Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,334 rules
Suspicious bitsadmin Download to AppData Temp via ClickFix Revenge Chain
This rule detects bitsadmin.exe performing a transfer that downloads a remote http resource into the user AppData or Temp directory, the payload retrieval step of the ClickFix campaign following a Windows Run dialog paste. bitsadmin used interactively to fetch executables into user writable folders is a well known living off the land download technique. This catches the staging of the second stage binary.
HuntRule TeamWindowsprocess_creationHigh82Premium2026-06-19Suspicious File Download via certutil
This rule detects certutil.exe being used with URL-cache download arguments to retrieve remote files, a living-off-the-land technique used by RansomHub affiliates to stage tooling. certutil is not a general purpose downloader, so its use to fetch remote content commonly indicates ingress tool transfer by an adversary.
HuntRule TeamWindowsprocess_creationMedium367Premium2026-06-19Suspicious Boot Configuration Change to Safeboot Minimal via bcdedit
This rule detects use of bcdedit to set the boot configuration to safeboot minimal, forcing the host to reboot into Safe Mode where most endpoint security agents do not load. The ToyMaker intrusion used this to disable protections before hands-on-keyboard activity, so it is a high-confidence defense-evasion signal preceding credential theft or ransomware deployment.
HuntRule TeamWindowsprocess_creationHigh1910Premium2026-06-19Suspicious Active Directory Discovery via ADFind
This rule detects execution of the ADFind reconnaissance utility which Black Basta operators use to enumerate Active Directory users groups and computers during the discovery phase of an intrusion. While ADFind is a legitimate administrative tool its presence on endpoints is frequently associated with pre ransomware reconnaissance.
HuntRule TeamWindowsprocess_creationMedium453Premium2026-06-18Malicious UAT-8302 Hidden PowerShell Execution of whatpc.ps1
This rule detects PowerShell running the whatpc.ps1 script with an execution policy bypass and a hidden window, matching the UAT-8302 reconnaissance stager. The named script drives host profiling and follow-on tasking while the hidden bypass flags suppress user visibility and controls. Execution of this specific script under these flags indicates active UAT-8302 operations.
HuntRule TeamWindowsprocess_creationHigh166Premium2026-06-18Suspicious AdFind Active Directory Reconnaissance Tool Execution (via process_creation)
This rule detects execution of the AdFind command-line Active Directory query tool, frequently staged by ransomware operators for domain reconnaissance. Fog and Akira operators deployed adfind.exe following SonicWall SSL VPN compromise to enumerate the domain.
HuntRule TeamWindowsprocess_creationMedium361Premium2026-06-18Malicious Notepad++ Updater Chain via gup.exe Spawning update.exe (via process_creation)
This rule detects the Notepad++ GUP updater gup.exe spawning update.exe, the NSIS-based infection chain seen in the nation-state Notepad++ supply-chain compromise. The trusted updater is subverted to launch a malicious installer that side-loads the Chrysalis payload.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-06-18Malicious DtlCrashCatch DLL Side-Loading via OneDrive Sync Service by SPECTRALVIPER
This rule detects the OneDrive.Sync.Service.exe process loading DtlCrashCatch.dll, a side-loaded and injected module used by the SPECTRALVIPER backdoor. This activity is associated with the OceanLotus (APT32) espionage campaign that abuses a trusted signed OneDrive binary for DLL search-order hijacking. Catching this specific side-load is important because it reveals code injection and stealthy execution under a legitimate process context.
HuntRule TeamWindowsimage_loadHigh387Premium2026-06-18Malicious Direct etcd Write to Kubernetes Registry via ETCDCTL_API (via process_creation)
This rule detects direct writes to the Kubernetes object store held in etcd by invoking etcdctl v3 against the /registry key space. Attackers who compromise etcd use this to inject privileged pods or hidden namespace resources that never pass through the kube-apiserver. Bypassing the API server evades admission controllers and audit logging while granting node and cluster takeover.
HuntRule TeamWindowsprocess_creationHigh321Premium2026-06-18Masquerading Kimsuky Registry Run Key Persistence for Malware Loader (via registry_set)
This rule detects creation of a CurrentVersion Run autorun value named NetService or WindowsSecurityCheck, the persistence behavior used by the Kimsuky KimJongRAT loader to relaunch its PE and PowerShell payloads at logon. Adversaries leverage benign sounding run key names to survive reboots while masquerading as system services, making early detection critical for surfacing persistence before data collection.
HuntRule TeamWindowsregistry_setMedium94Premium2026-06-18Suspicious Download to Windows appcompat Directory via PowerShell
This rule detects PowerShell using Invoke-WebRequest to write an executable into the Windows appcompat directory as observed after Triofox CVE-2025-12480 exploitation. Attackers stage payloads such as SAgentInstaller.exe in unusual system paths to evade attention.
HuntRule TeamWindowsprocess_creationHigh495Premium2026-06-18Malicious Remote Desktop Enablement via Netsh
This rule detects netsh enabling the Remote Desktop service in the firewall to open inbound RDP for lateral movement. This was observed during Obscura ransomware deployment. Opening RDP on hosts that normally block it extends the attacker foothold across the network.
HuntRule TeamWindowsprocess_creationHigh316Premium2026-06-18Malicious Cloud Metadata Credential SSRF via HTTP (via proxy)
This rule detects HTTP requests to the cloud instance metadata IAM security credentials path on Linux hosts. Attackers exploiting the LMDeploy server side request forgery vulnerability coerced the inference engine into fetching temporary IAM credentials from the metadata service. Requests reaching the metadata credentials endpoint from an application server indicate credential theft through SSRF.
HuntRule TeamWebproxyHigh72Premium2026-06-18Suspicious NirSoft Credential Recovery Tools Execution
This rule detects execution of the NirSoft credential recovery tools netpass.exe and WebBrowserPassView.exe. The Christmas Miracle actor dropped these utilities to extract stored network and browser passwords. Their presence on a server indicates active credential harvesting by an intruder.
HuntRule TeamWindowsprocess_creationHigh135Premium2026-06-18Malicious Discord RAT Module Download from GitHub via Proxy
This rule detects retrieval of Discord RAT plugin modules hosted on the public Discord-RAT-2.0 GitHub repository. The malware dynamically downloads and reflectively loads capability modules such as credential theft, webcam capture, and token stealers from this raw content path.
HuntRule TeamWebproxyHigh131Premium2026-06-18