Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,421 rules
Malicious Recovery Inhibition via Shadow Copy and WinRE Tampering
This rule detects command lines that delete Volume Shadow Copies with vssadmin or disable the Windows Recovery Environment with reagentc, actions used by NOVABLIGHT to prevent system and file recovery. Inhibiting recovery is a common precursor to destructive or extortion activity.
HuntRule TeamWindowsprocess_creationHigh266Premium2026-06-04Suspicious Disk Image File Written by a Browser or Mail Client (via file_event)
This rule detects a browser or email client writing an ISO, IMG or VHD disk-image file to disk, the delivery half of an HTML-smuggling campaign that packages a payload inside a container to bypass Mark-of-the-Web and mail-attachment controls. HTML smuggling and container-file delivery are recurring initial-access techniques in the Red Canary Threat Detection Report. Detecting image files dropped by internet-facing apps surfaces smuggled payloads before they are mounted and run.
HuntRule TeamWindowsfile_eventMedium2010Premium2026-06-04Suspicious Batch Script Unhiding Files via Attrib From Temp
This rule detects a batch script spawning attrib.exe to clear hidden and system attributes, a staging step used by Zhong Stealer to reveal and execute dropped components. Clearing attributes on files via a randomly named batch is uncommon in benign activity.
HuntRule TeamWindowsprocess_creationMedium112Premium2026-06-04Suspicious Windows Defender Exclusion Added via PowerShell (via process_creation)
This rule detects PowerShell adding a Microsoft Defender exclusion via Add-MpPreference. The SonicCrypt crypter behind TA585 MonsterV2 deliveries added its payload to Defender exclusions to evade scanning.
HuntRule TeamWindowsprocess_creationMedium153Premium2026-06-04Malicious macOS Payload Download and Execution via curl Piped to zsh
This rule detects a remote payload being downloaded with curl and immediately piped into the zsh or sh shell for execution on macOS. This loader behavior was used by the MacSync stealer and RAT documented by Huntress to fetch and run its second stage without touching disk. Piping downloaded content straight into an interpreter is a hallmark of fileless staging and warrants investigation.
HuntRule TeamMacosprocess_creationHigh122Premium2026-06-04Malicious Microsoft Defender Default Action Changed to Allow Any Threat - PowerShell (via powershell)
This rule detects change Defender default action to allow any threats.
HuntRule TeamWindowspowershellHigh121Premium2026-06-04Suspicious Ahnenblatt Application Execution From User-Writable Directory
This rule detects the legitimate Ahnenblatt genealogy application Ahnenblatt4.exe running from a Temp or AppData directory. In the RenEngine campaign this signed application was abused as a DLL side-loading host by dropping it next to malicious borlndmm.dll and cc32290mt.dll to launch HijackLoader as reported by Kaspersky. Execution of this uncommon application from a user-writable path signals a DLL search-order hijack rather than normal use.
HuntRule TeamWindowsprocess_creationHigh112Premium2026-06-04WWLIB DLL Sideloading via WinWord Outside Office Directory in KamiKakaBot Chain (via image_load)
This rule detects WinWord.exe loading WWLIB.dll from a path outside the legitimate Microsoft Office installation directory, the DLL sideloading pair used by KamiKakaBot when a masqueraded Office binary is executed from an ISO or temporary folder. Adversaries leverage this sideload to run malicious code under a trusted Office process, making detection valuable for catching the initial execution stage.
HuntRule TeamWindowsimage_loadHigh71Premium2026-06-04Malicious Sed Tampering of Juniper Syslog Configuration by UNC3886 (via process_creation)
This rule detects sed modifying the Junos syslog configuration file at /mfs/var/etc/syslog.conf, the logging suppression technique UNC3886 used to disable syslog before operating on compromised routers. Editing the appliance syslog configuration indicates deliberate impairment of defenses.
HuntRule TeamLinuxprocess_creationHigh73Premium2026-06-04Suspicious Local Account Creation via Net User
This rule detects local account creation using the net user add command which the REF0657 actors used to add a helpdesk account through a malicious service for persistent access. Interactive account creation may be legitimate for administrators so this activity should be corroborated with the creating context.
HuntRule TeamWindowsprocess_creationMedium245Premium2026-06-04Windows Process Creation: curl.exe Using NTLM with Empty Username (-u :)
Alerts when curl is run on Windows with --ntlm and empty -u : credentials, a pattern that may leak the current user's NTLMv2 response.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3610Free2026-06-04Malicious Event Log Tampering via wevtutil Channel Disable by FunkSec Ransomware (via process_creation)
This rule detects use of wevtutil to disable the Security and Application event log channels, a defense-evasion action performed by FunkSec ransomware to blind logging before encryption. Adversaries turn off event channels so their tampering, service termination and encryption activity is not recorded for responders.
HuntRule TeamWindowsprocess_creationHigh143Premium2026-06-03Obfuscated Fickle Stealer Injection Path Store prepares.dat Under Public (via file_event)
This rule detects creation of prepares.dat in the public users directory, the file where Fickle Stealer stores base64-encoded paths of injected components for its multi-stage execution. Adversaries leverage this world-writable location to persist loader state, making detection of the fixed filename and path a useful indicator of an active Fickle infection.
HuntRule TeamWindowsfile_eventMedium375Premium2026-06-03Suspicious Cached Logon Disable via Winlogon CachedLogonsCount (via registry_set)
This rule detects modification of the Winlogon CachedLogonsCount value, which the Lotus Wiper sets to zero to remove cached domain credentials and hinder recovery. Disabling cached logons contributes to the destructive impact of the wiper against energy and utilities targets. Detecting this rare registry change highlights defense weakening prior to disk destruction.
HuntRule TeamWindowsregistry_setMedium272Premium2026-06-03Suspicious Certutil URLCache Download
This rule detects certutil.exe used with the urlcache option to download a remote file. The DragonRank SEO-poisoning operators abused certutil urlcache to pull additional tooling onto compromised IIS servers. Certutil functioning as a downloader is a living-off-the-land ingress technique that evades controls expecting a browser or dedicated transfer tool.
HuntRule TeamWindowsprocess_creationHigh83Premium2026-06-03