Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,458 rules
Suspicious WindowsCodecs DLL Sideload from Non System Path by Fighting Ursa
This rule detects WindowsCodecs.dll being loaded from a location outside the Windows system directories, the DLL search order hijack Fighting Ursa uses when a renamed calc.exe sideloads a malicious copy to run its batch payload. Loading a system DLL name from a user path indicates sideloading rather than legitimate use. Detecting this exposes the sideload stage of the infection.
HuntRule TeamWindowsimage_loadMedium262Premium2026-05-11Possible Check Point Management Application Token Authentication as Administrator (via checkpoint)
This rule detects Check Point management audit records showing an authentication performed with an application token that results in system_admin access. Rapid7 tied this pattern to exploitation of the CVE-2026-16232 SmartConsole authentication bypass where forged SSO tickets granted administrative sessions. Administrative logon using an application token rather than interactive credentials is a strong indicator of the bypass being exploited.
HuntRule TeamCheckpointauditMedium184Premium2026-05-11Malicious Citrix WFShell Spawning Command Interpreter via Command Line
This rule detects the Citrix wfshell.exe or cmstart.exe process spawning a command interpreter, a post-exploitation chain observed after abuse of the Citrix Bleed vulnerability CVE-2023-4966 leading to LockBit ransomware. These Citrix components should not launch shells. Detecting the chain exposes hands-on-keyboard activity following gateway compromise.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-05-11Suspicious IAM Policy Attachment Granting AdministratorAccess
This rule detects an AttachUserPolicy call that attaches the AWS managed AdministratorAccess policy to an IAM user. After compromising an EC2 instance and stealing IMDS credentials the attacker created a rogue IAM user and granted it full administrator rights for persistence and privilege escalation. Sudden attachment of AdministratorAccess to a user is high-signal for cloud account takeover.
HuntRule TeamAwscloudtrailHigh444Premium2026-05-11Malicious Office Application Spawning a Command Shell or Script Interpreter (via process_creation)
This rule detects a Microsoft Office application such as Word, Excel, PowerPoint or Outlook launching a command shell or script interpreter, the classic child-process signature of a malicious macro or exploited document. Phishing-driven Windows Command Shell and script execution rank among the most prevalent techniques in the Red Canary Threat Detection Report, marking the transition from initial access to code execution. Detecting interpreter children of Office processes surfaces the intrusion at that hand-off.
HuntRule TeamWindowsprocess_creationHigh151Premium2026-05-11Malicious Bring-Your-Own-Vulnerable-Driver Load By BlackByte
This rule detects loading of vulnerable kernel drivers abused by BlackByte to disable endpoint protection. BlackByte deployed the RtCore64 DBUtil_2_3 zamguard64 and gdrv vulnerable drivers to gain kernel-level code execution. Loading a known-vulnerable signed driver is a BYOVD technique that lets attackers terminate security products and tamper with the kernel.
HuntRule TeamWindowsimage_loadHigh133Premium2026-05-11Possible Ivanti Connect Secure Path Traversal Exploitation
This rule detects HTTP requests to the Ivanti Connect Secure TOTP backup-code endpoint containing directory traversal sequences, the access pattern used to exploit the authentication bypass zero-day. Threat actors chain this traversal to reach restricted API paths and deploy webshells. Detecting these requests exposes active exploitation of the Ivanti appliance.
HuntRule TeamWebwebserverHigh211Premium2026-05-11Suspicious Microsoft Defender Exclusion Added via PowerShell
This rule detects PowerShell adding a Microsoft Defender exclusion path, a defense-evasion step performed by Pure Crypter before deploying its payload. Attackers exclude their staging directories from antivirus scanning so subsequent malicious files execute undetected, making unexpected Add-MpPreference exclusions a reliable evasion indicator.
HuntRule TeamWindowsprocess_creationMedium133Premium2026-05-11Cleo File Transfer Software Spawning Command Interpreter
This rule detects a Cleo managed file transfer process spawning a command interpreter such as cmd, PowerShell or Bash, the post-exploitation behavior of CVE-2024-55956 autorun abuse leading to Cobalt Strike by CL0P. A Cleo product launching a shell indicates exploitation of the Cleo Harmony VLTrader or LexiCom software.
HuntRule TeamWindowsprocess_creationHigh122Premium2026-05-11Malicious Active Directory Federated Trust Added (via office365)
This rule detects scenarios where an federated trust is added by an attacker.
HuntRule TeamAzureoffice365High103Premium2026-05-11Suspicious Subprocess Spawned by LiteLLM Proxy Process (via process_creation)
This rule detects a LiteLLM proxy Python process spawning a shell or network utility. Such a child process is consistent with the subprocess execution abused in CVE-2026-42271. A LiteLLM proxy does not normally launch shells or download tools.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-05-11Suspicious Chafer Backdoor HTTP C2 Communication via Proxy
This rule detects HTTP requests to the comm.aspx endpoint used by the Chafer backdoor for command-and-control communication. Observed in NCC Group research analyzing the Chafer backdoor beaconing to comm.aspx over HTTP. Identifying this request path helps detect infected hosts contacting Chafer C2 infrastructure.
HuntRule TeamWebproxyLow3010Premium2026-05-11Malicious AppDomainManager Injection via MyAppDomainManager DLL Load
This rule detects a .NET process loading a module named MyAppDomainManager.dll, the hijack DLL used by CL-STA-1062 to abuse the AppDomainManager configuration in chrome_setup.exe.config and run the TinyRCT backdoor inside a trusted process. Catching this load reveals CLR AppDomainManager injection used for defense evasion and stealthy code execution.
HuntRule TeamWindowsimage_loadHigh103Premium2026-05-11Malicious File Encryption via Kraken Ransomware Encryptor Binary
This rule detects execution of the Kraken ransomware encryptor with its characteristic key, path, timeout and directory command-line switches. The binary encrypts victim files and appends the .zpsc extension while dropping a ransom note. Detecting the encryptor invocation provides a late-stage indicator of active ransomware deployment.
HuntRule TeamWindowsprocess_creationHigh122Premium2026-05-11Suspicious Active Directory Enumeration via ADFind (via process_creation)
This rule detects execution of ADFind or a binary carrying ADFind's characteristic query switches used to enumerate domain accounts, computers and trusts. Emotet operators run ADFind during staging to map the Active Directory environment before lateral movement. Broad directory reconnaissance from an interactive host is rarely legitimate outside of sanctioned administration.
HuntRule TeamWindowsprocess_creationMedium167Premium2026-05-11