Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,382 rules
Malicious Service Abuse with Backdoored "command Failure" - Reg via Command (via process_creation)
This rule detects modify the configuration of a service to trigger an action when the service is crashed.
HuntRule TeamWindowsprocess_creationHigh347Premium2026-07-01Suspicious MonsterV2 Payload Masquerading as Windows Health Executable (via process_creation)
This rule detects execution of WinHealth.exe or WindowsSecurity.exe, filenames the SonicCrypt crypter used to disguise the MonsterV2 payload. The crypter spawned these binaries through a Task Scheduler COM object to load the RAT.
HuntRule TeamWindowsprocess_creationMedium113Premium2026-07-01Malicious NotPetya Payload Execution via Rundll32 Ordinal Export from Windows Directory
This rule detects rundll32 launching a DLL from the Windows root directory by ordinal export number one which matches the NotPetya execution pattern documented by NCC Group. The ransomware was copied into the Windows folder and executed via its first ordinal to encrypt disks and spread laterally.
HuntRule TeamWindowsprocess_creationMedium91Premium2026-07-01Windows Process: SystemSettingsAdminFlows.exe Used to Disable Windows Defender
Alerts when SystemSettingsAdminFlows.exe is launched with command-line arguments consistent with disabling Windows Defender.
Chirag Damani (KPMG India), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh311Free2026-07-01Failed WMI NTEventLogFile ClearEventLog attempts (Windows WMI Event 5858)
Alerts on WMI errors (Event 5858) tied to attempted NTEventLogFile ClearEventLog calls on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowswmiMedium173Free2026-07-01Suspicious AnyDesk Silent Install With Unattended Password
This rule detects AnyDesk being configured with the --set-password flag to enable unattended access without user interaction. The Librarian Ghouls APT installs AnyDesk this way to maintain covert remote control of compromised machines for data theft and crypto mining. Silent password provisioning of a remote-access tool is a common hands-on-keyboard persistence step.
HuntRule TeamWindowsprocess_creationHigh167Premium2026-06-30Suspicious Triada mms-core.jar Backdoor Dropped in App Data
This rule detects creation of an mms-core.jar file within an application data directory which the Triada trojan drops as a backdoor module loaded into hooked processes. This module implements the trojan command handling used to intercept SMS and manipulate clipboard cryptocurrency addresses. The specific filename in a per-app data path is a reliable Triada artifact.
HuntRule TeamAndroidfile_eventHigh423Premium2026-06-30Suspicious Quick Assist Spawning Command Interpreter or Download Tooling via Process Creation
This rule detects the Quick Assist remote assistance tool spawning a command interpreter or download utility, a technique used in social engineering attacks where operators abuse Quick Assist to run scripted downloads. Storm-1811 leveraged this to fetch Qakbot and Cobalt Strike leading to Black Basta ransomware, so a legitimate support binary launching cmd, PowerShell or curl warrants investigation.
HuntRule TeamWindowsprocess_creationMedium131Premium2026-06-30Malicious curl Insecure Download to AppData or Temp
This rule detects curl.exe writing a downloaded file into the AppData or Temp directory using the insecure flag, the ClickFix installation pattern used in OpenClaw brand-lure campaigns to fetch infostealer payloads before immediate execution. Attackers instruct victims to paste a terminal command that curls the payload to a user writable path. Downloading executables into AppData or Temp with certificate checks disabled is a strong staging indicator.
HuntRule TeamWindowsprocess_creationHigh122Premium2026-06-30Suspicious Defender Exclusion for Public Controller Path (via process_creation)
This rule detects PowerShell adding a Microsoft Defender exclusion for a Controller folder under C:\Users\Public as done by the Efimer Trojan to protect its payload. Whitelisting an attacker-controlled directory in a world-writable location lets the malware run and update without being scanned. This combination of Add-MpPreference and a public path is rarely legitimate.
HuntRule TeamWindowsprocess_creationHigh61Premium2026-06-30Suspicious CTFMON Masquerade Persistence via Run Key (via registry_set)
This rule detects a Run key value referencing a ctfmon.bat script, a persistence mechanism used by the SugarGh0st RAT that masquerades as the legitimate CTFMON input service. The batch launcher re-executes the malware at logon while blending in with expected process names.
HuntRule TeamWindowsregistry_setMedium389Premium2026-06-30Suspicious Script Execution from Alternate Data Stream via WScript
This rule detects wscript executing content stored in an alternate data stream, seen when an APT targeting Vietnamese human rights defenders hid a PowerShell scheduler in a log.txt ADS. Execution from a colon-delimited stream path conceals the payload from casual file inspection. ADS-hosted scripts are a defense evasion technique used to stage hidden persistence.
HuntRule TeamWindowsprocess_creationMedium404Premium2026-06-30LegionLoader Process Hollowing via SysWOW64 explorer.exe Self-Invocation (via process_creation)
This rule detects explorer.exe launched with explorer.exe passed as its own argument, the anomalous invocation used by the LegionLoader shellcode to spawn a SysWOW64 explorer.exe target for process hollowing. Legitimate Windows shell launches never pass the binary name as a command-line argument, so this pattern surfaces the injection host before LegionLoader is mapped into memory.
HuntRule TeamWindowsprocess_creationMedium93Premium2026-06-30Suspicious Run Key Persistence Pointing to Temp or Public Folder
This rule detects creation of autorun registry values whose payload path resides in a temporary or public user writable directory which Phobos ransomware uses to survive reboots. Legitimate software rarely persists from these transient locations so this pattern is a reliable indicator of malicious persistence.
HuntRule TeamWindowsregistry_setHigh141Premium2026-06-30Suspicious PowerShell Download of scrss or ekrn Masquerading Scripts
This rule detects PowerShell referencing scrss.ps1 or ekrn.ps1, downloader script names used in the Gamaredon and Turla collaboration to fetch and stage further payloads. The script names imitate the legitimate csrss and ESET ekrn processes, and their presence in PowerShell activity indicates masqueraded ingress tooling and command execution.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-06-30