Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,330 rules
Suspicious Winlogon Shell Persistence via Registry by Key Group
This rule detects modification of the Winlogon Shell value to something other than the default explorer.exe, a persistence technique used by Key Group ransomware to auto-run its payload at logon. Any non-default shell value on this key indicates hijacked user-session startup and should be investigated.
HuntRule TeamWindowsregistry_setHigh361Premium2026-06-21Suspicious Spectre Ops Staging in CullinetProgram Directory via file_event
This rule detects the Spectre Ops stealer staging files inside a CullinetProgram directory under AppData Roaming, which it pairs with a Startup folder entry for persistence. The uniquely named working directory holds the malware components between reboots. This distinctive folder name is not associated with legitimate software and reliably marks the stealer footprint on disk.
HuntRule TeamWindowsfile_eventHigh414Premium2026-06-20Suspicious Command in RunMRU Registry Indicating ClickFix Execution (via registry_set)
This rule detects a RunMRU registry entry containing a script interpreter or download command, a host artifact left when a victim pastes a ClickFix payload into the Windows Run dialog. The RunMRU key records the exact command executed through Win plus R.
HuntRule TeamWindowsregistry_setHigh133Premium2026-06-20Suspicious Autorun Registry Key Pointing to User-Writable Path (via registry_set)
This rule detects a write to a Run or RunOnce autostart key whose value references an executable located in a user-writable directory such as AppData, Temp, ProgramData or the Public folder. Malware commonly plants persistence in these keys so its dropper re-runs at logon while living outside trusted program paths. An autorun entry pointing into a staging directory is a classic persistence indicator.
HuntRule TeamWindowsregistry_setMedium279Premium2026-06-20Suspicious HTA Download via mshta and Curl in Process Creation
This rule detects mshta being used together with curl to fetch and execute a remote HTA payload, the ClickFix delivery chain attributed to Scarlet Goldfinch. Victims are socially engineered into pasting a command that downloads and runs the HTA, giving the attacker code execution through a signed Windows binary that bypasses application controls.
HuntRule TeamWindowsprocess_creationHigh72Premium2026-06-20Suspicious Virtual Machine Detection via Registry Query (via process_creation)
This rule detects reg.exe querying the Virtual Machine Guest Parameters registry key used to fingerprint hypervisor or sandbox environments. This anti-analysis check was observed prior to Lynx ransomware deployment. Adversaries use it to decide whether to continue execution or evade automated analysis sandboxes.
HuntRule TeamWindowsprocess_creationMedium111Premium2026-06-20Suspicious TruffleHog Secret Scanner Execution
This rule detects execution of the TruffleHog secret-scanning tool on developer or build hosts, where adversaries run it to harvest credentials and API keys from repositories and filesystems. It is associated with software supply chain attacks that repurpose legitimate developer utilities for credential theft. Detecting unexpected TruffleHog runs flags opportunistic secret collection.
HuntRule TeamWindowsprocess_creationMedium228Premium2026-06-20Malicious Tycoon 2FA AiTM Phishing WebSocket Channel
This rule detects the Tycoon 2FA phishing kit opening its adversary-in-the-middle relay over the fixed /web6socket/socket.io WebSocket endpoint. This path is unique to the kit and identifies a victim connecting to the AiTM proxy used to steal session cookies.
HuntRule TeamWebproxyHigh131Premium2026-06-20Suspicious Text-File Payload Staging in Temp (via file_event)
This rule detects creation of specifically named text staging files used to hold base64-encoded .NET loaders and encrypted configuration. The SHADOW#REACTOR campaign used a text-only staging pipeline before in-memory Remcos RAT deployment.
HuntRule TeamWindowsfile_eventHigh234Premium2026-06-20Malicious XRed Backdoor Persistence via Synaptics Run Key (via registry_set)
This rule detects the XRed backdoor establishing persistence through a Run key value named Synaptics Pointing Device Driver that points into the ProgramData\Synaptics directory. The value name masquerades as a legitimate touchpad driver while the executable path is a non-standard ProgramData location dropped by trojanized InstantView installers. Attackers use this autorun entry to survive reboots and maintain backdoor access for keylogging and data theft.
HuntRule TeamWindowsregistry_setHigh439Premium2026-06-20Suspicious Mirage Kitten SspiCli.dll Search-Order Hijack via AppVShNotify.exe (via image_load)
This rule detects AppVShNotify.exe loading SspiCli.dll from outside System32, a DLL search-order hijack used by Mirage Kitten to execute malware under a trusted App-V binary against Middle East and Africa targets. Sideloading a system DLL name from an unexpected path lets the attacker run code stealthily while masquerading as a legitimate Windows component.
HuntRule TeamWindowsimage_loadHigh412Premium2026-06-20Malicious DLL Side-Loading of msimg32 via Silverlight.Configuration.exe
This rule detects Silverlight.Configuration.exe loading msimg32.dll from outside the Windows system directories. The Horns and Hooves campaign abused this signed binary to side-load a planted msimg32.dll and execute the NetSupport loader under a trusted process.
HuntRule TeamWindowsimage_loadHigh133Premium2026-06-20Suspicious Deletion of Explorer RunMRU Values
This rule detects deletion of values under the Explorer RunMRU key, an anti-forensic step in newer NetSupport RAT ClickFix loaders. The malware removed RunMRU entries to erase evidence that the victim had pasted the malicious command into the Windows Run dialog. Programmatic clearing of RunMRU history is an indicator of indicator-removal activity.
HuntRule TeamWindowsregistry_setMedium132Premium2026-06-20Malicious MicrosoftUpdate Run Key Persistence via Axios Compromise
This rule detects creation of a CurrentVersion Run value named MicrosoftUpdate that launches the renamed wt.exe interpreter as used by the Windows variant of the Axios supply chain RAT. The benign looking value name paired with a ProgramData interpreter path indicates masquerading persistence for the backdoor.
HuntRule TeamWindowsregistry_setHigh365Premium2026-06-20Suspicious New Member Added to an Exchange Administration Group - Medium Risk (via security)
This rule detects scenarios where a new member is added to a sensitive group related to Exchange server.
HuntRule TeamWindowssecurityMedium91Premium2026-06-20