Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,316 rules
Malicious setcap Assigning cap_sys_admin for GameOverlay Privilege Escalation (via process_creation)
This rule detects setcap granting effective inheritable and permitted file capabilities such as cap_sys_admin to an executable, the step the GameOverlay Ubuntu OverlayFS exploit CVE-2023-2640 and CVE-2023-32629 uses to smuggle privileged capabilities across a copy-up. Assigning powerful capabilities to non-root executables is a strong local privilege escalation indicator.
HuntRule TeamLinuxprocess_creationHigh102Premium2026-06-27Suspicious Aimmy Cheat Loader Executing Renamed LuaJIT Launcher via process_creation
This rule detects the trojanized Aimmy game cheat that uses Aimmy.bat to launch AimmyLauncher.exe, a renamed LuaJIT interpreter which executes malicious Lua bytecode. The threat abuses a signed scripting engine to run attacker supplied Lua while posing as a gaming aimbot. Flagging the batch launcher and the renamed interpreter surfaces the living off scripting execution chain before the bytecode payload runs.
HuntRule TeamWindowsprocess_creationMedium343Premium2026-06-27Malicious Active Directory Database Backup via wbadmin to Loopback Admin Share (via process_creation)
This rule detects wbadmin backing up the NTDS database and registry hives while including ntds.dit in the target set, the domain credential-theft technique used in the Akira intrusion to copy the directory database via a loopback admin share. Adversaries abuse wbadmin to snapshot ntds.dit and the SYSTEM and SECURITY hives for offline hash extraction, so a wbadmin job referencing ntds.dit is a high-confidence dumping indicator.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-06-27Suspicious Font File Passed as Argument to Script Interpreter via Lua Loader (via process_creation)
This rule detects the TTF Trap loader in which a WScript or CScript host launches a bundled Lua or AutoIt interpreter and passes a file with a .ttf extension as the script to execute. Legitimate font files are never executed as interpreter scripts. This masquerade of a loader script as a font is characteristic of the campaign.
HuntRule TeamWindowsprocess_creationMedium162Premium2026-06-27Malicious Impacket WMIExec ADMIN Share Output Redirection
This rule detects the Impacket wmiexec pattern where a command is executed through WMI and its output is redirected to the local ADMIN$ share on 127.0.0.1. The BlackJack group used WMIExec for remote command execution during lateral movement, and this loopback ADMIN$ redirection is characteristic of the tool.
HuntRule TeamWindowsprocess_creationHigh136Premium2026-06-27Suspicious Root Filesystem Remount as Writable on Appliance via Mount (via process_creation)
This rule detects the mount command remounting the root filesystem as read-write on Linux-based appliances. Actors exploiting Ivanti Connect Secure zero-days remounted the normally read-only appliance filesystem to tamper with installers and plant webshells. Making a hardened appliance root writable is an abnormal precursor to persistence and integrity tampering.
HuntRule TeamLinuxprocess_creationMedium113Premium2026-06-27Suspicious SafeBoot RunOnce Persistence for Safe Mode Encryption by RA World
This rule detects registry additions creating a RunOnce entry under the SafeBoot key, a technique the RA World ransomware group uses to force execution after rebooting the host into safe mode where security tooling is inactive. Encrypting in safe mode evades endpoint defenses that do not load there. Detecting this configuration exposes preparation for defense-evasive ransomware execution.
HuntRule TeamWindowsprocess_creationHigh172Premium2026-06-27Malicious Salat Stealer Microsoft Defender Disable via Multiple Set-MpPreference Flags (via process_creation)
This rule detects PowerShell invoking Set-MpPreference with the behavior, real-time, or script-scanning disable flags used by the Salat Stealer Rust loader to turn off Microsoft Defender protections before deploying its payload. Adversaries leverage this to blind endpoint protection ahead of credential theft and exfiltration, making early detection critical for stopping the intrusion.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-06-27SmartLoader Execution via LuaJIT Interpreter Running Obfuscated Text Script (via process_creation)
This rule detects a renamed LuaJIT interpreter named compiler.exe executing a gc.txt script, the SmartLoader stage delivered through fake AI tools targeting developers. The malware ships lua51.dll and compiler.exe alongside gc.txt so a trusted-looking binary runs an obfuscated Lua payload from a plain text file, making this pairing a reliable loader signal before infostealer retrieval.
HuntRule TeamWindowsprocess_creationMedium417Premium2026-06-27Suspicious Larva-24009 Scheduled Task Masquerading as Google Update or Intel Driver (via process_creation)
This rule detects schtasks creation of persistence tasks whose names impersonate legitimate Google update or Intel Ethernet driver tasks as used by the Larva-24009 phishing campaign. Attackers reuse trusted task naming to blend malicious persistence with normal scheduled jobs.
—Windowsprocess_creationMedium131Premium2026-06-27Suspicious Hardcoded Legacy Chrome User-Agent from Sparkling Pisces Tooling (via proxy)
This rule detects HTTP requests carrying the hardcoded legacy user-agent string Chrome/31.0.1650.57 embedded in Sparkling Pisces malware. Traffic from this obsolete browser version is anomalous on modern networks and can reveal the keylogger or backdoor beaconing out.
HuntRule TeamWebproxyMedium52Premium2026-06-26Suspicious Gh0stGambit Run Key Persistence for Phone Executable
This rule detects a Run key value named Phone pointing at a Phone executable being written for persistence. The Gh0stGambit dropper set this autorun entry to relaunch its payload across reboots. Autorun persistence under this specific value and image name maps to the Gh0st RAT deployment chain.
HuntRule TeamWindowsregistry_setHigh51Premium2026-06-26Malicious Event Log Cleared - Native (via security, system)
This rule detects cleared the event logs.
HuntRule TeamWindowssecurity, systemHigh349Premium2026-06-26Suspicious Vidar Second-Stage Download via Structured index.zip Dropzone Paths (via proxy)
This rule detects HTTP requests for index.zip archives under file-type-segmented dropzone paths such as /pe/, /dll/, /py/, /ps/ and /bat/, the second-stage retrieval pattern used by an access-code-gated DocuSign-themed delivery chain that dropped the Vidar information stealer as analyzed by Joe Sandbox. Adversaries organize payload dropzones by artifact type behind an access gate, so requests matching this structured path layout indicate retrieval of a staged payload.
HuntRule TeamWebproxyMedium61Premium2026-06-26Suspicious Rundll32 Loading DLL From User Desktop
This rule detects rundll32.exe loading a DLL located under a user Desktop directory, a staging pattern seen when LockBit 3.0 payloads were dropped alongside a launcher batch file during hands-on-keyboard intrusions. Legitimate software rarely places and runs DLLs directly from the Desktop. Flagging this location reveals attacker-controlled payloads executed via a trusted signed binary.
HuntRule TeamWindowsprocess_creationMedium438Premium2026-06-26