Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,359 rules
DCOM Lateral Movement - Via MMC20 (via powershell)
This rule detects execute the Impacket DCOMexec tool in order to abuse DCOM services.
HuntRule TeamWindowspowershellHigh247Premium2026-07-29Malicious mshta.exe Spawning bitsadmin via ClickFix Phantom Meet
This rule detects mshta.exe spawning bitsadmin.exe, the process chain produced by the ClickFix Phantom Meet campaign where a pasted clipboard command runs a remote HTA that then uses bitsadmin to download follow on executables. Neither mshta launching bitsadmin nor this fake meeting lure is normal user behavior. The parent child relationship is a high confidence detection of the ClickFix delivery chain.
HuntRule TeamWindowsprocess_creationHigh152Premium2026-07-29Suspicious Mshta Execution of Remote Payload from Explorer via ClickFix Lure (via process_creation)
This rule detects mshta launched by explorer with a remote http argument, the ClickFix fake CAPTCHA pattern where a user pastes an attacker command into the Run dialog to fetch a remote HTA.
HuntRule TeamWindowsprocess_creationHigh143Premium2026-07-29Suspicious PSexec Application Execution (via process_creation)
This rule detects installs and executes PSexec.
HuntRule TeamWindowsprocess_creationMedium1810Premium2026-07-29Malicious LockBit Rundll32 Execution With gdll Export and -pass Argument
This rule detects rundll32.exe invoking a DLL export named gdll together with a -pass argument, the loader pattern used by LockBit 3.0 payloads staged from a batch file on the user Desktop. Huntress observed operators abusing a TeamViewer session to drop and run this payload for ransomware deployment. Catching the export and password-flag combination flags encryptor execution before file encryption completes.
HuntRule TeamWindowsprocess_creationHigh151Premium2026-07-29Malicious Anonymous Access Performed to Multiple Targets (via security)
This rule detects would attempt to enumerate hosts and collect relevant information using anonymous access. Vulnerability scanners, enumeration software or tool like CrackMapexec may generate such behavior.
HuntRule TeamWindowssecurityHigh92Premium2026-07-29Malicious Run Key Persistence with xcschemer Value
This rule detects creation of a Run key value named xcschemer. SideWinder used this autorun value to persist its loader across reboots, and the specific value name is a strong indicator of this campaign on Windows hosts.
HuntRule TeamWindowsregistry_setHigh81Premium2026-07-29Malicious EDR Termination via rundll32 Loading polers.dll Targeting Fortinet Processes (via process_creation)
This rule detects the Interlock EDR killer which uses rundll32.exe to invoke the exported start routine of polers.dll and terminate security processes matching the Forti pattern through a vulnerable anti cheat driver. The watchdog repeatedly relaunches to keep defenses down. This command line is unique to the tooling.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-07-29Suspicious New Network File Share Created (via security)
This rule detects scenarios when a new file share is created.
HuntRule TeamWindowssecurityMedium52Premium2026-07-29Suspicious Lazarus queue.bat Persistence Dropped in Startup Folder
This rule detects the creation of a file named queue.bat inside a Windows Startup folder which is the persistence mechanism used by the Lazarus DeceptiveDevelopment and Contagious Interview campaigns. The batch file relaunches the malicious Node.js and Python loader chain at every logon. Attackers use it to maintain foothold on developer machines targeted through fake job interviews.
HuntRule TeamWindowsfile_eventHigh125Premium2026-07-29Suspicious File Download via Certutil URLCache
This rule detects certutil abused as a downloader through its urlcache and file flags to retrieve a remote payload over HTTP. This LOLBin technique was documented delivering executables into the temp directory before execution. Living-off-the-land downloads via certutil let attackers stage tooling while evading application controls.
HuntRule TeamWindowsprocess_creationMedium348Premium2026-07-29Suspicious svchost Masquerading Executed Outside System Directory
This rule detects a process named svchost.exe running from any location other than the System32 or SysWOW64 directories, matching the GopherWhisper JabGopher component that spawns a fake svchost.exe host for LaxGopher injection. The legitimate service host only executes from System, so a copy elsewhere reveals masquerading and process injection.
HuntRule TeamWindowsprocess_creationHigh131Premium2026-07-29Malicious Self-Deletion Via Fsutil SetZeroData
This rule detects fsutil.exe being used with the setZeroData operation to overwrite file contents with zeros. BlackByte used fsutil setZeroData to zero out and self-delete its own binary after execution to hinder forensic recovery. Zeroing file data through fsutil is an anti-forensic indicator removal action rarely performed by legitimate administration.
HuntRule TeamWindowsprocess_creationHigh319Premium2026-07-29Suspicious COLDRIVER RunMRU History Clearing via Reg Delete (via process_creation)
This rule detects deletion of the Explorer RunMRU registry key through reg delete which the COLDRIVER ClickFix chain performs to erase evidence of the Run dialog command the victim was tricked into executing. Programmatic clearing of RunMRU is a strong anti forensics signal.
HuntRule TeamWindowsprocess_creationMedium61Premium2026-07-29Malicious Script Execution from WinRAR Extraction Directory via CVE-2023-38831
This rule detects a command interpreter executing a script staged in a WinRAR temporary extraction directory named Rar$DIa. CVE-2023-38831 abuses a filename spoofing flaw so that opening a decoy document triggers execution of an adjacent script from the Rar$ temp path. This yields attacker code execution when the victim merely opens a crafted archive.
HuntRule TeamWindowsprocess_creationHigh278Premium2026-07-28