Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,286 rules
Malicious ValleyRAT KernelQuick Rootkit Service and Shellcode Store Registry Keys
This rule detects registry writes to the kernelquick kernel-driver service key and to the HKLM\SOFTWARE\IpDates key used by ValleyRAT's kernel rootkit component to register its driver and stash shellcode. These fixed key names are unique to the ValleyRAT rootkit and indicate installation of its kernel-level hiding and persistence layer.
HuntRule TeamWindowsregistry_setHigh80Premium2026-09-09Malicious Silver Fox BYOVD Vulnerable Driver Service Creation
This rule detects creation of the kernel service entries named Termaintor or Amsdk_Service that the Silver Fox APT registers to load the vulnerable amsdk.sys driver in a bring-your-own-vulnerable-driver attack. The driver is abused via IOCTL 0x80002048 to terminate security product processes, so these service names indicate an in-progress endpoint-defense-disabling operation preceding ValleyRAT injection.
HuntRule TeamWindowsregistry_setHigh80Premium2026-09-09Malicious WezRat Persistence via Chrome Updater Run Key
This rule detects a Run key value named Chrome Updater pointing to Updater.exe, the persistence and masquerade used by the WezRat backdoor. The malware disguises its autostart as a Chrome update component to appear benign. Detecting the named value with its Updater.exe target exposes the implant persistence.
HuntRule TeamWindowsregistry_setHigh120Premium2026-09-09Malicious Windows Defender Exclusion Added (via registry_set)
This rule detects new Windows Defender exclusion entries for paths or processes, a defense evasion step used by Raspberry Robin to prevent detection of its payloads. Attacker-driven exclusion writes let malware run unscanned, so unexpected additions to the Defender Exclusions keys are high-value indicators.
HuntRule TeamWindowsregistry_setHigh80Premium2026-09-09Malicious RemusStealer Credential Exfiltration to pics TLD C2
This rule detects HTTP POST requests to hosts under the .pics top-level domain whose body carries access_token and step parameters, the exfiltration pattern of RemusStealer distributed by this ecosystem. This structured upload to an uncommon TLD signals active credential and session-token theft.
HuntRule TeamWebproxyHigh110Premium2026-09-09Malicious NSIS_InetLoad User-Agent C2 Traffic in Malware Distribution Ecosystem
This rule detects outbound HTTP requests carrying the User-Agent NSIS_InetLoad (Mozilla), a fixed string emitted by NSIS-based downloaders in this malware distribution ecosystem when fetching second-stage payloads. This unusual agent is a reliable network indicator of the loader stage.
HuntRule TeamWebproxyHigh170Premium2026-09-09Suspicious TrueConf Update Chain Spawning Temporary Executable in Operation TrueChaos
This rule detects trueconf_windows_update.exe launching a .tmp executable, the supply-chain execution chain observed in Operation TrueChaos where a trojanized TrueConf updater drops and runs a Havoc payload. A signed-looking updater executing a temporary binary is anomalous and marks the initial loader stage.
HuntRule TeamWindowsprocess_creationHigh130Premium2026-09-09Suspicious Termination of Windows Security Health UI via taskkill
This rule detects forced termination of SecHealthUI.exe, the Windows Security notification UI, via taskkill, an action GachiLoader takes to suppress security alerts to the user. Killing the Defender interface component is a defense-evasion behavior with little legitimate cause.
HuntRule TeamWindowsprocess_creationHigh120Premium2026-09-09Malicious ValleyRAT RuntimeBroker Masquerade in RunTime Directory
This rule detects execution of RuntimeBroker.exe from C:\Program Files\RunTime, a masquerading location used by the Silver Fox APT to deploy its ValleyRAT loader. The legitimate RuntimeBroker.exe lives in System32, so a same-named binary under a RunTime folder is a trusted-name wrong-context indicator of the ValleyRAT dropper.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-09Malicious Shadow Copy Deletion via vssadmin
This rule detects vssadmin deleting all volume shadow copies quietly, an inhibit recovery step in the FunkSec ransomware chain. Removing shadow copies prevents victims from restoring encrypted files. Detecting it exposes recovery sabotage that typically precedes encryption.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-09Malicious Security Event Log Disabled via wevtutil
This rule detects wevtutil disabling the Security event log channel, a logging impairment used by FunkSec ransomware to hide its actions. Disabling the Security log blinds defenders to subsequent malicious activity. Detecting the command surfaces anti forensic behavior on the host.
HuntRule TeamWindowsprocess_creationHigh120Premium2026-09-09Malicious Defender Real Time Monitoring Disabled via Set-MpPreference
This rule detects PowerShell disabling Microsoft Defender real time monitoring through Set-MpPreference, an impairment step in the FunkSec ransomware routine. Turning off real time protection lets the encryptor and its tools run without interference. Detecting the command exposes defense evasion before encryption.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-09-09Possible Akira Ransomware VM Shutdown via vim-cmd
This rule detects use of vim-cmd to power off virtual machines on an ESXi host, a step the Akira Rust ransomware performs before encrypting VM files. The encryptor enumerates guests with getallvms and forces them off to release locked disks. Detecting it can stop the attack before mass encryption begins.
HuntRule TeamLinuxprocess_creationHigh50Premium2026-09-09Malicious BugSleep Scheduled Task Persistence with Sample Comment
This rule detects creation of a scheduled task carrying the literal description sample comment, a fingerprint of the BugSleep backdoor deployed by MuddyWater. The malware registers a task named after its mutex with this hardcoded comment and a thirty minute trigger. Detecting the constant comment string exposes the backdoor persistence.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-09Suspicious PowerShell Execution via SyncAppvPublishingServer LOLBIN
This rule detects abuse of the signed SyncAppvPublishingServer.vbs script to proxy execution of PowerShell, a technique used in the GuLoader to Remcos infection chain. The LNK lure invokes this LOLBIN to run obfuscated PowerShell that stages shellcode. Detecting the script use surfaces the proxied execution step of the chain.
HuntRule TeamWindowsprocess_creationHigh90Premium2026-09-09