Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,389 rules
Suspicious Vulnerable Driver Load for BYOVD Abuse by DragonForce Ransomware (via driver_load)
This rule detects loading of the TrueSight.sys or RentDrv.sys vulnerable drivers that DragonForce abuses in a bring-your-own-vulnerable-driver technique to call ZwTerminateProcess and disable endpoint protection. Attackers exploit these signed drivers to kill security agents from kernel space. Flagging their load exposes tampering with defensive tooling.
HuntRule TeamWindowsdriver_loadMedium3710Premium2026-06-25Malicious System Crash Behavior Manipulation - WMImplant - Registry (via registry_event)
This rule detects abuses the Windows "system failure and recovery" capacities (CrashControl) to store information or to establish persistence.
HuntRule TeamWindowsregistry_eventHigh419Premium2026-06-25Malicious Head Mare Credential Dumping via XenAllPasswordPro
This rule detects execution of XenAllPasswordPro with the -a switch writing to report.html, the credential-recovery tool used by Head Mare to harvest stored passwords into an HTML report. Presence of this dual-use recovery utility in an interactive attack context signals active credential theft.
HuntRule TeamWindowsprocess_creationHigh115Premium2026-06-25Malicious IIS Worker Process Spawning Command Shell via process_creation
This rule detects the IIS worker process w3wp.exe spawning a command interpreter, PowerShell or certutil which is a strong indicator of web shell command execution on a compromised web server. Kaspersky observed a Behinder web shell driving w3wp.exe to launch cmd.exe and download follow-on payloads. Web shell to shell transitions are an early sign of hands-on-keyboard server intrusion.
HuntRule TeamWindowsprocess_creationHigh123Premium2026-06-25Uncommon Kimsuky OneNote Document Spawning Script Interpreter (via process_creation)
This rule detects Microsoft OneNote launching a scripting or shell interpreter such as wscript, cscript, mshta, cmd or powershell, the execution behavior seen when Kimsuky embeds rows of VBS files inside a .ONE document disguised with a Hangul document icon. OneNote spawning an interpreter is abnormal for legitimate note-taking and is a reliable indicator of embedded-object abuse for initial execution.
HuntRule TeamWindowsprocess_creationHigh345Premium2026-06-25Possible CVE-2023-23397 Outlook Forced Authentication via Outbound LDAP (via network_connection)
This rule detects a Windows host initiating an outbound LDAP or Global Catalog connection to a non-private external address, which is anomalous because directory traffic normally stays inside the enterprise. Exploitation of CVE-2023-23397 can direct a client to an external LDAP endpoint as part of the forced authentication chain against Microsoft Outlook. Traffic to an external directory service indicates possible credential coercion or beaconing and warrants investigation.
HuntRule TeamWindowsnetwork_connectionMedium141Premium2026-06-25Suspicious Double Extension PDF Executable via Process Creation
This rule detects execution of a file using a .pdf.exe double extension. The Lumma stealer is distributed with this masquerading trick so the payload appears to be a document while it is in fact an executable, tricking users into launching the stealer.
HuntRule TeamWindowsprocess_creationMedium377Premium2026-06-25Suspicious SugarGh0st Persistence via CTFMON Masqueraded Run Key (via registry_set)
This rule detects a Run key persistence entry referencing CTFM0N.exe, a binary named to impersonate the legitimate ctfmon.exe with a zero substituted for the letter O. The SugarGh0st RAT used this masqueraded autorun value to survive reboot.
HuntRule TeamWindowsregistry_setHigh102Premium2026-06-25Suspicious Remote Execution via WMIC Node Process Call Create
This rule detects wmic.exe with the node parameter invoking process call create which the ColunmTK APT41 cluster uses to run install.bat on remote hosts for lateral movement. The technique executes commands against a specified target without dropping a service binary. It is important because remote WMIC execution is a stealthy hands-on-keyboard propagation method.
HuntRule TeamWindowsprocess_creationMedium73Premium2026-06-25Suspicious GigaWiper Execution Counter under OneDrive Environment Key
This rule detects writes to the HKCU SOFTWARE OneDrive Environment key which GigaWiper abuses as an execution counter to track its wiping stages. This uncommon registry location under a OneDrive branded path is a distinctive marker of the destructive backdoor tracking its own progress.
HuntRule TeamWindowsregistry_setMedium84Premium2026-06-25Malicious Volume Shadow Copy Deletion via vssadmin by RA World
This rule detects deletion of all volume shadow copies through vssadmin, an inhibit-recovery action the RA World ransomware group performs to prevent victims from restoring encrypted files. Destroying shadow copies is a hallmark of ransomware staging. Detecting this exposes imminent or in-progress encryption impact on the host.
HuntRule TeamWindowsprocess_creationHigh252Premium2026-06-24Suspicious Restic Cloud Backup Exfiltration via Renamed winupdate Binary via process_creation
This rule detects the restic backup tool being run, including copies renamed to winupdate.exe, with arguments targeting a Wasabi or S3 object store. The threat actor renamed restic to a Windows-update-like name and used it to back up and exfiltrate victim data to attacker-controlled cloud storage, so this pattern indicates staged bulk exfiltration disguised as backup activity.
HuntRule TeamWindowsprocess_creationHigh182Premium2026-06-24Malicious UAC Bypass via ms-settings Shell Open Command Registry Hijack (via registry_set)
This rule detects modification of the ms-settings protocol handler shell open command under the current user classes hive, the registry hijack that a Kimsuky campaign chained to trigger a batch file with elevated rights through fodhelper style auto-elevation. Adversaries leverage this key because trusted binaries query it while running high integrity, making early detection critical for catching privilege escalation before elevated payload execution.
HuntRule TeamWindowsregistry_setHigh121Premium2026-06-24Suspicious Octo Tempest Domain and Network Reconnaissance Tooling (via process_creation)
This rule detects execution of reconnaissance utilities such as PingCastle ADRecon and Advanced IP Scanner. Octo Tempest ran these tools to map Active Directory and the internal network for lateral movement and targeting.
HuntRule TeamWindowsprocess_creationMedium112Premium2026-06-24Suspicious Renamed git Binary gcmd.exe Execution (via process_creation)
This rule detects execution of gcmd.exe, a renamed copy of the legitimate git binary used by APT-C-60 to proxy execution of its loader from a masqueraded LICENSES.LOG directory. Renaming a signed tool defeats name-based allowlists while preserving the trusted binary behavior the actor relies on.
HuntRule TeamWindowsprocess_creationHigh143Premium2026-06-24