Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,378 rules
Suspicious Process Memory Dump via ProcDump Full Dump Flag
This rule detects ProcDump invoked with the accept eula and full memory dump flags which the NetSupport actor used through a renamed binary to capture process memory including LSASS and this matters because full memory dumps of running processes are a common credential access technique and the renamed binary reflects deliberate evasion of image name detections.
HuntRule TeamWindowsprocess_creationMedium182Premium2026-07-06Suspicious Payload Staging in Public Libraries Directory via file_event
This rule detects database style config files being written to the Users Public Libraries directory, the staging location GoSerpent uses for its encrypted configuration and collected data. This path is not a normal write target for applications. Files appearing here indicate backdoor staging and data collection.
HuntRule TeamWindowsfile_eventMedium163Premium2026-07-06Malicious Defender Exclusion for Executables via Add-MpPreference (via process_creation)
This rule detects PowerShell adding a Microsoft Defender exclusion by file extension through Add-MpPreference with ExclusionExtension, the defense-evasion behavior used by the Lua-based loader targeting the education and gaming sectors to exempt executable and library files from scanning. Adversaries leverage this to blind Defender across whole drive extensions before dropping payloads, making early detection critical for stopping the loader before persistence and C2 are established.
HuntRule TeamWindowsprocess_creationHigh112Premium2026-07-06Malicious Windows Event Log Clearing via Wevtutil
This rule detects wevtutil being used to clear the Security or System event logs, an anti-forensic action that destroys traces of intrusion activity. The Gentlemen ransomware clears these logs to hinder incident response. Detecting the log wipe exposes deliberate defense evasion during a ransomware attack.
HuntRule TeamWindowsprocess_creationHigh414Premium2026-07-05Suspicious Domain Admins Group Enumeration via net.exe (via process_creation)
This rule detects enumeration of the Domain Admins group with net localgroup and the /domain switch, used for privilege-mapping discovery during a compromised-vendor intrusion. Attackers query privileged group membership to identify high-value accounts before lateral movement. While administrators occasionally run this, its appearance alongside credential dumping is high signal.
HuntRule TeamWindowsprocess_creationLow151Premium2026-07-05Malicious DPAPI Credential Decryption via PowerShell ProtectedData Unprotect
This rule detects PowerShell invoking the DPAPI ProtectedData Unprotect method to decrypt secrets from the current user context. SocGholish operators used this to unprotect stolen browser credential material after staging it locally. This lets attackers recover plaintext passwords without touching disk artifacts that alert defenders.
HuntRule TeamWindowsps_scriptHigh196Premium2026-07-05Malicious FakeSG Scheduled Task VCC_runner2 NetSupport Loader (via process_creation)
This rule detects creation of a scheduled task named VCC_runner2 via schtasks. The FakeSG campaign registers this task to run a script chain that unpacks and launches a NetSupport RAT, so this distinctive task name indicates the fake-update loader persisting on the host.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-07-05Suspicious Project CAV3RN logAzure.txt Configuration Drop (via file_event)
This rule detects creation of a file named logAzure.txt, a configuration artifact written by the Project CAV3RN espionage framework that abuses Outlook calendar events and DNS for command-and-control. The fixed configuration filename is a distinctive host-based indicator of this framework staging its settings on disk.
HuntRule TeamWindowsfile_eventMedium103Premium2026-07-05Malicious Hidden Local Account via Winlogon SpecialAccounts UserList
This rule detects modification of the Winlogon SpecialAccounts UserList registry key which hides a local account from the Windows logon screen, a defense-evasion technique used alongside AnyDesk abuse to conceal an attacker-created administrator account. Writing to this key is almost never legitimate and indicates deliberate account hiding.
HuntRule TeamWindowsregistry_setHigh102Premium2026-07-05Malicious Security Product Bypass via defendnot Loader
This rule detects execution of the defendnot loader, a tool analyzed by Huntress that registers a fake antivirus through the Windows Security Center API to silently disable Microsoft Defender. The loader drops a ctx.bin configuration and injects defendnot.dll into taskmgr.exe to persist the fake AV registration. Because defendnot exists solely to neutralize Defender, its execution is a high-confidence defense-evasion indicator.
HuntRule TeamWindowsprocess_creationHigh3910Premium2026-07-05Malicious HiddenGh0st Guest Account Activation and Admin Group Addition (via process_creation)
This rule detects activation of the built in guest account followed by adding it to the local administrators group as used by the HiddenGh0st MS-SQL intrusion for persistence. Re enabling and elevating the guest account is a rarely legitimate backdoor technique.
—Windowsprocess_creationHigh113Premium2026-07-05Suspicious Data Exfiltration Tool S3 Browser Execution (via process_creation)
This rule detects execution of the S3 Browser client, the third-party utility Muddled Libra uses to stage and exfiltrate collected data to attacker-controlled S3 buckets. Presence of S3 Browser on servers and admin hosts is abnormal and aligns with bulk cloud exfiltration after domain compromise.
HuntRule TeamWindowsprocess_creationMedium212Premium2026-07-05ValleyRAT Keylog Output File Creation in ProgramData (via file_event)
This rule detects creation of a sys.key file under ProgramData, the keystroke-log output artifact written by ValleyRAT when its keylogger module is activated via configuration or registry key. Adversaries leverage a low-profile filename in a machine-wide directory to collect captured input for later exfiltration, making early detection critical for exposing active collection before credentials and sensitive data leave the host.
HuntRule TeamWindowsfile_eventMedium2710Premium2026-07-05Malicious Kimsuky Troll Stealer Collected Data Staging Files with gte1 Extension (via file_event)
This rule detects creation of Troll Stealer staging files under the local AppData folder that follow the tokenized naming scheme used for exfiltration containers such as tsd, tfd, tbd and ccmd with the .gte1 extension. These encrypted collection files hold stolen SSH, FileZilla, browser and system data prior to upload, making their creation a high-confidence sign of active data theft.
HuntRule TeamWindowsfile_eventHigh73Premium2026-07-05Suspicious Scheduled Task SystemSoundsService2 Creation via Process Creation
This rule detects creation of a scheduled task named SystemSoundsService2 through schtasks.exe, a masquerading name GoldenJackal uses to persist its air-gap tooling on government systems. The name imitates a legitimate Windows sounds service to blend in. This indicates scheduled-task persistence by an espionage actor.
HuntRule TeamWindowsprocess_creationHigh349Premium2026-07-05