implant.
HuntRule TeamWindowsimage_loadHigh329Premium2026-08-19Suspicious PowerShell Download to Disk Then Execute (via process_creation)
This rule detects PowerShell downloading a remote file and saving it to disk with an output path, a common precursor to executing a staged payload. AresLoader retrieves its DLL over HTTP with an OutFile parameter before starting the process. Download-to-disk followed by local execution is a recurring ingress-tool-transfer behavior.
HuntRule TeamWindowsprocess_creationMedium299Premium2026-08-19Suspicious mstsc Launch of RDP File From User Download or Temp Path (via process_creation)
This rule detects the Remote Desktop client mstsc.exe opening a .rdp configuration file from a Downloads, Temp or AppData location, the delivery pattern of the rogue RDP campaign that phished malicious .rdp files enabling remote application mode and drive redirection. Executing an attacker-supplied RDP file connects victims to actor-controlled servers with resource redirection.
HuntRule TeamWindowsprocess_creationMedium231Premium2026-08-19KrbRelayUp Service Installation - Native (via system)
This rule detects escalate privileges while abusing KrbRelayUp attack.
HuntRule TeamWindowssystemHigh398Premium2026-08-19Suspicious DarkVNC vncdll64.dll Hidden VNC Module Load
This rule detects loading of vncdll64.dll, the hidden VNC module used by DarkVNC to create a covert desktop session inside explorer.exe for interactive remote control. This named module is specific to the DarkVNC toolset and its load indicates hands on keyboard access hidden from the victim.
HuntRule TeamWindowsimage_loadMedium122Premium2026-08-19Suspicious Service Installation Masquerading as winupd
This rule detects installation of a Windows service named winupd, a masquerade used by the INC Ransom group to run a renamed PsExec binary under a plausible Windows-update name. Service creation with this deceptive name is not expected from legitimate software and indicates hands-on-keyboard execution and lateral movement.
HuntRule TeamWindowssystemHigh445Premium2026-08-19Suspicious NSPX30 DLL Side-Loading of comx3 via RsStub (via image_load)
This rule detects the RsStub.exe binary loading comx3.dll, the DLL side-loading chain that launches the NSPX30 implant by abusing a legitimate executable. Loading this attacker-supplied DLL into a trusted process delivers the AitM-enabled backdoor while evading signature checks.
HuntRule TeamWindowsimage_loadMedium112Premium2026-08-19Suspicious Security Software Discovery via PowerShell SecurityCenter2 AntivirusProduct Query (via process_creation)
This rule detects PowerShell querying the root/SecurityCenter2 AntivirusProduct WMI class, the security-software discovery step Troll Stealer runs while profiling a victim before credential theft. Adversaries enumerate installed antivirus to tailor evasion, so this query outside of administrative inventory tooling is a meaningful reconnaissance indicator.
HuntRule TeamWindowsprocess_creationMedium92Premium2026-08-19Malicious Credential Hive Copy from Volume Shadow Copy
This rule detects a copy command referencing a HarddiskVolumeShadowCopy path together with a credential store name such as SAM, SYSTEM, or ntds.dit, a technique Huntress observed for extracting locked hives from a shadow copy. Attackers duplicate credential databases from the snapshot to bypass file locks before offline cracking. Copying hive files out of a shadow copy is a strong credential-access indicator.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-08-19Malicious Curl to Shell Dropper from Paste Site via Command Line
This rule detects a shell command that downloads a script from a public paste site such as rentry.co or glot.io and pipes it directly into a shell interpreter. This one-line fetch-and-execute pattern is used by the OpenClaw AI skill marketplace supply chain campaign to deliver macOS stealer payloads. Detecting it exposes ingress tool transfer that bypasses on-disk staging and gives the attacker immediate code execution.
HuntRule TeamWindowsprocess_creationHigh153Premium2026-08-19