Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,442 rules
Suspicious User and Network Namespace Creation via unshare on Linux
This rule detects use of unshare to create combined user and network namespaces as leveraged by the Copy Fail and DirtyFrag Linux page cache exploits in Elastic research. Unprivileged user namespace creation is a common precursor to kernel exploitation that grants capabilities inside the new namespace for privilege escalation.
HuntRule TeamLinuxprocess_creationMedium142Premium2026-05-22Suspicious Edgecution Decryption Key Storage in Edge AppKey Value (via registry_set)
This rule detects creation of a non standard AppKey value under the HKCU Microsoft Edge key where Edgecution stores the hex string used to decrypt strings inside its Python backdoor. The genuine Edge configuration does not use an AppKey value in this location.
HuntRule TeamWindowsregistry_setMedium215Premium2026-05-21Malicious Shadow Copy Deletion via vssadmin Delete Shadows (via process_creation)
This rule detects vssadmin deleting all volume shadow copies quietly, the inhibit-recovery step in the RansomHub intrusion performed alongside log clearing before encryption. Adversaries destroy shadow copies so victims cannot restore files without paying, so this command outside a maintenance window is a strong pre-encryption impact indicator.
HuntRule TeamWindowsprocess_creationMedium101Premium2026-05-21Suspicious UAT-8302 Scheduled Task Creation for Recon Tooling
This rule detects schtasks creating tasks named ReconLiteDebug or RunWhatPC, matching the UAT-8302 persistence that schedules its host-profiling and command tooling under recognizable task names. These campaign-specific task names betray the attacker even when the underlying payload is renamed. Presence of either scheduled task indicates UAT-8302 foothold and tasking.
HuntRule TeamWindowsprocess_creationHigh296Premium2026-05-21Suspicious Indirect Command Execution via Pcalua for UAC Bypass
This rule detects use of the Program Compatibility Assistant pcalua to indirectly launch a command which the Lazarus chain used to bypass user account control and break parent child process lineage as documented by NCC Group. Attackers proxy execution through pcalua to evade detections that key on direct parent processes.
HuntRule TeamWindowsprocess_creationMedium451Premium2026-05-21Suspicious SQL Service Principal Name Enumeration via Setspn
This rule detects setspn.exe querying for SQL related service principal names which the ColunmTK APT41 cluster uses to identify Kerberoastable service accounts. Enumerating MSSQL SPNs precedes requesting and cracking their Kerberos tickets offline. It matters because this reconnaissance directly enables credential compromise of high privilege database accounts.
HuntRule TeamWindowsprocess_creationMedium467Premium2026-05-21OCSP Responder Auditing Settings Changed or Disabled (via security)
This rule detects would attempt to alter or disable OCSP responder auditing settings to evade detection and perform further escalation via ADCS vulnerabilities.
HuntRule TeamWindowssecurityHigh91Premium2026-05-21Suspicious PowMix Scheduled Task Launching LNK via Explorer
This rule detects creation of a scheduled task that runs explorer.exe against a shortcut file, matching the PowMix botnet persistence that fires a daily task at 11:00 to relaunch its malicious LNK through Explorer. Abusing explorer.exe to open an attacker LNK on a schedule masks the loader chain as ordinary shell activity. This persistence pattern indicates a PowMix foothold on the host.
HuntRule TeamWindowsprocess_creationHigh328Premium2026-05-21Suspicious sshpass Noninteractive SSH Password Authentication (via process_creation)
This rule detects use of sshpass to supply an SSH password on the command line, the method ShinyHunters used for credential spraying across PeopleSoft nodes listed in /etc/hosts during the education sector campaign. Adversaries rely on sshpass to automate password-based lateral movement, and passing credentials inline is rarely legitimate in enterprise environments, so this behavior deserves scrutiny.
HuntRule TeamLinuxprocess_creationMedium93Premium2026-05-21Suspicious Domain Trust Enumeration via Nltest
This rule detects nltest querying domain trusts or domain controllers, an Active Directory reconnaissance step performed by the Malichus malware after exploiting Cleo file transfer software. Enumerating trusts and controllers helps attackers plan lateral movement across the domain. This discovery activity commonly follows initial access on an exposed server.
HuntRule TeamWindowsprocess_creationMedium237Premium2026-05-21Malicious Akira ESXi Encryptor Execution
This rule detects execution of the Akira ESXi encryptor identified by its distinctive virtual-machine targeting arguments. Akira operators ran the Linux ESXi encryptor with flags such as --stopvm --vmonly and --ep to shut down and encrypt virtual machines. These combined VM-control encryptor arguments indicate active hypervisor-level ransomware deployment against an ESXi host.
HuntRule TeamLinuxprocess_creationHigh82Premium2026-05-21Malicious Remote XSL Script Execution via WMIC Squiblytwo Technique
This rule detects WMIC invoking a remote XSL stylesheet via the format switch which is the squiblytwo technique used by the Lazarus chain to execute attacker script content as analysed by NCC Group. Loading a remote XSL through a signed system binary evades application control and downloads code from adversary infrastructure.
HuntRule TeamWindowsprocess_creationHigh151Premium2026-05-21Suspicious PsExec Copying Payload To Windows Temp (via process_creation)
This rule detects PsExec running as SYSTEM to copy a payload into the Windows temp directory, a lateral movement and staging pattern used to distribute the Rhysida ransomware. Remote execution that copies binaries into windows temp is characteristic of hands-on ransomware deployment across hosts.
HuntRule TeamWindowsprocess_creationMedium214Premium2026-05-21Suspicious Linux Log Sanitization via sed In-Place Edit
This rule detects sed being used to edit web and appliance log files in place, matching OVERSTEP anti-forensic behavior that strips attacker artifacts from SonicWall SMA logs. Selective log tampering conceals exploitation and backdoor activity from responders.
HuntRule TeamLinuxprocess_creationMedium141Premium2026-05-21Suspicious DLL Payload Dropped Under Non-Standard Assembly Directory (via file_event)
This rule detects the creation of a DLL under the non-standard C\assembly\tmp staging directory used by the DCOM Upload and Execute backdoor documented by Deep Instinct. The backdoor abuses the DCOM MSI install server to upload and load a managed assembly for remote code execution. Detecting this drop exposes lateral tool transfer before the payload is loaded into a victim process.
HuntRule TeamWindowsfile_eventHigh132Premium2026-05-21