Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,318 rules
Possible Adversary-in-the-Middle Proxy Login via Crafted URL Parameters
This rule detects HTTP requests carrying the qrc and login_hint URL parameters used by an adversary-in-the-middle proxy that relays victims to a spoofed Outlook login page. This tradecraft was observed in an HTML smuggling campaign that harvested Microsoft 365 credentials and session tokens. AiTM session theft bypasses multi-factor authentication and enables account takeover.
HuntRule TeamWebproxyMedium142Premium2026-06-26Malicious APT29 DLL Side-Loading via msoev.exe from Windows Tasks Directory (via process_creation)
This rule detects the signed msoev binary executing from the Windows Tasks directory, the side-loading launcher APT29 used to load the Duke malware in the German Embassy lure campaign. Running this legitimate binary from C:\Windows\Tasks side-loads a malicious Mso DLL from the same folder. Execution of msoev from this path is highly anomalous.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-06-25Suspicious GCP Log Sink Tampering for Defense Evasion (via gcp)
This rule detects Google Cloud audit-log operations that update, disable, or delete logging sinks and buckets, a defense-evasion tactic used to blind visibility during cloud attacks. Adversaries suppress log export so their subsequent actions are not recorded.
HuntRule TeamGcpgcp.auditMedium396Premium2026-06-25Malicious SQL SA Admin User Enabled (via application)
This rule detects enables the disabled (recommended) SA admin account on the SQL Server instance.
HuntRule TeamMssqlapplicationHigh132Premium2026-06-25Suspicious EastWind Named Pipe Creation
This rule detects creation of a named pipe whose name starts with the Y prefix used by EastWind implants for inter-process communication and local tasking. Named pipes with this structure support covert component coordination, so their appearance on endpoints should be correlated with the DRM staging activity.
HuntRule TeamWindowspipe_createdMedium103Premium2026-06-25Malicious IIS Native Module Installation via Appcmd IsapiCachesModule (via process_creation)
This rule detects appcmd.exe installing a native IIS module named IsapiCachesModule backed by a caches.dll image as used by the Larva-25003 IIS malware. Registering a malicious native module allows the actor to intercept and manipulate all HTTP traffic on the server.
—Windowsprocess_creationHigh122Premium2026-06-25Suspicious Ivanti Dropper Hidden Files in /tmp During CVE-2025-22457 Exploitation (via file_event)
This rule detects creation of the hidden single-letter dropper files in /tmp used during CVE-2025-22457 exploitation to stage the TRAILBLAZE and BRUSHFIRE injection chain. These short hidden paths on the Ivanti appliance indicate active exploitation and payload staging.
HuntRule TeamLinuxfile_eventMedium101Premium2026-06-25Malicious File Upload to SAP NetWeaver Metadata Uploader Endpoint
This rule detects HTTP POST requests to the SAP NetWeaver Visual Composer metadatauploader endpoint exploited in CVE-2025-31324. Threat actors abuse this unauthenticated upload flaw to drop JSP web shells and achieve remote code execution on internet-facing SAP servers. Detecting these uploads catches initial access before web shell deployment.
HuntRule TeamWebwebserverHigh132Premium2026-06-25Suspicious Vulnerable Driver Load for BYOVD Abuse by DragonForce Ransomware (via driver_load)
This rule detects loading of the TrueSight.sys or RentDrv.sys vulnerable drivers that DragonForce abuses in a bring-your-own-vulnerable-driver technique to call ZwTerminateProcess and disable endpoint protection. Attackers exploit these signed drivers to kill security agents from kernel space. Flagging their load exposes tampering with defensive tooling.
HuntRule TeamWindowsdriver_loadMedium3710Premium2026-06-25Malicious System Crash Behavior Manipulation - WMImplant - Registry (via registry_event)
This rule detects abuses the Windows "system failure and recovery" capacities (CrashControl) to store information or to establish persistence.
HuntRule TeamWindowsregistry_eventHigh419Premium2026-06-25Malicious Head Mare Credential Dumping via XenAllPasswordPro
This rule detects execution of XenAllPasswordPro with the -a switch writing to report.html, the credential-recovery tool used by Head Mare to harvest stored passwords into an HTML report. Presence of this dual-use recovery utility in an interactive attack context signals active credential theft.
HuntRule TeamWindowsprocess_creationHigh105Premium2026-06-25Possible Citrix NetScaler CVE-2023-4966 Session Token Disclosure
This rule detects HTTP requests to the OpenID configuration discovery endpoints on Citrix NetScaler that are abused by CVE-2023-4966 to disclose session memory and steal valid session tokens. When paired with an abnormally large Host header these requests indicate exploitation attempts against an exposed NetScaler appliance for session hijacking.
HuntRule TeamWebwebserverMedium111Premium2026-06-25Malicious IIS Worker Process Spawning Command Shell via process_creation
This rule detects the IIS worker process w3wp.exe spawning a command interpreter, PowerShell or certutil which is a strong indicator of web shell command execution on a compromised web server. Kaspersky observed a Behinder web shell driving w3wp.exe to launch cmd.exe and download follow-on payloads. Web shell to shell transitions are an early sign of hands-on-keyboard server intrusion.
HuntRule TeamWindowsprocess_creationHigh113Premium2026-06-25Uncommon Kimsuky OneNote Document Spawning Script Interpreter (via process_creation)
This rule detects Microsoft OneNote launching a scripting or shell interpreter such as wscript, cscript, mshta, cmd or powershell, the execution behavior seen when Kimsuky embeds rows of VBS files inside a .ONE document disguised with a Hangul document icon. OneNote spawning an interpreter is abnormal for legitimate note-taking and is a reliable indicator of embedded-object abuse for initial execution.
HuntRule TeamWindowsprocess_creationHigh345Premium2026-06-25Possible CVE-2023-23397 Outlook Forced Authentication via Outbound LDAP (via network_connection)
This rule detects a Windows host initiating an outbound LDAP or Global Catalog connection to a non-private external address, which is anomalous because directory traffic normally stays inside the enterprise. Exploitation of CVE-2023-23397 can direct a client to an external LDAP endpoint as part of the forced authentication chain against Microsoft Outlook. Traffic to an external directory service indicates possible credential coercion or beaconing and warrants investigation.
HuntRule TeamWindowsnetwork_connectionMedium131Premium2026-06-25