Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,385 rules
Suspicious Rundll32 Loading DLL From User Desktop
This rule detects rundll32.exe loading a DLL located under a user Desktop directory, a staging pattern seen when LockBit 3.0 payloads were dropped alongside a launcher batch file during hands-on-keyboard intrusions. Legitimate software rarely places and runs DLLs directly from the Desktop. Flagging this location reveals attacker-controlled payloads executed via a trusted signed binary.
HuntRule TeamWindowsprocess_creationMedium448Premium2026-06-26Suspicious Outlook Security Manager DLL Load for Mail Harvesting (via image_load)
This rule detects the Grandoreiro banking trojan loading the secman or secman64 Outlook Security Manager component to iterate mailbox folders and harvest addresses for spam propagation. These third-party COM libraries are rarely present on standard endpoints. Their appearance alongside Outlook automation indicates mailbox collection.
HuntRule TeamWindowsimage_loadMedium142Premium2026-06-26Malicious GhostSocks Loader Execution with johnpidar Argument via process_creation
This rule detects process command lines containing the distinctive johnpidar argument. This hardcoded flag is passed to the GhostSocks loader delivered by fake OpenClaw installers, and its presence on a command line is a strong indicator of active infostealer and SOCKS proxy execution on the host.
HuntRule TeamWindowsprocess_creationHigh3910Premium2026-06-26Malicious rundll32 Loading DLL from WebDAV SSL Share
This rule detects rundll32 loading a DLL from a WebDAV SSL share indicated by the @SSL path token, an intrusion step observed in ACR Stealer delivery chains. Executing a remotely hosted DLL over WebDAV lets the attacker run code without writing the payload to local disk and evades application controls.
HuntRule TeamWindowsprocess_creationHigh243Premium2026-06-26Suspicious Scheduled Task Creation Spawned by Microsoft Office
This rule detects a Microsoft Office application spawning schtasks to register a scheduled task which mirrors the Cobalt Kitty initial access chain described by WithSecure where a malicious Word document created a persistence task. An Office document launching schtasks is highly abnormal and typically indicates macro driven persistence or execution following a phishing lure.
HuntRule TeamWindowsprocess_creationHigh1410Premium2026-06-26Suspicious Forest Blizzard GooseEgg Batch Launcher Chain (via process_creation)
This rule detects execution of the GooseEgg batch launcher files that write and invoke servtask.bat. Forest Blizzard used execute.bat and doit.bat to drop servtask.bat and trigger CVE-2022-38028 privilege escalation.
HuntRule TeamWindowsprocess_creationMedium82Premium2026-06-26Suspicious SCMBanker Remote Utilities RMM Install via Silent Msiexec
This rule detects a silent MSI install of the hosts.msi package which SCMBanker uses to deploy the Remote Utilities RMM agent for hands-on-keyboard control during banking fraud. Attackers abuse legitimate remote-management software to evade endpoint controls and maintain interactive access. A quiet install of this specific package indicates unauthorized RMM deployment.
HuntRule TeamWindowsprocess_creationMedium153Premium2026-06-26Malicious TELEPUZ ClickFix Stager via Hidden PowerShell Grab Endpoint
This rule detects a hidden execution-policy-bypass PowerShell command that pulls a payload from an index.php grab endpoint which is the ClickFix stager of the TELEPUZ malware-as-a-service delivered through Vidar chains. Victims are lured into pasting the command from a fake verification prompt. The specific grab API path combined with bypass flags marks the malicious download.
HuntRule TeamWindowsprocess_creationHigh203Premium2026-06-26Malicious APT29 DLL Side-Loading via msoev.exe from Windows Tasks Directory (via process_creation)
This rule detects the signed msoev binary executing from the Windows Tasks directory, the side-loading launcher APT29 used to load the Duke malware in the German Embassy lure campaign. Running this legitimate binary from C:\Windows\Tasks side-loads a malicious Mso DLL from the same folder. Execution of msoev from this path is highly anomalous.
HuntRule TeamWindowsprocess_creationHigh171Premium2026-06-25Suspicious EastWind Named Pipe Creation
This rule detects creation of a named pipe whose name starts with the Y prefix used by EastWind implants for inter-process communication and local tasking. Named pipes with this structure support covert component coordination, so their appearance on endpoints should be correlated with the DRM staging activity.
HuntRule TeamWindowspipe_createdMedium113Premium2026-06-25Malicious IIS Native Module Installation via Appcmd IsapiCachesModule (via process_creation)
This rule detects appcmd.exe installing a native IIS module named IsapiCachesModule backed by a caches.dll image as used by the Larva-25003 IIS malware. Registering a malicious native module allows the actor to intercept and manipulate all HTTP traffic on the server.
—Windowsprocess_creationHigh122Premium2026-06-25Suspicious Vulnerable Driver Load for BYOVD Abuse by DragonForce Ransomware (via driver_load)
This rule detects loading of the TrueSight.sys or RentDrv.sys vulnerable drivers that DragonForce abuses in a bring-your-own-vulnerable-driver technique to call ZwTerminateProcess and disable endpoint protection. Attackers exploit these signed drivers to kill security agents from kernel space. Flagging their load exposes tampering with defensive tooling.
HuntRule TeamWindowsdriver_loadMedium3710Premium2026-06-25Malicious System Crash Behavior Manipulation - WMImplant - Registry (via registry_event)
This rule detects abuses the Windows "system failure and recovery" capacities (CrashControl) to store information or to establish persistence.
HuntRule TeamWindowsregistry_eventHigh419Premium2026-06-25Malicious Head Mare Credential Dumping via XenAllPasswordPro
This rule detects execution of XenAllPasswordPro with the -a switch writing to report.html, the credential-recovery tool used by Head Mare to harvest stored passwords into an HTML report. Presence of this dual-use recovery utility in an interactive attack context signals active credential theft.
HuntRule TeamWindowsprocess_creationHigh115Premium2026-06-25Malicious IIS Worker Process Spawning Command Shell via process_creation
This rule detects the IIS worker process w3wp.exe spawning a command interpreter, PowerShell or certutil which is a strong indicator of web shell command execution on a compromised web server. Kaspersky observed a Behinder web shell driving w3wp.exe to launch cmd.exe and download follow-on payloads. Web shell to shell transitions are an early sign of hands-on-keyboard server intrusion.
HuntRule TeamWindowsprocess_creationHigh123Premium2026-06-25