Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,347 rules
Suspicious CasPol Execution Spawned by PowerShell for Injection
This rule detects the .NET CasPol.exe utility being launched by PowerShell, a system binary proxy execution chain used by the XWorm LATAM campaign to hollow CasPol and host the RAT payload. CasPol is seldom executed interactively, and a PowerShell parent is highly suspicious.
HuntRule TeamWindowsprocess_creationHigh131Premium2026-06-11Suspicious Massive Remote Schedule Task Creation via Named Pipes - CrackMapExec with ATexec (via security)
This rule detects remotely creates a scheduled task on multiple hosts over named pipes to execute commands or elevate privileges.
HuntRule TeamWindowssecurityMedium133Premium2026-06-11Download of Fake Messaging App Update APK
This rule detects proxy or web download requests for APK files masquerading as updates for popular messaging and social apps. Arid Viper distributed Android spyware as fake update packages such as whatsapp-update.apk, messenger-update.apk, google-play-update.apk and instagram-update.apk. These update-themed APK names impersonate trusted applications to trick users into sideloading spyware.
HuntRule TeamWebproxyMedium417Premium2026-06-11Malicious Named Pipe kesknq for Token Impersonation (via pipe_created)
This rule detects creation of the named pipe kesknq used for privilege escalation and token impersonation in an Apache ActiveMQ exploitation leading to LockBit. The specific pipe name was reused across the getsystem routine and a service of the same name. Named pipe impersonation lets the operator elevate from a service context to SYSTEM.
HuntRule TeamWindowspipe_createdHigh132Premium2026-06-11Suspicious Edgecution Malicious Extension Load via Headless Edge (via process_creation)
This rule detects Microsoft Edge being launched with a load-extension argument together with headless mode and a Recovery user data directory as used by Edgecution to run its malicious browser extension backdoor. Legitimate Edge sessions do not side load unpacked extensions in headless mode.
HuntRule TeamWindowsprocess_creationHigh101Premium2026-06-11Malicious BlackCat Boot Configuration Change to Safe Mode with Networking via bcdedit (via process_creation)
This rule detects bcdedit being used to force the system to boot into Safe Mode with networking, a pre-ransomware defense-evasion step observed in the Nitrogen campaign before BlackCat encryption. Adversaries reboot endpoints into Safe Mode so that most security agents do not load while the ransomware still reaches network shares, making this a high-value early indicator of imminent encryption.
HuntRule TeamWindowsprocess_creationHigh106Premium2026-06-11Malicious SharePoint spinstall Web Shell Access Leaking Machine Keys
This rule detects web requests to the spinstall web shell dropped during on-premises SharePoint exploitation. Microsoft observed spinstall0.aspx and its variants deployed to leak the server MachineKey via GET requests. Retrieval of the ASP.NET machine key enables forged payloads and full compromise, so any access to this web shell is a critical finding.
HuntRule TeamWebwebserverCritical142Premium2026-06-11Malicious Disabling of rsyslog or auditd Logging Services (via process_creation)
This rule detects commands that stop, disable, mask, or kill the rsyslog or auditd logging services on Linux. The Group-IB XMRig covert Linux PAM abuse campaign disables these services to blind host defenses before mining and persistence activity. Impairing logging is a strong pre-attack signal that an adversary is preparing to operate without leaving audit trails.
HuntRule TeamLinuxprocess_creationHigh93Premium2026-06-11Suspicious WinRAR Silent Archive Staging
This rule detects WinRAR invoked with the specific silent recursion and monitoring flag combination used to stage data for exfiltration. This behavior matches Akira operators who archive victim files quietly prior to theft. This distinctive flag set is uncommon in normal usage and indicates automated collection of files before ransomware exfiltration.
HuntRule TeamWindowsprocess_creationMedium102Premium2026-06-11Suspicious Staged Payload Execution from User Downloads or Pictures Folder
This rule detects execution of attacker-staged binaries with names such as FunnyApp.exe, RedSun.exe, or z.exe from user Downloads or Pictures folders. These payloads were staged during a Huntress-investigated intrusion following VPN access and used to advance the attack, including bring-your-own-vulnerable-driver activity. Execution of these specific filenames from staging directories indicates deployment of hands-on-keyboard tooling.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-06-11Malicious NotDoor Outlook VBA Persistence via VbaProject.OTM Deployment (via process_creation)
This rule detects command lines that copy a staging file into the Outlook VbaProject.OTM macro container used by the NotDoor backdoor for persistence. Overwriting VbaProject.OTM lets attacker VBA code execute on Outlook startup and mail events.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-06-11Malicious Docker Client Targeting Remote Exposed 2375 API
This rule detects the docker client invoked with a remote host flag pointing at TCP port 2375 to run or exec against an exposed Docker Engine API. The Dero miner worm abuses this to deploy malicious containers onto unauthenticated hosts and spread its cryptojacking payload. Remote docker run or exec over 2375 is a clear container-takeover behavior.
HuntRule TeamLinuxprocess_creationHigh73Premium2026-06-11Malicious Shell Spawned by Windows Script Host (via process_creation)
This rule detects wscript or cscript spawning PowerShell, cmd or another script host, the staging behavior Gootloader and SocGholish use when a first-stage JScript file launches a second stage. A script host launching a shell is an execution technique tracked in the Red Canary Threat Detection Report. Detecting this parent-child pair surfaces script-based malware progressing to its next stage.
HuntRule TeamWindowsprocess_creationHigh131Premium2026-06-11Suspicious Windows Defender Exclusion for PowerShell via Add-MpPreference (via process_creation)
This rule detects the AsyncRAT loader disabling Microsoft Defender coverage by adding process and path exclusions through Add-MpPreference. The campaign excludes the entire C drive and the powershell.exe process to protect its staged payloads. Adding a scripting host as a Defender exclusion is rarely legitimate.
HuntRule TeamWindowsprocess_creationHigh483Premium2026-06-10Suspicious Renamed Pythonw Interpreter Execution via XWorm Loader (via process_creation)
This rule detects execution of the pythonw interpreter that has been renamed away from its original filename, a masquerading technique used by an XWorm loader that ships pythonw as pw.exe to run obfuscated Python payloads.
HuntRule TeamWindowsprocess_creationMedium112Premium2026-06-10