Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,264 rules
Suspicious Remote Management C2 Subdomain Resolution
This rule detects DNS resolution of upload[1-4].am.remote.management style hostnames used as command-and-control and data-upload endpoints in this Brazilian RMM-abuse spam campaign. The structured am.remote.management pattern with a numbered upload prefix is the operator infrastructure receiving exfiltrated data through abused remote monitoring tooling.
HuntRule TeamWindowsdns_queryMedium60Premium2026-09-09Possible Telegram API Command and Control DNS Query
This rule detects DNS resolution of api.telegram.org, the endpoint used by YoroTrooper for Telegram-based command-and-control and data exfiltration. Multiple threat actors abuse the Telegram Bot API as a resilient web-service C2 channel. Because legitimate applications also use Telegram, this signal is provided at low confidence and should be correlated with other host activity.
HuntRule TeamWindowsdns_queryLow20Premium2026-09-09Suspicious Run Key Persistence via UpdateCheck Value in Operation TrueChaos
This rule detects creation of an UpdateCheck value under a Windows Run key, the autostart persistence mechanism used in Operation TrueChaos to relaunch the Havoc loader at logon. A masquerading update-check value written to a Run key is an established persistence indicator for this campaign.
HuntRule TeamWindowsregistry_setMedium30Premium2026-09-09Malicious ValleyRAT KernelQuick Rootkit Service and Shellcode Store Registry Keys
This rule detects registry writes to the kernelquick kernel-driver service key and to the HKLM\SOFTWARE\IpDates key used by ValleyRAT's kernel rootkit component to register its driver and stash shellcode. These fixed key names are unique to the ValleyRAT rootkit and indicate installation of its kernel-level hiding and persistence layer.
HuntRule TeamWindowsregistry_setHigh30Premium2026-09-09Malicious Silver Fox BYOVD Vulnerable Driver Service Creation
This rule detects creation of the kernel service entries named Termaintor or Amsdk_Service that the Silver Fox APT registers to load the vulnerable amsdk.sys driver in a bring-your-own-vulnerable-driver attack. The driver is abused via IOCTL 0x80002048 to terminate security product processes, so these service names indicate an in-progress endpoint-defense-disabling operation preceding ValleyRAT injection.
HuntRule TeamWindowsregistry_setHigh30Premium2026-09-09Suspicious Run Key Persistence Pointing to AppData Local Copy
This rule detects a Run key autostart entry whose target is an executable copied into the AppData Local directory, the persistence pattern used by the PureHVNC loader distributed through the impersonated Kling AI site. The loader copies itself into the user profile and registers a Run value to survive reboot. Detecting it exposes the persistence foothold.
HuntRule TeamWindowsregistry_setMedium30Premium2026-09-09Malicious WezRat Persistence via Chrome Updater Run Key
This rule detects a Run key value named Chrome Updater pointing to Updater.exe, the persistence and masquerade used by the WezRat backdoor. The malware disguises its autostart as a Chrome update component to appear benign. Detecting the named value with its Updater.exe target exposes the implant persistence.
HuntRule TeamWindowsregistry_setHigh90Premium2026-09-09Suspicious Image File Execution Options Debugger Hijack (via registry_set)
This rule detects a Debugger value being set under an Image File Execution Options key, an IFEO hijack Raspberry Robin uses to redirect or persist execution. Setting a Debugger entry causes an arbitrary program to launch whenever the target image runs, a technique with little legitimate use outside debugging tools.
HuntRule TeamWindowsregistry_setMedium20Premium2026-09-09Malicious Windows Defender Exclusion Added (via registry_set)
This rule detects new Windows Defender exclusion entries for paths or processes, a defense evasion step used by Raspberry Robin to prevent detection of its payloads. Attacker-driven exclusion writes let malware run unscanned, so unexpected additions to the Defender Exclusions keys are high-value indicators.
HuntRule TeamWindowsregistry_setHigh30Premium2026-09-09Suspicious RoboForm Update Run Key Masquerade (via registry_set)
This rule detects an HKLM Run value named RoboForm Update pointing to a binary outside the legitimate RoboForm install path, a persistence masquerade used by PlugX in the SmugX campaign. The technique blends the autostart entry with a trusted product name while launching a sideloaded loader from a staging directory.
HuntRule TeamWindowsregistry_setMedium90Premium2026-09-09Suspicious TrueConf Update Chain Spawning Temporary Executable in Operation TrueChaos
This rule detects trueconf_windows_update.exe launching a .tmp executable, the supply-chain execution chain observed in Operation TrueChaos where a trojanized TrueConf updater drops and runs a Havoc payload. A signed-looking updater executing a temporary binary is anomalous and marks the initial loader stage.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-09Suspicious Termination of Windows Security Health UI via taskkill
This rule detects forced termination of SecHealthUI.exe, the Windows Security notification UI, via taskkill, an action GachiLoader takes to suppress security alerts to the user. Killing the Defender interface component is a defense-evasion behavior with little legitimate cause.
HuntRule TeamWindowsprocess_creationHigh80Premium2026-09-09Suspicious Defender Exclusion Added via Add-MpPreference by GachiLoader
This rule detects use of Add-MpPreference with an ExclusionPath or ExclusionExtension argument, a Microsoft Defender tampering step GachiLoader performs to whitelist its payload directories before staging. Attacker-driven exclusion changes carve blind spots into endpoint protection and precede malware deployment.
HuntRule TeamWindowsprocess_creationMedium220Premium2026-09-09Malicious Forced Deletion of Security Vendor Kernel Drivers by ValleyRAT
This rule detects command-line forced deletion of kernel driver files belonging to Chinese and mainstream security vendors such as 360, Huorong, Tencent and Kaspersky, an anti-defense step ValleyRAT executes to blind endpoint protection before deploying its rootkit. Deleting vendor .sys files by force is a strong impairment-of-defenses indicator.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-09-09Suspicious IP Release and Renew via Minimized cmd During Driver Install
This rule detects a minimized cmd shell chaining ipconfig /release and /renew, a network-flap trick ValleyRAT performs to mask connectivity loss while it installs its stealth kernel driver. The minimized-window start combined with a release-then-renew sequence in one command is anomalous and points to the rootkit installation routine.
HuntRule TeamWindowsprocess_creationMedium30Premium2026-09-09