Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,427 rules
Malicious Veeam Credential Dumping Script Execution
This rule detects execution referencing a PowerShell script named to extract stored Veeam backup credentials which ransomware operators use to obtain privileged accounts. Observed in NCC Group research into active ransomware families pairing Mimikatz with a Veeam credential script. Harvesting backup credentials enables lateral movement and recovery sabotage which makes this a strong credential-access signal.
HuntRule TeamWindowsprocess_creationHigh96Premium2026-06-01Suspicious Credential Added to Existing Application for OAuth Persistence in Entra ID (via azure auditlogs)
This rule detects Entra ID audit events that add certificates or secrets to an existing application registration, the technique SolarWinds actors used to inject their own credentials into trusted OAuth apps for durable cloud access. New credentials on established applications can let an attacker authenticate as that service principal, so these changes should be reviewed as potential persistence.
HuntRule TeamAzureauditlogsMedium157Premium2026-06-01Malicious BoomBox Run Key Persistence via MicroNativeCacheSvc (via registry_set)
This rule detects creation of a CurrentVersion Run value named MicroNativeCacheSvc or referencing the NativeCacheSvc DLL used by the BoomBox downloader. This autostart entry ensures the malicious NativeCache DLL is relaunched on logon, maintaining persistence for the Nobelium implant.
HuntRule TeamWindowsregistry_setHigh92Premium2026-05-31Suspicious DLL Sideloading via usysdiag.exe Loading sensapi.dll via NailaoLocker (via image_load)
This rule detects the NailaoLoader stage of NailaoLocker ransomware which side loads a malicious sensapi.dll through the legitimate security tool usysdiag.exe to decrypt and run the locker payload. The genuine sensapi.dll ships in System32 so a copy loaded from the usysdiag application directory is anomalous. This pairing indicates the loader.
HuntRule TeamWindowsimage_loadMedium133Premium2026-05-31Suspicious Lateral Movement via PsExec Service (via process_creation)
This rule detects the PsExec service executable running on a host, which indicates remote command execution through the Service Control Manager. Nokoyawa operators use PsExec together with WMI to move laterally and deploy Cobalt Strike and the ransomware across the network. PsExec service activity outside of sanctioned administration is a strong lateral-movement signal.
HuntRule TeamWindowsprocess_creationMedium152Premium2026-05-31Malicious UAC Bypass via mscfile Handler Hijack (via registry_set)
This rule detects a command being written under HKCU Classes\mscfile\shell\open\command, the registry hijack eventvwr.exe follows to auto-elevate an attacker process while bypassing UAC. The mscfile handler hijack is a privilege-escalation technique tracked in the Red Canary Threat Detection Report. Detecting this modification surfaces a UAC-bypass preparation.
HuntRule TeamWindowsregistry_setHigh83Premium2026-05-31Suspicious Telegram Bot API Command and Control Communication (via proxy)
This rule detects outbound web requests to the Telegram Bot API endpoint on api.telegram.org that include a bot path, a command and control channel HookSpoofer stealer abuses to exfiltrate stolen data. The stealer posts harvested credentials and files to a hardcoded bot token. Because Telegram is also used legitimately this indicator is low confidence and best correlated with host stealer activity.
HuntRule TeamWebproxyLow488Premium2026-05-31Suspicious DAEMON Tools Exfiltration Binary Execution via envchk.exe (via process_creation)
This rule detects execution of envchk.exe, a masqueraded utility used by the DAEMON Tools supply chain backdoor to collect and exfiltrate host identifiers such as the MAC address and hostname. The tool transmits reconnaissance data to attacker infrastructure. Detecting this binary surfaces data collection and exfiltration activity.
HuntRule TeamWindowsprocess_creationMedium132Premium2026-05-31Suspicious Shell Password Gathering Referencing System Preferences (via process_creation)
This rule detects a shell command line referencing both system preferences and password, the shell-based credential-gathering pattern Red Canary associated with Atomic Stealer on macOS. This wording is used to coax users into entering their password while impersonating a system settings prompt, so its appearance warrants review for credential theft.
HuntRule TeamMacosprocess_creationLow181Premium2026-05-31Suspicious Renamed credwiz Binary Execution via Process Creation
This rule detects execution of the Windows Credential Wizard binary under typosquatted names used by the Russian actor Secret Blizzard to side-load its DUser.dll payload. Renaming the trusted credwiz.exe to cridviz.exe or crezly.exe is a masquerading technique that helps the DLL side-loading chain evade name-based detection.
HuntRule TeamWindowsprocess_creationHigh237Premium2026-05-31Suspicious PowerShell Spawning .NET LOLBIN (via process_creation)
This rule detects PowerShell spawning uncommon .NET framework utilities used as living-off-the-land execution proxies. The Veil#Drop loader cascaded through these binaries as fallback execution paths for its payload.
HuntRule TeamWindowsprocess_creationHigh152Premium2026-05-31Malicious SYSTEM Registry Hive Dump via reg.exe by Sandworm
This rule detects reg.exe saving the HKLM SYSTEM hive to a file, a credential access step Sandworm uses to obtain secrets for offline extraction. Exporting registry hives is a common precursor to dumping cached secrets and boot keys.
HuntRule TeamWindowsprocess_creationHigh205Premium2026-05-31Suspicious RedHook Android RAT WebSocket Device Channel (via proxy)
This rule detects WebSocket connections to the RedHook Android RAT device channel identified by the ws/device path with the misspelled menberId parameter. The RAT maintains a real-time control socket to the operator using this distinctive URI. Detecting it flags a live command-and-control session from an infected device.
HuntRule TeamWebproxyHigh103Premium2026-05-31Suspicious Remote Thread Created in notepad Process
This rule detects a remote thread being created inside a notepad process which is the CreateRemoteThread injection step described in the WithSecure Windows lab where shellcode was written into a suspended notepad and executed. Notepad is rarely a legitimate target of cross process thread creation so this pattern is a reliable process injection indicator.
HuntRule TeamWindowscreate_remote_threadMedium191Premium2026-05-31SearchIndexer Suspicious Process Activity (via process_creation)
This rule detects scenarios where SearchIndexer spwaned another process with the same name, or when SearchIndexer process exists in an unexpected directory.
HuntRule TeamWindowsprocess_creationMedium147Premium2026-05-31