Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,354 rules
Suspicious Run Key Masquerading as GoogleUpdate From Wrong Path via Registry Set (via registry_set)
This rule detects a Run key autostart entry masquerading as GoogleUpdate but pointing to a payload outside the legitimate Google update directory, a persistence and masquerading technique used by malware from MSIX installers per Red Canary. A trusted-looking name paired with the wrong file path is a high-confidence indicator of a malicious autorun disguised as software updater.
HuntRule TeamWindowsregistry_setHigh317Premium2026-08-14PowerShell Remote Download From Bunny CDN Host
This rule detects PowerShell download activity referencing a b-cdn.net Bunny CDN host, an abused delivery infrastructure in the LummaStealer campaign. Attackers stage payloads on legitimate CDN domains to blend malicious downloads with normal traffic.
HuntRule TeamWindowsps_scriptMedium113Premium2026-08-14Suspicious Lateral Movement Detection - Based on "special Groups" Feature (via security)
This rule detects scenarios where a user of a predefined set of group(s) logs on a target machine.
HuntRule TeamWindowssecurityMedium207Premium2026-08-14Malicious IFEO Debugger Hijack of vds.exe by FishMonger
This rule detects registration of an Image File Execution Options Debugger value for vds.exe, a persistence and defense-evasion technique used by the FishMonger group deploying SprySOCKS. The activity abuses the IFEO mechanism so that a malicious binary is launched whenever the Virtual Disk Service is invoked. Detecting this key is important because it silently redirects execution of a legitimate system component to attacker-controlled code.
HuntRule TeamWindowsregistry_setHigh71Premium2026-08-14Suspicious Stately Taurus Visual Studio Code Tunnel Abuse via VSCode CLI (via process_creation)
This rule detects execution of the Visual Studio Code command line binary with the tunnel argument, which creates a remote-access tunnel back to a VSCode account. The Stately Taurus espionage group abused this feature to obtain interactive reverse-shell access to government hosts in Southeast Asia while blending in with legitimate developer traffic. Abuse of a trusted developer tool for command and control lets the actor evade network controls and persist covertly.
HuntRule TeamWindowsprocess_creationMedium102Premium2026-08-14Possible Ngrok RDP Tunnel Exposure via TCP 3389
This rule detects command lines that tunnel TCP port 3389 which exposes internal Remote Desktop Protocol to the internet. The BlackJack group used ngrok tcp 3389 to reach RDP on compromised hosts, and such tunneling enables covert lateral movement and remote interactive access.
HuntRule TeamWindowsprocess_creationMedium198Premium2026-08-14Malicious Vulnerable Driver HwRwDrv Loaded for BYOVD
This rule detects loading of the HwRwDrv vulnerable driver, a bring-your-own-vulnerable-driver component observed in a Huntress-tracked Tiflux RMM malspam campaign to gain privileged kernel access. Attackers load this signed but vulnerable driver to tamper with protected processes and security tooling. Presence of this driver name is a strong indicator of BYOVD privilege escalation.
HuntRule TeamWindowsdriver_loadHigh148Premium2026-08-14Suspicious HDUtil Loader Execution with NoUac Arguments via process_creation
This rule detects the OkoBot HDUtil.exe loader running with its distinctive nouac and noattach arguments to launch further payloads. These custom flags are specific to the OkoBot framework targeting cryptocurrency wallet users. The unusual argument set is a reliable execution fingerprint for the loader.
HuntRule TeamWindowsprocess_creationHigh205Premium2026-08-14Suspicious PerfWatson2 Execution from Local AppData
This rule detects a process named PerfWatson2.exe running from a user LocalAppData directory, where the genuine Visual Studio telemetry helper never lives. CL-STA-1062 stages a masqueraded PerfWatson2.exe in LOCALAPPDATA as part of its backdoor toolset. Flagging the trusted name in this unexpected location reveals an implant impersonating a developer utility.
HuntRule TeamWindowsprocess_creationMedium141Premium2026-08-14Suspicious Event Log Clearing via wevtutil During Ransomware Activity
This rule detects wevtutil clearing Windows event logs which ransomware operators perform to destroy evidence of intrusion and lateral movement. Clearing logs immediately before or after encryption impairs incident response and timeline reconstruction.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-08-14Malicious Scheduled Task Masquerading as Auto Update via schtasks (via process_creation)
This rule detects creation of a scheduled task named Auto apdate that launches Trays.exe at logon with highest privileges, the persistence mechanism used in the AnyDesk phishing campaign targeting Russian aerospace firms. The misspelled update-themed task name masquerades as a benign auto-updater to hide malicious auto-start, so catching the task registration exposes the persistence before the tool executes.
HuntRule TeamWindowsprocess_creationHigh371Premium2026-08-14Malicious Brutforce on Windows OpenSSH Server with Valid Users (via security)
This rule detects sSH brutforce a Windows OpenSSH server with a valid user.
HuntRule TeamWindowssecurityHigh102Premium2026-08-14Malicious Word Spawning Rundll32 Loading DLL from Roaming Word Folder
This rule detects winword.exe launching rundll32.exe to load a DLL staged under the AppData Roaming Microsoft Word directory which is the Hancitor maldoc execution chain preceding Cuba ransomware. The malicious macro drops and side loads the loader from a user writable path. It is important because this parent child pattern reliably marks initial Hancitor infection.
HuntRule TeamWindowsprocess_creationHigh403Premium2026-08-13Suspicious Service DLL Persistence Under Masquerading Service Names
This rule detects a ServiceDll value being set under the COMSysConfig or StorSyncSvc service keys which the ColunmTK APT41 cluster registers to load a malicious DLL through a svchost hosted service. The names impersonate legitimate Windows components to blend in. It is important because ServiceDll hijacking grants stealthy SYSTEM level persistence.
HuntRule TeamWindowsregistry_setHigh384Premium2026-08-13Suspicious PowerShell Invoke-WebRequest Download of Executable Payload
This rule detects PowerShell using Invoke-WebRequest to download an executable payload to disk. UAT-6382 used this technique after web-shell access to pull additional tooling from staging infrastructure over a non-standard port, a common ingress-tool-transfer step preceding beacon deployment.
HuntRule TeamWindowsprocess_creationMedium143Premium2026-08-13