Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,348 rules
Suspicious Renamed Pythonw Interpreter Execution via XWorm Loader (via process_creation)
This rule detects execution of the pythonw interpreter that has been renamed away from its original filename, a masquerading technique used by an XWorm loader that ships pythonw as pw.exe to run obfuscated Python payloads.
HuntRule TeamWindowsprocess_creationMedium112Premium2026-06-10Malicious QEMU Covert Network Tunnel via User-Mode netdev Socket (via process_creation)
This rule detects qemu-system emulator processes started with a user-mode network device that connects to a remote socket while running headless. Actors abuse QEMU by launching it with -netdev user socket connect to a remote host and -nographic to build a covert tunnel out of an environment, so this command line indicates network tunneling through a legitimate virtualization binary rather than normal VM use.
HuntRule TeamWindowsprocess_creationHigh276Premium2026-06-10Suspicious AutoIt Execution from PIF File Masquerade
This rule detects an AutoIt interpreter running with a pif extension image such as Flour.pif from a user writable location. This masquerade delivered an RC4 decrypted Vidar Stealer payload in the KMSPico drive-by chain. Renaming the AutoIt engine to a pif hides script based execution from casual review.
HuntRule TeamWindowsprocess_creationMedium102Premium2026-06-10Suspicious Bedrock AgentCore Runtime Invocation on Wildcard Resources (via aws)
This rule detects Bedrock AgentCore code interpreter and agent runtime invocations that, in the Agent God Mode scenario, are abused through wildcard IAM permissions to execute code across agent boundaries. Invocation of these runtimes by unexpected principals can indicate exploitation of excessive privileges for arbitrary execution in the AI environment.
HuntRule TeamAwscloudtrailLow265Premium2026-06-10Suspicious China Chopper Web Shell in Temporary ASP.NET Files
This rule detects compiled App_Web assemblies written into the Temporary ASP.NET Files directory, the artifact left when Tropic Trooper's China Chopper web shell embedded in an Umbraco page is compiled by IIS. While ASP.NET compiles legitimate pages here too, unexpected App_Web DLLs on a static or CMS server warrant review for web shell activity.
HuntRule TeamWindowsfile_eventMedium83Premium2026-06-10Suspicious Svchost Executed From Outside System32
This rule detects the svchost.exe image executing from a directory other than the Windows system folders as seen when the persistent actor ran a masqueraded svchost from ProgramData and this matters because the genuine service host always launches from System32 or SysWOW64 so any other path is a reliable masquerading indicator.
HuntRule TeamWindowsprocess_creationHigh177Premium2026-06-10Enabling RDP service via reg.exe command execution
Detects the execution of reg.exe and subsequent command line arguments for enabling RDP service on the host
HuntRule TeamWindowsprocess_creationHigh363Premium2026-06-10Suspicious WhatsAppBackup Data Staging Archive Creation
This rule detects creation of a WhatsAppData.zip archive inside a WhatsAppBackup directory on the system drive. Silver Fox drops a Python stealer that collects victim data into this fixed staging path before exfiltration. A backup themed archive assembled at this hardcoded location signals collection ahead of data theft.
HuntRule TeamWindowsfile_eventHigh448Premium2026-06-10Suspicious AWS SAML Provider Enumeration for Federation Recon (via cloudtrail)
This rule detects enumeration of configured SAML identity providers through the IAM ListSAMLProviders call, a discovery step Muddled Libra performs to understand federation and plan cross tenant identity abuse. Because this API is rarely called in day to day operations, its use by an interactive or unfamiliar principal points to adversary reconnaissance of the trust configuration.
HuntRule TeamAwscloudtrailMedium364Premium2026-06-10Malicious TEARPAGE wtsapi32.dll Side-Load via BdeUISrv by UNC2970 (via image_load)
This rule detects the BitLocker helper BdeUISrv.exe loading wtsapi32.dll from outside the System32 directory, the DLL search-order hijack UNC2970 used to side-load the TEARPAGE loader. A signed system binary loading a system-named DLL from an unexpected path is a strong side-loading indicator.
HuntRule TeamWindowsimage_loadHigh81Premium2026-06-10Malicious NotDoor Outlook Macro Auto-Execution Enablement via Registry (via registry_set)
This rule detects registry modifications that make Outlook load a macro provider on boot and lower Outlook macro security, a persistence and defense evasion technique used by the NotDoor backdoor. Legitimate software rarely enables LoadMacroProviderOnBoot together with a relaxed macro security level.
HuntRule TeamWindowsregistry_setMedium73Premium2026-06-10Masquerading Kimsuky Troll Stealer Scheduled Task Deletion of ChromeUpdateTaskMachineUAC via schtasks (via process_creation)
This rule detects deletion of the scheduled task named ChromeUpdateTaskMachineUAC through schtasks, a cleanup behavior the Troll Stealer dropper used by Kimsuky performs to remove a masquerading update task after execution. Removing a disguised task named after a browser updater is an uncommon defense-evasion action tied to this intrusion, making it a useful post-compromise signal.
HuntRule TeamWindowsprocess_creationHigh2910Premium2026-06-10Malicious Regsvr32 Scriptlet or Remote COM Object Execution (via process_creation)
This rule detects regsvr32.exe registering a scriptlet through scrobj.dll or loading a COM object from a remote URL, the "Squiblydoo" proxy-execution pattern. Regsvr32 is a recurring System Binary Proxy Execution technique in the Red Canary Threat Detection Report, abused to run attacker script code under a signed Microsoft binary while bypassing application allowlisting. Detecting the scrobj and remote-URL invocations flags the evasion.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-06-10Suspicious SocGholish Domain User Enumeration via net1
This rule detects enumeration of the domain users group using net1 with the /domain switch. This behavior was observed in SocGholish fake update intrusions during hands-on-keyboard reconnaissance. Attackers use it to map account membership before lateral movement toward victim peers.
HuntRule TeamWindowsprocess_creationMedium103Premium2026-06-10Suspicious Command Shell Spawned by WMI Provider Host Targeting ADMIN Share (via process_creation)
This rule detects cmd.exe spawned by the WMI provider host with a command line referencing the ADMIN administrative share, a remote execution pattern Volt Typhoon uses to run commands and stage output over WMI. Combining a WMI parent with administrative share access reflects remote lateral movement rather than routine local scripting, making it a strong signal of interactive intrusion activity.
HuntRule TeamWindowsprocess_creationHigh122Premium2026-06-10