Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,308 rules
Malicious Project CAV3RN DNS Configuration Recovery via cloudlanecdn.com (via dns_query)
This rule detects DNS queries to encoded subdomains of cloudlanecdn.com, a channel used by the Project CAV3RN espionage framework to recover configuration data from DNS AAAA records. The encoded label structure and attacker-controlled domain indicate covert command-and-control and data-encoding activity that should not appear in normal traffic.
HuntRule TeamNetworkdns_queryHigh424Premium2026-07-02Suspicious Wscript Executing UN VBS Cleanup Script via Command Line (via process_creation)
This rule detects wscript.exe executing a VBScript named UN.vbs, the cleanup component used by the Parallax RAT to remove infection artifacts. It is associated with the Parallax RAT campaign reported by Uptycs. Attackers run this script to erase traces after establishing access, so the execution is a useful indicator of post-infection cleanup activity.
HuntRule TeamWindowsprocess_creationLow429Premium2026-07-02Suspicious Ivanti Connect Secure License Keys-Status Command Injection Request (via webserver)
This rule detects HTTP requests to the Ivanti Connect Secure /api/v1/license/keys-status/ endpoint that embed a shell command separator followed by an interpreter reference. Actors chained a semicolon and python invocation onto this path to achieve command injection and drop reverse shells. Requests to this endpoint carrying inline command syntax indicate active exploitation.
HuntRule TeamWebwebserverHigh246Premium2026-07-02Malicious UNC1549 MINIBIKE DLL Side-Load of secur32.dll via FileCoAuth (via image_load)
This rule detects the OneDrive-associated FileCoAuth.exe binary loading a secur32.dll from a non-system directory, the side-load path for UNC1549 MINIBIKE and MINIBUS backdoors. The suspected Iranian actor abused a trusted-looking executable to load a malicious DLL of the same name as a system library. Loading secur32.dll from outside System32 through FileCoAuth is a high-fidelity side-loading indicator.
HuntRule TeamWindowsimage_loadHigh162Premium2026-07-02Suspicious Spoofed Inbound Email With Failed Authentication and Anonymous Internal Sender (via m365)
This rule detects inbound messages that fail SPF, DKIM, and composite authentication yet are marked as internal organization senders while authenticating anonymously. This combination reflects the routing and misconfiguration abuse used by phishing actors to spoof trusted internal domains and bypass tenant protections. Detecting the mismatch between claimed internal origin and failed authentication surfaces domain-spoofing phishing that would otherwise appear trustworthy to recipients.
HuntRule TeamM365exchangeMedium361Premium2026-07-02Possible DLL Side-Loading via DicomPortable Spawned by ITarian RmmService
This rule detects DicomPortable launched by the ITarian RmmService process which the phishing RMM campaigns abuse to side-load HijackLoader and DeerStealer through a trojanized DLL. Chaining a legitimate RMM service into a vulnerable portable binary lets adversaries execute malware under a trusted parent. Detecting this parent-child pair surfaces DLL search order hijacking used for stealer delivery.
HuntRule TeamWindowsprocess_creationHigh83Premium2026-07-02Suspicious File Download via Certutil URLCache
This rule detects certutil being used with its url cache download flags which the ALPHV intrusion leveraged as a living off the land downloader to stage tooling and this matters because certutil is a signed system binary frequently abused to retrieve remote payloads and its download flags rarely appear in legitimate certificate operations.
HuntRule TeamWindowsprocess_creationMedium52Premium2026-07-02Suspicious PowerShell Invoke-WebRequest and Invoke-Expression Download Cradle via ClickFix
This rule detects PowerShell combining Invoke-WebRequest with Invoke-Expression to download and execute a payload in memory as seen in the ClickFix Revenge of detection campaign. This download cradle avoids writing the payload to disk and is triggered from a pasted Run dialog command. The pairing of remote fetch and dynamic execution is a strong malicious signal.
HuntRule TeamWindowsps_scriptMedium121Premium2026-07-02Malicious DLL Side-Loading of SBAMBRES.DLL by VIPRE Binary via DeedRAT (via image_load)
This rule detects the legitimate VIPRE MambaSafeModeUI.exe binary loading SBAMBRES.DLL from the ProgramData Micro directory, the side-loading step that launches the DeedRAT backdoor. Genuine VIPRE components load this DLL from their install directory, not ProgramData.
HuntRule TeamWindowsimage_loadHigh163Premium2026-07-01Suspicious notepad Spawned by mshta for Process Injection
This rule detects mshta spawning notepad which in the WithSecure Windows lab was created suspended as an injection host for a Covenant Grunt implant. The script host mshta launching notepad has no legitimate purpose and strongly suggests it is being used as a hollow target for process injection.
HuntRule TeamWindowsprocess_creationHigh315Premium2026-07-01Suspicious Child Process Spawned by WmiPrvSe
This rule detects the WMI provider host WmiPrvSe.exe spawning command interpreters or scripting engines. This process tree is characteristic of remote WMI execution abuse for code execution and lateral movement. Shell processes parented to WmiPrvSe should be reviewed for unauthorized activity.
HuntRule TeamWindowsprocess_creationMedium101Premium2026-07-01Conhost Suspicious Command Execution
Detects use of conhost in "headless" mode. By running conhost.exe in "headless" mode, it means that no visible window will pop up on the victim's machine.
HuntRule TeamWindowsprocess_creationHigh72Premium2026-07-01Suspicious Windows Credential Manager Enumeration (via process_creation)
This rule detects cmdkey /list or vaultcmd /list enumerating saved credentials in the Windows Credential Manager, a credentials-from-password-stores technique used to reveal cached logins for lateral movement. Credential Manager enumeration is tracked in the Red Canary Threat Detection Report. Detecting these commands surfaces stored-credential discovery.
HuntRule TeamWindowsprocess_creationMedium167Premium2026-07-01Malicious Apache Camel Exec Header Injection
This rule detects HTTP requests containing Apache Camel exec-command headers used to bypass the header filter in CVE-2025-27636 and CVE-2025-29891. Attackers inject CamelExecCommandExecutable and CamelExecCommandArgs headers to run arbitrary commands on vulnerable Camel routes. Presence of these headers in inbound traffic indicates exploitation attempts.
HuntRule TeamWebwebserverHigh132Premium2026-07-01Malicious Service Abuse with Backdoored "command Failure" - Reg via Command (via process_creation)
This rule detects modify the configuration of a service to trigger an action when the service is crashed.
HuntRule TeamWindowsprocess_creationHigh347Premium2026-07-01