Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,456 rules
Suspicious Batch Execution From Hidden __MACOSX Archive Path (via process_creation)
This rule detects a command shell executing a batch file from a hidden __MACOSX directory extracted from a delivery archive, the initial execution step of this Cobalt Strike infection chain. Legitimate workflows do not run scripts from __MACOSX archive residue.
HuntRule TeamWindowsprocess_creationHigh125Premium2026-05-12Windows Execution of tanstack_runner.js via bun.exe
Flags bun.exe launching a script via "run tanstack_runner.js" on Windows.
Leonardo Gasparini, Huntrule TeamWindowsprocess_creationHigh171Free2026-05-12Linux process execution indicators for TanStack preinstall supply-chain payloads
Flags Linux processes running a Bun-based TanStack runner (and related Python pyz payload execution) indicative of supply-chain compromise.
Leonardo Gasparini, Huntrule TeamLinuxprocess_creationHigh172Free2026-05-12Windows TanStack Supply-Chain File Creation Indicators via router_init.js and router_runtime.js
Alerts on Windows creation of router/tanstack runner and router_runtime files used in a TanStack supply-chain attack pattern.
Leonardo Gasparini, Huntrule TeamWindowsfile_eventMedium182Free2026-05-12Linux File Creation Indicators for TanStack Runner and Persistence Components
Alerts on creation of TanStack-style runner/persistence filenames on Linux, including .claude/.vscode router_runtime.js and /tmp/transformers.pyz.
Leonardo Gasparini, Huntrule TeamLinuxfile_eventMedium163Free2026-05-12Windows DNS Queries to git-tanstack.com and filev2.getsession.org
Alert on Windows DNS lookups of git-tanstack.com and filev2.getsession.org tied to supply-chain C2/exfil.
Leonardo Gasparini, Huntrule TeamWindowsdns_queryMedium133Free2026-05-12Malicious SSLoad Downloader C2 Beacon via Custom SSLoad User-Agent (via proxy)
This rule detects outbound HTTP traffic carrying the hardcoded SSLoad User-Agent used by the SSLoad downloader when it registers a fingerprinted host and beacons for tasks to its command-and-control server. This bespoke agent string is not produced by legitimate software and identifies the downloader stage of the intrusion on the wire.
HuntRule TeamWebproxyHigh71Premium2026-05-11Suspicious PAM Backdoor via pam_exec Configuration Change
This rule detects modification of a PAM configuration file to load pam_exec.so, a pluggable authentication module backdoor described in Elastic Linux persistence research. By adding a pam_exec directive to an sshd PAM stack the attacker runs an arbitrary script on each authentication for persistence and credential capture. Edits to files under /etc/pam.d that introduce pam_exec are highly suspicious.
HuntRule TeamLinuxprocess_creationHigh306Premium2026-05-11Suspicious Excel Outbound Network Connection
This rule detects Excel.exe initiating an outbound network connection, which is unusual for a spreadsheet application that has no child process. In the WithSecure Initial Access Lab 4 an Excel 4.0 SLK macro injects meterpreter shellcode into Excel itself which then beacons over HTTPS to a non-Microsoft address. Attackers keep the malicious code inside the Office host to avoid spawning a suspicious child process.
HuntRule TeamWindowsnetwork_connectionMedium365Premium2026-05-11Suspicious Windows Event Log Clearing via wevtutil (via process_creation)
This rule detects wevtutil being used to clear Windows event logs. This behavior was observed in Cyber Partisans activity aimed at espionage and disruption to destroy forensic evidence after intrusion. Because administrators occasionally clear logs during maintenance, matches should be correlated with the surrounding activity and account context.
HuntRule TeamWindowsprocess_creationMedium152Premium2026-05-11Suspicious Microsoft Defender Security Components Disabled - Command (via process_creation)
This rule detects disable Defender security features.
HuntRule TeamWindowsprocess_creationMedium1610Premium2026-05-11Suspicious UAC Bypass via Fodhelper Child Process
This rule detects fodhelper.exe spawning a child process, the hallmark of the ms-settings protocol handler UAC bypass used by BQTLock to elevate before injecting Remcos into explorer.exe. Fodhelper does not normally launch child processes outside of Settings interactions.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-05-11ArmouryLoader Persistence via Scheduled Task AsusUpdateServiceUA (via process_creation)
This rule detects creation of a scheduled task named AsusUpdateServiceUA, the persistence artifact ArmouryLoader registers to relaunch its shellcode payload at logon or on a short recurring interval while masquerading as an Asus update service. Adversaries use a plausible vendor task name to survive reboots and blend into legitimate software, making early detection critical for exposing the loader before CoffeeLoader delivery.
HuntRule TeamWindowsprocess_creationMedium158Premium2026-05-11Suspicious WindowsCodecs DLL Sideload from Non System Path by Fighting Ursa
This rule detects WindowsCodecs.dll being loaded from a location outside the Windows system directories, the DLL search order hijack Fighting Ursa uses when a renamed calc.exe sideloads a malicious copy to run its batch payload. Loading a system DLL name from a user path indicates sideloading rather than legitimate use. Detecting this exposes the sideload stage of the infection.
HuntRule TeamWindowsimage_loadMedium262Premium2026-05-11Possible Check Point Management Application Token Authentication as Administrator (via checkpoint)
This rule detects Check Point management audit records showing an authentication performed with an application token that results in system_admin access. Rapid7 tied this pattern to exploitation of the CVE-2026-16232 SmartConsole authentication bypass where forged SSO tickets granted administrative sessions. Administrative logon using an application token rather than interactive credentials is a strong indicator of the bypass being exploited.
HuntRule TeamCheckpointauditMedium184Premium2026-05-11