Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,424 rules
Malicious Modification of Ivanti web Binary by TRAILBLAZE Injection (via file_event)
This rule detects writes to the Ivanti Connect Secure /home/bin/web process binary, the target of the in-memory TRAILBLAZE and BRUSHFIRE injection chain during CVE-2025-22457 exploitation. Modification of this core appliance binary indicates implant injection and compromise.
HuntRule TeamLinuxfile_eventMedium103Premium2026-06-02Suspicious External IP Lookup to ipify Service (via dns_query)
This rule detects DNS resolution of the ipify external IP-lookup service, which adversaries query at the start of instant-messaging command and control to discover the victim public address. Malware pairs this lookup with sessions to Discord or Telegram APIs to fingerprint the environment before beaconing. The lookup is dual-use, so correlate with unsigned or masquerading binaries for higher confidence.
HuntRule TeamWindowsdns_queryLow112Premium2026-06-02Possible Pre-Auth SSRF via VMware Workspace One UEM BlobHandler CVE-2021-22054
This rule detects HTTP requests to the VMware Workspace One UEM BlobHandler.ashx endpoint carrying a Url parameter. CVE-2021-22054 is a pre-authentication server-side request forgery reached through this handler with an encrypted Url payload as detailed by Assetnote, letting attackers pivot to internal services and cloud metadata.
HuntRule TeamWebwebserverHigh1810Premium2026-06-02Malicious Mimikatz Malicious Security Package (SSP) Exfiltrates Cleartext Passwords in File (via file_event)
This rule detects loaded the Mimikatz SSP "mimilib.dll" into the LSA process in order to exfiltrate clear text passwords into a file.
HuntRule TeamWindowsfile_eventHigh122Premium2026-06-02Suspicious Regsvr32 Loading DLL From Temp Directory (via process_creation)
This rule detects regsvr32 executing silently against a DLL located in the temp directory which the SneakyChef loader chain uses to register and run its SugarGh0st payload. Silent regsvr32 execution of a non-standard DLL path is a signed proxy execution technique that bypasses application allowlisting.
HuntRule TeamWindowsprocess_creationMedium111Premium2026-06-02Malicious BlackBeard SCR Payload Execution (via process_creation)
This rule detects execution of WebDeepPlayer.scr, a screensaver-disguised executable used to deliver the BlackBeard payload in Boggy Serpens operations. The .scr extension conceals an executable that runs on user interaction, so its launch indicates delivery of the malware to the endpoint.
HuntRule TeamWindowsprocess_creationHigh102Premium2026-06-02Malicious MuddyWater ManageOnDriveUpdater Scheduled Task Persistence
This rule detects creation of a scheduled task named ManageOnDriveUpdater, the persistence mechanism used by the MuddyWater MuddyViper implant. The task name imitates a OneDrive update service to blend in, and its registration signals attacker-established persistence following a spearphishing intrusion.
HuntRule TeamWindowsprocess_creationHigh471Premium2026-06-02Suspicious Clearing of Linux Authentication and History Logs
This rule detects removal or truncation of Linux authentication and shell history artifacts such as auth.log wtmp btmp and bash_history which the Salt Typhoon intrusions performed to erase evidence of access on compromised network devices and hosts. Deleting or emptying these files is a strong indicator of anti forensic activity following unauthorized access.
HuntRule TeamLinuxprocess_creationHigh103Premium2026-06-02Suspicious IMDS IAM Credential Retrieval From Container Workload
This rule detects a command line that queries the EC2 Instance Metadata Service credentials path 169.254.169.254 latest meta-data iam security-credentials to retrieve IAM role credentials. In EKS clusters where IMDSv2 is not enforced, a compromised pod uses this request to steal the worker node role credentials and escalate beyond the pod identity. This matters because it lets container workloads impersonate the underlying node and reach broader AWS permissions.
HuntRule TeamWindowsprocess_creationMedium159Premium2026-06-02Suspicious Network Share Enumeration via SharpShares
This rule detects execution of the SharpShares tool which enumerates accessible network shares across the domain as seen in the WithSecure lab where the operator compiled and ran SharpShares to map reachable shares. Broad share enumeration is a reconnaissance step used to locate sensitive data and lateral movement paths which makes it a useful discovery detection.
HuntRule TeamWindowsprocess_creationMedium112Premium2026-06-02Suspicious Chisel Reverse Tunnel Execution by UAT-9686
This rule detects execution of a Chisel client establishing a reverse SOCKS tunnel over HTTP. UAT-9686 deploys Chisel alongside a reverse SSH tunnel to maintain remote access to compromised Cisco email appliances. Reverse tunnels let an actor pivot into internal networks while blending with web traffic.
HuntRule TeamWindowsprocess_creationMedium3310Premium2026-06-02Malicious Lazarus RustyAttr Payload Retrieval via curl to Support Cloudstore C2 (via process_creation)
This rule detects the macOS curl download used by Lazarus RustyAttr activity to fetch a shell payload over an insecure -L -k connection from support.cloudstore.business or support.docsend.site as reported by Group-IB. Adversaries retrieve the second-stage script from this infrastructure before executing it through AppleScript, making this an early indicator of the intrusion.
HuntRule TeamMacosprocess_creationHigh118Premium2026-06-02Suspicious Khmer Shadow C2 Beacon with Malformed Chrome User-Agent (via proxy)
This rule detects outbound requests carrying the malformed Chrome 131 on Windows 10 user-agent string used by the Khmer Shadow implant to blend its C2 traffic. Adversaries craft this non-standard agent value that does not match any real browser build. The exact malformed string provides a low-noise channel indicator for this espionage cluster.
HuntRule TeamWebproxyMedium224Premium2026-06-02Malicious Credential Exfiltration to webhook.site
This rule detects curl posting data to a webhook.site endpoint, the exfiltration channel used by the Shai-Hulud worm to send harvested secrets to attacker-controlled webhooks. The worm labels these requests to correlate stolen data from each compromised host.
HuntRule TeamWindowsprocess_creationHigh102Premium2026-06-02Suspicious Office Application Spawning Script Interpreter (via process_creation)
This rule detects Excel or Word spawning a scripting interpreter such as wscript or powershell which the DarkGate remote template injection chain triggers to move from a malicious document to a VBS and PowerShell stager. Office applications launching script hosts is a hallmark of macro and template based initial access.
HuntRule TeamWindowsprocess_creationHigh63Premium2026-06-02