Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,371 rules
Suspicious WARMCOOKIE Scheduled Task for rundll32 Persistence via process_creation
This rule detects creation of a scheduled task that runs rundll32 against the WARMCOOKIE loader RtlUpd at a short recurring interval to maintain persistence. The backdoor registers a task firing every ten minutes to ensure continuous execution. The combination of a minute-based recurrence with rundll32 loading this DLL is characteristic of WARMCOOKIE.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-07-11Malicious Audit Policy Disabled by Command Line (via security)
This rule detects attempts disbaled the audit policy for defense evasion purposes.
HuntRule TeamWindowssecurityHigh123Premium2026-07-11NetSupport Manager RAT Execution From a User-Writable Path (via process_creation)
This rule detects the NetSupport Manager remote-control client (client32.exe) running from a user-writable directory such as AppData, ProgramData or Temp, where adversaries deploy the otherwise-legitimate RMM tool as a covert remote access trojan. Abuse of remote monitoring and management software is a leading access technique in the Red Canary Threat Detection Report. Because sanctioned installs live in Program Files, execution from user paths is a strong indicator of malicious NetSupport deployment.
HuntRule TeamWindowsprocess_creationHigh188Premium2026-07-11Malicious Active Directory Replication Request Indicating DCSync
This rule detects a directory service access event granting the replicating directory changes right which the ALPHV actor exercised through a credential tool to perform DCSync and pull domain hashes and this matters because outside of domain controllers and a small set of sync services the request for the replication extended right is a high fidelity indicator of DCSync credential theft.
HuntRule TeamWindowssecurityHigh121Premium2026-07-11Suspicious SoftPerfect Network Scanner Execution for Discovery
This rule detects execution of the SoftPerfect Network Scanner netscan.exe used for internal network discovery. The Christmas Miracle actor ran this tool to map reachable hosts and services before lateral movement. Unsanctioned network scanning is a common precursor to broader compromise.
HuntRule TeamWindowsprocess_creationMedium72Premium2026-07-11Suspicious UAC Bypass via iscsicpl Auto-Elevation in Operation TrueChaos
This rule detects iscsicpl.exe spawning a command interpreter or script host child process, an auto-elevation UAC bypass abused in Operation TrueChaos against Southeast Asian government targets. iscsicpl launching cmd, powershell or a temporary binary indicates privilege escalation ahead of Havoc C2 deployment.
HuntRule TeamWindowsprocess_creationHigh191Premium2026-07-11Malicious GPO Permission Abuse via SharpGPOAbuse
This rule detects execution of SharpGPOAbuse, a tool CrazyHunter operators use to weaponize edit rights over a Group Policy Object for domain-wide code execution. Abusing GPO permissions lets an attacker push tasks or scripts to every host in scope. Presence of this tooling indicates active privilege abuse against Active Directory.
HuntRule TeamWindowsprocess_creationHigh112Premium2026-07-11Suspicious Remote Connection to ADWS Port 9389 via security
This rule detects Windows Filtering Platform event 5156 recording an allowed inbound connection to TCP port 9389, the Active Directory Web Services port. Correlating the real source address from event 5156 exposes remote ADWS enumeration that would otherwise appear as localhost in Directory Service logs, so non-loopback connections to 9389 indicate potential SOAPHound style directory collection.
HuntRule TeamWindowssecurityMedium73Premium2026-07-11Malicious Cobalt Strike Default Named Pipe Creation (via pipe_created)
This rule detects creation of named pipes matching Cobalt Strike default and post-exploitation patterns such as msagent_, postex_ and status_ pipes used for beacon inter-process communication and privilege escalation. Cobalt Strike is among the most prevalent adversary tools in the Red Canary Threat Detection Report, used across ransomware and espionage intrusions for command and control. Detecting its characteristic named pipes surfaces beacon activity that often evades network-based controls.
HuntRule TeamWindowspipe_createdHigh52Premium2026-07-11Malicious SharePoint spinstall0 Webshell Dropped in LAYOUTS
This rule detects the spinstall0.aspx file being written into the SharePoint LAYOUTS directory. Attackers exploiting the ToolShell chain drop this ASPX webshell to steal machine keys and maintain access. Creation of spinstall0.aspx in LAYOUTS is a definitive post-exploitation indicator.
HuntRule TeamWindowsfile_eventCritical132Premium2026-07-11Suspicious Registry Run Key Persistence Masquerading as Microsoft Updater (via process_creation)
This rule detects reg.exe adding a CurrentVersion Run value named updater that points to a Microsoft Updater directory. Maranhao Stealer establishes persistence with this masqueraded autorun entry in the user AppData path.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-07-11Suspicious MoustachedBouncer Command Execution from SMB EDGEIN Directory via Cmd (via process_creation)
This rule detects cmd.exe reading operator commands from the SMB share directory EDGEIN, the command channel used by the MoustachedBouncer SharpDisco backdoor to pipe attacker input into a shell. This behavior indicates remote command-and-control tasking through a network share.
HuntRule TeamWindowsprocess_creationMedium317Premium2026-07-11Deleting Windows Defender scheduled tasks
Detects the deletion of scheduled tasks related to Windows Defender.
HuntRule TeamWindowsprocess_creationHigh63Premium2026-07-11Malicious Backup and Shadow Copy Destruction via Native Utilities
This rule detects the deletion of volume shadow copies, backup catalogs, and recovery configuration through native Windows utilities, a recovery-inhibition step performed by Hunters International affiliates before encryption. Destroying backups to prevent restoration is a hallmark of ransomware impact activity and should be treated as high priority.
HuntRule TeamWindowsprocess_creationHigh182Premium2026-07-11Suspicious Process Execution from WinRAR Temporary Extraction Directory
This rule detects executables and batch scripts launching from the WinRAR temporary extraction path Temp\Rar$. The CVE-2023-38831 zero-day tricks users into running a spoofed-extension file that WinRAR extracts and executes from this directory. Such execution indicates archive-based exploitation and user-driven initial access.
HuntRule TeamWindowsprocess_creationMedium103Premium2026-07-11