Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,299 rules
Malicious DPAPI Credential Decryption via PowerShell ProtectedData Unprotect
This rule detects PowerShell invoking the DPAPI ProtectedData Unprotect method to decrypt secrets from the current user context. SocGholish operators used this to unprotect stolen browser credential material after staging it locally. This lets attackers recover plaintext passwords without touching disk artifacts that alert defenders.
HuntRule TeamWindowsps_scriptHigh186Premium2026-07-05Malicious FakeSG Scheduled Task VCC_runner2 NetSupport Loader (via process_creation)
This rule detects creation of a scheduled task named VCC_runner2 via schtasks. The FakeSG campaign registers this task to run a script chain that unpacks and launches a NetSupport RAT, so this distinctive task name indicates the fake-update loader persisting on the host.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-07-05Suspicious Cron Persistence File Creation in System Cron Directories (via file_event)
This rule detects creation or modification of files under Linux system cron directories that adversaries use for scheduled task persistence. In the Group-IB XMRig covert Linux PAM abuse campaign the miner establishes persistence through cron entries. Because cron persistence survives reboots and blends with legitimate scheduling, monitoring these paths helps surface unauthorized recurring execution.
HuntRule TeamLinuxfile_eventMedium158Premium2026-07-05Suspicious macOS Quarantine Bypass via xattr and chmod After curl Download
This rule detects a shell one liner that downloads a payload with curl then strips the com.apple.quarantine attribute and makes it executable as used by UNC5142 macOS ClickFix delivery. This behavior bypasses Gatekeeper so downloaded malware can run without user prompts.
HuntRule TeamMacosprocess_creationHigh265Premium2026-07-05Suspicious Project CAV3RN logAzure.txt Configuration Drop (via file_event)
This rule detects creation of a file named logAzure.txt, a configuration artifact written by the Project CAV3RN espionage framework that abuses Outlook calendar events and DNS for command-and-control. The fixed configuration filename is a distinctive host-based indicator of this framework staging its settings on disk.
HuntRule TeamWindowsfile_eventMedium103Premium2026-07-05Malicious SharePoint ToolShell Exploitation Request to ToolPane (via webserver)
This rule detects the exploitation request pattern for the SharePoint ToolShell vulnerabilities, a POST to the ToolPane endpoint in edit display mode with a spoofed SignOut referer used to bypass authentication. This request pattern corresponds to CVE-2025-49706 and CVE-2025-49704 exploitation rather than legitimate access.
HuntRule TeamWebwebserverHigh234Premium2026-07-05Malicious Hidden Local Account via Winlogon SpecialAccounts UserList
This rule detects modification of the Winlogon SpecialAccounts UserList registry key which hides a local account from the Windows logon screen, a defense-evasion technique used alongside AnyDesk abuse to conceal an attacker-created administrator account. Writing to this key is almost never legitimate and indicates deliberate account hiding.
HuntRule TeamWindowsregistry_setHigh92Premium2026-07-05Malicious Security Product Bypass via defendnot Loader
This rule detects execution of the defendnot loader, a tool analyzed by Huntress that registers a fake antivirus through the Windows Security Center API to silently disable Microsoft Defender. The loader drops a ctx.bin configuration and injects defendnot.dll into taskmgr.exe to persist the fake AV registration. Because defendnot exists solely to neutralize Defender, its execution is a high-confidence defense-evasion indicator.
HuntRule TeamWindowsprocess_creationHigh3710Premium2026-07-05Malicious HiddenGh0st Guest Account Activation and Admin Group Addition (via process_creation)
This rule detects activation of the built in guest account followed by adding it to the local administrators group as used by the HiddenGh0st MS-SQL intrusion for persistence. Re enabling and elevating the guest account is a rarely legitimate backdoor technique.
—Windowsprocess_creationHigh103Premium2026-07-05Suspicious macOS Data Staging via ditto to Temp Archive in Attacker Directory (via process_creation)
This rule detects the ditto utility archiving collected data into a temp out.zip or writing into the attacker working directory used by the macOS ClickFix AppleScript stealer. Adversaries leverage ditto to bundle browser and wallet data for exfiltration to their C2 server.
HuntRule TeamMacosprocess_creationMedium194Premium2026-07-05Suspicious Data Exfiltration Tool S3 Browser Execution (via process_creation)
This rule detects execution of the S3 Browser client, the third-party utility Muddled Libra uses to stage and exfiltrate collected data to attacker-controlled S3 buckets. Presence of S3 Browser on servers and admin hosts is abnormal and aligns with bulk cloud exfiltration after domain compromise.
HuntRule TeamWindowsprocess_creationMedium202Premium2026-07-05ValleyRAT Keylog Output File Creation in ProgramData (via file_event)
This rule detects creation of a sys.key file under ProgramData, the keystroke-log output artifact written by ValleyRAT when its keylogger module is activated via configuration or registry key. Adversaries leverage a low-profile filename in a machine-wide directory to collect captured input for later exfiltration, making early detection critical for exposing active collection before credentials and sensitive data leave the host.
HuntRule TeamWindowsfile_eventMedium2710Premium2026-07-05Malicious Kimsuky Troll Stealer Collected Data Staging Files with gte1 Extension (via file_event)
This rule detects creation of Troll Stealer staging files under the local AppData folder that follow the tokenized naming scheme used for exfiltration containers such as tsd, tfd, tbd and ccmd with the .gte1 extension. These encrypted collection files hold stolen SSH, FileZilla, browser and system data prior to upload, making their creation a high-confidence sign of active data theft.
HuntRule TeamWindowsfile_eventHigh73Premium2026-07-05Suspicious Scheduled Task SystemSoundsService2 Creation via Process Creation
This rule detects creation of a scheduled task named SystemSoundsService2 through schtasks.exe, a masquerading name GoldenJackal uses to persist its air-gap tooling on government systems. The name imitates a legitimate Windows sounds service to blend in. This indicates scheduled-task persistence by an espionage actor.
HuntRule TeamWindowsprocess_creationHigh329Premium2026-07-05Suspicious XScan Network Vulnerability Scanner Execution After Citrix Bleed Exploitation
This rule detects execution of the XScan network scanner with finger and vulnerability scanning flags against a subnet, matching internal reconnaissance seen after Citrix Bleed exploitation by Unit 42. Adversaries sweep the environment for hosts and weaknesses which precedes lateral movement and marks an active operator on the network.
HuntRule TeamWindowsprocess_creationMedium81Premium2026-07-05