Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,433 rules
Malicious Named Pipe Netcat Reverse Shell via Shell (via process_creation)
This rule detects a reverse shell built from a named pipe relayed through netcat on Linux hosts. The marimo blockchain botnet campaign used mkfifo and nc to relay an interactive shell back to attacker infrastructure. This combination of a fifo and netcat is a well known reverse shell construct that warrants immediate investigation.
HuntRule TeamLinuxprocess_creationHigh389Premium2026-05-27Suspicious Service NetDnsActivatorSharing Creation via Process Creation
This rule detects creation of a Windows service named NetDnsActivatorSharing via sc.exe, a persistence artifact of the GoldenJackal air-gapped toolset. The name imitates a plausible networking service to evade casual review. This indicates service-based persistence by an espionage actor targeting isolated networks.
HuntRule TeamWindowsprocess_creationHigh101Premium2026-05-27Suspicious Exchange Online Mail Flow Rule or Connector Creation via Compromised Account
This rule detects creation or modification of Exchange Online transport rules, inbound connectors, or DKIM signing configuration, matching post-compromise mailbox tampering observed in the Kali365 device code phishing ecosystem. Adversaries add mail flow rules and connectors to reroute, hide, or spoof mail after taking over an account. These mailbox-infrastructure changes support business email compromise and mass phishing distribution.
HuntRule TeamM365exchangeMedium92Premium2026-05-27Possible Nagios XI Unauthenticated Terminal Web Shell Access
This rule detects access to the Nagios XI terminal endpoint which exposes an interactive web shell, an access path abused to gain unauthenticated command execution on the appliance. Requests to this terminal path from unexpected sources indicate probing or exploitation of the web shell functionality.
HuntRule TeamWebwebserverMedium427Premium2026-05-27Malicious BYOVD Driver Signed by Revoked Certificate Load (via image_load)
This rule detects the loading of a kernel driver signed with the revoked or expired certificates reused by the AVKiller EDR killer shared across multiple ransomware operators. The driver carries a randomized name and fake CrowdStrike version information but is signed by the revoked Changsha Hengxiang or expired Fuzhou Dingxin certificates, a strong indicator of bring your own vulnerable driver abuse.
HuntRule TeamWindowsimage_loadHigh145Premium2026-05-27Suspicious AWS EC2 Windows Password Retrieval via GetPasswordData
This rule detects use of the EC2 GetPasswordData API which returns the encrypted local administrator password for a Windows instance. In the Wiz hybrid cloud response case an attacker with stolen AWS credentials called GetPasswordData to recover local admin passwords and pivot onto EC2 hosts. This is important because password retrieval across instances is a strong precursor to interactive host access and lateral movement into the compute layer.
HuntRule TeamAwscloudtrailMedium122Premium2026-05-27Suspicious Okta Sign-On Policy Lifecycle Modification
This rule detects Okta policy lifecycle update or delete events affecting authentication policies. Adversaries who compromise an Okta admin weaken or remove sign-on and MFA policies to keep access, so lifecycle changes to policies warrant review against expected administration.
HuntRule TeamOktaoktaMedium111Premium2026-05-27Suspicious RegAsm Process Hollowing for DarkCloud Stealer
This rule detects RegAsm.exe launching outside of normal .NET build or install workflows. The DarkCloud stealer infection chain injects its payload into a hollowed RegAsm.exe process to execute under a trusted Microsoft binary. RegAsm running without a legitimate .NET tooling parent is a strong process hollowing indicator.
HuntRule TeamWindowsprocess_creationMedium3110Premium2026-05-27Suspicious Prefetch Deletion for Anti-Forensics
This rule detects deletion of files from the Windows Prefetch directory, an anti-forensic action The Gentlemen ransomware used to remove execution artifacts alongside Defender logs. Clearing Prefetch data is a deliberate attempt to hinder investigation and indicates active cleanup by an intruder.
HuntRule TeamWindowsprocess_creationMedium92Premium2026-05-27Suspicious Sisfader RAT Loader DLL Written to Local AppData
This rule detects creation of a DLL named to appear as a helper component in the user Local AppData directory which the Sisfader RAT drops as its loader. Observed in NCC Group research on CVE-2017-8570 RTF documents delivering the Sisfader RAT. A helper-named DLL staged in a user profile directory is an indicator of masqueraded malware persistence.
HuntRule TeamWindowsfile_eventMedium115Premium2026-05-27Malicious Reverse Tunnel Agent Execution with Hidden Server Flags
This rule detects execution of agent.exe with -server and -hide command-line flags, the reverse tunnel implant used in a Huntress-investigated Nightmare-Eclipse intrusion that connected to staybud.dpdns.org over port 443. The -hide flag conceals the agent window while -server points to the attacker relay, establishing a yamux-based reverse tunnel. This flag combination reflects covert command-and-control tunneling.
HuntRule TeamWindowsprocess_creationHigh336Premium2026-05-27Malicious PeerBlight Command and Control Beacon to qtss.cc Domain
This rule detects DNS resolution of the qtss.cc domain, the ZinFoq command and control infrastructure contacted by the PeerBlight Linux backdoor for beaconing. Resolution of this domain indicates an infected host reaching out to attacker-controlled C2. The domain is a known PeerBlight indicator and has no legitimate business use.
HuntRule TeamNetworkdns_queryHigh285Premium2026-05-27Suspicious KeePass Configuration Discovery via PowerShell Script
This rule detects execution of the Find-KeePassConfig PowerShell function, used by the ransomware actor Storm-0501 to locate KeePass password database configuration files for credential theft. Discovering KeePass configs is a precursor to extracting master keys and stored secrets from password vaults.
HuntRule TeamWindowsps_scriptHigh299Premium2026-05-26Malicious LSASS Memory Dump via Rundll32 comsvcs.dll MiniDump
This rule detects rundll32.exe invoking the comsvcs.dll MiniDump export to dump process memory, a LOLBIN LSASS dumping technique documented by Huntress. Attackers first resolve the LSASS process id via tasklist and then dump its memory to harvest plaintext credentials and hashes. Because comsvcs MiniDump has no legitimate administrative use, this is a high-confidence credential-theft signal.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-05-26Suspicious NightSpire Encryptor Execution Producing nspire Extension via process_creation
This rule detects execution of the enc.exe encryptor associated with NightSpire ransomware or command lines referencing the .nspire extension it appends. This activity represents the encryption stage of the intrusion where victim files are locked, and its detection enables rapid response to limit ransomware impact.
HuntRule TeamWindowsprocess_creationHigh283Premium2026-05-26