Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,446 rules
Suspicious wscript Execution of Short-Name JavaScript from AppData (via process_creation)
This rule detects GootBot persistence where a scheduled task runs wscript.exe against a second-stage JavaScript file using its short name ending in a tilde-one JS pattern inside an AppData subfolder. Execution of a short-name js from AppData by the script host is characteristic of the GootLoader chain. Legitimate software rarely launches scripts this way.
HuntRule TeamWindowsprocess_creationMedium382Premium2026-05-20Suspicious SD-WAN Compromise Reverse Tunnel via gsocket
This rule detects execution of the gsocket or gs-netcat tunneling utilities, matching the Cisco Catalyst SD-WAN exploitation where operators deploy gsocket to establish an outbound relay through firewalls. The Global Socket toolkit provides resilient encrypted access that bypasses inbound restrictions on compromised network devices. Presence of these tools on an appliance indicates covert remote access.
HuntRule TeamLinuxprocess_creationMedium153Premium2026-05-20Obfuscated Firewall Configuration Enumerated - Command (via process_creation)
This rule detects extract current Windows firewall configuration to prepare an attack.
HuntRule TeamWindowsprocess_creationHigh215Premium2026-05-20Enable WDigest using PowerShell (ps_module)
Rule to detect registry modifications to enable WDigest using powershell script modules.
HuntRule TeamWindowsps_moduleMedium252Premium2026-05-20Suspicious AWS IAM User Creation Using Support Impersonation Name
This rule detects the creation of an AWS IAM user named aws_support which the TeamTNT Doppelganger campaign creates and grants administrative permissions to in order to establish a persistent privileged foothold disguised as a legitimate AWS support account.
HuntRule TeamAwscloudtrailHigh103Premium2026-05-20Suspicious Hidden Local Account Creation Via Net User
This rule detects creation of a local account whose name ends with a dollar sign using net user with the add flag. DragonRank created a hidden admins$ local account to maintain access on compromised web servers. Appending a trailing dollar sign hides the account from casual net user enumeration making this a stealthy persistence and account-manipulation move.
HuntRule TeamWindowsprocess_creationHigh482Premium2026-05-20Suspicious Security Software Enumeration on macOS
This rule detects enumeration of macOS security tooling such as Little Snitch, a discovery step malware performs to detect network monitoring and endpoint defenses before proceeding. Identifying protective software lets the malware adjust behavior or avoid noisy network activity.
HuntRule TeamMacosprocess_creationMedium161Premium2026-05-20Suspicious Access to Chrome Login Data on macOS (via process_creation)
This rule detects command-line access to the Chrome Login Data SQLite database on macOS, where stealers extract saved browser credentials and session cookies. macOS infostealers copy or query this file to harvest stored passwords and authenticated web sessions for account takeover.
HuntRule TeamMacosprocess_creationMedium2610Premium2026-05-20Suspicious Marimo Terminal WebSocket RCE Access via Webserver
This rule detects access to the marimo terminal WebSocket endpoint that an attacker abused for remote code execution as the initial pivot in an LLM-guided intrusion toward an internal database. The endpoint exposes an interactive shell over the notebook interface. Requests to this path from untrusted sources indicate attempted exploitation of the exposed marimo service.
HuntRule TeamWebwebserverMedium131Premium2026-05-20Suspicious LDAP Enumeration of Certificate Templates (via security)
This rule detects LDAP queries enumerating pKICertificateTemplate objects, an AD CS reconnaissance step used to find misconfigured templates vulnerable to certificate-based privilege escalation. This activity commonly precedes malicious certificate requests observed in Security Events 4886 and 4887.
HuntRule TeamWindowssecurityLow366Premium2026-05-20Suspicious Run Key Persistence via reg add
This rule detects reg.exe writing a value under a CurrentVersion Run or RunOnce key, a common autorun persistence mechanism. Adversaries add these entries so their payload executes automatically at user logon, and living-off-the-land toolkits frequently script this step.
HuntRule TeamWindowsprocess_creationMedium345Premium2026-05-20Possible Citrix NetScaler Webshell Deployment under VPN Theme Directory (CVE-2023-3519) (via webserver)
This rule detects requests to PHP files located under the NetScaler VPN theme directory. This maps to post-exploitation of CVE-2023-3519 where attackers write a PHP webshell to /var/vpn/theme after the buffer overflow. Access to a PHP resource in this static theme path indicates a deployed webshell used for persistent remote command execution.
HuntRule TeamWebwebserverHigh433Premium2026-05-20Suspicious VMware and Cortex Binaries Executing From User-Writable Paths
This rule detects processes named after legitimate VMware guest tools or the Palo Alto Cortex updater running from AppData, Temp, or other user-writable directories. Actors in the Africa financial-sector campaign renamed their PoshC2 tooling to vmtoolsd.exe, vm3dservice.exe and CortexUpdater.exe to blend in. Trusted binary names executing from non-standard paths indicate masquerading.
HuntRule TeamWindowsprocess_creationHigh387Premium2026-05-20Suspicious Executable Running from PerfLogs Directory
This rule detects execution of a binary from the Windows PerfLogs directory which ransomware operators use as a staging location for tooling. Observed in NCC Group research into active ransomware families dropping a min.exe binary into the PerfLogs directory. Execution from PerfLogs is highly abnormal which makes it a useful indicator of stager or tooling activity.
HuntRule TeamWindowsprocess_creationMedium92Premium2026-05-20Suspicious Curl Output Piped To Bash On macOS via ClickFix
This rule detects a curl download whose output is piped directly into a bash shell on macOS, matching the ClickFix social-engineering chain that tricks users into pasting a terminal command. This technique is used to deliver the Odyssey and ACR infostealers after a fake Cloudflare human-verification prompt. Fetching and executing remote code in one step lets the operator run a payload with no file written to disk beforehand.
HuntRule TeamMacosprocess_creationMedium134Premium2026-05-20