Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,087 rules
Suspicious Secure Deletion of Free Space via Cipher (via process_creation)
This rule detects cipher.exe run with the /w wipe switch, which overwrites free disk space and is abused to destroy recoverable data or securely erase attacker artifacts. Data destruction via cipher is an impact and anti-forensic technique tracked in the Red Canary Threat Detection Report. Detecting this invocation surfaces deliberate data wiping.
HuntRule TeamWindowsprocess_creationMedium40Premium2026-09-04Malicious Account Set with Kerberos DES Encryption Activated - Weakness Introduction (via security)
This rule detects set an account with DES Kerberos encryption to perform ticket brutforce.
HuntRule TeamWindowssecurityHigh20Premium2026-09-04Suspicious Browser Extension Sideload From a User Path (via process_creation)
This rule detects a Chromium-based browser launched with --load-extension pointing at an extension in AppData, Temp or ProgramData, the persistence behavior ChromeLoader uses to inject a malicious browser extension. Loading an unpacked extension from a user-writable path is a technique tracked in the Red Canary Threat Detection Report. Detecting this invocation surfaces browser hijacking for adware or credential theft.
HuntRule TeamWindowsprocess_creationMedium10Premium2026-09-04Malicious LSASS Credential Dump with LSASSY - Process (via process_creation)
This rule detects remotely dump LSASS credentials using the LSASSY tool.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-04Malicious Account Set with Kerberos Pre-authentication Not Required - AS-REP Roasting (via security)
This rule detects set an account with Kerberos pre-authentication not required to perform offline brutforce. Account with this status can be checked with the following command > "Get-ADUser -Filter 'useraccountcontrol -band 4194304' -Properties useraccountcontrol".
HuntRule TeamWindowssecurityHigh10Premium2026-09-03Possible Logged-On Session Discovery via Quser or Qwinsta (via process_creation)
This rule detects quser or qwinsta enumerating interactive logon sessions, a system-owner and remote-session discovery step attackers use to find active administrators before lateral movement. Session discovery is tracked in the Red Canary Threat Detection Report. Detecting these queries surfaces reconnaissance of who is logged on.
HuntRule TeamWindowsprocess_creationLow20Premium2026-09-03Suspicious PSexec Service Installation (via security)
This rule detects installs PSexec service.
HuntRule TeamWindowssecurityMedium20Premium2026-09-03PowerShell Proxy Execution via SyncAppvPublishingServer (via process_creation)
This rule detects SyncAppvPublishingServer being used to smuggle a PowerShell command through its argument, a signed-binary proxy technique that runs script code while masking the parent as a trusted App-V component. SyncAppvPublishingServer abuse is a defense-evasion technique tracked in the Red Canary Threat Detection Report. Detecting this pattern surfaces script execution hidden behind a signed binary.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-09-03Suspicious DLL Execution via Odbcconf LOLBIN (via process_creation)
This rule detects odbcconf.exe registering or executing a DLL through its regsvr action or a response file, a signed-binary proxy technique used to run attacker code past application allowlisting. Odbcconf abuse has appeared in Raspberry Robin activity profiled in the Red Canary Threat Detection Report. Detecting these invocations surfaces trusted-binary DLL execution.
HuntRule TeamWindowsprocess_creationMedium20Premium2026-09-03SocGholish Fake Browser Update Script Execution (via process_creation)
This rule detects the Windows Script Host running a JavaScript file whose name impersonates a browser update, the delivery-and-execution behavior behind SocGholish drive-by fake-update lures. SocGholish is a prevalent initial-access threat profiled in the Red Canary Threat Detection Report that uses malicious JScript to stage follow-on payloads. Detecting the fake-update script surfaces the intrusion at the execution stage before hands-on-keyboard activity.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-03Malicious Sticky Key File Created from CMD Copy (via file_event)
This rule detects replace the original sethc.exe file by cmd.exe.
HuntRule TeamWindowsfile_eventHigh00Premium2026-09-03Suspicious PSexec Execution Over SMB Share (via security)
This rule detects execute PSexec on a remote host via SMB.
HuntRule TeamWindowssecurityMedium10Premium2026-09-03Obfuscated Paste-and-Run Execution From the Windows Run Dialog (via process_creation)
This rule detects explorer.exe directly spawning PowerShell, mshta or curl with a remote URL or encoded payload, the signature of a ClickFix/paste-and-run lure that tricks a user into pasting an attacker command into the Run dialog. Paste-and-run social engineering is one of the fastest-rising initial-access techniques in the Red Canary Threat Detection Report, delivering stealers and loaders. Detecting interpreter children of explorer carrying remote or encoded commands surfaces the intrusion at first execution.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-09-03Malicious LSASS Credential Dump with LSASSY - Admin Share (via security)
This rule detects remotely dump LSASS credentials using the LSASSY tool.
HuntRule TeamWindowssecurityHigh30Premium2026-09-03Suspicious Impact of 'SMOKEDHAM Backdoor' with MSDTC Service Privilege Escalation via Command Line (via process_creation)
This rule detects activity related to 'SMOKEDHAM backdoor' which manipulate the default running service accounf of the MSDTC service in order to DLL side-load a malicious binary.
HuntRule TeamWindowsprocess_creationMedium00Premium2026-09-03