Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,512 rules
Suspicious NetSupport RAT client32 Execution
This rule detects execution of client32.exe, the NetSupport Manager remote control client. The Horns and Hooves campaign delivered NetSupport RAT as client32.exe for remote access, and its presence outside sanctioned NetSupport deployments should be investigated.
HuntRule TeamWindowsprocess_creationMedium398Premium2026-05-06Malicious Active Directory Database (NTDS.dit) Extraction (via process_creation)
This rule detects extraction of the Active Directory database via ntdsutil Install-From-Media snapshots or shadow-copy access to ntds.dit, which yields every domain credential hash for offline cracking and forging. NTDS credential access is a high-impact technique in the Red Canary Threat Detection Report and a common precursor to domain-wide compromise. Detecting these extraction commands surfaces a domain-controller-level credential theft.
HuntRule TeamWindowsprocess_creationCritical246Premium2026-05-06Possible Kentico Xperience Staging Sync Authentication Bypass via SyncServer Endpoint (via webserver)
This rule detects requests to the Kentico Xperience staging synchronization web service which is abused in the pre-auth RCE chain to upload objects after a password digest authentication bypass. Access to this SOAP endpoint from untrusted sources should be reviewed.
HuntRule TeamWebwebserverMedium451Premium2026-05-06Malicious Domain Group Membership Change (via powershell)
This rule detects if a member is added to a domain group via PowerShell.
HuntRule TeamWindowspowershellHigh385Premium2026-05-05Malicious Jamf Pro SSRF Targeting Cloud Metadata via imageUrl (via webserver)
This rule detects requests to the Jamf Pro eduFeatureSettingsTest endpoint whose imageUrl parameter references the cloud instance metadata address 169.254.169.254. This is the full-read SSRF CVE-2021-39303 and CVE-2021-40809 aimed at stealing AWS instance credentials from the metadata service. Detecting it surfaces active theft of cloud IAM credentials through the vulnerable server.
HuntRule TeamWebwebserverCritical113Premium2026-05-05Suspicious Watering Hole Exfiltration to Fake wp-includes Endpoint via SilentSelfie
This rule detects HTTP POST requests to the path /wp-includes/ms-menu.php, a fake WordPress endpoint used by the SilentSelfie watering hole campaign to receive stolen geolocation, WebRTC IP and webcam selfie data from visitors of compromised Kurdish websites. The ms-menu.php filename does not exist in genuine WordPress installations. Traffic to it indicates victim data exfiltration.
HuntRule TeamWebproxyHigh352Premium2026-05-05Malicious TeamPCP Trivy C2 Beacon to ICP Canister and Cloudflare Tunnel (via dns_query)
This rule detects DNS resolution of the Internet Computer canister fallback host the Cloudflare tunnel and the aquasecurtiy typosquat domain used as command-and-control by the TeamPCP implant embedded in the compromised Trivy v0.69.4 release. These hosts serve payloads and receive exfiltrated credentials so a lookup indicates an infected build or developer host beaconing out.
HuntRule TeamLinuxdns_queryHigh191Premium2026-05-05Suspicious Scheduled Task Persistence Referencing AppData Roaming
This rule detects schtasks.exe creating a task whose action points to an executable staged under the user AppData Roaming directory, the persistence pattern used by TrickBot after copying itself into that location. Malware favors AppData Roaming because it is user writable and survives across sessions. Scheduled tasks launching binaries from a roaming profile path are uncommon for legitimate software.
HuntRule TeamWindowsprocess_creationMedium275Premium2026-05-05Suspicious Execution of freenode Linux Backdoor Helper Binary
This rule detects execution of the helper binary used by the Linux backdoor from the freenode IRC network compromise. Observed in NCC Group research analyzing that Linux backdoor which deploys a helper at /bin/dh. Detecting this uncommon helper path helps surface rootkit-supported backdoor activity on Linux hosts.
HuntRule TeamLinuxprocess_creationHigh192Premium2026-05-05Suspicious Scheduled Task Executing VBScript via Process Creation
This rule detects creation of a scheduled task that runs VBScript through wscript or cscript, matching UAC-0099 persistence that fires a VBS loader every few minutes to relaunch a hidden PowerShell beacon. Adversaries chain the task scheduler with script hosts for resilient, low-profile persistence.
HuntRule TeamWindowsprocess_creationMedium404Premium2026-05-05Malicious PowerShell or Command Shell Spawned by SQL Server via xp_cmdshell
This rule detects the SQL Server process sqlservr.exe spawning PowerShell or cmd.exe, behavior produced when the GhostRedirector group abuses the xp_cmdshell stored procedure to run operating system commands. A database engine launching a shell indicates SQL-based remote code execution used for downloading tooling and establishing footholds on Windows servers.
HuntRule TeamWindowsprocess_creationHigh171Premium2026-05-05Malicious QEMU SSH Tunnel via Scheduled Task on Nonstandard Port (via process_creation)
This rule detects a scheduled task launching qemu-system-x86_64 to establish an SSH tunnel on nonstandard port 22022, a covert access technique observed after SolarWinds Web Help Desk exploitation. Observed in Elastic Security Labs telemetry where a TPMProfiler task runs QEMU to proxy traffic and evade network controls for persistent remote access.
HuntRule TeamWindowsprocess_creationHigh143Premium2026-05-05Malicious Event Log Clearing via wevtutil by The Gentlemen RaaS (via process_creation)
This rule detects wevtutil clearing the Security, Application, or System event logs, an anti-forensic action performed by The Gentlemen ransomware operators to erase traces of intrusion. Wiping logs hampers incident response and hides prior activity. Detection of log clearing is a strong indicator of hands-on-keyboard compromise.
HuntRule TeamWindowsprocess_creationHigh418Premium2026-05-05Suspicious Self-Deletion Batch Artifact by JadeProx TriBack Loader (via file_event)
This rule detects creation of the ~del.vbs.bat self-deletion artifact dropped by the JadeProx TriBack loader to remove its own components and cover its tracks. The distinctive double-extension cleanup file marks post-execution defense evasion. Detecting it exposes JadeProx anti-forensic activity.
HuntRule TeamWindowsfile_eventMedium152Premium2026-05-05Malicious Exchange Transport Agent Injection via Configuration File (via file_event)
This rule detects load an artifact in the Exchange transport agent.
HuntRule TeamWindowsfile_eventHigh3910Premium2026-05-05