Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,453 rules
Suspicious Port Forwarding Configuration via netsh portproxy (via process_creation)
This rule detects configuration of an IPv4 or IPv6 port forwarding rule using netsh portproxy. Fire Ant used netsh portproxy on servers and workstations to pivot and relay traffic deeper into segmented networks, sometimes abusing IPv6 to bypass IPv4 filtering. Network administrators may occasionally use portproxy for legitimate forwarding.
HuntRule TeamWindowsprocess_creationMedium285Premium2026-05-16Suspicious FileFix TypedPaths Entry Containing PowerShell or URL
This rule detects an Explorer TypedPaths registry value that records a PowerShell command or HTTP URL, the forensic artifact left when a FileFix lure has the victim paste an obfuscated command into the File Explorer address bar. TypedPaths normally stores browsed folder locations, not scripts or web addresses. A command string or URL in this value indicates the FileFix address-bar execution technique.
HuntRule TeamWindowsregistry_setHigh303Premium2026-05-16Suspicious Azure NSG Rule Opening SSH to the Internet
This rule detects creation or modification of a Network Security Group rule that exposes SSH port 22 to any source address, the network-backdoor action performed in the Azure Fabric intrusion to enable inbound remote access. Opening management ports to 0.0.0.0/0 is a high-risk change and a common cloud persistence step.
HuntRule TeamAzureactivitylogsMedium151Premium2026-05-16Suspicious PowerShell Stager Download of Spf Script by Seedworm
This rule detects PowerShell referencing the Spf.ps1 stager under a remote install path used by the Seedworm MuddyWater actor. The script initiates the next stage of the intrusion against Middle East targets. PowerShell fetching a remote install script is a common first-stage execution technique.
HuntRule TeamWindowsps_scriptMedium122Premium2026-05-16Suspicious Mustang Panda Scheduled Task SolidPDFPcl2Bmp Creation (via process_creation)
This rule detects creation of the SolidPDFPcl2Bmp scheduled task that relaunches the pcl2bmp sideloading host every five minutes in the Mustang Panda ZOHOMURK campaign. Adversaries register a five-minute recurring task pointing at the sideloaded binary in Public Documents to maintain execution. The task name paired with the Public Documents target path is highly specific.
HuntRule TeamWindowsprocess_creationMedium326Premium2026-05-16Suspicious Access to Kubernetes Service Account Token via Curl or Wget (via process_creation)
This rule detects curl or wget accessing the mounted Kubernetes service account token path, a credential theft technique observed in current threats to Kubernetes environments. The service account token grants API access with the pod's privileges, so reading it with a download tool indicates an attacker harvesting cluster credentials from a compromised container.
HuntRule TeamLinuxprocess_creationHigh92Premium2026-05-16Suspicious Secedit Security Policy Export for Reconnaissance (via process_creation)
This rule detects secedit.exe exporting the local security policy configuration to a temp file as observed during the SoftEther VPN intrusion reconnaissance. Attackers export the policy to understand password and account restrictions before creating backdoor users.
—Windowsprocess_creationMedium3210Premium2026-05-16Malicious Shadow Copy Deletion and Recovery Tampering by BabLock Ransomware
This rule detects deletion of volume shadow copies and disabling of Windows recovery, hallmarks of BabLock ransomware pre-encryption activity. The operators run vssadmin Delete Shadows and bcdedit recoveryenabled No to prevent victims restoring their data. This inhibits recovery and maximizes the impact of the encryption stage.
HuntRule TeamWindowsprocess_creationHigh72Premium2026-05-16Malicious Payload Decoding via Certutil
This rule detects certutil using its decode function against PDF-named files to reconstruct an executable payload from base64, a defense-evasion and deobfuscation step. This was observed in a Vietnamese threat actor chain delivering PureRAT. Abusing certutil to decode disguised files bypasses download controls and unpacks the next-stage loader.
HuntRule TeamWindowsprocess_creationHigh2710Premium2026-05-16Suspicious Registry SYSTEM Hive Dump via Reg Save (via process_creation)
This rule detects reg.exe saving the HKLM SYSTEM hive to a local file, a credential access technique used in the MS-SQL intrusion to extract secrets for offline processing. Saving the SYSTEM hive to a user writable path is rarely part of legitimate administration.
—Windowsprocess_creationMedium242Premium2026-05-15Suspicious NetSupport client32 Execution from ProgramData (via process_creation)
This rule detects execution of the NetSupport Manager remote control client client32.exe from a CommunicationLayer directory under ProgramData. The JS#SMUGGLER campaign installed NetSupport RAT to this path.
HuntRule TeamWindowsprocess_creationHigh193Premium2026-05-15Suspicious JSP Webshell Written to SAP irj work Directory (via file_event)
This rule detects JSP files being written under the SAP servlet_jsp irj work directory, the deployment location where CVE-2025-31324 exploitation dropped webshells such as forwardsap.jsp and helper.jsp. New JSP files appearing in this runtime path indicate server software component abuse. This is a reliable webshell persistence signal.
HuntRule TeamWindowsfile_eventHigh92Premium2026-05-15Suspicious VBA Runtime Loaded by Process from OneNote Exported Directory
This rule detects a process running from the OneNote exported attachment or temp directory loading the VBE7.dll VBA runtime, indicating macro or script execution from a weaponised OneNote embedded file. Legitimate applications rarely execute from the OneNote Exported path, so loading the VBA engine from there signals malicious code launched via a OneNote phishing lure.
HuntRule TeamWindowsimage_loadHigh103Premium2026-05-15Suspicious Boot Recovery Disabled via bcdedit Before Encryption (via process_creation)
This rule detects bcdedit disabling Windows boot recovery, an inhibit-recovery step performed by Mallox ransomware before file encryption. Adversaries turn off automatic recovery so victims cannot restore systems after encryption, making this a common pre-encryption impact indicator that warrants investigation alongside surrounding activity.
HuntRule TeamWindowsprocess_creationMedium1710Premium2026-05-15Malicious Turla PNG Dropper Service Masquerading as Windows Error Reporting via Service Creation
This rule detects installation of a Windows service using names that masquerade as legitimate Windows Error Reporting components which the Turla PNG Dropper uses for persistence. Observed in NCC Group research on the returning Turla PNG Dropper which registers services such as WerFaultSvc and RegRunnerSvc to load steganographic payloads. Detecting these masquerading service installations helps catch stealthy persistence by this espionage actor.
HuntRule TeamWindowssystemHigh112Premium2026-05-15