Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,454 rules
Malicious Office 365 Email Forwarding Rule to External Domain (via office365)
This rule detects creates a forwarding rules to a non company email in order to collect information.
HuntRule TeamAzureoffice365High244Premium2026-05-14Suspicious AdInsight Execution from ProgramData via Scheduled Task by WikiLoader
This rule detects a renamed AdInsight executable running from the ProgramData directory, the persistence payload a scheduled task launches in the spoofed GlobalProtect WikiLoader campaign. A signed utility executed from a non-standard writable path indicates masquerading and sideloading rather than legitimate use. Detecting this exposes the persistence and execution stage of the loader.
HuntRule TeamWindowsprocess_creationMedium461Premium2026-05-14ZOHOMURK Non-Browser Zoho and IPFetcher User-Agents (via proxy)
This rule detects the hardcoded Zoho client and IPFetcher user-agent strings used by the ZOHOMURK implant when abusing Zoho WorkDrive and ipinfo.io during the Mustang Panda campaign. Adversaries reuse these non-browser agent strings for OAuth, folder enumeration and external IP discovery. Because legitimate Zoho software does not emit these exact tokens, the agents provide a reliable channel indicator.
HuntRule TeamWebproxyMedium112Premium2026-05-14Suspicious File Download via Certutil URLCache [Huntress] #2
This rule detects certutil.exe downloading a remote file using the urlcache option, a LOLBIN download technique Huntress observed after Wing FTP CVE-2025-47812 exploitation. Attackers use certutil to retrieve payloads over HTTP while blending in with a trusted signed binary. Certutil retrieving content from a URL is a common ingress tool transfer indicator that warrants review of the fetched resource.
HuntRule TeamWindowsprocess_creationMedium141Premium2026-05-14Suspicious Command Processor AutoRun Persistence via Registry Set
This rule detects writes to the Command Processor AutoRun registry value, which forces a command to run whenever cmd.exe starts and was used for persistence in the Uncorking Old Wine Cobalt Strike loader. This value is rarely set by legitimate software and is a well-known event-triggered execution vector.
HuntRule TeamWindowsregistry_setHigh143Premium2026-05-14Possible PAN-OS Auth Bypass via Double-Encoded Path Traversal to ztp_gate (CVE-2025-0108)
This rule detects requests to the PAN-OS unauth path that use double-encoded traversal sequences to reach authenticated PHP scripts such as ztp_gate.php, matching the Nginx and Apache path confusion auth bypass for CVE-2025-0108 documented by Assetnote. The double-encoded %252e segments defeat the X-pan-AuthCheck routing and expose privileged management endpoints. This encoded traversal against ztp_gate indicates an attempt to bypass authentication on the management interface.
HuntRule TeamWebwebserverHigh432Premium2026-05-14Malicious Domain Admin Account Escalation via net group (via process_creation)
This rule detects a net group command adding an account to the Domain Admins or Enterprise Admins group over the domain. Operators exploiting BeyondTrust Remote Support via CVE-2026-1731 created a domain account and escalated it into these privileged groups.
HuntRule TeamWindowsprocess_creationHigh4810Premium2026-05-14Suspicious WinSvcUpd Scheduled Task Persistence via schtasks (via process_creation)
This rule detects creation of a scheduled task named WinSvcUpd that runs PowerShell with a bypassed execution policy at logon with highest privileges. The GPUGate malware registered this task masquerading as a Windows update service for persistence.
HuntRule TeamWindowsprocess_creationHigh234Premium2026-05-14Malicious macOS.Gaslight Persistence via Apple-Namespace LaunchAgent (via file_event)
This rule detects creation of the LaunchAgent property list that the macOS.Gaslight Rust backdoor uses for persistence, masquerading inside the Apple com.apple namespace with the label com.apple.system.services.activity. Genuine Apple daemons are not installed as user LaunchAgents under this exact label. Its presence indicates the Gaslight implant is establishing persistence.
HuntRule TeamMacosfile_eventHigh259Premium2026-05-14Suspicious RDP Wds StartupPrograms Persistence Modification (via registry_set)
This rule detects modification of the Terminal Server rdpwd StartupPrograms value which lists programs launched when a Remote Desktop session starts. Adversaries append their payload to this value to persist and execute code on incoming RDP logons.
HuntRule TeamWindowsregistry_setMedium357Premium2026-05-14Suspicious Outlaw Payload Download via wget dota Archive
This rule detects wget or curl retrieving the Outlaw botnet staging script or the dota.tar.gz archive that unpacks the miner and SSH brute-force components. This download step bootstraps the full infection after initial access on a Linux host. The specific script and archive names are consistent Outlaw distribution artifacts.
HuntRule TeamLinuxprocess_creationHigh123Premium2026-05-14Suspicious Scheduled Task TPMProfiler Executing QEMU Emulator
This rule detects creation of a scheduled task named TPMProfiler or a task configured to run qemu-system-x86_64, the persistence and execution mechanism observed after SolarWinds Web Help Desk exploitation where a QEMU emulator was launched to evade host-level inspection. Masquerading a task as a benign TPM profiler while it starts a full system emulator is a deliberate concealment tactic. This pairing of task name and QEMU binary is a reliable compromise indicator.
HuntRule TeamWindowsprocess_creationHigh401Premium2026-05-14Malicious Linux XorDDoS gcc.pid Device Marker File via file_event
This rule detects creation of the /var/run/gcc.pid device-identifier file that the Linux XorDDoS trojan reads and writes to track infected hosts. This hardcoded artifact path is a distinctive marker of the XorDDoS campaign delivering DDoS malware, so its appearance indicates an active infection.
HuntRule TeamLinuxfile_eventHigh162Premium2026-05-14LightSpy macOS Implant PID File Creation in Users Shared
This rule detects creation of the file irc.pid under the Users Shared directory, a fixed artifact written by the macOS variant of the LightSpy surveillance implant to track its running instance. Huntress recovered this PID file alongside plugin fetching and WebSocket command-and-control. The specific path and filename are a reliable host indicator of the implant executing on macOS.
HuntRule TeamMacosfile_eventMedium73Premium2026-05-14Suspicious Kimsuky Run Key Persistence via Masqueraded Value (via registry_set)
This rule detects creation of a Run key value named Everything, install or tdll, autostart names Kimsuky used to persist its PebbleDash based tools under benign looking labels. The autostart relaunches the implant at logon while masquerading as ordinary software. Detecting these value names surfaces registry persistence tied to the campaign.
HuntRule TeamWindowsregistry_setMedium62Premium2026-05-14