Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,370 rules
Possible Ivanti Connect Secure Path Traversal Exploitation
This rule detects HTTP requests to the Ivanti Connect Secure TOTP backup-code endpoint containing directory traversal sequences, the access pattern used to exploit the authentication bypass zero-day. Threat actors chain this traversal to reach restricted API paths and deploy webshells. Detecting these requests exposes active exploitation of the Ivanti appliance.
HuntRule TeamWebwebserverHigh211Premium2026-05-11Cleo File Transfer Software Spawning Command Interpreter
This rule detects a Cleo managed file transfer process spawning a command interpreter such as cmd, PowerShell or Bash, the post-exploitation behavior of CVE-2024-55956 autorun abuse leading to Cobalt Strike by CL0P. A Cleo product launching a shell indicates exploitation of the Cleo Harmony VLTrader or LexiCom software.
HuntRule TeamWindowsprocess_creationHigh122Premium2026-05-11Malicious Active Directory Federated Trust Added (via office365)
This rule detects scenarios where an federated trust is added by an attacker.
HuntRule TeamAzureoffice365High103Premium2026-05-11Suspicious Subprocess Spawned by LiteLLM Proxy Process (via process_creation)
This rule detects a LiteLLM proxy Python process spawning a shell or network utility. Such a child process is consistent with the subprocess execution abused in CVE-2026-42271. A LiteLLM proxy does not normally launch shells or download tools.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-05-11Malicious AppDomainManager Injection via MyAppDomainManager DLL Load
This rule detects a .NET process loading a module named MyAppDomainManager.dll, the hijack DLL used by CL-STA-1062 to abuse the AppDomainManager configuration in chrome_setup.exe.config and run the TinyRCT backdoor inside a trusted process. Catching this load reveals CLR AppDomainManager injection used for defense evasion and stealthy code execution.
HuntRule TeamWindowsimage_loadHigh103Premium2026-05-11Malicious File Encryption via Kraken Ransomware Encryptor Binary
This rule detects execution of the Kraken ransomware encryptor with its characteristic key, path, timeout and directory command-line switches. The binary encrypts victim files and appends the .zpsc extension while dropping a ransom note. Detecting the encryptor invocation provides a late-stage indicator of active ransomware deployment.
HuntRule TeamWindowsprocess_creationHigh122Premium2026-05-11Malicious WSH Script Execution from WebDAV Share (via process_creation)
This rule detects wscript.exe or cscript.exe executing a script hosted on a remote WebDAV share as shown by the DavWWWRoot path token, a delivery method abused through malicious URL and LNK files pointing at Cloudflare tunnel WebDAV servers. Script execution directly from a WebDAV UNC path is rarely legitimate.
HuntRule TeamWindowsprocess_creationHigh215Premium2026-05-10Malicious DLL Sideloading via LOLBins from ProgramData by Dohdoor
This rule detects trusted Windows utilities loading propsys or batmeter DLLs from ProgramData or the Public directory. The Dohdoor campaign sideloads its payload through living-off-the-land binaries such as OpenWith and mblctr running from unusual paths. A signed utility loading a system-named DLL from a writable directory is a strong sideloading indicator.
HuntRule TeamWindowsimage_loadHigh464Premium2026-05-10Masquerading Certificate Issuance with Certighost cdc and rmd Request Attributes (via security)
This rule detects certificate issuance events carrying the cdc or rmd request attributes used by the Certighost CVE-2026-54121 exploit to steer a Certificate Authority toward an attacker-chosen client Domain Controller. Adversaries leverage these attributes to obtain a certificate that authenticates as a Domain Controller machine account, making early detection critical for exposing certificate-based DC impersonation before DCSync.
HuntRule TeamWindowssecurityHigh121Premium2026-05-10Malicious Ransomware Ransom Note README-RECOVER File Creation
This rule detects creation of README-RECOVER ransom note text files, the note naming convention dropped during the Qilin ransomware encryption stage. These notes appear across directories once mass file encryption completes. Their creation is a definitive indicator that ransomware impact has already occurred and requires immediate response.
HuntRule TeamWindowsfile_eventHigh447Premium2026-05-10Possible Origin Logger C2 Exfiltration via Hardcoded User Agent and Gate Endpoints via proxy
This rule detects Origin Logger keylogger command and control traffic that beacons with a hardcoded Firefox/99.0 user agent to /gate and /login exfiltration endpoints. Origin Logger is an AgentTesla derived stealer that harvests browser credentials and web session data. Correlating the fixed user agent with the exfil URI paths surfaces credential theft egress while suppressing benign Firefox browsing.
HuntRule TeamWebproxyHigh375Premium2026-05-09Malicious Spool Process Spawned a CMD Shell - PrintNightmare Vulnerability - CVE-2021-36958 (via process_creation)
This rule detects exploits the PrintNightmare vulnerability and obtained a CMD shell.
HuntRule TeamWindowsprocess_creationHigh205Premium2026-05-09Malicious Outlook Process Memory Dump via procdump
This rule detects procdump creating a full memory dump of the Outlook process, a technique the ToddyCat APT used to extract email data and credentials from memory. The attackers ran procdump64.exe with -ma against OUTLOOK.exe to capture its address space for later mining. Dumping the memory of a mail client is a strong sign of credential and email data theft rather than routine troubleshooting.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-05-09Malicious WebDAV Payload Execution via rundll32 davclnt.dll (via process_creation)
This rule detects rundll32.exe invoking DavSetCookie from davclnt.dll, a WebDAV execution technique used by the TimbreStealer campaign to run remote payloads. Executing through the WebDAV client library retrieves and launches code from a remote share under a signed binary.
HuntRule TeamWindowsprocess_creationHigh433Premium2026-05-09Malicious ESXi Snapshot Removal Loop Inhibiting Recovery (via process_creation)
This rule detects vim-cmd removing all snapshots across virtual machines, the recovery-inhibition step used by Cicada3301 ransomware on ESXi hosts prior to encryption. Adversaries delete snapshots so encrypted guests cannot be rolled back, making a snapshot removeall operation a strong pre-encryption recovery-tampering signal.
HuntRule TeamLinuxprocess_creationHigh82Premium2026-05-09