Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,081 rules
EAP Service Activation by Liontail Framework for DLL Sideloading - Via Command (via process_creation)
This rule detects enable the Eaphost component in order to perform a DLL sideloading attack.
HuntRule TeamWindowsprocess_creationMedium00Premium2026-09-05Suspicious Commonly-Hijacked DLL Loaded From a User-Writable Path (via image_load)
This rule detects a process loading a frequently search-order-hijacked system DLL name from a user-writable directory such as AppData, Temp or ProgramData, indicating DLL search-order hijacking where an attacker-planted DLL is loaded instead of the legitimate one. DLL hijacking is a persistent defense-evasion and persistence technique in the Red Canary Threat Detection Report. Detecting these known-abused DLL names loading from non-system paths surfaces the hijack.
HuntRule TeamWindowsimage_loadMedium10Premium2026-09-05Malicious User Password Change Using Current Hash Password - ChangeNTLM - Mimikatz (via security)
This rule detects resets a user account by using the compromised NTLM password hash. The newly clear text password defined by the attacker can be then used in order to login into services like Outlook Web Access (OWA), RDP, SharePoint... As ID 4723 refers to user changing is own password, the SubjectSid and TargetSid should be equal. However in a change initiated by Mimikatz, they will be different. Correlate the event ID 4723, 4624 and 5145 using the "SubjectLogonId" field to identify the source of the reset.
HuntRule TeamWindowssecurityHigh10Premium2026-09-05Suspicious Account Password Set to Never Expire. (via security)
This rule detects scenarios where an account password is set to never expire.
HuntRule TeamWindowssecurityMedium00Premium2026-09-05Malicious Cluster-Admin Role Binding Creation (via audit)
This rule detects creation of a ClusterRoleBinding or RoleBinding, which can grant an attacker cluster-admin privileges over a Kubernetes cluster, a privilege-escalation and persistence technique in cloud-native environments. Abusive role binding is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting these requests surfaces an attempt to entrench elevated access.
HuntRule TeamKubernetesauditHigh10Premium2026-09-05Suspicious Email-Hiding Inbox Rule Creation (via exchange)
This rule detects creation of a mailbox rule that automatically deletes messages or moves them to obscure folders such as RSS Feeds or Junk, a defense-evasion behavior adversaries use to hide security alerts and their own correspondence after account compromise. Email-hiding rules feature in the Red Canary Threat Detection Report as a post-compromise persistence and evasion tactic in business email compromise. Detecting these rules surfaces attacker efforts to stay unnoticed.
HuntRule TeamM365exchangeMedium00Premium2026-09-05Malicious Modification of a Computer Account SPN (via security)
This rule detects update the Service Principal Name (SPN) of a computer account in order to perform "Kerberos redirection" and escalate privileges.
HuntRule TeamWindowssecurityHigh00Premium2026-09-05Suspicious Massive Group Membership Changes (via security)
This rule detects will add a compromised account into different domain groups in order to gain access to all the assets under the control of those concerned groups.
HuntRule TeamWindowssecurityMedium20Premium2026-09-05Malicious Mailbox Audit Bypass Association in Exchange Online (via exchange)
This rule detects an account being added to the mailbox audit bypass list, which stops Exchange from logging that account's mailbox actions, a defense-evasion technique used to hide mailbox access and rule creation. Mailbox audit bypass is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting this operation surfaces an attacker suppressing mailbox telemetry.
HuntRule TeamM365exchangeHigh00Premium2026-09-05Malicious High Risk Active Directory Group Membership Change (via security)
This rule detects scenarios where a suspicious group membership is changed.
HuntRule TeamWindowssecurityHigh30Premium2026-09-05Suspicious Making a File Executable in a Temp Directory (via process_creation)
This rule detects chmod granting execute permission to a file staged in /tmp, /dev/shm or /var/tmp, a common step between dropping a payload and running it on Linux. Setting execute bits on temp-directory files is a defense-evasion and execution-preparation technique tracked in the Red Canary Threat Detection Report. Detecting it surfaces a payload being armed for execution.
HuntRule TeamLinuxprocess_creationMedium10Premium2026-09-05Malicious Account Marked as Sensitive and Cannot Be Delegated Had Its Protection Removed (via security)
This rule detects removes security protection from a sensitive account to escalate privileges.
HuntRule TeamWindowssecurityHigh30Premium2026-09-05Suspicious IAM Access Key Creation for Persistence (via cloudtrail)
This rule detects creation of a new IAM access key, a cloud account-manipulation technique attackers use to establish durable programmatic access to an AWS account after compromising a principal. Adding access keys for persistence is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting the CreateAccessKey call surfaces a potential backdoor credential being minted.
HuntRule TeamAwscloudtrailMedium30Premium2026-09-05Malicious Active Directory Enumeration via SharpHound or BloodHound (via process_creation)
This rule detects execution of the SharpHound collector or the Invoke-BloodHound cmdlet using its characteristic collection-method arguments, which harvest Active Directory objects, sessions and access-control relationships to map attack paths to Domain Admin. Large-scale AD discovery like this is a common pre-lateral-movement step seen across intrusions in the Red Canary Threat Detection Report. Detecting the collector's invocation surfaces reconnaissance before the adversary pivots.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-05Malicious Host Constrained Delegation Settings Changed for Potential Abuse (Rubeus) - Kerberos Only (via security)
This rule detects modifies host delegation settings for privilege escalation.
HuntRule TeamWindowssecurityHigh10Premium2026-09-05