Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,368 rules
Suspicious Registry Modification Disabling RestrictedAdmin Mode (via process_creation)
This rule detects a reg add command disabling RestrictedAdmin mode under the LSA key. The SLOW#TEMPEST campaign disabled this protection to enable pass-the-hash remote desktop logons during lateral movement.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-07-16Suspicious Credential Store Access for WinSCP and PuTTY via PowerShell (via ps_script)
This rule detects PowerShell script content referencing WinSCP and PuTTY session registry stores or the Windows Credential Manager enumeration API, the credential theft behavior of the SEO poisoning infostealer. These paths and calls harvest saved SSH, SFTP and enterprise credentials. Scripts touching these secrets stores are a strong credential access indicator.
HuntRule TeamWindowsps_scriptMedium122Premium2026-07-16AnyDesk Network
Detects use of AnyDesk
HuntRule TeamWindowsdns_queryHigh113Premium2026-07-16Suspicious Child Process Spawned From Java Following Web Exploitation
This rule detects a Java process spawning a command shell or discovery utility, the post-exploitation behavior seen after ShinyHunters exploited the Oracle PeopleSoft PeopleTools zero-day to gain code execution. A Java application server launching cmd, PowerShell or reconnaissance commands is a strong web-exploitation indicator. This pattern precedes remote-management deployment and lateral movement.
HuntRule TeamWindowsprocess_creationHigh226Premium2026-07-16Suspicious Child Process Spawned by 3CXDesktopApp via Supply Chain Compromise
This rule detects the 3CXDesktopApp.exe process spawning a command interpreter such as cmd.exe or powershell.exe. During the 3CX supply chain compromise the trojanized client executed follow-on commands to profile the host and retrieve second-stage payloads after sideloading a malicious ffmpeg.dll. The VoIP client has no legitimate reason to launch shells.
HuntRule TeamWindowsprocess_creationHigh93Premium2026-07-15Suspicious Efimer Persistence via Run Controller Value (via registry_set)
This rule detects creation of a controller value under the current user Run key used by the Efimer crypto-stealing Trojan for persistence. Efimer spreads through mass-mailing and installs a clipboard hijacker that swaps cryptocurrency wallet addresses. The named autorun entry re-launches the controller component at every logon.
HuntRule TeamWindowsregistry_setHigh101Premium2026-07-15Suspicious Process Execution From Recycle Bin Directory
This rule detects execution of an executable located inside a Recycle Bin directory such as RECYCLER.BIN or $Recycle.Bin. In a case analyzed by Kaspersky a CEFHelper.exe payload was launched from RECYCLER.BIN on a USB drive to enable DLL sideloading. Legitimate software is not executed from the Recycle Bin so this location strongly indicates staging of a hidden payload for defense evasion.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-07-15Malicious Veeam Credential Extraction via sqlcmd Query (via process_creation)
This rule detects the use of sqlcmd to query the Credentials table of the VeeamBackup database, a technique used in Akira ransomware intrusions to recover stored backup infrastructure credentials for lateral movement and backup destruction. Direct sqlcmd access to the Veeam credential table is not typical of routine administration.
HuntRule TeamWindowsprocess_creationHigh259Premium2026-07-15PureHVNC RAT Execution via AutoIt Interpreter from WordGenius Technologies Directory (via process_creation)
This rule detects the PureHVNC AutoIt interpreter, renamed SwiftWrite.pif or AutoIt3.exe, executing a compiled script from the WordGenius Technologies directory in the user profile. Adversaries run the RAT through AutoIt to abuse a legitimate interpreter and evade static detection, making the combination of the renamed interpreter and the campaign install path a reliable execution signal.
HuntRule TeamWindowsprocess_creationHigh286Premium2026-07-15Malicious regsvr32 DLL Execution with Custom Install Argument
This rule detects regsvr32 executed silently with the /n and /i install switches to register and pass a custom argument to a DLL, a technique observed in the AppleSeed triple-combo campaign that ran tripservice.dll with the marker /i:tgvyh. It captures signed-binary proxy execution used to run attacker DLL code while bypassing application controls. Detecting this is important because the combination of /s /n /i on regsvr32 rarely appears in legitimate software.
HuntRule TeamWindowsprocess_creationHigh237Premium2026-07-15Suspicious Event Log Clearing via wevtutil (via process_creation)
This rule detects use of wevtutil to clear Windows event logs which was observed being run in a loop over multiple log channels during a BitLocker ransomware intrusion. Clearing logs removes forensic evidence of attacker activity. Destroying event history hinders incident response and hides the actions leading up to encryption.
HuntRule TeamWindowsprocess_creationMedium3810Premium2026-07-15Suspicious Cloudflared Tunnel Execution with Token
This rule detects execution of the cloudflared client to run a named tunnel with an embedded token, establishing an outbound encrypted channel that bypasses perimeter controls. Akira ransomware operators used cloudflared tunnels for covert remote access into victim networks. Unsanctioned tunneling tools provide attackers persistent command and control that evades firewall inspection.
HuntRule TeamWindowsprocess_creationMedium209Premium2026-07-15Malicious Nova Ransomware Note and Encrypted File Extension via File Event
This rule detects creation of the Nova ransomware note README_NOVA.me alongside files bearing the .xgWLckNV extension appended during encryption. These artifacts are dropped as Nova encrypts a host and demands ransom.
HuntRule TeamWindowsfile_eventHigh164Premium2026-07-14Malicious Defender Behavior Monitoring Disable via Set-MpPreference
This rule detects commands that disable Microsoft Defender behavior monitoring through Set-MpPreference or the MpPreference registry path. A fake KMSPico installer delivering Vidar Stealer used a javaw hosted stage to switch off behavior monitoring before running AutoIt. Turning off behavior monitoring lets the loader execute without real-time detection.
HuntRule TeamWindowsps_scriptHigh83Premium2026-07-14Suspicious Recursive Credential and Wallet Search Written to Temp Inventory File
This rule detects a recursive filesystem search for wallet and credential material whose results are written to a temporary inventory file which matches the collection behavior observed when adversaries abuse AI command line tools to harvest secrets. Automating discovery of keys and wallets into a single staging file precedes exfiltration. Detecting this pattern surfaces credential and data collection on the host.
HuntRule TeamWindowsprocess_creationMedium71Premium2026-07-14