Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,427 rules
Suspicious SharpShares Network Share Enumeration Tool Execution
This rule detects execution of SharpShares, an offensive tool that enumerates accessible network shares across a domain, matching the discovery stage of the vibe-coded malware intrusion. Operators run SharpShares to map reachable shares before staging and exfiltration. Its execution indicates active share reconnaissance by an intruder.
HuntRule TeamWindowsprocess_creationMedium213Premium2026-05-31Suspicious Script Interpreter Spawned by OneNote via Embedded File (via process_creation)
This rule detects onenote.exe spawning a command shell or scripting engine, matching campaigns that embed HTA, BAT, VBS, JSE, CMD and WSF files inside OneNote documents to launch loaders such as QakBot, IcedID and RedLine. OneNote does not normally start these interpreters.
HuntRule TeamWindowsprocess_creationHigh4610Premium2026-05-31Suspicious WScript Execution of VBScript from WhatsApp Transfers Folder via process_creation
This rule detects wscript.exe executing a .vbs file from the WhatsApp Desktop LocalState Transfers directory. The WhatsApp-delivered VBScript campaign runs its loader from this download staging path. Script execution out of a messenger transfer folder is a strong initial-access and execution indicator.
HuntRule TeamWindowsprocess_creationHigh365Premium2026-05-30ScreenConnect SetupWizard Authentication Bypass Path Traversal (CVE-2024-1709)
This rule detects web requests to the ScreenConnect SetupWizard.aspx endpoint followed by an extra trailing path segment, the request shape that triggers the CVE-2024-1709 authentication bypass. Huntress observed this pattern used to reach the setup wizard on already configured servers and create attacker administrator accounts. A trailing path after SetupWizard.aspx is not produced by normal setup flows and indicates exploitation.
HuntRule TeamWebwebserverHigh337Premium2026-05-30Suspicious Reconnaissance Spawned by Injected SearchProtocolHost via process_creation
This rule detects PikaBot post injection reconnaissance where a hollowed SearchProtocolHost.exe process spawns native discovery utilities such as whoami, ipconfig and netstat. PikaBot injects into SearchProtocolHost.exe using indirect syscalls before enumerating the host and network. The Windows indexing host does not legitimately launch these recon tools, so this parent child pairing is a high confidence indicator of injected loader activity.
HuntRule TeamWindowsprocess_creationHigh93Premium2026-05-30Exchange WebShell Creation
These commands were used to create a WebShell by exploiting ProxyShell vulnerabilities
HuntRule TeamWindowsprocess_creationMedium142Premium2026-05-30Suspicious sslconf Execution From AppData EdgeUpdate Directory
This rule detects a process named sslconf.exe running from a user AppData EdgeUpdate\Install path, matching the SectopRAT payload staged by the FakeAgent Claude Desktop malvertising campaign. The binary masquerades under an EdgeUpdate directory name in a user-writable location that legitimate Edge updater components never use. Execution from this wrong context indicates malware persistence and RAT activity.
HuntRule TeamWindowsprocess_creationHigh61Premium2026-05-30Mshta Spawning PowerShell or Command Shell
This rule detects mshta.exe spawning powershell.exe or cmd.exe as a child process. YoroTrooper used an HTA to JScript to PowerShell execution chain to run reverse shells and stage further tooling. Mshta launching a scripting interpreter is a classic proxy-execution and living-off-the-land pattern used to evade application controls.
HuntRule TeamWindowsprocess_creationHigh163Premium2026-05-30Suspicious Remote Thread Injection into Task Manager
This rule detects a remote thread being created in taskmgr.exe, an injection target used by the defendnot tool to host its fake antivirus registration DLL as analyzed by Huntress. Attackers inject into a signed system process to persist Security Center manipulation and evade scrutiny. Remote thread creation into Task Manager is unusual and indicates process injection for defense evasion.
HuntRule TeamWindowscreate_remote_threadMedium112Premium2026-05-30Suspicious C2 Beacon via cpp-httplib User Agent
This rule detects outbound HTTP requests carrying the cpp-httplib user agent, matching the Potemkin loader command-and-control channel observed with the test_agent identifier. The loader is built on the cpp-httplib library and this user agent rarely appears in legitimate enterprise browsing. Its presence in proxy or web telemetry indicates loader check-in and tasking.
HuntRule TeamWebproxyHigh316Premium2026-05-30Suspicious SMTP Submission Connection From Non-Mail Process
This rule detects an outbound connection to TCP port 587 (SMTP submission) initiated by a process that is not a known mail client. This behavior matches .NET infostealers such as Agent Tesla and XLoader that were hidden in bitmap resources and exfiltrate stolen credentials directly over SMTP. Direct SMTP use by arbitrary binaries is a strong data-theft indicator.
HuntRule TeamWindowsnetwork_connectionMedium189Premium2026-05-30Suspicious Scheduled Task Executing DeElevate64
This rule detects a scheduled task configured via schtasks to run DeElevate64.exe. This behavior matches Ivanti CVE-2025-0282 intrusions where attackers established persistence and privilege manipulation through a scheduled task launching this binary. Scheduled tasks referencing uncommon named binaries are a persistence indicator warranting review of the task action and origin.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-05-30Suspicious Dism Execution from ProgramData Directory (via process_creation)
This rule detects execution of Dism.exe from the ProgramData directory rather than its legitimate System32 location. The FLUX#CONSOLE campaign copied Dism there to sideload a malicious DismCore.dll via search order hijacking.
HuntRule TeamWindowsprocess_creationHigh246Premium2026-05-30Suspicious AWS GetFederationToken Console Access by JavaGhost (via cloudtrail)
This rule detects use of the STS GetFederationToken API, which JavaGhost abuses to mint federated console sign-in sessions from stolen long-term IAM credentials. Generating console access via federation lets the actor operate interactively in the AWS account while blending with legitimate application-token usage.
HuntRule TeamAwscloudtrailMedium219Premium2026-05-30Malicious Zloader C2 Communication Over HTTP
This rule detects HTTP requests to the Zloader command-and-control gate path milagrecf.php observed in the attempted attack against Intel 471. The fixed PHP gate receives beacons from the loader after the malicious Excel 4.0 macro executes. The hardcoded C2 path identifies compromised hosts contacting the operator regardless of the C2 host.
HuntRule TeamWebproxyHigh153Premium2026-05-30