Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,351 rules
Suspicious Plink Reverse Tunnel Establishment
This rule detects a plink or renamed SSH client establishing a reverse port-forward tunnel using the -R option. UAT-5647 deployed a renamed plink binary such as iestatus.exe with -R to build a reverse SSH tunnel back to attacker infrastructure. Reverse SSH tunnels give attackers persistent interactive access and a pivot channel that bypasses inbound firewall restrictions.
HuntRule TeamWindowsprocess_creationMedium234Premium2026-06-09Suspicious Webshell Written To F5 TMUI Web Directory
This rule detects creation of a PHP or JSP file within the F5 BIG-IP xui web directory tree which is where operators dropped webshells after TMUI exploitation as described in NCC Group RIFT F5 TMUI intelligence. Adversaries plant these webshells to maintain persistent remote command execution on the appliance so any script file appearing in these image and script paths is highly suspicious.
HuntRule TeamLinuxfile_eventHigh132Premium2026-06-09Suspicious Access to SonicWall SMA JSP Webshell
This rule detects HTTP requests to JSP webshells planted on a compromised SonicWall SMA appliance. In the 0-day exploitation the actor placed error.jsp and errorDialog.jsp under the workplace directory and proxied them to a local listener to execute commands. Access to these attacker-planted endpoints indicates active webshell interaction and hands-on-keyboard control of the appliance.
HuntRule TeamWebwebserverHigh81Premium2026-06-09Possible MOVEit Transfer Exploitation via MOVEitISAPI action m2 and X-siLock Headers
This rule detects requests to MOVEitISAPI.dll with action=m2 that also carry X-siLock control headers, matching the MOVEit Transfer RCE chain analyzed by Assetnote for CVE-2023-34362. The X-siLock headers drive internal session-variable manipulation used in the SQL injection to RCE path. Detecting this handler and header pairing surfaces active exploitation of the MOVEit ISAPI extension.
HuntRule TeamWebwebserverHigh132Premium2026-06-09Suspicious NTUSER.MAN Mandatory Profile File Created for Logon Persistence (via file_event)
This rule detects creation of an NTUSER.MAN mandatory user profile file inside a local user profile directory, a logon-persistence technique attributed to APT32 by 360 Advanced Threat Research in which a crafted binary registry hive is dropped as NTUSER.MAN so malicious autostart entries execute at user logon without administrative rights. Adversaries abuse the mandatory profile mechanism to load an attacker-built HKCU hive that never passes through the registry API, evading registry-callback based monitoring.
HuntRule TeamWindowsfile_eventMedium93Premium2026-06-09In-Memory Process Injection via Mavinject INJECTRUNNING (via process_creation)
This rule detects mavinject.exe called with the INJECTRUNNING flag, which injects a DLL into a running process through a signed Microsoft binary, a stealthy execution and defense-evasion technique. Mavinject abuse is tracked in the Red Canary Threat Detection Report. Detecting this invocation surfaces trusted-binary process injection.
HuntRule TeamWindowsprocess_creationHigh205Premium2026-06-09Suspicious Registry Query for Stored Credentials (via process_creation)
This rule detects reg.exe querying registry locations for stored passwords or autologon credentials, an unsecured-credentials technique used to harvest plaintext secrets left in the registry. Searching the registry for credentials is tracked in the Red Canary Threat Detection Report. Detecting these queries surfaces credential discovery on the host.
HuntRule TeamWindowsprocess_creationMedium82Premium2026-06-09Suspicious Hidden PowerShell Download Cradle via ClickFix (via process_creation)
This rule detects a hidden window PowerShell process invoking DownloadString to pull a remote second stage, matching the HarborWatch ClickFix chain that runs a base64 command to fetch code from a remote text file. A hidden PowerShell window combined with a web download is a strong indicator of scripted delivery.
HuntRule TeamWindowsprocess_creationMedium473Premium2026-06-08Suspicious Run Key Persistence Pointing to Documents Folder (via registry_set)
This rule detects creation of a HKCU Run key whose value points to an executable hidden inside a user Documents subfolder, a persistence pattern used by the BundleBot stealer. Legitimate software installs to Program Files, so a Run entry launching a binary from the user Documents tree is a strong sign of malware autostart.
HuntRule TeamWindowsregistry_setMedium72Premium2026-06-08Suspicious Payload Download to Temp Masquerading as System32 File (via process_creation)
This rule detects PowerShell using Invoke-WebRequest to save a payload into the temp directory under a system32 style filename. OneNote delivered malware wrote files such as system32.exe and system32.bat into the user temp path to blend in before launching them.
HuntRule TeamWindowsprocess_creationMedium131Premium2026-06-08Possible MuddyWater C2 Domain Resolution
This rule detects DNS resolution of the domain screenai.online, a command-and-control host observed in a MuddyWater APT campaign that combined WMI execution and remote management tool abuse against Middle East targets. It captures beaconing infrastructure lookups tied to the intrusion. Detecting this is important because resolution of this campaign-specific domain is a high-confidence indicator of an infected host reaching out to attacker infrastructure.
HuntRule TeamWindowsdns_queryHigh408Premium2026-06-08Suspicious SonicWall SMA init.d Persistence Launching deploy_new.py
This rule detects the workplace init script executing deploy_new.py which the actor used for persistence on a compromised SonicWall SMA appliance. The 0-day exploitation established a boot-time service under /etc/init.d/workplace to relaunch attacker tooling after reboots. Boot persistence on an internet-facing appliance provides durable access that survives restarts and patching attempts.
HuntRule TeamLinuxprocess_creationHigh353Premium2026-06-08Suspicious npm Credential Scan via whoami and npmrc Access
This rule detects the npm whoami identity check combined with access to the .npmrc credential file, a credential-harvesting step in the Shai Hulud 2.0 worm. The malicious payload queries npm /-/whoami and reads .npmrc to steal publishing tokens for propagating to further packages. Automated npm authentication probing paired with npmrc token access is a strong indicator of supply-chain credential theft.
HuntRule TeamWindowsprocess_creationLow2410Premium2026-06-08Suspicious AdFind Active Directory Enumeration via OWASSRF Post-Exploitation (via process_creation)
This rule detects use of the AdFind reconnaissance utility by process name or by its characteristic query flags, a discovery step performed after OWASSRF exploitation of Exchange servers. Attackers enumerate domain accounts trusts and objects to plan lateral movement, so AdFind activity outside sanctioned administration is a hands-on-keyboard indicator.
HuntRule TeamWindowsprocess_creationMedium52Premium2026-06-08Suspicious node Execution of sync.js from NodeJS Masquerade Directory
This rule detects node running a sync.js payload from a NodeJS named directory used as a masquerade staging location in the AsyncAPI npm supply chain compromise. Executing a sync.js loader from a fake NodeJS folder is the import-time payload delivery step that pulls the second stage from the attacker C2.
HuntRule TeamWindowsprocess_creationMedium318Premium2026-06-08