Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,446 rules
Suspicious IAM CreateLoginProfile For Root User via AWS AssumeRoot Abuse
This rule detects an IAM CreateLoginProfile event that establishes console access for the root user which follows abuse of STS AssumeRoot to plant durable access in a member account. Adversaries create a root login profile to convert temporary root credentials into persistent account takeover.
HuntRule TeamAwscloudtrailHigh321Premium2026-05-20Suspicious Domain Trust Discovery via Nltest
This rule detects nltest enumerating trusted domains, an Active Directory discovery step used to map trust relationships for lateral movement. This was observed after SonicWall VPN exploitation preceding Akira ransomware. Domain trust enumeration from user context or servers often marks hands-on-keyboard reconnaissance.
HuntRule TeamWindowsprocess_creationMedium175Premium2026-05-20Suspicious RunMRU Entry Containing Script Download from ClickFix
This rule detects a RunMRU history value that records a scripted download command such as PowerShell or mshta invoking a remote resource. ClickFix social engineering has the victim paste the command into the Run dialog which leaves the payload in RunMRU before it is cleared. Script interpreters and download utilities in the Run dialog history strongly suggest a ClickFix style delivery.
HuntRule TeamWindowsregistry_setMedium51Premium2026-05-20Suspicious Scheduled Task Creation Pointing to AppData (via process_creation)
This rule detects creation of a scheduled task whose action points to an executable inside the user AppData directory. Nokoyawa-linked loaders register an hourly task in AppData Roaming to maintain persistence for IcedID and follow-on tooling. Scheduled tasks launching binaries from AppData are unusual and a common persistence mechanism for commodity loaders.
HuntRule TeamWindowsprocess_creationMedium3510Premium2026-05-19Possible Metabase Pre-Auth RCE via H2 JDBC Injection on Setup Validate (CVE-2023-38646) (via webserver)
This rule detects requests to the Metabase setup validate endpoint carrying an H2 JDBC connection string with a trace level directive referencing the application jar. This maps to CVE-2023-38646 where a leaked setup token allows unauthenticated H2 injection to write and execute code. An attacker uses this chain to achieve remote code execution before authentication.
HuntRule TeamWebwebserverHigh161Premium2026-05-19Malicious Defender Real-Time Monitoring Disable via Registry
This rule detects the DisableRealtimeMonitoring registry value being enabled to turn off Microsoft Defender real-time scanning. This was observed during Cephalus ransomware deployment alongside service stops and exclusions. Disabling real-time monitoring removes on-access detection so the encryptor can run freely.
HuntRule TeamWindowsregistry_setHigh163Premium2026-05-19Possible System and File Discovery via System_profiler or Mdfind (via process_creation)
This rule detects system_profiler or mdfind enumerating host details and indexed files, a system-information and file-discovery step attackers use to profile a macOS endpoint after initial access. Host discovery is tracked in the Red Canary Threat Detection Report macOS coverage. Detecting these queries surfaces reconnaissance of the system.
HuntRule TeamMacosprocess_creationLow81Premium2026-05-19Suspicious MSHTA Remote HTML Application Execution via Amatera Stealer ClickFix
This rule detects mshta.exe launching an HTML application from a remote URL, the ClickFix delivery step for the Amatera Stealer 4.0.2 variant. The victim is lured into running a copied command that pulls an HTA from attacker infrastructure. Remote mshta execution is a common living-off-the-land loader technique and should be reviewed against expected administrative activity.
HuntRule TeamWindowsprocess_creationMedium394Premium2026-05-19Suspicious propsys.dll Sideload via ComputerDefaults UAC Bypass (via image_load)
This rule detects ComputerDefaults.exe loading propsys.dll from outside the Windows system directories, the DLL sideload and UAC bypass the 8220 Gang chains to elevate and continue its cryptomining deployment. The auto-elevating ComputerDefaults binary is abused to load an attacker propsys.dll placed in a writable path. Detecting this non-system load surfaces the UAC bypass and sideloading step.
HuntRule TeamWindowsimage_loadHigh259Premium2026-05-19Malicious Obsidian Spawning Command Interpreter via Shell Commands Plugin
This rule detects the Obsidian note taking application spawning PowerShell, cmd or a shell as abused by the PhantomPulse RAT delivery chain through the Shell Commands plugin in Elastic research. A document editor launching a command interpreter is anomalous and indicates weaponized vault content executing attacker code.
HuntRule TeamWindowsprocess_creationHigh328Premium2026-05-19Suspicious Mshta Execution Of Remote HTA
This rule detects mshta.exe executing an HTA hosted at a remote http or https URL. In the WithSecure Initial Access Lab 2 the Koadic stager is delivered as a remote HTA run directly by mshta. Attackers use mshta to fetch and run remote HTML applications as a proxy execution and download technique.
HuntRule TeamWindowsprocess_creationHigh159Premium2026-05-19Suspicious Atera Agent Silent Installation via Command Line (via process_creation)
This rule detects silent installation of the Atera RMM agent identified by its IntegratorLogin and CompanyId command-line parameters. Adversaries deploy Atera as an unsanctioned remote access channel using these silent-install arguments, so their presence outside an approved rollout indicates RMM misuse.
HuntRule TeamWindowsprocess_creationMedium111Premium2026-05-19Suspicious schtasks Persistence Spawned from PowerShell or Script Chain
This rule detects schtasks creating a scheduled task when launched from a PowerShell or command-shell parent, a persistence step observed in the Suky Castle ClickFix-style campaign where an obfuscated PowerShell to cmd to attrib to schtasks chain established persistence. It captures scheduled-task creation originating from an interactive scripting context rather than an installer. Detecting this is important because attacker-driven schtasks activity typically descends from a script host rather than a legitimate management tool.
HuntRule TeamWindowsprocess_creationMedium175Premium2026-05-19Malicious Directory Enumeration With Recon Tooling User Agent via Azure AD Graph
This rule detects Azure AD Graph requests carrying user agents belonging to known enumeration frameworks such as AzureHound BloodHound and AADInternals as described in Elastic research on AAD Graph activity logs. These tool signatures against the legacy Graph service indicate active directory reconnaissance for privilege escalation paths.
HuntRule TeamAzureazureactivityHigh122Premium2026-05-19Suspicious Nmap Scripting Engine User-Agent in HTTP Requests (via webserver)
This rule detects HTTP requests carrying the Nmap Scripting Engine user-agent string, indicating automated NSE web probing against exposed services. Scanning activity of this kind precedes exploitation as adversaries enumerate service versions and vulnerabilities. Identifying the NSE user-agent surfaces active reconnaissance targeting internet-facing or ICS-adjacent web assets.
HuntRule TeamWebwebserverMedium104Premium2026-05-19