Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,309 rules
Malicious Service Abuse with Backdoored "command Failure" - Reg via Command (via process_creation)
This rule detects modify the configuration of a service to trigger an action when the service is crashed.
HuntRule TeamWindowsprocess_creationHigh347Premium2026-07-01Malicious Iptables Drop of Syslog Forwarding Ports on Ivanti Connect Secure (via process_creation)
This rule detects iptables commands adding DROP rules for the syslog forwarding ports 514 and 6514 on Ivanti Connect Secure, an anti-forensics step observed during zero-day exploitation to sever remote log delivery. Blocking log egress on an appliance indicates active defense evasion by an intruder.
HuntRule TeamLinuxprocess_creationHigh169Premium2026-07-01Suspicious MonsterV2 Payload Masquerading as Windows Health Executable (via process_creation)
This rule detects execution of WinHealth.exe or WindowsSecurity.exe, filenames the SonicCrypt crypter used to disguise the MonsterV2 payload. The crypter spawned these binaries through a Task Scheduler COM object to load the RAT.
HuntRule TeamWindowsprocess_creationMedium103Premium2026-07-01Malicious NotPetya Payload Execution via Rundll32 Ordinal Export from Windows Directory
This rule detects rundll32 launching a DLL from the Windows root directory by ordinal export number one which matches the NotPetya execution pattern documented by NCC Group. The ransomware was copied into the Windows folder and executed via its first ordinal to encrypt disks and spread laterally.
HuntRule TeamWindowsprocess_creationMedium91Premium2026-07-01Suspicious DEEPPOST Data Exfiltration URI Pattern via BrazenBamboo
This rule detects HTTP requests to the /api/third/file/upload/ endpoint used by the BrazenBamboo DEEPPOST exfiltration tool to upload stolen files. DEEPPOST posted collected data to attacker infrastructure over a fixed API path. Detecting this URI reveals active data theft from compromised hosts.
HuntRule TeamWebproxyMedium112Premium2026-07-01Suspicious macOS Installer Invocation Spawned via Zoom Opener Helper (via process_creation)
This rule detects the macOS installer utility being launched with package and target arguments from a Zoom helper context. This maps to the ZoomOpener local webserver drive-by chain where a crafted launch request triggers installation of an attacker-supplied package. An attacker abuses this to silently install malicious software leading to remote code execution.
HuntRule TeamMacosprocess_creationMedium174Premium2026-07-01Windows Process: SystemSettingsAdminFlows.exe Used to Disable Windows Defender
Alerts when SystemSettingsAdminFlows.exe is launched with command-line arguments consistent with disabling Windows Defender.
Chirag Damani (KPMG India), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh291Free2026-07-01Failed WMI NTEventLogFile ClearEventLog attempts (Windows WMI Event 5858)
Alerts on WMI errors (Event 5858) tied to attempted NTEventLogFile ClearEventLog calls on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowswmiMedium153Free2026-07-01Suspicious AnyDesk Silent Install With Unattended Password
This rule detects AnyDesk being configured with the --set-password flag to enable unattended access without user interaction. The Librarian Ghouls APT installs AnyDesk this way to maintain covert remote control of compromised machines for data theft and crypto mining. Silent password provisioning of a remote-access tool is a common hands-on-keyboard persistence step.
HuntRule TeamWindowsprocess_creationHigh137Premium2026-06-30Malicious ShadowGuard eBPF Rootkit Control via Magic Kill Signal (via process_creation)
This rule detects the kill command issued with the out-of-range signals 900 and 901, the covert control channel used to command the ShadowGuard eBPF rootkit in the Shadow espionage campaigns. Real signals never exceed 64, so these magic values are interpreted only by the rootkit to toggle its process allow-list and hiding behavior.
HuntRule TeamLinuxprocess_creationHigh182Premium2026-06-30Malicious TBK DVR Command Injection Exploitation via RondoDox (via webserver)
This rule detects RondoDox botnet exploitation of the TBK DVR command injection flaw CVE-2024-3721 by requesting the device.rsp endpoint with the distinctive S_O_S_T_R_E_A_MAX command marker. This request injects operating system commands to drop the loader. The pattern is unique to the exploit.
HuntRule TeamWebwebserverHigh299Premium2026-06-30Suspicious Triada mms-core.jar Backdoor Dropped in App Data
This rule detects creation of an mms-core.jar file within an application data directory which the Triada trojan drops as a backdoor module loaded into hooked processes. This module implements the trojan command handling used to intercept SMS and manipulate clipboard cryptocurrency addresses. The specific filename in a per-app data path is a reliable Triada artifact.
HuntRule TeamAndroidfile_eventHigh413Premium2026-06-30Possible Linux Hardware Reconnaissance via Dmidecode Baseboard Query
This rule detects execution of dmidecode requesting baseboard information, a host-fingerprinting step used by the Prometei botnet alongside reads of /proc/cpuinfo. Malware profiles infected systems this way before cryptomining. While inventory tools may use dmidecode, its use by unexpected parents warrants review.
HuntRule TeamLinuxprocess_creationLow329Premium2026-06-30Suspicious Quick Assist Spawning Command Interpreter or Download Tooling via Process Creation
This rule detects the Quick Assist remote assistance tool spawning a command interpreter or download utility, a technique used in social engineering attacks where operators abuse Quick Assist to run scripted downloads. Storm-1811 leveraged this to fetch Qakbot and Cobalt Strike leading to Black Basta ransomware, so a legitimate support binary launching cmd, PowerShell or curl warrants investigation.
HuntRule TeamWindowsprocess_creationMedium121Premium2026-06-30Malicious curl Insecure Download to AppData or Temp
This rule detects curl.exe writing a downloaded file into the AppData or Temp directory using the insecure flag, the ClickFix installation pattern used in OpenClaw brand-lure campaigns to fetch infostealer payloads before immediate execution. Attackers instruct victims to paste a terminal command that curls the payload to a user writable path. Downloading executables into AppData or Temp with certificate checks disabled is a strong staging indicator.
HuntRule TeamWindowsprocess_creationHigh112Premium2026-06-30