Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,056 rules
Suspicious Plink SSH Tunnel Execution (via process_creation)
This rule detects the Plink command line SSH client being launched with port forwarding flags, a tunneling technique used by the Agrius group to proxy traffic and reach internal systems. Adversaries abuse Plink to create covert channels through perimeter defenses, which is rarely benign on endpoints.
HuntRule TeamWindowsprocess_creationMedium00Premium2026-09-09Malicious LSASS Credential Dump via ProcDump (via process_creation)
This rule detects ProcDump being used to create a full memory dump of the LSASS process, a credential access technique observed in the Agrius MoneyBird intrusions against Israeli organizations. Adversaries dump LSASS to harvest cached credentials and enable lateral movement, so this activity strongly indicates hands-on-keyboard compromise.
HuntRule TeamWindowsprocess_creationHigh00Premium2026-09-09Possible Remcos C2 Connection from eilowutil Process
This rule detects outbound connections from eilowutil.exe to TCP port 7060, matching the injected Remcos process and non standard C2 port in the GuLoader campaign. A process injected via GuLoader beacons out over an uncommon high port to the Remcos controller. Detecting it exposes established command and control on the host.
HuntRule TeamWindowsnetwork_connectionMedium00Premium2026-09-09Malicious dal_keepalives.dll Sideloaded By Signed Binary (via image_load)
This rule detects loading of dal_keepalives.dll, a uniquely named malicious module sideloaded through signed binaries in the Stayin Alive campaign against telecoms and government ministries in Asia. The specific DLL name is a distinctive loader artifact with no legitimate use.
HuntRule TeamWindowsimage_loadHigh00Premium2026-09-09Suspicious CoinLoader DLL Sideload From Z-1-36-81 Directory (via image_load)
This rule detects a DLL being loaded from a directory named Z-1-36-81, the fixed staging folder CoinLoader uses for DLL sideloading. This distinctive directory constant is an artifact of the loader and is not associated with any legitimate software distribution.
HuntRule TeamWindowsimage_loadMedium00Premium2026-09-09Suspicious Cortex XDR Binary Sideloading winutils.dll (via image_load)
This rule detects the Cortex XDR component cy.exe loading a winutils.dll module, the DLL sideloading chain the Rorschach ransomware abuses to decrypt and inject its payload. Leveraging a trusted security tool to sideload a malicious DLL is a stealthy loading technique unlikely to appear in benign telemetry.
HuntRule TeamWindowsimage_loadMedium30Premium2026-09-09Malicious Storm-2603 Ransom Note File Creation
This rule detects the creation of the ransom note file 'How to decrypt my data.txt' dropped by Storm-2603 ransomware payloads. Appearance of this file across user directories signals that file encryption has already executed on the host and the operator is presenting extortion instructions to the victim.
HuntRule TeamWindowsfile_eventHigh00Premium2026-09-09Possible Akira Ransomware Note or Encrypted Extension Creation
This rule detects creation of files with the akiranew extension or the akiranew.txt ransom note produced by the Akira Rust ransomware variant. Both artifacts appear only after files have been encrypted on the host. Detecting them confirms an active Akira encryption event for rapid isolation.
HuntRule TeamLinuxfile_eventHigh00Premium2026-09-09Suspicious WezRat Keylog File in Temp Directory
This rule detects creation of the fixed keylog output file 10105060.txt in the user Temp directory used by the WezRat backdoor. The malware records captured keystrokes to this static filename before exfiltration. Detecting the artifact confirms keylogging activity on the host.
HuntRule TeamWindowsfile_eventMedium20Premium2026-09-09Suspicious BugSleep Marker File in Public Directory
This rule detects creation of a file named a.txt in the C-Users-Public directory, an existence marker used by the BugSleep backdoor during its injection routine. The malware writes and checks this public path artifact to coordinate its shellcode injection into browser and remote access processes. Detecting the marker can surface the backdoor on the host.
HuntRule TeamWindowsfile_eventMedium00Premium2026-09-09Possible Ransomware Note or Encrypted File Extension Creation
This rule detects creation of ransom note files or files renamed with encrypted extensions used by the ransomware families compared in this research. The specific note names and extensions appear only after data has been encrypted on the victim host. Detecting them confirms an active encryption event so responders can isolate the machine.
HuntRule TeamWindowsfile_eventHigh50Premium2026-09-08Suspicious Executable Written to User Documents Subfolder (via file_event)
This rule detects an executable being dropped into a subfolder of a user Documents directory, matching BundleBot behaviour of hiding its payload under a randomly named Documents folder. Executables rarely originate here through normal use, so writes of this kind warrant inspection for stealer staging.
HuntRule TeamWindowsfile_eventLow30Premium2026-09-08Possible React2Shell CVE-2025-55182 Prototype Pollution Exploitation
This rule detects web requests carrying prototype pollution markers that reach Node.js command execution primitives. This is the exploitation pattern for CVE-2025-55182 also known as React2Shell against public facing Node.js and React applications.
HuntRule TeamWebwebserverHigh10Premium2026-09-08Xeno Stealer Persistence via Display Calibration Run Key
This rule detects creation of a Run key value named Display Calibration used by the Xeno stealer for autostart persistence. The value points to a JAR staged under the GameDVR directory and masquerades as a benign display setting.
HuntRule TeamWindowsregistry_setHigh50Premium2026-09-08Hidden PowerShell Archive Extraction via ExtractToDirectory
This rule detects a hidden PowerShell process using the System IO Compression ZipFile ExtractToDirectory method together with an execution policy bypass. The Xeno loader uses this routine to unpack its bundled Java runtime and stealer payload.
HuntRule TeamWindowsprocess_creationMedium00Premium2026-09-08