Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,318 rules
Suspicious Vidar Second-Stage Download via Structured index.zip Dropzone Paths (via proxy)
This rule detects HTTP requests for index.zip archives under file-type-segmented dropzone paths such as /pe/, /dll/, /py/, /ps/ and /bat/, the second-stage retrieval pattern used by an access-code-gated DocuSign-themed delivery chain that dropped the Vidar information stealer as analyzed by Joe Sandbox. Adversaries organize payload dropzones by artifact type behind an access gate, so requests matching this structured path layout indicate retrieval of a staged payload.
HuntRule TeamWebproxyMedium61Premium2026-06-26Suspicious Rundll32 Loading DLL From User Desktop
This rule detects rundll32.exe loading a DLL located under a user Desktop directory, a staging pattern seen when LockBit 3.0 payloads were dropped alongside a launcher batch file during hands-on-keyboard intrusions. Legitimate software rarely places and runs DLLs directly from the Desktop. Flagging this location reveals attacker-controlled payloads executed via a trusted signed binary.
HuntRule TeamWindowsprocess_creationMedium438Premium2026-06-26Suspicious Outlook Security Manager DLL Load for Mail Harvesting (via image_load)
This rule detects the Grandoreiro banking trojan loading the secman or secman64 Outlook Security Manager component to iterate mailbox folders and harvest addresses for spam propagation. These third-party COM libraries are rarely present on standard endpoints. Their appearance alongside Outlook automation indicates mailbox collection.
HuntRule TeamWindowsimage_loadMedium132Premium2026-06-26Malicious GhostSocks Loader Execution with johnpidar Argument via process_creation
This rule detects process command lines containing the distinctive johnpidar argument. This hardcoded flag is passed to the GhostSocks loader delivered by fake OpenClaw installers, and its presence on a command line is a strong indicator of active infostealer and SOCKS proxy execution on the host.
HuntRule TeamWindowsprocess_creationHigh3910Premium2026-06-26Malicious rundll32 Loading DLL from WebDAV SSL Share
This rule detects rundll32 loading a DLL from a WebDAV SSL share indicated by the @SSL path token, an intrusion step observed in ACR Stealer delivery chains. Executing a remotely hosted DLL over WebDAV lets the attacker run code without writing the payload to local disk and evades application controls.
HuntRule TeamWindowsprocess_creationHigh223Premium2026-06-26Suspicious Scheduled Task Creation Spawned by Microsoft Office
This rule detects a Microsoft Office application spawning schtasks to register a scheduled task which mirrors the Cobalt Kitty initial access chain described by WithSecure where a malicious Word document created a persistence task. An Office document launching schtasks is highly abnormal and typically indicates macro driven persistence or execution following a phishing lure.
HuntRule TeamWindowsprocess_creationHigh1410Premium2026-06-26Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs
This rule detects a delegated permission grant that targets an Entra agent blueprint access_agent scope, the consent step that lets an attacker-controlled app drive an assistive AI agent. Adversaries obtain delegated access to agents that can send mail and act on the user behalf, so a grant referencing access_agent indicates agent hijacking through illicit consent.
HuntRule TeamAzureauditlogsHigh427Premium2026-06-26Suspicious Forest Blizzard GooseEgg Batch Launcher Chain (via process_creation)
This rule detects execution of the GooseEgg batch launcher files that write and invoke servtask.bat. Forest Blizzard used execute.bat and doit.bat to drop servtask.bat and trigger CVE-2022-38028 privilege escalation.
HuntRule TeamWindowsprocess_creationMedium72Premium2026-06-26Suspicious SCMBanker Remote Utilities RMM Install via Silent Msiexec
This rule detects a silent MSI install of the hosts.msi package which SCMBanker uses to deploy the Remote Utilities RMM agent for hands-on-keyboard control during banking fraud. Attackers abuse legitimate remote-management software to evade endpoint controls and maintain interactive access. A quiet install of this specific package indicates unauthorized RMM deployment.
HuntRule TeamWindowsprocess_creationMedium153Premium2026-06-26Suspicious Sudoers NOPASSWD Rule Written For Passwordless Privilege Escalation
This rule detects writes to the sudoers configuration that grant passwordless all-command access which adversaries use to establish persistent privilege escalation on Linux hosts. Granting NOPASSWD ALL to a controlled account lets an attacker reliably regain root without supplying credentials.
HuntRule TeamLinuxprocess_creationHigh434Premium2026-06-26Suspicious AppleScript Execution via osascript Inline Command
This rule detects osascript invoked with an inline -e command on macOS, the AppleScript execution technique used by the AMOS stealer to display fake password prompts and drive credential theft. While osascript has legitimate administrative uses, inline execution from unexpected parents is a common stealer behavior. This should be reviewed alongside process lineage and subsequent credential access.
HuntRule TeamMacosprocess_creationMedium131Premium2026-06-26Malicious TELEPUZ ClickFix Stager via Hidden PowerShell Grab Endpoint
This rule detects a hidden execution-policy-bypass PowerShell command that pulls a payload from an index.php grab endpoint which is the ClickFix stager of the TELEPUZ malware-as-a-service delivered through Vidar chains. Victims are lured into pasting the command from a fake verification prompt. The specific grab API path combined with bypass flags marks the malicious download.
HuntRule TeamWindowsprocess_creationHigh203Premium2026-06-26Suspicious Entra Sign-In Interrupt With High Aggregated Risk via AiTM DNS Hijacking (via azure)
This rule surfaces Microsoft Entra sign-ins carrying a high aggregated risk score alongside interrupt or success result codes, the pattern seen when SOHO router DNS hijacking redirects victims through an adversary-in-the-middle proxy that replays authentication. Adversaries use the hijacked DNS to intercept credentials and tokens, so high-risk sign-ins clustered with these result codes warrant investigation for token theft and mailbox access.
HuntRule TeamAzuresigninlogsMedium354Premium2026-06-26Suspicious DeadLock Ransomware C2 Proxy Request to prrq.php Endpoint (via proxy)
This rule detects HTTP requests to the /prrq.php proxy endpoint used by DeadLock ransomware to reach C2 proxy servers whose addresses are rotated through Polygon smart contracts per Group-IB. Adversaries route control and ransom-negotiation traffic through these proxy PHP endpoints, so requests to this path signal DeadLock C2 activity.
HuntRule TeamWebproxyMedium192Premium2026-06-26Malicious Cobalt Strike C2 Beaconing via REST URI Paths and Legacy MSIE User-Agent (via proxy)
This rule detects HTTP command-and-control beaconing that combines the /rest/funcStatus and /rest/policy/3/ URI paths with a legacy MSIE 7.0 .NET CLR User-Agent, a Malleable C2 profile used by a multi-stage Cobalt Strike loader analyzed by Joe Sandbox. Adversaries craft these profiles to blend beacon traffic into ordinary web requests, making the combined URI and User-Agent pattern a reliable signal of an active beacon before hands-on-keyboard activity.
HuntRule TeamWebproxyHigh375Premium2026-06-26