Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,345 rules
Suspicious OAuth Application Registration with Localhost Reply URL via Azure AD
This rule detects registration or update of an Azure AD OAuth application whose reply or redirect URL points to an anomalous localhost loopback endpoint such as http://localhost:7823/access/. This behavior was observed in OAuth application attacks researched by Huntress where adversaries register illicit applications to harvest tokens. Attackers abuse consented OAuth apps to maintain persistent access to cloud mailboxes and data, so anomalous reply URLs are a strong early indicator of illicit app registration.
HuntRule TeamAzureauditlogsHigh405Premium2026-06-12Malicious Mimikatz Credential Access Module Invocation
This rule detects command lines invoking Mimikatz credential-access modules such as privilege debug sekurlsa logonPasswords or lsadump sam. The BabyLockerKZ MedusaLocker operator used these Mimikatz modules to dump credentials during pre-encryption operations. Chained privilege debug and LSASS or SAM dumping commands are unambiguous credential-theft activity preceding lateral movement and ransomware.
HuntRule TeamWindowsprocess_creationHigh141Premium2026-06-12Suspicious Edge Update Setup Spawning PowerShell via ClearFake
This rule detects a MicrosoftEdgeUpdateSetup lure executable spawning PowerShell. The ClearFake fake-update campaign delivers a spoofed Edge updater that launches PowerShell to fetch and run its next stage, an execution chain that legitimate browser updates do not produce.
HuntRule TeamWindowsprocess_creationHigh122Premium2026-06-12ToneShell Backdoor GUID Store SystemRuntimeLag.inc in ProgramData (via file_event)
This rule detects creation of the SystemRuntimeLag.inc file that the Frankenstein ToneShell variant writes under ProgramData to store its per-host victim GUID. This uniquely named artifact is not associated with legitimate software and marks the backdoor recording its infection state.
HuntRule TeamWindowsfile_eventMedium93Premium2026-06-12Suspicious Hidden Account Creation - With Fast Deletion (via security)
This rule detects creates a hidden local account. See also rule "User account creation disguised in a computer account".
HuntRule TeamWindowssecurityMedium102Premium2026-06-12Malicious PlugX DLL Side-Loading via LMIGuardianSvc from SamsungDriver Directory (via process_creation)
This rule detects the legitimate LMIGuardianSvc binary executing from a SamsungDriver directory created by Mustang Panda to side-load PlugX. The signed binary search-order loads a malicious LMIGuardianDll from this attacker-controlled path. Running this LogMeIn component from a non-standard user directory is anomalous.
HuntRule TeamWindowsprocess_creationHigh217Premium2026-06-12Malicious UNC4841 FOXDOOR Shell Execution from Non-Standard Path (via process_creation)
This rule detects execution of the FOXDOOR shell component from the hardcoded /usr/share/foxdoor/ directory used by UNC4841 on compromised Barracuda ESG appliances. The path and binary name are attacker-controlled artifacts that provide interactive backdoor access. Detecting execution from this planted directory reveals active hands-on-keyboard operation on the appliance.
HuntRule TeamLinuxprocess_creationHigh241Premium2026-06-12Suspicious PowerShell Execution of Script from Netlogon Share by Cyber Anarchy Squad
This rule detects PowerShell launched with an execution policy bypass to run a script hosted on the domain netlogon share. The Cyber Anarchy Squad uses this technique to distribute and execute tooling such as rm.ps1 across compromised environments. Bypassing execution policy to run a remote logon-share script indicates malicious lateral distribution.
HuntRule TeamWindowsprocess_creationHigh154Premium2026-06-12Suspicious Run Key Persistence via Masqueraded svhostss Value by Elpaco Ransomware
This rule detects creation of a Run key value named svhostss which masquerades as the legitimate Windows svchost process. Elpaco ransomware, a Mimic variant, uses this autorun entry to persist across reboots. The deceptive naming combined with an autorun context indicates persistence for a ransomware payload.
HuntRule TeamWindowsregistry_setHigh93Premium2026-06-12Suspicious Java Runtime Executing JAR from User Download or Temp Directory
This rule detects java.exe or javaw.exe running a JAR file from a user download, Temp or AppData path, the execution stage of the Java RAT delivered through HTML smuggling in tax themed phishing. A JRE launching a JAR from a download folder is a common cross platform RAT delivery pattern rather than normal application behavior.
HuntRule TeamWindowsprocess_creationMedium454Premium2026-06-12Possible Rogue Device Registration in Entra ID After Device Code Phishing
This rule detects registration of a new device in Entra ID which commonly follows successful device-code phishing. In the Dangerous Invitations campaign the Russian actor registered attacker-controlled devices to obtain durable access after luring targets with spoofed European security event invitations. Adding a rogue device is a stealthy persistence mechanism that can bypass conditional access and sustain access to the tenant.
HuntRule TeamAzureauditlogsMedium419Premium2026-06-11Suspicious Renamed Python Interpreter WinAeroModule via Process Creation
This rule detects execution of a binary named WinAeroModule.exe, a masquerading name GoldenJackal gives to a renamed Python interpreter used to run its collection and exfiltration scripts on air-gapped hosts. The name mimics a Windows Aero theme component to appear benign. This indicates masqueraded interpreter execution supporting espionage tooling.
HuntRule TeamWindowsprocess_creationMedium227Premium2026-06-11Suspicious EastWind Implant Execution from ProgramData DRM Directory
This rule detects execution of a process from the C\ProgramData\Microsoft\DRM directory, a staging path used by the EastWind campaign for DLL sideloading and implant hosting. Legitimate DRM components do not run from this location, so process execution here signals attacker payload deployment and warrants investigation.
HuntRule TeamWindowsprocess_creationHigh113Premium2026-06-11Suspicious CasPol Execution Spawned by PowerShell for Injection
This rule detects the .NET CasPol.exe utility being launched by PowerShell, a system binary proxy execution chain used by the XWorm LATAM campaign to hollow CasPol and host the RAT payload. CasPol is seldom executed interactively, and a PowerShell parent is highly suspicious.
HuntRule TeamWindowsprocess_creationHigh131Premium2026-06-11Suspicious Massive Remote Schedule Task Creation via Named Pipes - CrackMapExec with ATexec (via security)
This rule detects remotely creates a scheduled task on multiple hosts over named pipes to execute commands or elevate privileges.
HuntRule TeamWindowssecurityMedium133Premium2026-06-11