Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Malicious SharePoint ToolShell Exploitation via ToolPane Endpoint
This rule detects a POST request to the SharePoint ToolPane endpoint in edit mode with a referer set to the SignOut page, the exact exploitation pattern of the ToolShell on-premises SharePoint vulnerabilities. This unauthenticated request chain is used to forge ViewState and achieve remote code execution and should be treated as active exploitation.
HuntRule TeamWebwebserverCritical20Premium2026-09-14Malicious Remote Encryptor Execution via WMIC Process Call Create (Chaos Ransomware)
This rule detects the Chaos ransomware group using WMIC to remotely spawn its encryptor binary with campaign-specific arguments such as lkey, encrypt_step and work_mode. Remote process creation over WMI is used to deploy the encryptor across the network. This behavior indicates active ransomware deployment combined with lateral movement.
HuntRule TeamWindowsprocess_creationCritical50Premium2026-09-11Potential StyleSmuggler (CVE-2026-75650) Exploitation Attempt - Magento GraphQL Styles Parameter (via webserver)
Detects POST requests to the Magento GraphQL endpoint carrying a styles[...] query parameter, the pattern reported for exploitation of StyleSmuggler (CVE-2026-75650), an unauthenticated remote code execution vulnerability in Magento Open Source and Adobe Commerce 2.4.4 through 2.4.9. A match indicates an exploitation attempt, not confirmed compromise; correlate with implant process and file indicators on the host.
HuntRule TeamWindowswebserverCritical820Free2026-09-10Suspicious wmicodegen.dll Sideload by inetinfo.exe (UAT-8099 Cobalt Strike)
This rule detects the IIS process inetinfo.exe loading wmicodegen.dll, a DLL sideloading technique UAT-8099 uses to run Cobalt Strike on compromised web servers. The inetinfo.exe process has no legitimate reason to load this library. This load indicates in-memory beacon deployment via search-order hijacking.
HuntRule TeamWindowsimage_loadCritical20Premium2026-09-10Malicious Dynamicweb Unauthenticated Administrator Creation via Setup Default.aspx (via webserver)
This rule detects requests to the Dynamicweb Access Setup Default.aspx page invoking the createadministrator action with adminusername and adminpassword parameters. This logic flaw in Dynamicweb 9.5.0 through 9.12.7 lets an unauthenticated attacker create an administrator account and then upload an ASPX webshell for RCE. Detecting it surfaces account creation abuse leading to full server compromise.
HuntRule TeamWebwebserverCritical40Premium2026-09-07Malicious DCSync Domain Replication Credential Theft (via process_creation)
This rule detects command lines invoking DCSync-style directory replication (lsadump::dcsync or a /dcsync switch), which abuses replication rights to pull password hashes for any account directly from a domain controller. DCSync is a high-impact credential-access technique in the Red Canary Threat Detection Report and a route to domain dominance. Detecting the replication request surfaces theft of privileged credentials without touching LSASS.
HuntRule TeamWindowsprocess_creationCritical10Premium2026-09-03Malicious DLL ServerLevelPluginDll Command Installation (via process_creation)
This rule detects scenarios where a DLL is loaded by the DNS server in order to escalate privileges or initiate a remote shell.
HuntRule TeamWindowsprocess_creationCritical10Premium2026-09-03Malicious DLL ServerLevelPluginDll Registration - Reg via Sysmon (via registry_set)
This rule detects scenarios where a DLL is loaded by the DNS server in order to escalate privileges or initiate a remote shell.
HuntRule TeamWindowsregistry_setCritical40Premium2026-09-02Malicious DarkGate hVNC Credential Stash via cmdkey
This rule detects DarkGate storing hardcoded hidden-VNC credentials with cmdkey using the SafeMode user and the darkgatepassword0 secret. This exact credential string is unique to DarkGate hVNC sessions and reliably identifies the loader establishing covert remote access.
HuntRule TeamWindowsprocess_creationCritical121Premium2026-08-05Malicious Ransomware Extension Class Registration for ELPACO-team by Elpaco Ransomware
This rule detects registration of the .ELPACO-team file extension class under HKLM Classes. Elpaco ransomware, a Mimic variant, registers its own encrypted-file extension to associate the ransom note handler after encryption. Presence of this class key indicates ransomware has executed and modified file associations on the host.
HuntRule TeamWindowsregistry_setCritical81Premium2026-08-01Malicious SUNBURST Command and Control DNS Query to avsvmcloud Domain (via dns_query)
This rule detects DNS lookups containing the avsvmcloud domain used as the SUNBURST first-stage command and control and victim beaconing channel. The backdoor encodes environment data into subdomains of avsvmcloud during its DGA-style callbacks. Detecting any avsvmcloud query is a high fidelity indicator of a SUNBURST compromised host.
HuntRule TeamWindowsdns_queryCritical336Premium2026-07-23Malicious Mimikatz Credential Dumping Command Line
This rule detects Mimikatz style command modules on the process command line such as privilege debug and sekurlsa logonPasswords. In the WithSecure Catching Lazarus Part Two research the actor runs these modules to dump credentials from lsass memory. Attackers use Mimikatz to harvest passwords and hashes for lateral movement.
HuntRule TeamWindowsprocess_creationCritical112Premium2026-07-23WordPress wp2shell Plugin Webshell Access via wp-content/plugins URL Path
Alert on HTTP requests targeting the wp2shell WordPress plugin path used for webshell execution/persistence.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverCritical323Free2026-07-19Malicious SharePoint spinstall0 Webshell Dropped in LAYOUTS
This rule detects the spinstall0.aspx file being written into the SharePoint LAYOUTS directory. Attackers exploiting the ToolShell chain drop this ASPX webshell to steal machine keys and maintain access. Creation of spinstall0.aspx in LAYOUTS is a definitive post-exploitation indicator.
HuntRule TeamWindowsfile_eventCritical132Premium2026-07-11Antivirus Remote Access Tool Signature Matches Known RAT Names
Alerts on antivirus detections referencing multiple known RAT family signature names in the event signature field.
Arnim Rupp (Nextron Systems), Huntrule Team—antivirusCritical162Free2026-06-15