Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,283 rules
Suspicious Keylog and Screenshot Files in windows-cache Directory (OtterCookie)
This rule detects creation of the collection artifacts 1.tmp and 2.jpeg inside a windows-cache directory, where the OtterCookie module stores keystroke logs and screenshots before exfiltration. These fixed staging paths and filenames are distinctive to the malware. Their appearance indicates active input capture and screen collection.
HuntRule TeamWindowsfile_eventHigh40Premium2026-09-10Suspicious Encrypted Implant File Creation for DLL Search Order Hijacking (RainyDay Turian PlugX)
This rule detects creation of encrypted implant files with distinctive names such as rdmin.src, Mcsitesdvisor.afx or winslivation.dat used by the RainyDay, Turian and PlugX variants. These files hold the encrypted payload that a legitimately signed application decrypts and loads via DLL search-order hijacking. Their appearance on disk indicates sideloading-based deployment.
HuntRule TeamWindowsfile_eventHigh30Premium2026-09-10Suspicious PS1Bot PowerShell Payload Written to ProgramData (via file_event)
This rule detects the PS1Bot malware framework writing its PowerShell payload ntu.ps1 into the ProgramData directory. PS1Bot is delivered through malvertising and stages obfuscated PowerShell modules from this location for in-memory execution. Script files created in ProgramData outside of installer activity are a strong indicator of staging.
HuntRule TeamWindowsfile_eventHigh60Premium2026-09-10Suspicious CyberLock Ransomware Encrypted File Creation
This rule detects creation of files bearing the .cyberlock extension, the marker appended by the ransomware distributed through fake AI-tool installers. Appearance of this extension indicates active encryption of user data on the host and imminent extortion.
HuntRule TeamWindowsfile_eventHigh60Premium2026-09-10Suspicious Executable Dropped in Public Users Directory Named Ctrlpanel (via file_event)
This rule detects creation of ctrlpanel.exe under the world-writable C:\Users\Public directory which the OfflRouter VBA virus drops as its payload dropper. Placing an executable in the Public profile is a common staging technique that avoids per-user path restrictions and blends with shared content.
HuntRule TeamWindowsfile_eventHigh00Premium2026-09-10Phobos 8Base Ransomware Encrypted File Extension Created
This rule detects files being renamed with the .8base extension appended by Phobos ransomware operated by the 8Base group. Phobos appends an extension containing a victim ID and contact email ending in .8base to each encrypted file. A wave of these file events signals active ransomware encryption on the host.
HuntRule TeamWindowsfile_eventHigh40Premium2026-09-10SapphireStealer Working Directory File Drop in Temp
This rule detects files being written under a sapphire\\work directory inside the user Temp folder. SapphireStealer uses %TEMP%\\sapphire\\work as its staging directory where it drops harvested Passwords.txt, Screenshot.png and log.zip before exfiltration. Activity in this fixed working path indicates active credential and data theft staging by the stealer.
HuntRule TeamWindowsfile_eventHigh30Premium2026-09-10Rhysida Ransomware Encrypted File Extension Created
This rule detects files being renamed with the .rhysida extension appended by Rhysida ransomware during encryption. Rhysida uses ChaCha20 to encrypt victim files and marks each with this extension. A burst of such file events indicates active mass encryption on the host.
HuntRule TeamWindowsfile_eventHigh50Premium2026-09-10Rhysida Ransomware Note CriticalBreachDetected.pdf Created
This rule detects the creation of a file named CriticalBreachDetected.pdf, the fixed ransom note dropped by Rhysida ransomware. Rhysida writes this note across affected directories after encrypting files. Detecting the note filename provides a high-confidence indicator that Rhysida encryption has already occurred on the host.
HuntRule TeamWindowsfile_eventHigh40Premium2026-09-09Malicious Qilin EDR Killer BYOVD Driver Load
This rule detects loading of the vulnerable drivers rwdrv.sys or hlpdrv.sys used by the Qilin EDR killer as a bring-your-own-vulnerable-driver toolkit. The rwdrv.sys component is a renamed ThrottleStop driver abused alongside hlpdrv.sys to gain kernel access for terminating protected security processes. Loading either driver indicates an attempt to disable endpoint defenses ahead of ransomware deployment.
HuntRule TeamWindowsdriver_loadHigh30Premium2026-09-09Malicious Known Vulnerable Driver Load for BYOVD Attack
This rule detects loading of known vulnerable kernel drivers such as viragt64.sys dbutil_2_3.sys zamguard64.sys RtCore64.sys gdrv.sys and empntdrv.sys which adversaries abuse in bring your own vulnerable driver attacks to disable security tooling and gain kernel level execution. Presence of these driver filenames loading on an endpoint is a strong indicator of privilege escalation or defense evasion activity.
HuntRule TeamWindowsdriver_loadHigh60Premium2026-09-09Cisco IOS XE Configuration Change by Web UI WSMA User
This rule detects running-configuration changes attributed to the SEP_webui_wsma_http user in Cisco IOS XE syslog. During exploitation of the Web UI vulnerability, configuration commits appeared as %SYS-5-CONFIG_P messages performed by SEP_webui_wsma_http, alongside %WEBUI-6-INSTALL_OPERATION_INFO ADD events. Configuration writes by this internal web-service account indicate abuse of the exposed management interface.
HuntRule TeamCiscoiosHigh90Premium2026-09-09Malicious ValleyRAT KernelQuick Rootkit Service and Shellcode Store Registry Keys
This rule detects registry writes to the kernelquick kernel-driver service key and to the HKLM\SOFTWARE\IpDates key used by ValleyRAT's kernel rootkit component to register its driver and stash shellcode. These fixed key names are unique to the ValleyRAT rootkit and indicate installation of its kernel-level hiding and persistence layer.
HuntRule TeamWindowsregistry_setHigh80Premium2026-09-09Malicious Silver Fox BYOVD Vulnerable Driver Service Creation
This rule detects creation of the kernel service entries named Termaintor or Amsdk_Service that the Silver Fox APT registers to load the vulnerable amsdk.sys driver in a bring-your-own-vulnerable-driver attack. The driver is abused via IOCTL 0x80002048 to terminate security product processes, so these service names indicate an in-progress endpoint-defense-disabling operation preceding ValleyRAT injection.
HuntRule TeamWindowsregistry_setHigh80Premium2026-09-09Malicious WezRat Persistence via Chrome Updater Run Key
This rule detects a Run key value named Chrome Updater pointing to Updater.exe, the persistence and masquerade used by the WezRat backdoor. The malware disguises its autostart as a Chrome update component to appear benign. Detecting the named value with its Updater.exe target exposes the implant persistence.
HuntRule TeamWindowsregistry_setHigh120Premium2026-09-09