Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,389 rules
Suspicious HiddenGh0st Rootkit Driver QAssist Written to System32 (via file_event)
This rule detects the creation of the QAssist.sys rootkit driver in the System32 directory as used by the HiddenGh0st malware to hide its files and activity. A newly written kernel driver with this name is a strong indicator of the rootkit component.
—Windowsfile_eventMedium234Premium2026-06-24Malicious Winlogon Shell Persistence Modification (via registry_set)
This rule detects modification of the Winlogon Shell registry value to something other than the default explorer.exe, a persistence technique used by MuddyWater per Group-IB. Adversaries alter the Winlogon Shell entry so their payload launches at every interactive logon, making changes to this value a strong persistence signal.
HuntRule TeamWindowsregistry_setHigh133Premium2026-06-24Suspicious Internet Explorer Helper Process Network Connection via network_connection
This rule detects outbound network connections originating from rarely-networked Internet Explorer helper binaries such as ieinstal.exe and ielowutil.exe. The REMCOS RAT injects into these signed processes to blend command-and-control traffic with trusted executables. Network activity from these utilities is anomalous and suggests process injection for evasion.
HuntRule TeamWindowsnetwork_connectionMedium101Premium2026-06-24SumatraPDF Execution from User Download Directory in Operation DreamJob (via process_creation)
This rule detects SumatraPDF.exe executing from a Downloads or Temp directory, matching the Operation DreamJob delivery in which a ZIP archive bundles a decoy PDF with a portable SumatraPDF.exe and a malicious libmupdf.dll for side-loading. Adversaries ship a portable signed reader alongside their loader so a single user action triggers execution from an untrusted location.
HuntRule TeamWindowsprocess_creationMedium325Premium2026-06-24Suspicious Process Execution from CHM Help File (via process_creation)
This rule detects the compiled HTML help viewer hh.exe spawning a command shell or PowerShell. The PHANTOM#SPIKE campaign delivered a malicious CHM file whose embedded script launched a hidden backdoor executable.
HuntRule TeamWindowsprocess_creationHigh242Premium2026-06-24Suspicious Single-Character Named Batch Script Execution Linked to Salt Typhoon
This rule detects the command interpreter executing a batch file whose name is a single character, an obfuscation and staging pattern observed in Salt Typhoon intrusions. One-letter script names are an anomalous convention rarely used by legitimate software, so single-character batch execution is a heuristic indicator of scripted attacker tooling.
HuntRule TeamWindowsprocess_creationMedium131Premium2026-06-24Malicious Chisel Reverse SOCKS Proxy Execution (via process_creation)
This rule detects command-line arguments consistent with a Chisel reverse SOCKS proxy client, tooling deployed by Turla during TinyTurla-NG operations. The reverse tunnel exposes internal hosts to attacker infrastructure and enables pivoting through the compromised network.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-06-24VSS Backup Deletion via WMI - Powershell (via powershell)
This rule detects delete existing VSS backup via WMI.
HuntRule TeamWindowspowershellHigh134Premium2026-06-24Suspicious Scheduled Task Creation Running as SYSTEM via Schtasks
This rule detects creation of a scheduled task configured to run under the SYSTEM account which the BLOODALCHEMY backdoor uses to establish elevated persistence. Creating SYSTEM level tasks via schtasks is a common attacker technique to survive reboots and run with maximum privileges though some administrative tooling may also do this.
HuntRule TeamWindowsprocess_creationMedium161Premium2026-06-24Suspicious NTDS Database Dump File Creation
This rule detects creation of files with an NTDS dump naming pattern which ransomware operators produce when extracting the Active Directory database for offline credential theft. Observed in NCC Group research into active ransomware families dumping NTDS content to text files. Capturing NTDS extraction artifacts helps detect domain-wide credential theft.
HuntRule TeamWindowsfile_eventMedium439Premium2026-06-24Malicious Triada binder.so Planted in Android System Framework
This rule detects creation of a binder.so library inside the Android system framework arm directory which the Triada trojan replaces to hook Zygote and inject into every app process. This system-level modification gives the malware persistent control over the device including clipboard wallet clipping and premium SMS abuse. A write to the framework native library path is highly abnormal on a clean device.
HuntRule TeamAndroidfile_eventHigh245Premium2026-06-23Suspicious File Download via certutil urlcache
This rule detects certutil used with the urlcache and split flags to download a remote file, an ingress tool transfer technique observed in the REF7707 espionage campaign. Adversaries abuse the signed certutil utility to retrieve payloads while blending in with trusted Windows binaries. This flag combination has no routine administrative use and reliably indicates tooling download.
HuntRule TeamWindowsprocess_creationHigh337Premium2026-06-23Suspicious Python Interpreter Execution Spawned by Script Host (via process_creation)
This rule detects python.exe launched by a Windows script host or command shell, matching the multi-stage URL to LNK to VBS to Python chain used in the Cloudflare tunnel RAT campaigns. Bundled Python installers were staged from WebDAV shares before running the interpreter.
HuntRule TeamWindowsprocess_creationMedium142Premium2026-06-23In-Memory Enabling of WDigest Cleartext Credential Caching (via registry_set)
This rule detects the UseLogonCredential value being set under the WDigest security provider, which forces Windows to cache cleartext passwords in memory so they can be harvested from LSASS. Re-enabling WDigest credential caching is a credential-access preparation technique tracked in the Red Canary Threat Detection Report. Detecting this registry change surfaces an attacker priming the host for plaintext credential theft.
HuntRule TeamWindowsregistry_setHigh325Premium2026-06-23Suspicious Minute-Interval Scheduled Task For MSCheck Backdoor (via process_creation)
This rule detects creation of a minute-recurring scheduled task launching an MSCheck executable, the persistence mechanism used by the Stealth Soldier backdoor. A frequent scheduled task pointing at a masqueraded system-update binary is characteristic of implant persistence rather than legitimate maintenance.
HuntRule TeamWindowsprocess_creationMedium101Premium2026-06-23