Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,321 rules
Malicious IIS Worker Process Spawning Command Shell via process_creation
This rule detects the IIS worker process w3wp.exe spawning a command interpreter, PowerShell or certutil which is a strong indicator of web shell command execution on a compromised web server. Kaspersky observed a Behinder web shell driving w3wp.exe to launch cmd.exe and download follow-on payloads. Web shell to shell transitions are an early sign of hands-on-keyboard server intrusion.
HuntRule TeamWindowsprocess_creationHigh113Premium2026-06-25Uncommon Kimsuky OneNote Document Spawning Script Interpreter (via process_creation)
This rule detects Microsoft OneNote launching a scripting or shell interpreter such as wscript, cscript, mshta, cmd or powershell, the execution behavior seen when Kimsuky embeds rows of VBS files inside a .ONE document disguised with a Hangul document icon. OneNote spawning an interpreter is abnormal for legitimate note-taking and is a reliable indicator of embedded-object abuse for initial execution.
HuntRule TeamWindowsprocess_creationHigh345Premium2026-06-25Possible CVE-2023-23397 Outlook Forced Authentication via Outbound LDAP (via network_connection)
This rule detects a Windows host initiating an outbound LDAP or Global Catalog connection to a non-private external address, which is anomalous because directory traffic normally stays inside the enterprise. Exploitation of CVE-2023-23397 can direct a client to an external LDAP endpoint as part of the forced authentication chain against Microsoft Outlook. Traffic to an external directory service indicates possible credential coercion or beaconing and warrants investigation.
HuntRule TeamWindowsnetwork_connectionMedium131Premium2026-06-25Suspicious Double Extension PDF Executable via Process Creation
This rule detects execution of a file using a .pdf.exe double extension. The Lumma stealer is distributed with this masquerading trick so the payload appears to be a document while it is in fact an executable, tricking users into launching the stealer.
HuntRule TeamWindowsprocess_creationMedium367Premium2026-06-25Suspicious CTF-Framed Vulnerability Scanner User Agent via Webserver
This rule detects HTTP User-Agents matching the CTF and CVE-hunt framing that attackers use while jailbreaking LLM services and mass-scanning for vulnerabilities. These agents self-identify with capture-the-flag and CVE-scanner labels as part of automated probing. Their presence indicates reconnaissance against internet-facing AI applications.
HuntRule TeamWebwebserverMedium238Premium2026-06-25Suspicious SugarGh0st Persistence via CTFMON Masqueraded Run Key (via registry_set)
This rule detects a Run key persistence entry referencing CTFM0N.exe, a binary named to impersonate the legitimate ctfmon.exe with a zero substituted for the letter O. The SugarGh0st RAT used this masqueraded autorun value to survive reboot.
HuntRule TeamWindowsregistry_setHigh92Premium2026-06-25Suspicious Remote Execution via WMIC Node Process Call Create
This rule detects wmic.exe with the node parameter invoking process call create which the ColunmTK APT41 cluster uses to run install.bat on remote hosts for lateral movement. The technique executes commands against a specified target without dropping a service binary. It is important because remote WMIC execution is a stealthy hands-on-keyboard propagation method.
HuntRule TeamWindowsprocess_creationMedium63Premium2026-06-25Suspicious GigaWiper Execution Counter under OneDrive Environment Key
This rule detects writes to the HKCU SOFTWARE OneDrive Environment key which GigaWiper abuses as an execution counter to track its wiping stages. This uncommon registry location under a OneDrive branded path is a distinctive marker of the destructive backdoor tracking its own progress.
HuntRule TeamWindowsregistry_setMedium74Premium2026-06-25Malicious Volume Shadow Copy Deletion via vssadmin by RA World
This rule detects deletion of all volume shadow copies through vssadmin, an inhibit-recovery action the RA World ransomware group performs to prevent victims from restoring encrypted files. Destroying shadow copies is a hallmark of ransomware staging. Detecting this exposes imminent or in-progress encryption impact on the host.
HuntRule TeamWindowsprocess_creationHigh242Premium2026-06-24Possible Mamba 2FA AiTM Phishing URL Pattern
This rule detects HTTP requests matching the Mamba 2FA adversary in the middle phishing URL structure of a single letter path segment m, n or o followed by a query string carrying a Base64 encoded victim token. Mamba 2FA relays Microsoft 365 credentials and session cookies through this pattern to bypass multifactor authentication. Because the pattern is broad it should be corroborated with the known relay domains before action.
HuntRule TeamWebproxyLow354Premium2026-06-24Suspicious Restic Cloud Backup Exfiltration via Renamed winupdate Binary via process_creation
This rule detects the restic backup tool being run, including copies renamed to winupdate.exe, with arguments targeting a Wasabi or S3 object store. The threat actor renamed restic to a Windows-update-like name and used it to back up and exfiltrate victim data to attacker-controlled cloud storage, so this pattern indicates staged bulk exfiltration disguised as backup activity.
HuntRule TeamWindowsprocess_creationHigh182Premium2026-06-24Malicious UAC Bypass via ms-settings Shell Open Command Registry Hijack (via registry_set)
This rule detects modification of the ms-settings protocol handler shell open command under the current user classes hive, the registry hijack that a Kimsuky campaign chained to trigger a batch file with elevated rights through fodhelper style auto-elevation. Adversaries leverage this key because trusted binaries query it while running high integrity, making early detection critical for catching privilege escalation before elevated payload execution.
HuntRule TeamWindowsregistry_setHigh121Premium2026-06-24Suspicious Octo Tempest Domain and Network Reconnaissance Tooling (via process_creation)
This rule detects execution of reconnaissance utilities such as PingCastle ADRecon and Advanced IP Scanner. Octo Tempest ran these tools to map Active Directory and the internal network for lateral movement and targeting.
HuntRule TeamWindowsprocess_creationMedium102Premium2026-06-24Suspicious Renamed git Binary gcmd.exe Execution (via process_creation)
This rule detects execution of gcmd.exe, a renamed copy of the legitimate git binary used by APT-C-60 to proxy execution of its loader from a masqueraded LICENSES.LOG directory. Renaming a signed tool defeats name-based allowlists while preserving the trusted binary behavior the actor relies on.
HuntRule TeamWindowsprocess_creationHigh143Premium2026-06-24Suspicious HiddenGh0st Rootkit Driver QAssist Written to System32 (via file_event)
This rule detects the creation of the QAssist.sys rootkit driver in the System32 directory as used by the HiddenGh0st malware to hide its files and activity. A newly written kernel driver with this name is a strong indicator of the rootkit component.
—Windowsfile_eventMedium234Premium2026-06-24