Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,351 rules
Malicious Regsvr32 Scriptlet or Remote COM Object Execution (via process_creation)
This rule detects regsvr32.exe registering a scriptlet through scrobj.dll or loading a COM object from a remote URL, the "Squiblydoo" proxy-execution pattern. Regsvr32 is a recurring System Binary Proxy Execution technique in the Red Canary Threat Detection Report, abused to run attacker script code under a signed Microsoft binary while bypassing application allowlisting. Detecting the scrobj and remote-URL invocations flags the evasion.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-06-10Suspicious SocGholish Domain User Enumeration via net1
This rule detects enumeration of the domain users group using net1 with the /domain switch. This behavior was observed in SocGholish fake update intrusions during hands-on-keyboard reconnaissance. Attackers use it to map account membership before lateral movement toward victim peers.
HuntRule TeamWindowsprocess_creationMedium103Premium2026-06-10Suspicious Command Shell Spawned by WMI Provider Host Targeting ADMIN Share (via process_creation)
This rule detects cmd.exe spawned by the WMI provider host with a command line referencing the ADMIN administrative share, a remote execution pattern Volt Typhoon uses to run commands and stage output over WMI. Combining a WMI parent with administrative share access reflects remote lateral movement rather than routine local scripting, making it a strong signal of interactive intrusion activity.
HuntRule TeamWindowsprocess_creationHigh122Premium2026-06-10Malicious AMOS Stealer AppleScript Execution via osascript
This rule detects osascript executing AppleScript that shells out to remove quarantine attributes and grant execution permissions, a technique used by the Atomic (AMOS) Stealer delivered through fake DeepSeek installer sites. Attackers combine do shell script with xattr and chmod to run unsigned payloads while evading Gatekeeper, so this activity is a strong indicator of macOS stealer staging.
HuntRule TeamMacosprocess_creationHigh171Premium2026-06-10Suspicious Cron Persistence via etc cron.d tsar (via file_event)
This rule detects creation of a tsar cron job under etc cron.d as observed in the BrokenSesame research for host persistence. Dropping a system cron file lets an attacker run code as root on a schedule after escaping a container. The specific filename in the system cron directory is a strong persistence indicator.
HuntRule TeamLinuxfile_eventHigh226Premium2026-06-10OpenSSH Server Firewall Configuration on Windows - Command (via process_creation)
This rule detects configure the Windows firewall to allow incoming connections to perform stealthy lateral movement.
HuntRule TeamWindowsprocess_creationHigh41Premium2026-06-09VSS Backup Deletion - WMI (via process_creation)
This rule detects delete existing VSS backup.
HuntRule TeamWindowsprocess_creationHigh145Premium2026-06-09Malicious Azure Deletion of Resource Locks and Immutability Policies
This rule detects deletion of Azure resource locks and blob immutability policies, an anti-recovery step preceding storage ransomware. Removing locks and immutability protections strips the guardrails that would otherwise prevent an actor from overwriting or destroying blob data. A burst of these delete operations on storage resources indicates preparation for data destruction or ransom.
HuntRule TeamAzureactivitylogsHigh132Premium2026-06-09Suspicious SNS Email Subscription for Data Exfiltration
This rule detects an SNS Subscribe call using the email protocol, an exfiltration setup step in the AWS SNS abuse scenario researched by Elastic. Attackers subscribe an external email address to a topic then publish stolen credentials or data to it over a trusted AWS channel. Email subscriptions created by unexpected principals should be reviewed for data theft.
HuntRule TeamAwscloudtrailMedium338Premium2026-06-09Suspicious Windows Sandbox Configuration Execution for AsyncRAT via Process Creation
This rule detects WindowsSandbox.exe launched with a .wsb configuration file, the technique MirrorFace uses in Operation AkaiRyu to run AsyncRAT inside Windows Sandbox and evade host-based monitoring. Interactive Windows Sandbox use driven by a dropped .wsb config is uncommon on managed endpoints. This indicates sandbox-based evasion hosting a remote access trojan.
HuntRule TeamWindowsprocess_creationMedium163Premium2026-06-09Malicious Khmer Shadow DLL Sideloading via VMwareNamespaceCmd Loading vmtools (via image_load)
This rule detects the signed VMwareNamespaceCmd binary loading a vmtools DLL from outside the trusted VMware install path, the side-loading behavior used to run the Khmer Shadow loader against Cambodian government entities. Adversaries drop a malicious vmtools.dll beside a relocated VMware binary to execute under a trusted process. Loads originating outside Program Files expose the sideloaded implant.
HuntRule TeamWindowsimage_loadHigh344Premium2026-06-09Suspicious PowerShell Masquerading as Windows Terminal via process_creation
This rule detects a process whose original file name is PowerShell but which executes under the wt.exe Windows Terminal file name. The axios supply chain payload renamed powershell.exe to wt.exe to evade name-based detection, so a mismatch between the internal PowerShell identity and a wt.exe image name indicates a masqueraded interpreter.
HuntRule TeamWindowsprocess_creationHigh111Premium2026-06-09Suspicious SMB Admin Share Accessed (via security)
This rule detects connect to the administrative SMB share.
HuntRule TeamWindowssecurityMedium187Premium2026-06-09Suspicious Teams Message Soft Delete by Agent Identity via M365 Audit
This rule detects soft deletion of Teams channel messages, the cleanup step observed when a compromised Entra agent identity posts internal phishing links and then removes the evidence. Adversaries delete their own messages to hide internal spearphishing and slow investigation, so agent-driven message deletions in Teams warrant correlation with preceding message-send activity.
HuntRule TeamM365auditMedium345Premium2026-06-09Malicious Reverse SSH Tunnel via Plink for RDP Forwarding
This rule detects use of the Plink SSH client to establish a reverse tunnel that forwards local RDP back to attacker infrastructure which Conti operators use for persistent remote access. Observed in NCC Group research on Conti operations after the leaks using a renamed Plink binary over port 53. Reverse RDP tunneling through SSH is a strong indicator of hands-on-keyboard intrusion.
HuntRule TeamWindowsprocess_creationHigh247Premium2026-06-09