Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,359 rules
Batch Script Execution From RECYCLERS.BIN Masquerade Directory
This rule detects process execution referencing a RECYCLERS.BIN directory, a masquerade of the Windows Recycle Bin used as a hidden staging location in the DLL side-loading campaign to run tmp.bat. Executing scripts from a directory imitating the Recycle Bin is a defense-evasion and staging indicator.
HuntRule TeamWindowsprocess_creationHigh403Premium2026-07-25TinyLoader Persistence via txtfile Shell Open Command Hijack (via registry_set)
This rule detects modification of the txtfile shell open command handler so that opening any text file first launches an attacker binary, the file-association hijack TinyLoader uses for persistence. Adversaries leverage this handler so the loader runs whenever a user opens a .txt file, then still opens the file to avoid suspicion.
HuntRule TeamWindowsregistry_setHigh132Premium2026-07-25Operator Bring Your Own Tools
Detects use of custom scripts i.e. BAT files.
HuntRule TeamWindowsprocess_creationHigh367Premium2026-07-25Masquerading Kerberos Ticket Abuse via Rubeus (via process_creation)
This rule detects Rubeus command-line actions such as kerberoast, asreproast and tgtdeleg, which request and extract Kerberos tickets for offline cracking or impersonation. Rubeus-driven Kerberos abuse is a credential-access technique tracked in the Red Canary Threat Detection Report. Detecting these actions surfaces ticket theft aimed at privilege escalation.
HuntRule TeamWindowsprocess_creationHigh94Premium2026-07-25Malicious PyPI Package Installation from Gleaming Pisces Supply Chain (via process_creation)
This rule detects installation of the malicious PyPI packages real-ids, coloredtxt, beautifultext, or minisound published by Gleaming Pisces to deliver the PondRAT backdoor. Installing these poisoned packages compromises developer and build systems through the software supply chain.
HuntRule TeamWindowsprocess_creationHigh358Premium2026-07-24Suspicious Hidden PowerShell Download and Archive Expansion
This rule detects hidden-window PowerShell that downloads content with Invoke-WebRequest and expands an archive in the same command. This chain was used to retrieve and unpack the XWorm loader, combining ingress tool transfer with a hidden window to evade user awareness.
HuntRule TeamWindowsprocess_creationHigh93Premium2026-07-24Malicious LSASS Credentials Dump via Task Manager - File (via file_creation)
This rule detects provides an indicator of a user accessing the task manager in order to eventually dump the LSASS process content using the "Details" tab > right click on "lsass.exe" > Create a dump file.
HuntRule TeamWindowsfile_creationHigh168Premium2026-07-24Suspicious Credential File Harvesting of NPM Claude and SSH Secrets
This rule detects a command that reads sensitive credential files including the npm token store the Claude MCP configuration and SSH private keys. Malicious npm packages harvest these files to steal registry tokens API keys and keys for onward access. Detecting bulk reads of these secret paths reveals credential theft staged from a compromised developer machine.
HuntRule TeamWindowsprocess_creationMedium244Premium2026-07-24Suspicious Remote Scheduled Task Creation via schtasks for Lateral Movement (via process_creation)
This rule detects schtasks.exe creating a task against a remote system with a run-as account, the remote task scheduling method used during SUNBURST lateral movement to execute payloads on other hosts. Remote schtasks create with a system run level is rare in normal administration. Detecting it exposes lateral tool execution across the environment.
HuntRule TeamWindowsprocess_creationMedium201Premium2026-07-24Malicious Regsvr32 Registration of DynamicWrapperX (via process_creation)
This rule detects regsvr32 registering the dynwrapx ActiveX component. DarkWatchMan RAT registers DynamicWrapperX to invoke Windows API calls from its JavaScript payload.
HuntRule TeamWindowsprocess_creationHigh345Premium2026-07-24Suspicious Scheduled Task Masquerading As System Process
This rule detects schtasks creating a task named after a core Windows process such as winlogon csrss or dllhost. The PowerRAT and DCRAT campaign registered scheduled tasks impersonating winlogon csrss and dllhost triggered at logon or on a minute interval. Naming a scheduled task after a trusted system process combines persistence with masquerading to evade casual task review.
HuntRule TeamWindowsprocess_creationHigh388Premium2026-07-24Malicious Security Service Tampering via wmic PathName Query (via process_creation)
This rule detects the use of wmic to enumerate services by their executable path and delete or stop those belonging to Sophos endpoint protection, a technique used by Terminator and its variants to disable security tooling before deploying ransomware or a cryptominer. The command selects services whose PathName matches a security vendor string and invokes delete or stopservice.
HuntRule TeamWindowsprocess_creationHigh92Premium2026-07-24Suspicious Scheduled Task Named mail for Loader Persistence
This rule detects creation of a scheduled task named mail, used in this attack to persist the XWorm loader. Scheduled task creation with a generic disguised name is a common persistence method and warrants review of the referenced task action.
HuntRule TeamWindowsprocess_creationMedium277Premium2026-07-24Malicious New Member Added to a "OCS/Lync/Skype for Business" Administration Group - Medium Risk (via security)
This rule detects scenarios where a new member is added to a sensitive administration group related to OCS/Lync/Skype for Business in order to scan topology, infiltrate servers and move laterally.
HuntRule TeamWindowssecurityHigh123Premium2026-07-24Suspicious Duke Malware DLLs Written to Windows Tasks Directory (via file_event)
This rule detects the Duke malware support DLLs being written into the Windows Tasks directory during the APT29 German Embassy campaign side-loading chain. Dropping Mso.dll and AppVIsvSubsystems64.dll into C:\Windows\Tasks stages the side-loading pair for msoev execution. DLL creation in this task directory is abnormal and indicates payload staging.
HuntRule TeamWindowsfile_eventHigh128Premium2026-07-24