Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,362 rules
Suspicious Scheduled Task Named mail for Loader Persistence
This rule detects creation of a scheduled task named mail, used in this attack to persist the XWorm loader. Scheduled task creation with a generic disguised name is a common persistence method and warrants review of the referenced task action.
HuntRule TeamWindowsprocess_creationMedium277Premium2026-07-24Malicious New Member Added to a "OCS/Lync/Skype for Business" Administration Group - Medium Risk (via security)
This rule detects scenarios where a new member is added to a sensitive administration group related to OCS/Lync/Skype for Business in order to scan topology, infiltrate servers and move laterally.
HuntRule TeamWindowssecurityHigh123Premium2026-07-24Suspicious Duke Malware DLLs Written to Windows Tasks Directory (via file_event)
This rule detects the Duke malware support DLLs being written into the Windows Tasks directory during the APT29 German Embassy campaign side-loading chain. Dropping Mso.dll and AppVIsvSubsystems64.dll into C:\Windows\Tasks stages the side-loading pair for msoev execution. DLL creation in this task directory is abnormal and indicates payload staging.
HuntRule TeamWindowsfile_eventHigh128Premium2026-07-24SplashTop Process
Detects use of SplashTop
HuntRule TeamWindowsprocess_creationHigh101Premium2026-07-23Suspicious Curl Download and Silent MSI Install of Remote Management Software (via process_creation)
This rule detects a command chain that uses curl to fetch an MSI package and then runs msiexec with a silent install flag, the delivery technique used in the vishing campaign against US law firms to deploy SuperOps and other remote management tooling. Adversaries pair remote download with unattended installs to stand up remote access without user interaction, so this chained behavior is worth flagging.
HuntRule TeamWindowsprocess_creationMedium112Premium2026-07-23Suspicious MOVEit w3wp Child Process Execution via process_creation
This rule detects the MOVEit Transfer IIS worker process w3wp.exe spawning command interpreters, which is the expected behavior when a dropped ASPX web shell is executed. During CVE-2023-34362 exploitation the attacker used the web shell under w3wp to run follow-on commands, so interpreter children of this worker are a strong web exploitation signal.
HuntRule TeamWindowsprocess_creationMedium367Premium2026-07-23Default Account Usage
Threat actor (APT35) created user, enabled it, set password, add to admins and remote desktop users.
HuntRule TeamWindowsprocess_creationMedium392Premium2026-07-23Malicious NTDS.dit Extraction via ntdsutil IFM Snapshot (via process_creation)
This rule detects use of ntdsutil to create an install-from-media snapshot, the technique Storm-1175 uses to extract the NTDS.dit Active Directory database and steal domain credential hashes during Medusa ransomware operations. Adversaries dump NTDS.dit to obtain every domain account hash for offline cracking and mass lateral movement, so this command on a domain controller is a critical credential-access alert.
HuntRule TeamWindowsprocess_creationHigh111Premium2026-07-23Malicious DcRAT Payload Masquerading as Mixed Reality.exe via process_creation
This rule detects execution of a binary named Mixed Reality.exe from the Windows Media Player directory, a masquerading trick used by Operation DragonReturn to stage its multi-stage DcRAT loader. The China-nexus actor placed the payload under a trusted vendor folder to blend with legitimate software while conducting espionage against Indian tax infrastructure, so early detection exposes the loader before injection and C2.
HuntRule TeamWindowsprocess_creationHigh92Premium2026-07-23Malicious SUNBURST Command and Control DNS Query to avsvmcloud Domain (via dns_query)
This rule detects DNS lookups containing the avsvmcloud domain used as the SUNBURST first-stage command and control and victim beaconing channel. The backdoor encodes environment data into subdomains of avsvmcloud during its DGA-style callbacks. Detecting any avsvmcloud query is a high fidelity indicator of a SUNBURST compromised host.
HuntRule TeamWindowsdns_queryCritical336Premium2026-07-23Suspicious action.inf Dropped Alongside ViPNet Update Loader
This rule detects the creation of an action.inf file inside a ViPNet update directory which carries the extra_command configuration consumed by the malicious update loader. This drop is part of a backdoor masquerading as ViPNet updates that stores its attacker-controlled parameters next to the substituted binary. Catching the config write reveals the staging step before execution.
HuntRule TeamWindowsfile_eventMedium314Premium2026-07-23Suspicious DLL Sideloading via Signed Utility Binaries Used by Storm-2603
This rule detects execution of signed helper binaries such as 7z.exe, clink_x86.exe, MpCmdRun.exe and VMToolsEng.exe from outside their legitimate installation directories, a DLL search-order hijacking technique abused by Storm-2603 to load malicious payload DLLs under a trusted process. Running these tools from user-writable or temporary paths is anomalous and indicates staged loader activity during the intrusion.
HuntRule TeamWindowsprocess_creationMedium161Premium2026-07-23Suspicious WScript Execution Spawned by Microsoft Word (via process_creation)
This rule detects wscript.exe spawned as a child of Microsoft Word, indicating macro-driven script execution. The returning Bumblebee campaign used a macro-enabled document that dropped a temp script and ran it via wscript to fetch the loader.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-07-23Malicious Mimikatz Credential Dumping Command Line
This rule detects Mimikatz style command modules on the process command line such as privilege debug and sekurlsa logonPasswords. In the WithSecure Catching Lazarus Part Two research the actor runs these modules to dump credentials from lsass memory. Attackers use Mimikatz to harvest passwords and hashes for lateral movement.
HuntRule TeamWindowsprocess_creationCritical122Premium2026-07-23Suspicious BITSAdmin File Transfer Download (via process_creation)
This rule detects use of bitsadmin with the transfer switch to download a remote payload which the LilacSquid actor uses to retrieve the MeshAgent remote management tool. Living-off-the-land download via the Background Intelligent Transfer Service evades network monitoring and blends with legitimate update traffic.
HuntRule TeamWindowsprocess_creationMedium2910Premium2026-07-23