Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,264 rules
Suspicious Dell ControlVault DLL Load by Unexpected Process (ReVault)
This rule detects processes other than the legitimate Windows Biometric service host loading the Dell ControlVault libraries bcmbipdll.dll or BCMStorageAdapter.dll. The ReVault attack abuses ControlVault firmware vulnerabilities, and abnormal processes loading these libraries indicate exploitation attempts against the security co-processor. Such loads can lead to code execution and firmware-level persistence.
HuntRule TeamWindowsimage_loadMedium70Premium2026-09-10Suspicious Keylog and Screenshot Files in windows-cache Directory (OtterCookie)
This rule detects creation of the collection artifacts 1.tmp and 2.jpeg inside a windows-cache directory, where the OtterCookie module stores keystroke logs and screenshots before exfiltration. These fixed staging paths and filenames are distinctive to the malware. Their appearance indicates active input capture and screen collection.
HuntRule TeamWindowsfile_eventHigh40Premium2026-09-10Suspicious Encrypted Implant File Creation for DLL Search Order Hijacking (RainyDay Turian PlugX)
This rule detects creation of encrypted implant files with distinctive names such as rdmin.src, Mcsitesdvisor.afx or winslivation.dat used by the RainyDay, Turian and PlugX variants. These files hold the encrypted payload that a legitimately signed application decrypts and loads via DLL search-order hijacking. Their appearance on disk indicates sideloading-based deployment.
HuntRule TeamWindowsfile_eventHigh10Premium2026-09-10Suspicious PS1Bot PowerShell Payload Written to ProgramData (via file_event)
This rule detects the PS1Bot malware framework writing its PowerShell payload ntu.ps1 into the ProgramData directory. PS1Bot is delivered through malvertising and stages obfuscated PowerShell modules from this location for in-memory execution. Script files created in ProgramData outside of installer activity are a strong indicator of staging.
HuntRule TeamWindowsfile_eventHigh60Premium2026-09-10Suspicious CyberLock Ransomware Encrypted File Creation
This rule detects creation of files bearing the .cyberlock extension, the marker appended by the ransomware distributed through fake AI-tool installers. Appearance of this extension indicates active encryption of user data on the host and imminent extortion.
HuntRule TeamWindowsfile_eventHigh10Premium2026-09-10Suspicious Web Shell File Written to IIS wwwroot Directory
This rule detects creation of server-side script files such as .aspx or .ashx within an IIS wwwroot directory by a process, which is how AntSword and China Chopper web shells were planted after UAT-6382 exploited Cityworks. Web shells dropped into the web root give the operator persistent remote command execution over HTTP against the compromised server.
HuntRule TeamWindowsfile_eventMedium10Premium2026-09-10Suspicious Executable Dropped in Public Users Directory Named Ctrlpanel (via file_event)
This rule detects creation of ctrlpanel.exe under the world-writable C:\Users\Public directory which the OfflRouter VBA virus drops as its payload dropper. Placing an executable in the Public profile is a common staging technique that avoids per-user path restrictions and blends with shared content.
HuntRule TeamWindowsfile_eventHigh00Premium2026-09-10Phobos 8Base Ransomware Encrypted File Extension Created
This rule detects files being renamed with the .8base extension appended by Phobos ransomware operated by the 8Base group. Phobos appends an extension containing a victim ID and contact email ending in .8base to each encrypted file. A wave of these file events signals active ransomware encryption on the host.
HuntRule TeamWindowsfile_eventHigh20Premium2026-09-10SapphireStealer Working Directory File Drop in Temp
This rule detects files being written under a sapphire\\work directory inside the user Temp folder. SapphireStealer uses %TEMP%\\sapphire\\work as its staging directory where it drops harvested Passwords.txt, Screenshot.png and log.zip before exfiltration. Activity in this fixed working path indicates active credential and data theft staging by the stealer.
HuntRule TeamWindowsfile_eventHigh20Premium2026-09-10Rhysida Ransomware Encrypted File Extension Created
This rule detects files being renamed with the .rhysida extension appended by Rhysida ransomware during encryption. Rhysida uses ChaCha20 to encrypt victim files and marks each with this extension. A burst of such file events indicates active mass encryption on the host.
HuntRule TeamWindowsfile_eventHigh50Premium2026-09-10Rhysida Ransomware Note CriticalBreachDetected.pdf Created
This rule detects the creation of a file named CriticalBreachDetected.pdf, the fixed ransom note dropped by Rhysida ransomware. Rhysida writes this note across affected directories after encrypting files. Detecting the note filename provides a high-confidence indicator that Rhysida encryption has already occurred on the host.
HuntRule TeamWindowsfile_eventHigh10Premium2026-09-09URL Shortcut File Created in Startup Folder for Persistence
This rule detects the creation of a .url shortcut file inside a Windows Startup folder. The Yashma ransomware planted a .url startup file to relaunch its payload at logon. Attackers abuse Startup-folder shortcut files to achieve low-privilege persistence that runs automatically for the affected user.
HuntRule TeamWindowsfile_eventMedium30Premium2026-09-09Malicious Qilin EDR Killer BYOVD Driver Load
This rule detects loading of the vulnerable drivers rwdrv.sys or hlpdrv.sys used by the Qilin EDR killer as a bring-your-own-vulnerable-driver toolkit. The rwdrv.sys component is a renamed ThrottleStop driver abused alongside hlpdrv.sys to gain kernel access for terminating protected security processes. Loading either driver indicates an attempt to disable endpoint defenses ahead of ransomware deployment.
HuntRule TeamWindowsdriver_loadHigh20Premium2026-09-09Suspicious Vulnerable ASUS AsIO3.sys Driver Load
This rule detects loading of the ASUS AsIO3.sys kernel driver, a vulnerable driver abused in this bring-your-own-vulnerable-driver technique. The driver exposes IOCTLs that grant arbitrary kernel memory access, which the actor leverages for privilege escalation and to bypass process allowlisting, so its load outside a genuine ASUS software context is a strong exploitation indicator.
HuntRule TeamWindowsdriver_loadMedium10Premium2026-09-09Malicious Known Vulnerable Driver Load for BYOVD Attack
This rule detects loading of known vulnerable kernel drivers such as viragt64.sys dbutil_2_3.sys zamguard64.sys RtCore64.sys gdrv.sys and empntdrv.sys which adversaries abuse in bring your own vulnerable driver attacks to disable security tooling and gain kernel level execution. Presence of these driver filenames loading on an endpoint is a strong indicator of privilege escalation or defense evasion activity.
HuntRule TeamWindowsdriver_loadHigh40Premium2026-09-09