Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,087 rules
Malicious Shell Spawned by Mshta Delivery (via process_creation)
This rule detects mshta.exe spawning PowerShell, cmd or another script host, the delivery-to-execution handoff seen in ClickFix, Lumma Stealer and SmartApeSG fake-update chains. Mshta launching a shell is an execution technique tracked in the Red Canary Threat Detection Report. Detecting this parent-child pair surfaces HTA-driven payload execution.
HuntRule TeamWindowsprocess_creationHigh00Premium2026-09-03Suspicious Silent Installation of Remote Management Software (via process_creation)
This rule detects silent or unattended command-line installation of remote monitoring and management tools such as AnyDesk, ScreenConnect, Atera or ConnectWise, which adversaries deploy for stealthy remote access that blends into legitimate IT tooling. Abuse of RMM software for remote access is a technique repeatedly profiled in the Red Canary Threat Detection Report. Detecting unattended installs surfaces attacker-controlled remote access being established.
HuntRule TeamWindowsprocess_creationMedium30Premium2026-09-03Malicious SQL Server - Brutforce Enumeration with Non Existing Users - Login (via application)
This rule detects enumerate potential existing SQL users, resulting in failed logins with unexisting or invalid accounts.
HuntRule TeamMssqlapplicationHigh20Premium2026-09-03Suspicious Removal of the macOS Quarantine Attribute via Xattr (via process_creation)
This rule detects xattr being used to strip the com.apple.quarantine attribute from a file, which bypasses the Gatekeeper prompt so a downloaded binary launches without the trust warning. Quarantine-attribute removal is a defense-evasion technique in the Red Canary Threat Detection Report macOS coverage. Detecting it surfaces an attempt to silently run downloaded content.
HuntRule TeamMacosprocess_creationMedium10Premium2026-09-03DSRM Password Changed - Native (via security)
This rule detects reset or synchronize with another domain account the DSRM (Directory Services Restore Mode) password in order to escalate privileges.
HuntRule TeamWindowssecurityHigh00Premium2026-09-03Malicious Remote Script Piped to a Shell on macOS (via process_creation)
This rule detects a macOS command line that downloads remote content with curl and pipes it straight into a shell or osascript, the paste-and-run delivery behavior behind macOS stealers such as Atomic and Odyssey that trick users into running a one-liner in Terminal. macOS paste-and-run stealer campaigns are called out in the Red Canary Threat Detection Report. Detecting the download-and-execute pipe surfaces infostealer installation at the execution stage.
HuntRule TeamMacosprocess_creationHigh20Premium2026-09-03Uncommon macOS Keychain Credential Access via Security Utility (via process_creation)
This rule detects use of the built-in security utility to dump the keychain or extract stored generic and internet passwords, a credential-access behavior used by macOS stealers to harvest saved secrets. Credential theft from the keychain supports the infostealer activity documented in the Red Canary Threat Detection Report. Because interactive keychain dumping is uncommon, detecting these security-command patterns surfaces credential harvesting.
HuntRule TeamMacosprocess_creationHigh00Premium2026-09-03PowerShell Storing an Encoded Payload in the Registry (via process_creation)
This rule detects PowerShell writing a base64 or byte-array value into an HKCU registry key, the fileless persistence and staging behavior seen in Solarmarker and Yellow Cockatoo intrusions. Storing an encoded payload in the registry is a defense-evasion and persistence technique tracked in the Red Canary Threat Detection Report. Detecting this write surfaces a fileless payload being cached for later execution.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-03Malicious DCSync Domain Replication Credential Theft (via process_creation)
This rule detects command lines invoking DCSync-style directory replication (lsadump::dcsync or a /dcsync switch), which abuses replication rights to pull password hashes for any account directly from a domain controller. DCSync is a high-impact credential-access technique in the Red Canary Threat Detection Report and a route to domain dominance. Detecting the replication request surfaces theft of privileged credentials without touching LSASS.
HuntRule TeamWindowsprocess_creationCritical10Premium2026-09-03Malicious Shared Library Preload Persistence via ld.so.preload (via process_creation)
This rule detects modification of /etc/ld.so.preload, which forces a shared library to load into every dynamically linked process, a stealthy persistence and privilege-escalation technique used by Linux rootkits. Ld.so.preload hijacking is tracked in the Red Canary Threat Detection Report. Detecting the change surfaces a system-wide library hijack.
HuntRule TeamLinuxprocess_creationHigh00Premium2026-09-03Suspicious Security Software Discovery via WMI or Defender Query (via process_creation)
This rule detects command lines that enumerate installed antivirus or EDR products through the SecurityCenter2 WMI namespace or Get-MpComputerStatus, a security-software-discovery step taken to plan defense evasion. Security software discovery is tracked in the Red Canary Threat Detection Report. Detecting these queries surfaces an attacker profiling defenses before acting.
HuntRule TeamWindowsprocess_creationMedium00Premium2026-09-03Malicious DLL ServerLevelPluginDll Command Installation (via process_creation)
This rule detects scenarios where a DLL is loaded by the DNS server in order to escalate privileges or initiate a remote shell.
HuntRule TeamWindowsprocess_creationCritical10Premium2026-09-03Malicious Scheduled Persistent Task with SYSTEM Privileges Creation (via process_creation)
This rule detects creates a privileged task to establish persistence.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-03VSS Backup Deletion or Resize (via process_creation)
This rule detects delete or resize existing VSS backup.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-03Malicious Wdigest Authentication Enabled - Reg via Command (via process_creation)
This rule detects enable Wdgiest authention so passwords are stored in clear text and can be dumped.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-03