Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,285 rules
Suspicious Mint Sandstorm MediaPl DLL Loaded from Media Player AppData Path (via image_load)
This rule detects loading of MediaPl.dll from the user AppData Local Microsoft Media Player directory. Mint Sandstorm dropped this malicious DLL into a Media Player folder to masquerade as legitimate media components while executing implant code.
HuntRule TeamWindowsimage_loadHigh51Premium2026-07-10LegionLoader DLL Sideloading via VMware mksSandbox Loading Fake libcrypto (via image_load)
This rule detects the legitimate VMware-signed mksSandbox.exe loading a libcrypto-1_1-x64.dll from outside the trusted VMware installation path, the DLL side-loading behavior used to stage LegionLoader after a fake CAPTCHA and Cloudflare Turnstile lure. Adversaries abuse a signed binary to execute a malicious OpenSSL impersonating DLL under a trusted process, making early detection critical for surfacing loader activity before browser credential and wallet theft.
HuntRule TeamWindowsimage_loadHigh73Premium2026-07-10Malicious Windows Defender Exclusion Added for PowerShell and conhost
This rule detects Add-MpPreference being used to register Windows Defender process exclusions for powershell or conhost. The ClipBanker campaign distributed through a trojanized Proxifier excluded its own living-off-the-land binaries from Defender scanning to run undetected as reported by Kaspersky. Adding process exclusions for these interpreters is a strong defense-evasion signal that precedes payload execution.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-07-10Malicious Service Creation - Command (via process_creation)
This rule detects create a service for persistence.
HuntRule TeamWindowsprocess_creationHigh63Premium2026-07-10Suspicious Outbound Network Connection from Windows Dialer Process
This rule detects the legitimate Windows dialer.exe process in System32 initiating outbound network connections which is anomalous because the tool is rarely executed and does not normally beacon. In the copyright infringement infostealer campaign the loader injected shellcode into system32 dialer.exe to proxy command and control traffic making dialer network activity a strong compromise signal.
HuntRule TeamWindowsnetwork_connectionHigh151Premium2026-07-10Malicious XMRig Cryptominer Connecting to SupportXMR Pool (JINX-0132)
This rule detects a process command line referencing the supportxmr.com mining pool used by the JINX-0132 cryptojacking campaign. It matters because a mining pool address on a server is a direct indicator of resource hijacking following exposed DevOps API exploitation.
HuntRule TeamLinuxprocess_creationHigh474Premium2026-07-10NjRAT Fileless Keylogger Storage via Registry Value (via registry_set)
This rule detects registry values containing NjRAT keystroke markers such as bracketed ENTER, TAP, or Back tokens, the fileless storage NjRAT uses to buffer captured keystrokes in the registry. Adversaries leverage registry-resident keylog data to avoid touching disk while collecting credentials, making these distinctive value contents a strong host artifact for detection.
HuntRule TeamWindowsregistry_setHigh82Premium2026-07-10In-Memory Reverse Shell and In-Memory Payload Staging During Ivanti CSA Exploitation (via process_creation)
This rule detects reverse shell establishment through netcat with the command-execution flag spawning a shell, or payload staging into the memory-backed /dev/shm directory, both observed during Houken exploitation of Ivanti Cloud Service Appliance devices. Adversaries leverage these techniques to obtain interactive access and stage tooling without touching disk, making early detection critical for catching hands-on-keyboard activity on the appliance.
HuntRule TeamLinuxprocess_creationHigh229Premium2026-07-10AWS Bedrock Guardrail Updated via UpdateGuardrail API
Alerts on CloudTrail-reported Amazon Bedrock guardrail updates, which may signal attempts to weaken safety controls.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamAwscloudtrailMedium241Free2026-07-10AWS Bedrock Guardrail Deletion via CloudTrail DeleteGuardrail API
Alerts on CloudTrail DeleteGuardrail events indicating an AWS Bedrock guardrail was removed.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamAwscloudtrailMedium203Free2026-07-10PowerShell Spawned by Headless Conhost (via process_creation)
This rule detects powershell.exe launched as a child of conhost.exe running with the --headless argument, a hidden-console execution pattern used in the PureRAT infection chain to run a covert download command. Adversaries leverage headless conhost to hide interactive console activity from the user, making this uncommon parent-child pairing a useful signal of scripted payload staging.
HuntRule TeamWindowsprocess_creationMedium121Premium2026-07-09Malicious GHOSTPULSE DLL Side-Loading of libcurl via VBoxSVC
This rule detects the VirtualBox VBoxSVC executable loading a libcurl DLL from outside its normal installation directory which is the side-loading path GHOSTPULSE abuses to execute its stager. The rule excludes loads from genuine VirtualBox directories to focus on the malicious wrong context placement.
HuntRule TeamWindowsimage_loadHigh258Premium2026-07-09Suspicious ctfmon.exe Execution With Command-Line Arguments via PikaBot Injection
This rule detects ctfmon.exe launched with command-line parameters, which is anomalous because the legitimate Text Services process normally runs without arguments. PikaBot spawns a suspended ctfmon.exe with a numeric switch such as -p 1234 to host injected shellcode through thread hijacking. Catching this deviation exposes early stage process injection used to evade endpoint controls.
HuntRule TeamWindowsprocess_creationHigh117Premium2026-07-09Suspicious SQL Server Payload Staging via bcp queryout (via process_creation)
This rule detects the SQL Server bulk copy program launched from the sqlservr process to export binary data from a database table to a file using the queryout parameter. The STAC6451 cluster abused exposed SQL Server instances and xp_cmdshell to stage Mimic ransomware and supporting tools on disk through bcp queryout.
HuntRule TeamWindowsprocess_creationMedium105Premium2026-07-09Suspicious Entra Agent Service Principal Sign-In With PowerShell User Agent via Sign-In Logs
This rule detects a service principal sign-in using a PowerShell user agent against Entra Agent ID identities, a pattern of automated credential misuse where an attacker authenticates as an AI agent through scripted Graph calls. Because assigned agents normally authenticate through their own runtime rather than interactive PowerShell tooling, this user agent on service principal sign-ins indicates hands-on-keyboard abuse of agent credentials.
HuntRule TeamAzuresigninlogsMedium371Premium2026-07-09