Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,370 rules
Malicious Shai-Hulud npm Payload Execution via bun_environment Script (via process_creation)
This rule detects execution of the Shai-Hulud worm install-hook payloads setup_bun.js and bun_environment.js, dropped and run via npm pre/post-install scripts during the supply-chain compromise. These scripts scan for cloud and SSH credentials and self-propagate, so their execution signals active infection of the npm ecosystem.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-05-12Malicious Volgmer Payload Storage in WMI Security Registry Key
This rule detects creation of specific named values under the WMI Security registry key used by the Hidden Cobra Volgmer backdoor to hide its encoded configuration and payload. Writing data to this rarely used registry location under these hardcoded GUID value names is a high-confidence indicator of a Volgmer infection.
HuntRule TeamWindowsregistry_setHigh223Premium2026-05-12Suspicious Execution of Microsoft.Http.Api.exe from AppData
This rule detects execution of a binary named Microsoft.Http.Api.exe from a user AppData path, used by the SHELBY backdoor to masquerade as a legitimate Microsoft component. A Microsoft-branded executable running from AppData rather than a system directory indicates masquerading and side-loading staging used to blend malicious execution with trusted software.
HuntRule TeamWindowsprocess_creationHigh153Premium2026-05-12Suspicious GoGRPC Persistence via Realtek HD Audio Run Key (via process_creation)
This rule detects a PowerShell command that sets a CurrentVersion Run value named Realtek HD Audio pointing to an executable in the roaming AppData folder as used by the GoGRPC backdoor. Legitimate Realtek audio software does not persist from AppData.
HuntRule TeamWindowsprocess_creationHigh134Premium2026-05-12Suspicious VMware Tools Binary Executing from Non-Standard Path
This rule detects a process named vmtools.exe or vmwared.exe running from a directory outside the legitimate VMware installation tree. CL-STA-1062 masquerades its loader as VMware guest tooling to evade analyst scrutiny on virtualized targets. Spotting the trusted filename in the wrong path exposes a masqueraded implant rather than genuine VMware software.
HuntRule TeamWindowsprocess_creationHigh162Premium2026-05-12Suspicious Batch Execution From Hidden __MACOSX Archive Path (via process_creation)
This rule detects a command shell executing a batch file from a hidden __MACOSX directory extracted from a delivery archive, the initial execution step of this Cobalt Strike infection chain. Legitimate workflows do not run scripts from __MACOSX archive residue.
HuntRule TeamWindowsprocess_creationHigh125Premium2026-05-12Windows Execution of tanstack_runner.js via bun.exe
Flags bun.exe launching a script via "run tanstack_runner.js" on Windows.
Leonardo Gasparini, Huntrule TeamWindowsprocess_creationHigh171Free2026-05-12Linux process execution indicators for TanStack preinstall supply-chain payloads
Flags Linux processes running a Bun-based TanStack runner (and related Python pyz payload execution) indicative of supply-chain compromise.
Leonardo Gasparini, Huntrule TeamLinuxprocess_creationHigh172Free2026-05-12Malicious SSLoad Downloader C2 Beacon via Custom SSLoad User-Agent (via proxy)
This rule detects outbound HTTP traffic carrying the hardcoded SSLoad User-Agent used by the SSLoad downloader when it registers a fingerprinted host and beacons for tasks to its command-and-control server. This bespoke agent string is not produced by legitimate software and identifies the downloader stage of the intrusion on the wire.
HuntRule TeamWebproxyHigh71Premium2026-05-11Suspicious PAM Backdoor via pam_exec Configuration Change
This rule detects modification of a PAM configuration file to load pam_exec.so, a pluggable authentication module backdoor described in Elastic Linux persistence research. By adding a pam_exec directive to an sshd PAM stack the attacker runs an arbitrary script on each authentication for persistence and credential capture. Edits to files under /etc/pam.d that introduce pam_exec are highly suspicious.
HuntRule TeamLinuxprocess_creationHigh346Premium2026-05-11Suspicious UAC Bypass via Fodhelper Child Process
This rule detects fodhelper.exe spawning a child process, the hallmark of the ms-settings protocol handler UAC bypass used by BQTLock to elevate before injecting Remcos into explorer.exe. Fodhelper does not normally launch child processes outside of Settings interactions.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-05-11Malicious Citrix WFShell Spawning Command Interpreter via Command Line
This rule detects the Citrix wfshell.exe or cmstart.exe process spawning a command interpreter, a post-exploitation chain observed after abuse of the Citrix Bleed vulnerability CVE-2023-4966 leading to LockBit ransomware. These Citrix components should not launch shells. Detecting the chain exposes hands-on-keyboard activity following gateway compromise.
HuntRule TeamWindowsprocess_creationHigh131Premium2026-05-11Suspicious IAM Policy Attachment Granting AdministratorAccess
This rule detects an AttachUserPolicy call that attaches the AWS managed AdministratorAccess policy to an IAM user. After compromising an EC2 instance and stealing IMDS credentials the attacker created a rogue IAM user and granted it full administrator rights for persistence and privilege escalation. Sudden attachment of AdministratorAccess to a user is high-signal for cloud account takeover.
HuntRule TeamAwscloudtrailHigh444Premium2026-05-11Malicious Office Application Spawning a Command Shell or Script Interpreter (via process_creation)
This rule detects a Microsoft Office application such as Word, Excel, PowerPoint or Outlook launching a command shell or script interpreter, the classic child-process signature of a malicious macro or exploited document. Phishing-driven Windows Command Shell and script execution rank among the most prevalent techniques in the Red Canary Threat Detection Report, marking the transition from initial access to code execution. Detecting interpreter children of Office processes surfaces the intrusion at that hand-off.
HuntRule TeamWindowsprocess_creationHigh151Premium2026-05-11Malicious Bring-Your-Own-Vulnerable-Driver Load By BlackByte
This rule detects loading of vulnerable kernel drivers abused by BlackByte to disable endpoint protection. BlackByte deployed the RtCore64 DBUtil_2_3 zamguard64 and gdrv vulnerable drivers to gain kernel-level code execution. Loading a known-vulnerable signed driver is a BYOVD technique that lets attackers terminate security products and tamper with the kernel.
HuntRule TeamWindowsimage_loadHigh133Premium2026-05-11