Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,284 rules
Malicious Cobalt Strike Default Named Pipe Creation (via pipe_created)
This rule detects creation of named pipes matching Cobalt Strike default and post-exploitation patterns such as msagent_, postex_ and status_ pipes used for beacon inter-process communication and privilege escalation. Cobalt Strike is among the most prevalent adversary tools in the Red Canary Threat Detection Report, used across ransomware and espionage intrusions for command and control. Detecting its characteristic named pipes surfaces beacon activity that often evades network-based controls.
HuntRule TeamWindowspipe_createdHigh52Premium2026-07-11Possible ReverseSocks5 Tunneling Tool Execution on Linux (via process_creation)
This rule detects execution of the ReverseSocks5 tunneling utility staged as R5 under /tmp or /var during PAN-OS Captive Portal zero-day exploitation. Attackers use this SOCKS5 tunnel to proxy traffic and maintain covert access into the internal network.
HuntRule TeamLinuxprocess_creationMedium103Premium2026-07-11Malicious SharePoint spinstall0 Webshell Dropped in LAYOUTS
This rule detects the spinstall0.aspx file being written into the SharePoint LAYOUTS directory. Attackers exploiting the ToolShell chain drop this ASPX webshell to steal machine keys and maintain access. Creation of spinstall0.aspx in LAYOUTS is a definitive post-exploitation indicator.
HuntRule TeamWindowsfile_eventCritical122Premium2026-07-11Suspicious Registry Run Key Persistence Masquerading as Microsoft Updater (via process_creation)
This rule detects reg.exe adding a CurrentVersion Run value named updater that points to a Microsoft Updater directory. Maranhao Stealer establishes persistence with this masqueraded autorun entry in the user AppData path.
HuntRule TeamWindowsprocess_creationHigh61Premium2026-07-11Suspicious MoustachedBouncer Command Execution from SMB EDGEIN Directory via Cmd (via process_creation)
This rule detects cmd.exe reading operator commands from the SMB share directory EDGEIN, the command channel used by the MoustachedBouncer SharpDisco backdoor to pipe attacker input into a shell. This behavior indicates remote command-and-control tasking through a network share.
HuntRule TeamWindowsprocess_creationMedium317Premium2026-07-11Possible GCleaner Loader C2 Check-in via cpa ping php Endpoint via proxy
This rule detects GCleaner loader command and control check-ins that request the /cpa/ping.php endpoint carrying a substr parameter. GCleaner is a pay per install loader that pulls follow on payloads after beaconing to its panel. The distinctive URI and query structure identifies the loader control channel independent of the rotating C2 IP addresses.
HuntRule TeamWebproxyHigh366Premium2026-07-11Deleting Windows Defender scheduled tasks
Detects the deletion of scheduled tasks related to Windows Defender.
HuntRule TeamWindowsprocess_creationHigh63Premium2026-07-11Malicious Backup and Shadow Copy Destruction via Native Utilities
This rule detects the deletion of volume shadow copies, backup catalogs, and recovery configuration through native Windows utilities, a recovery-inhibition step performed by Hunters International affiliates before encryption. Destroying backups to prevent restoration is a hallmark of ransomware impact activity and should be treated as high priority.
HuntRule TeamWindowsprocess_creationHigh162Premium2026-07-11Suspicious Process Execution from WinRAR Temporary Extraction Directory
This rule detects executables and batch scripts launching from the WinRAR temporary extraction path Temp\Rar$. The CVE-2023-38831 zero-day tricks users into running a spoofed-extension file that WinRAR extracts and executes from this directory. Such execution indicates archive-based exploitation and user-driven initial access.
HuntRule TeamWindowsprocess_creationMedium93Premium2026-07-11Malicious SSH authorized_keys Modification Following Web Server Compromise (via process_creation)
This rule detects modification of an SSH authorized_keys file through shell commands that append or fetch key material, a persistence technique used after CVE-2025-55182 exploitation to plant attacker SSH keys on compromised servers. Adversaries add their own keys to guarantee durable remote access independent of the web application, so writes to authorized_keys from an exploited host warrant investigation.
HuntRule TeamLinuxprocess_creationMedium276Premium2026-07-11Suspicious Finger Client Execution for Command and Control
This rule detects execution of the legacy finger.exe client, which adversaries abuse to reach external hosts and exfiltrate command output over the finger protocol. Huntress observed finger used to contact an attacker IP following OWASSRF exploitation of Exchange. Because finger is effectively obsolete on modern networks, any execution warrants investigation.
HuntRule TeamWindowsprocess_creationHigh4210Premium2026-07-11Suspicious Cgroup release_agent Abuse for Container Escape
This rule detects command activity referencing the cgroup release_agent and notify_on_release mechanism used to break out of a container and execute code on the host. Writing a release_agent path that runs on cgroup teardown is a classic privileged container escape. Detecting this reference exposes an attempted breakout to the underlying node.
HuntRule TeamWindowsprocess_creationHigh355Premium2026-07-11Suspicious SAM Registry Hive Dump to Windows Temp by BianLian
This rule detects saving of the SAM registry hive into the Windows Temp directory, matching the credential access technique used by the BianLian ransomware group per Unit 42. Extracting the SAM hive lets the actor recover local account password hashes offline which supports lateral movement across the environment.
HuntRule TeamWindowsprocess_creationMedium71Premium2026-07-11Suspicious Microsoft Defender Real-Time Protection Disabled via Registry
This rule detects registry modifications that disable Microsoft Defender real-time monitoring under the Windows Defender policy keys. Microsoft observed services.exe abused to disable Defender via registry during post-exploitation of SharePoint before deploying Warlock ransomware. Turning off antivirus through policy keys clears the way for credential theft and encryption, so this change warrants immediate review.
HuntRule TeamWindowsregistry_setHigh348Premium2026-07-11Suspicious Veeam Backup Credential Harvesting via PowerShell (via ps_script)
This rule detects PowerShell activity that extracts and decrypts stored credentials from a Veeam backup server database. Abyss Locker operators ran an obfuscated variant of a public Veeam credential dumping script to recover accounts for lateral movement before deploying ransomware. Legitimate use of such scripts against production backup servers is uncommon.
HuntRule TeamWindowsps_scriptMedium3910Premium2026-07-10