Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,294 rules
Suspicious Self-Copied CMD Script in ProgramData (via file_event)
This rule detects creation of a command script named rEgX.cmd within the ProgramData directory. The Dead#Vax campaign copied itself to this file as part of its persistence and self-healing routine.
HuntRule TeamWindowsfile_eventHigh342Premium2026-07-07Malicious Webserver IIS Module Installed - Command (via process_creation) - Variant 2
This rule detects deploy an IIS module via the gacutil tool.
HuntRule TeamWindowsprocess_creationHigh61Premium2026-07-07Possible Targeted Kerberoasting via servicePrincipalName Modification
This rule detects addition of a servicePrincipalName value to a user account object. Adversaries with write access set an SPN on a target account to make it kerberoastable, then request a service ticket to crack the account password offline.
HuntRule TeamWindowssecurityMedium158Premium2026-07-07Suspicious Security Service Disable via SC Utility (via process_creation)
This rule detects the sc.exe service control utility being used to disable, stop or delete antivirus, EDR or event logging services. Ransomware intrusions abuse sc.exe to impair defenses so encryption and cleanup proceed unnoticed. Reconfiguring or removing protective services from the command line is a strong defense-evasion signal.
HuntRule TeamWindowsprocess_creationMedium311Premium2026-07-07Suspicious UPDTAE Backdoor Reverse Shell HTTP Beacon via Quad7 Operators
This rule detects HTTP requests carrying the hardcoded User-Agent value IOT together with POST requests to the /iot/post URI, the reverse shell beaconing pattern of the UPDTAE backdoor deployed by the Quad7 operators. The implant polls its C2 roughly every thirty seconds using this fixed header and path. The unusual static User-Agent and endpoint make this a reliable network indicator.
HuntRule TeamWebproxyHigh216Premium2026-07-07Malicious wp2shell User Agent in Web Requests (via webserver)
This rule detects inbound web requests carrying the wp2shell or rezwp2shell user-agent strings used by the exploitation tooling for CVE-2026-63030 and CVE-2026-60137. These agent values identify automated scanning and exploitation attempts against WordPress. The strings are tool-specific and rarely seen in benign traffic.
HuntRule TeamWebwebserverHigh232Premium2026-07-07Suspicious Cloud Security Agent Uninstallation via Shell (via process_creation)
This rule detects command lines that stop or uninstall cloud provider security agents such as Alibaba Aegis, Tencent YunJing, or BCM monitoring, a defense evasion step in malicious Linux shell scripts. Disabling these agents blinds cloud workload protection before the attacker deploys further payloads.
HuntRule TeamLinuxprocess_creationMedium295Premium2026-07-07Suspicious RunOnce Persistence Pointing to ProgramData Payload
This rule detects RunOnce registry values that launch a payload stored under ProgramData, the persistence pattern Raspberry Robin used with a randomly named executable in a ProgramData subfolder. Autostart entries executing binaries from ProgramData are unusual for signed software and indicate malware persistence.
HuntRule TeamWindowsregistry_setMedium279Premium2026-07-07NetScan Share Enumeration Write Access Check
Detects the creation of unique artifacts created by SoftPerfect NetScan when performing write-access checking on enumerated network shares
HuntRule TeamWindowssecurityMedium81Premium2026-07-07PowerShell Loader Execution of Skype.ps1 from Public Folder (via process_creation)
This rule detects PowerShell executing a Skype.ps1 loader staged in the C users Public folder, the AsyncRAT delivery behavior observed in campaigns abusing ScreenConnect and open directories. Adversaries leverage the world-writable Public path to stage and run a fileless .NET loader while masquerading as a common application.
HuntRule TeamWindowsprocess_creationHigh152Premium2026-07-07Suspicious Browser and Wallet Credential Theft via JavaScript Stealer
This rule detects a script or process accessing browser and cryptocurrency wallet credential stores for Chrome, Edge, MetaMask, Phantom and 1Password, matching the INVISIBLEFERRET JavaScript stealer that packages stolen data into a ZIP for exfiltration. This credential and wallet harvesting supports DPRK financial theft in the EtherHiding campaign.
HuntRule TeamWindowsprocess_creationLow113Premium2026-07-07Malicious ClickFix PowerShell Launching mshta with Remote URL (via process_creation)
This rule detects the ClickFix initial-access pattern where powershell.exe invokes mshta against a remote URL after a victim pastes a clipboard command through the Run dialog, as documented by Group-IB. Adversaries use this social-engineering chain to fetch and execute an HTA-based downloader, so the powershell-to-mshta URL pattern is a strong entry-point signal.
HuntRule TeamWindowsprocess_creationHigh267Premium2026-07-07Malicious Webserver IIS Module Installed - PowerShell (via powershell)
This rule detects deploy an IIS module via PowerShell.
HuntRule TeamWindowspowershellHigh303Premium2026-07-07Malicious Replication Privileges Accessed to Perform DCSync Attack (via security)
This rule detects use DCSync or SecretDump tool to exfiltrate Active Directory credentials.
HuntRule TeamWindowssecurityHigh101Premium2026-07-07Suspicious Executable Persistence in Startup Folder (via file_event)
This rule detects an executable being written into the user Startup folder, the persistence method used by the VVS Discord stealer to relaunch itself at logon. Placing a binary under Start Menu Programs Startup guarantees the stealer re-executes on every user sign-in.
HuntRule TeamWindowsfile_eventMedium282Premium2026-07-07