Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,375 rules
Suspicious LucidRook DLL Side-Loading via Renamed msedge.exe
This rule detects msedge.exe executing from a WindowsApps directory under the user profile, matching the LucidRook loader that renames the DISM index.exe binary to msedge.exe to side-load a malicious DismCore.dll. Legitimate Microsoft Edge runs from Program Files, so an msedge.exe launched from AppData WindowsApps is an impostor used for search-order hijacking. This behavior indicates initial execution of the Lua-based LucidRook malware.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-05-17Office Persistence via WLL Add-in Dropped to Word STARTUP Folder
This rule detects a .wll Word add-in written to the Microsoft Word STARTUP folder, the persistence mechanism used by the PortDoor backdoor against the Russian defense sector. Word automatically loads WLL add-ins from this folder at launch, giving attackers stealthy code execution on every Word start.
HuntRule TeamWindowsfile_eventHigh71Premium2026-05-17SPN Added to an Account by Command Line (via process_creation)
This rule detects adds a SPN to an account in order to perform different type of abuse (Kerberoast, delegation abuse, ...).
HuntRule TeamWindowsprocess_creationHigh113Premium2026-05-17Suspicious Self-Extracting Archive via tail Piped to funzip
This rule detects a shell piping the tail of a file into funzip, the self-extraction technique used by macOS Shlayer to unpack a password-protected archive appended to a dropper. This lets the adware carry and decompress its payload inline while hiding it from simple file inspection.
HuntRule TeamMacosprocess_creationHigh61Premium2026-05-17Malicious PlugX DLL Sideloading via Canon cnmpaui Utility (via image_load)
This rule detects the legitimate Canon cnmpaui.exe utility loading a cnmpaui.dll from a user AppData Roaming directory. UNC6384 abused DLL search-order sideloading with this signed Canon binary to load a malicious loader that decrypted and ran PlugX.
HuntRule TeamWindowsimage_loadHigh183Premium2026-05-17Malicious Massive Services Termination Burst (via process_creation)
This rule detects stop multiples services on a host. Attacker may target services related to databases, security products or backups (Veeam, Symantec, Acronis ...).
HuntRule TeamWindowsprocess_creationHigh121Premium2026-05-17Malicious Keylogger DLL Execution via Rundll32 klg.dll
This rule detects rundll32.exe loading a DLL named klg.dll which Interlock ransomware operators deploy as a keylogger to capture credentials and keystrokes. The specific module name executed through rundll32 is a reliable behavioral indicator of the keylogging component.
HuntRule TeamWindowsprocess_creationHigh113Premium2026-05-17Malicious DLL Side-Loading of vcl120.bpl From AppData via HijackLoader (via image_load)
This rule detects a vcl120.bpl Delphi runtime package being loaded from a user AppData Roaming directory, the side-loading step used by the IObit-abusing HijackLoader to stage AsyncRAT. The legitimate vcl120.bpl resides with its application, not under AppData.
HuntRule TeamWindowsimage_loadHigh131Premium2026-05-17Mirai and Rondo Payload Retrieval via Known Loader Paths
This rule detects outbound web requests to loader paths used to distribute Mirai binaries and the Rondo cryptominer. These retrievals follow CVE-2025-55182 exploitation of IoT and smart home devices.
HuntRule TeamWebproxyHigh239Premium2026-05-17Malicious Remote Payload Piped to Shell via Curl or Wget
This rule detects download utilities piping fetched content directly into a shell interpreter, the loader pattern the agentic container-escape actor used to stage its second-stage payload from an attacker server. Piping remote content into sh or bash executes untrusted code without touching disk. This is a common ingress tool transfer and execution technique.
HuntRule TeamLinuxprocess_creationHigh341Premium2026-05-16Malicious ServiceDll Hijack with QSC Loader DLL
This rule detects a service Parameters ServiceDll value being set to the QSC loader DLLs swprr.dll or rasautosvc.dll. The CloudComputating group hijacked a Windows service to load these DLLs from System32 and execute the QSC multi-plugin framework with service persistence.
HuntRule TeamWindowsregistry_setHigh441Premium2026-05-16Suspicious RevengeHotels JS Loader Spawning PowerShell (via process_creation)
This rule detects wscript executing a Fat named JavaScript file that then launches PowerShell as used in the RevengeHotels campaign to stage VenomRAT. The threat actor delivers phishing JS droppers whose PowerShell child fetches the remote access trojan. A script host running a Fat JS file with a PowerShell descendant is a strong sign of this loader chain.
HuntRule TeamWindowsprocess_creationHigh192Premium2026-05-16Suspicious Guest Account Enablement via net user for Privilege Abuse
This rule detects the built in guest account being activated through net user which the Gh0stGambit dropper abused for elevation. Enabling and repurposing the guest account provides a low visibility foothold for continued access. Activation of this normally disabled account is a strong sign of account manipulation.
HuntRule TeamWindowsprocess_creationHigh163Premium2026-05-16Suspicious Ukraine-Themed LNK Lure Files Dropped (via file_event)
This rule detects creation of shortcut lure files with region and messaging themed names used by the STEADY#URSA campaign for removable-media replication and social engineering against Ukrainian military targets.
HuntRule TeamWindowsfile_eventHigh102Premium2026-05-16Suspicious FileFix TypedPaths Entry Containing PowerShell or URL
This rule detects an Explorer TypedPaths registry value that records a PowerShell command or HTTP URL, the forensic artifact left when a FileFix lure has the victim paste an obfuscated command into the File Explorer address bar. TypedPaths normally stores browsed folder locations, not scripts or web addresses. A command string or URL in this value indicates the FileFix address-bar execution technique.
HuntRule TeamWindowsregistry_setHigh323Premium2026-05-16