Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,075 rules
Suspicious PebbleDash C2 Configuration Stored Under WMI Security Key (via registry_set)
This rule detects writes to the HKLM SYSTEM CurrentControlSet Control WMI Security value with the GUID used by the Kimsuky PebbleDash backdoor to store its encrypted command and control address. This registry location is not normally written by user applications.
—Windowsregistry_setHigh10Premium2026-09-05Malicious Invoke-WMIExec Lateral Movement Download and Execute (via ps_script)
This rule detects a PowerShell one liner that downloads Invoke-WMIExec via a web client and executes it against a remote target using a pass the hash argument as observed in the MeshAgent and SuperShell intrusion. This chains in memory script download with WMI based lateral movement.
—Windowsps_scriptHigh20Premium2026-09-05Suspicious Certutil UrlCache Download of Remote CAB Payload (via process_creation)
This rule detects certutil.exe using the urlcache and split options to download a remote CAB file into ProgramData as used by the Larva-26010 SoftEther VPN intrusion to stage tooling. This certutil pattern is a well known living off the land download technique.
—Windowsprocess_creationMedium40Premium2026-09-05Malicious Xctdoor XcLoader Execution via Regsvr32 AppX Path Abuse (via process_creation)
This rule detects regsvr32.exe loading a DLL named settings.lock from the Microsoft MicrosoftOffice365Hub AppX package settings directory. This loader technique is used by the Xctdoor and XcLoader backdoors to execute encrypted payloads from a user AppX path where legitimate COM registration is not expected.
—Windowsprocess_creationHigh30Premium2026-09-05Suspicious Hidden Backdoor Account Creation Ending With Dollar Sign (via process_creation)
This rule detects creation of hidden local accounts whose names end with a dollar sign such as mssql or adminweb1 as used by the MS-SQL intruder for stealthy persistence. Accounts ending in a dollar sign are hidden from the standard net user listing.
—Windowsprocess_creationMedium20Premium2026-09-05Malicious Potato Family Privilege Escalation Tool Execution (via process_creation)
This rule detects execution of Potato family token impersonation tools including JuicyPotatoNG, RasManPotato, SigmaPotato, BadPotato, and RustPotato used for local privilege escalation in the MS-SQL intrusion. These utilities abuse SeImpersonate privileges to elevate to SYSTEM.
—Windowsprocess_creationHigh00Premium2026-09-05Malicious Certutil Decode of Encoded Web Shell to ASPX (via process_creation)
This rule detects certutil.exe decoding a text file into an ASPX web shell within a web server images directory as seen in the targeted MS-SQL server intrusion. Certutil decoding output directly into a web accessible aspx file is a common web shell deployment technique.
—Windowsprocess_creationHigh10Premium2026-09-05Suspicious Linux CoinMiner Watchdog Staging in Shared Memory (via process_creation)
This rule detects a watchdog command that downloads the miner into a hidden .Sys_cache_backup file under dev shm using curl with a wget fallback as observed in the Linux SSH CoinMiner campaign. Fetching an executable into shared memory to survive removal is a hallmark of this miner.
—Linuxprocess_creationHigh10Premium2026-09-05Suspicious Linux Payload Download From Xrpl City Miner Host (via process_creation)
This rule detects wget or curl retrieving payloads from the download.xrpl.city host used to distribute the Linux SSH CoinMiner and its propagation modules. This host serves disguised archive and binary files during the infection chain.
—Linuxprocess_creationHigh10Premium2026-09-05Suspicious MSBuild Execution From Office or Archive Extraction Context (via process_creation)
This rule detects MSBuild.exe being launched by Office applications, mail clients, or archive tools which is a strong sign of a phishing driven LOLBin attack. In a normal development environment MSBuild is invoked by build tooling rather than by document or extraction processes.
—Windowsprocess_creationMedium10Premium2026-09-05Suspicious Kimsuky Scheduled Task Impersonating Google Update CGI (via process_creation)
This rule detects schtasks creation of persistence tasks named GoogleUpdateTaskMachineCGI or GoogleExtension that launch wscript or the Python backdoor beauty.py as used by the Kimsuky LNK campaign. These task names impersonate Google update jobs to hide short interval persistence.
—Windowsprocess_creationMedium20Premium2026-09-05Malicious Ladon PowerShell Attack Framework Import (via process_creation)
This rule detects PowerShell importing the Ladon attack framework module and invoking its modules such as SweetPotato, Runas, or MssqlCmd as observed in the MeshAgent and SuperShell intrusion. Ladon provides scanning, privilege escalation, and lateral movement capabilities.
—Windowsprocess_creationHigh40Premium2026-09-05Suspicious Fscan Internal Network Scanner Execution (via process_creation)
This rule detects execution of the fscan network scanner with host file and silent output options as observed in the MeshAgent and SuperShell intrusion. Fscan is used by the actor to enumerate internal hosts and open ports for lateral movement.
—Windowsprocess_creationMedium10Premium2026-09-05Suspicious Browser History Wipe via Rundll32 ClearMyTracksByProcess (via process_creation)
This rule detects rundll32.exe invoking InetCpl.cpl ClearMyTracksByProcess to clear browser history and cache as used by the HiddenGh0st malware to remove traces. This indicator flag combination erases stored browsing artifacts on the host.
—Windowsprocess_creationMedium00Premium2026-09-05Suspicious CRAT Injection Named Pipe ChromeUpdatePipe (via pipe_created)
This rule detects the creation of the named pipe ChromeUpdatePipe used by the CRAT payload to transmit injected code between processes. The pipe masquerades as a Chrome update channel and is a stable indicator of this backdoor family.
—Windowspipe_createdHigh10Premium2026-09-05