Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,323 rules
Malicious Triada binder.so Planted in Android System Framework
This rule detects creation of a binder.so library inside the Android system framework arm directory which the Triada trojan replaces to hook Zygote and inject into every app process. This system-level modification gives the malware persistent control over the device including clipboard wallet clipping and premium SMS abuse. A write to the framework native library path is highly abnormal on a clean device.
HuntRule TeamAndroidfile_eventHigh235Premium2026-06-23Suspicious File Download via certutil urlcache
This rule detects certutil used with the urlcache and split flags to download a remote file, an ingress tool transfer technique observed in the REF7707 espionage campaign. Adversaries abuse the signed certutil utility to retrieve payloads while blending in with trusted Windows binaries. This flag combination has no routine administrative use and reliably indicates tooling download.
HuntRule TeamWindowsprocess_creationHigh337Premium2026-06-23Suspicious Python Interpreter Execution Spawned by Script Host (via process_creation)
This rule detects python.exe launched by a Windows script host or command shell, matching the multi-stage URL to LNK to VBS to Python chain used in the Cloudflare tunnel RAT campaigns. Bundled Python installers were staged from WebDAV shares before running the interpreter.
HuntRule TeamWindowsprocess_creationMedium132Premium2026-06-23In-Memory Enabling of WDigest Cleartext Credential Caching (via registry_set)
This rule detects the UseLogonCredential value being set under the WDigest security provider, which forces Windows to cache cleartext passwords in memory so they can be harvested from LSASS. Re-enabling WDigest credential caching is a credential-access preparation technique tracked in the Red Canary Threat Detection Report. Detecting this registry change surfaces an attacker priming the host for plaintext credential theft.
HuntRule TeamWindowsregistry_setHigh325Premium2026-06-23Suspicious Minute-Interval Scheduled Task For MSCheck Backdoor (via process_creation)
This rule detects creation of a minute-recurring scheduled task launching an MSCheck executable, the persistence mechanism used by the Stealth Soldier backdoor. A frequent scheduled task pointing at a masqueraded system-update binary is characteristic of implant persistence rather than legitimate maintenance.
HuntRule TeamWindowsprocess_creationMedium91Premium2026-06-23Suspicious Scheduled Task with NetworkProfile Event Trigger (via process_creation)
This rule detects schtasks creating a task triggered on Microsoft-Windows-NetworkProfile operational events. The PHANTOM#SPIKE campaign used this uncommon event based trigger to persistently launch a custom CSharp backdoor.
HuntRule TeamWindowsprocess_creationHigh123Premium2026-06-23CastleLoader Stager HTTP Beacon via Misspelled GoogeBot User-Agent (via proxy)
This rule detects outbound HTTP requests carrying the misspelled GoogeBot user-agent used by the CastleLoader stager to retrieve follow-on TAG-150 payloads while masquerading as a search-engine crawler. Adversaries leverage crawler-like user-agents to blend malicious downloads into ordinary web traffic, making this distinctive typo a reliable delivery-stage indicator.
HuntRule TeamWebproxyHigh191Premium2026-06-23Suspicious SSRF Probe for Cloud Instance Metadata Service
This rule detects HTTP requests attempting to reach the cloud instance metadata service link local address through a url parameter. Attackers abuse server side request forgery to pull IAM security credentials from the metadata endpoint of a misconfigured public facing application.
HuntRule TeamWebwebserverHigh102Premium2026-06-23Malicious Credential Dumping via XenAllPasswordPro
This rule detects execution of the XenAllPasswordPro password recovery utility. The Crypt Ghouls group ran this tool to harvest stored credentials into an HTML report during their intrusions, and its presence on endpoints is rarely legitimate.
HuntRule TeamWindowsprocess_creationHigh229Premium2026-06-23Renamed Grandoreiro DLL Sideloading via mingwm10 from User-Writable Path (via image_load)
This rule detects a process loading a mingwm10 runtime DLL from a user-writable directory, the side-loading vehicle used by the Grandoreiro banking trojan in its Brazil-to-Mexico campaign where a renamed Duplicate Files Finder binary loads a malicious mingwm10 DLL. Adversaries drop the trojanized runtime beside a relocated legitimate binary to execute under a trusted process. Loads from download or temp paths rather than an install directory are anomalous.
HuntRule TeamWindowsimage_loadLow121Premium2026-06-23Suspicious Reactivation of Guest Account via net user (UAT-8099)
This rule detects reactivation of the built-in Guest account using net user guest with the active flag. UAT-8099 re-enables and elevates the Guest account to maintain covert administrative access to compromised IIS servers. Enabling the normally disabled Guest account is an account-manipulation persistence technique.
HuntRule TeamWindowsprocess_creationHigh317Premium2026-06-23IDAT Loader Delivery via Compromised WordPress wpstream youtube.min.js (via proxy)
This rule detects HTTP requests to the wpstream plugin youtube.min.js path used by the UAC-0184 IDAT Loader campaign to stage its steganographic payload from a compromised WordPress site. Adversaries leverage a legitimate-looking script path on a hijacked site to blend delivery traffic with normal content requests, making early detection critical for catching the intrusion at the delivery stage before Remcos RAT is deployed.
HuntRule TeamWebproxyMedium133Premium2026-06-23Malicious Scheduled Task EPolicyManager by Squidoor (via process_creation)
This rule detects creation of the scheduled task Microsoft\Windows\AppID\EPolicyManager used by the Squidoor backdoor to persist by mimicking a legitimate Windows AppID task. Registering persistence under a trusted-looking task path helps the actor survive reboots while avoiding operator suspicion.
HuntRule TeamWindowsprocess_creationHigh112Premium2026-06-23Suspicious Removable Media Spread via My Pictures Executable (via process_creation)
This rule detects execution of a binary named My Pictures.exe which VenomRAT copies onto removable drives to spread across hosts in the RevengeHotels campaign. The lure name mimics a familiar folder to trick users into launching it from a USB device. An executable using this decoy name is indicative of USB-based propagation.
HuntRule TeamWindowsprocess_creationMedium257Premium2026-06-23Malicious NTDS Credential Theft via Volume Shadow Copy via process_creation
This rule detects volume shadow copy creation with vssadmin or direct references to the ntds.dit Active Directory database used to steal domain credentials. Stately Taurus used vssadmin and NTDS.dit access on a compromised domain controller to harvest the credential store, a high-confidence sign of domain-wide credential access.
HuntRule TeamWindowsprocess_creationHigh241Premium2026-06-23