Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,453 rules
Office Persistence via WLL Add-in Dropped to Word STARTUP Folder
This rule detects a .wll Word add-in written to the Microsoft Word STARTUP folder, the persistence mechanism used by the PortDoor backdoor against the Russian defense sector. Word automatically loads WLL add-ins from this folder at launch, giving attackers stealthy code execution on every Word start.
HuntRule TeamWindowsfile_eventHigh71Premium2026-05-17SPN Added to an Account by Command Line (via process_creation)
This rule detects adds a SPN to an account in order to perform different type of abuse (Kerberoast, delegation abuse, ...).
HuntRule TeamWindowsprocess_creationHigh113Premium2026-05-17Suspicious Self-Extracting Archive via tail Piped to funzip
This rule detects a shell piping the tail of a file into funzip, the self-extraction technique used by macOS Shlayer to unpack a password-protected archive appended to a dropper. This lets the adware carry and decompress its payload inline while hiding it from simple file inspection.
HuntRule TeamMacosprocess_creationHigh61Premium2026-05-17Malicious PlugX DLL Sideloading via Canon cnmpaui Utility (via image_load)
This rule detects the legitimate Canon cnmpaui.exe utility loading a cnmpaui.dll from a user AppData Roaming directory. UNC6384 abused DLL search-order sideloading with this signed Canon binary to load a malicious loader that decrypted and ran PlugX.
HuntRule TeamWindowsimage_loadHigh173Premium2026-05-17Malicious Massive Services Termination Burst (via process_creation)
This rule detects stop multiples services on a host. Attacker may target services related to databases, security products or backups (Veeam, Symantec, Acronis ...).
HuntRule TeamWindowsprocess_creationHigh121Premium2026-05-17Malicious Keylogger DLL Execution via Rundll32 klg.dll
This rule detects rundll32.exe loading a DLL named klg.dll which Interlock ransomware operators deploy as a keylogger to capture credentials and keystrokes. The specific module name executed through rundll32 is a reliable behavioral indicator of the keylogging component.
HuntRule TeamWindowsprocess_creationHigh113Premium2026-05-17Malicious DLL Side-Loading of vcl120.bpl From AppData via HijackLoader (via image_load)
This rule detects a vcl120.bpl Delphi runtime package being loaded from a user AppData Roaming directory, the side-loading step used by the IObit-abusing HijackLoader to stage AsyncRAT. The legitimate vcl120.bpl resides with its application, not under AppData.
HuntRule TeamWindowsimage_loadHigh131Premium2026-05-17Mirai and Rondo Payload Retrieval via Known Loader Paths
This rule detects outbound web requests to loader paths used to distribute Mirai binaries and the Rondo cryptominer. These retrievals follow CVE-2025-55182 exploitation of IoT and smart home devices.
HuntRule TeamWebproxyHigh239Premium2026-05-17Malicious Remote Payload Piped to Shell via Curl or Wget
This rule detects download utilities piping fetched content directly into a shell interpreter, the loader pattern the agentic container-escape actor used to stage its second-stage payload from an attacker server. Piping remote content into sh or bash executes untrusted code without touching disk. This is a common ingress tool transfer and execution technique.
HuntRule TeamLinuxprocess_creationHigh341Premium2026-05-16Suspicious NTFS Symbolic Link Evaluation Enabled via fsutil for Remote Access (via process_creation)
This rule detects fsutil enabling remote-to-local or remote-to-remote symbolic link evaluation, an uncommon configuration change made in the RansomHub intrusion to let symlinks resolve across hosts during propagation and encryption. Adversaries flip these SymlinkEvaluation settings to reach files through crafted links that are normally blocked, so this fsutil behavior change is a distinctive attacker-preparation indicator.
HuntRule TeamWindowsprocess_creationMedium308Premium2026-05-16Suspicious Office VBA Security Downgrade via Registry (via registry_set)
This rule detects registry changes that enable programmatic access to the VBA object model and disable macro warnings which the OfflRouter virus sets to spread through Office documents without prompting. Weakening Office macro protections is a precursor to self-propagating macro malware and unattended code execution.
HuntRule TeamWindowsregistry_setMedium322Premium2026-05-16Malicious ServiceDll Hijack with QSC Loader DLL
This rule detects a service Parameters ServiceDll value being set to the QSC loader DLLs swprr.dll or rasautosvc.dll. The CloudComputating group hijacked a Windows service to load these DLLs from System32 and execute the QSC multi-plugin framework with service persistence.
HuntRule TeamWindowsregistry_setHigh441Premium2026-05-16Suspicious RevengeHotels JS Loader Spawning PowerShell (via process_creation)
This rule detects wscript executing a Fat named JavaScript file that then launches PowerShell as used in the RevengeHotels campaign to stage VenomRAT. The threat actor delivers phishing JS droppers whose PowerShell child fetches the remote access trojan. A script host running a Fat JS file with a PowerShell descendant is a strong sign of this loader chain.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-05-16Suspicious Guest Account Enablement via net user for Privilege Abuse
This rule detects the built in guest account being activated through net user which the Gh0stGambit dropper abused for elevation. Enabling and repurposing the guest account provides a low visibility foothold for continued access. Activation of this normally disabled account is a strong sign of account manipulation.
HuntRule TeamWindowsprocess_creationHigh163Premium2026-05-16Suspicious Ukraine-Themed LNK Lure Files Dropped (via file_event)
This rule detects creation of shortcut lure files with region and messaging themed names used by the STEADY#URSA campaign for removable-media replication and social engineering against Ukrainian military targets.
HuntRule TeamWindowsfile_eventHigh102Premium2026-05-16