Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,285 rules
Suspicious Veeam Backup Credential Harvesting via PowerShell (via ps_script)
This rule detects PowerShell activity that extracts and decrypts stored credentials from a Veeam backup server database. Abyss Locker operators ran an obfuscated variant of a public Veeam credential dumping script to recover accounts for lateral movement before deploying ransomware. Legitimate use of such scripts against production backup servers is uncommon.
HuntRule TeamWindowsps_scriptMedium3910Premium2026-07-10Malicious Cryptomining via AddInProcess Launching NEXA Miner (via process_creation)
This rule detects the .NET AddInProcess.exe binary executing with NEXA mining algorithm and pool arguments, the resource-hijacking payload dropped in this campaign to mine cryptocurrency on the victim host. Adversaries leverage AddInProcess as a signed proxy to run a bundled miner, making detection of the algorithm and pool flags a clear indicator of unauthorized mining.
HuntRule TeamWindowsprocess_creationHigh131Premium2026-07-10Malicious Scheduled Task Creation Named ComboxResetTask
This rule detects the creation of a scheduled task named ComboxResetTask. HoneyMyte used this task name to persist its CoolClient tooling in recent campaigns as reported by Kaspersky. This specific task name combined with schtasks creation indicates malicious persistence.
HuntRule TeamWindowsprocess_creationHigh113Premium2026-07-10Suspicious Atera Agent Installation via msiexec from PerfLogs Directory
This rule detects msiexec installing an MSI package staged in the C:\PerfLogs directory, observed in a Huntress-tracked intrusion where attackers deployed the Atera RMM agent from PerfLogs for persistence. PerfLogs is a non-standard software staging location and legitimate installers rarely run from it. Installation of remote management software from this path indicates attacker-driven persistence tooling.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-07-10Malicious Registry Run Key Persistence to ProgramData Batch File (via registry_set)
This rule detects a Registry Run key persistence entry whose value points to a batch file located under ProgramData, matching the MicrosoftUpdate run key that referenced a system.bat file in the compromised Axios NPM supply chain attack. Adversaries plant such entries under a benign-sounding name to survive reboot and relaunch their loader, so this pattern is a strong persistence indicator.
HuntRule TeamWindowsregistry_setHigh436Premium2026-07-10Suspicious Script Host Executing VBScript from System32 via Command Line
This rule detects wscript or cscript executing a VBScript located in the System32 directory, an anomaly Parallax RAT creates by staging a network reconnaissance script there and running it via a scheduled task. Legitimate user scripts rarely live in System32. Detecting the execution exposes discovery activity hiding in a system path.
HuntRule TeamWindowsprocess_creationMedium123Premium2026-07-10Suspicious Registry Run Key Persistence for PlugX GDatas Payload (via registry_set)
This rule detects a Run key value that points to an executable inside the Users Public GDatas directory, the persistence mechanism used to relaunch the PlugX loader at logon. Legitimate autostart entries do not execute binaries from this public path.
HuntRule TeamWindowsregistry_setHigh132Premium2026-07-10Suspicious AWS SAML Identity Provider Creation
This rule detects creation of a SAML identity provider through the IAM CreateSAMLProvider call. Adversaries register a rogue federation provider to establish durable authenticated access to the account, a persistence and account manipulation technique highlighted by Sekoia AWS detection guidance.
HuntRule TeamAwscloudtrailMedium93Premium2026-07-10Suspicious Data Exfiltration via Finger LOLBIN
This rule detects execution of finger.exe, a rarely used legacy binary abused as a living-off-the-land channel for data exfiltration and remote content retrieval. It was catalogued among data-exfiltration LOLBIN binaries. Any finger.exe execution in modern environments is anomalous and warrants review.
HuntRule TeamWindowsprocess_creationMedium71Premium2026-07-10Suspicious LD_PRELOAD Library Injection via PUMAKIT Userland Rootkit
This rule detects a process launched with the LD_PRELOAD environment variable pointing at a shared object under a system library path which the PUMAKIT userland rootkit uses to hook standard library calls and hide its presence. Adversaries preload a malicious shared object to intercept functions for stealth and persistence.
HuntRule TeamLinuxprocess_creationMedium419Premium2026-07-10Malicious SQL Server Dedicated Admin Connection (DAC) Mode Activated - Native (via application)
This rule detects enabled the DAC mode in order to bypass access controls, logon triggers, perform brute force attacks or run unauthorized queries.
HuntRule TeamMssqlapplicationHigh131Premium2026-07-10Suspicious Hidden Scheduled Task via TaskCache Security Descriptor Manipulation
This rule detects modification of the SD security-descriptor value under the scheduled-task TaskCache Tree registry hive, the technique used by the Tarrask malware attributed to Hafnium to hide a task so it does not appear in schtasks query output. Removing or altering the SD value conceals the persistence mechanism from defenders. This registry activity has no legitimate purpose and indicates deliberate task hiding.
HuntRule TeamWindowsregistry_setMedium3510Premium2026-07-10Suspicious BlueNoroff Hidden Payload Drop in Users Shared (via file_event)
This rule detects creation of the hidden files .pw or .pld under /Users/Shared/ on macOS. The BlueNoroff EdoneViewer dropper writes these hidden staging files to the world-readable Shared folder before executing its next stage, so their appearance indicates the backdoor unpacking its payload.
HuntRule TeamMacosfile_eventHigh373Premium2026-07-10Suspicious Recurring Scheduled Task Named WindowsHelper via schtasks
This rule detects creation of a frequently recurring scheduled task named WindowsHelper, used by Armored Likho to run its BusySnake loader chain every few minutes. The masquerading task name and short interval reflect the actor persistence configuration. A benign sounding high-frequency task from an untrusted source indicates persistence.
HuntRule TeamWindowsprocess_creationMedium71Premium2026-07-10Suspicious GhostLocker Watchdog Process Execution (via process_creation)
This rule detects execution of wuachost.exe, a watchdog process spawned by GhostLocker ransomware whose name masquerades as the legitimate Windows Update client wuauclt. The watchdog restarts the ransomware if terminated, making it a strong indicator of an active GhostSec infection.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-07-10