Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,323 rules
Suspicious Renamed git Binary gcmd.exe Execution (via process_creation)
This rule detects execution of gcmd.exe, a renamed copy of the legitimate git binary used by APT-C-60 to proxy execution of its loader from a masqueraded LICENSES.LOG directory. Renaming a signed tool defeats name-based allowlists while preserving the trusted binary behavior the actor relies on.
HuntRule TeamWindowsprocess_creationHigh143Premium2026-06-24Suspicious HiddenGh0st Rootkit Driver QAssist Written to System32 (via file_event)
This rule detects the creation of the QAssist.sys rootkit driver in the System32 directory as used by the HiddenGh0st malware to hide its files and activity. A newly written kernel driver with this name is a strong indicator of the rootkit component.
—Windowsfile_eventMedium234Premium2026-06-24Malicious Winlogon Shell Persistence Modification (via registry_set)
This rule detects modification of the Winlogon Shell registry value to something other than the default explorer.exe, a persistence technique used by MuddyWater per Group-IB. Adversaries alter the Winlogon Shell entry so their payload launches at every interactive logon, making changes to this value a strong persistence signal.
HuntRule TeamWindowsregistry_setHigh133Premium2026-06-24Suspicious Internet Explorer Helper Process Network Connection via network_connection
This rule detects outbound network connections originating from rarely-networked Internet Explorer helper binaries such as ieinstal.exe and ielowutil.exe. The REMCOS RAT injects into these signed processes to blend command-and-control traffic with trusted executables. Network activity from these utilities is anomalous and suggests process injection for evasion.
HuntRule TeamWindowsnetwork_connectionMedium101Premium2026-06-24SumatraPDF Execution from User Download Directory in Operation DreamJob (via process_creation)
This rule detects SumatraPDF.exe executing from a Downloads or Temp directory, matching the Operation DreamJob delivery in which a ZIP archive bundles a decoy PDF with a portable SumatraPDF.exe and a malicious libmupdf.dll for side-loading. Adversaries ship a portable signed reader alongside their loader so a single user action triggers execution from an untrusted location.
HuntRule TeamWindowsprocess_creationMedium325Premium2026-06-24Suspicious Process Execution from CHM Help File (via process_creation)
This rule detects the compiled HTML help viewer hh.exe spawning a command shell or PowerShell. The PHANTOM#SPIKE campaign delivered a malicious CHM file whose embedded script launched a hidden backdoor executable.
HuntRule TeamWindowsprocess_creationHigh232Premium2026-06-24Suspicious Single-Character Named Batch Script Execution Linked to Salt Typhoon
This rule detects the command interpreter executing a batch file whose name is a single character, an obfuscation and staging pattern observed in Salt Typhoon intrusions. One-letter script names are an anomalous convention rarely used by legitimate software, so single-character batch execution is a heuristic indicator of scripted attacker tooling.
HuntRule TeamWindowsprocess_creationMedium131Premium2026-06-24Malicious Chisel Reverse SOCKS Proxy Execution (via process_creation)
This rule detects command-line arguments consistent with a Chisel reverse SOCKS proxy client, tooling deployed by Turla during TinyTurla-NG operations. The reverse tunnel exposes internal hosts to attacker infrastructure and enables pivoting through the compromised network.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-06-24Malicious Langflow Exploitation Marker File Creation
This rule detects creation of the lang_pwn marker file that the Langflow CVE-2026-55255 exploitation chain drops to confirm successful code execution. The file acts as a proof-of-exploitation beacon left in the temp directory. Its presence is a high-confidence indicator that the host was compromised through the Langflow vulnerability.
HuntRule TeamLinuxfile_eventHigh209Premium2026-06-24Suspicious Network Connection From CUPS Foomatic-Rip Child Process
This rule detects an outbound network connection initiated by a child of the foomatic-rip print filter which indicates post-exploitation activity following abuse of the CUPS printing vulnerability. Adversaries who gain execution through the print filter reach out to command and control or download additional tooling from the compromised host.
HuntRule TeamLinuxnetwork_connectionHigh228Premium2026-06-24Suspicious Data Exfiltration to Telegram Bot API sendDocument (via proxy)
This rule detects HTTP requests to the Telegram Bot API sendDocument endpoint, the exfiltration channel used by 0bj3ctivityStealer to upload harvested credentials and wallet data as documents to an attacker-controlled bot. Adversaries leverage Telegram as a resilient exfiltration service that blends with legitimate traffic, making detection of bot document uploads useful for exposing data theft.
HuntRule TeamWebproxyMedium123Premium2026-06-24VSS Backup Deletion via WMI - Powershell (via powershell)
This rule detects delete existing VSS backup via WMI.
HuntRule TeamWindowspowershellHigh134Premium2026-06-24Suspicious Scheduled Task Creation Running as SYSTEM via Schtasks
This rule detects creation of a scheduled task configured to run under the SYSTEM account which the BLOODALCHEMY backdoor uses to establish elevated persistence. Creating SYSTEM level tasks via schtasks is a common attacker technique to survive reboots and run with maximum privileges though some administrative tooling may also do this.
HuntRule TeamWindowsprocess_creationMedium161Premium2026-06-24Suspicious NTDS Database Dump File Creation
This rule detects creation of files with an NTDS dump naming pattern which ransomware operators produce when extracting the Active Directory database for offline credential theft. Observed in NCC Group research into active ransomware families dumping NTDS content to text files. Capturing NTDS extraction artifacts helps detect domain-wide credential theft.
HuntRule TeamWindowsfile_eventMedium439Premium2026-06-24Malicious TeamPCP LiteLLM .pth Startup Hook and Payload Dropper (via file_event)
This rule detects the litellm_init.pth site-packages file and the p.py payload dropped by the trojanized LiteLLM PyPI releases 1.82.7 and 1.82.8 published by TeamPCP. The .pth mechanism forces arbitrary code execution during any Python interpreter startup so writing these files establishes a supply-chain backdoor that steals API keys SSH keys and cloud credentials.
HuntRule TeamLinuxfile_eventHigh151Premium2026-06-23