Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,090 rules
Malicious Scheduled Persistent Task with SYSTEM Privileges Creation (via process_creation)
This rule detects creates a privileged task to establish persistence.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-03VSS Backup Deletion or Resize (via process_creation)
This rule detects delete or resize existing VSS backup.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-03Malicious Wdigest Authentication Enabled - Reg via Command (via process_creation)
This rule detects enable Wdgiest authention so passwords are stored in clear text and can be dumped.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-03Malicious Boot Recovery Tampering via Bcdedit (via process_creation)
This rule detects bcdedit disabling automatic recovery or forcing the boot status policy to ignore failures, an inhibit-system-recovery step ransomware runs so victims cannot restore Windows after encryption. Boot-configuration tampering is an impact technique tracked in the Red Canary Threat Detection Report. Detecting these commands surfaces recovery being sabotaged ahead of encryption.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-03Malicious Task Manager Used for LSASS Dump - Kernel (via security)
This rule detects attempt to dump the LSASS process via the Task Manager.
HuntRule TeamWindowssecurityHigh00Premium2026-09-03Suspicious Persistence Load via Launchctl (via process_creation)
This rule detects launchctl loading or bootstrapping a job whose plist sits in a LaunchAgents or LaunchDaemons folder or a temp location, the activation step for launch-item persistence on macOS. Launchctl-driven persistence is a technique tracked in the Red Canary Threat Detection Report macOS coverage. Detecting the load surfaces a persistence mechanism being enabled.
HuntRule TeamMacosprocess_creationMedium10Premium2026-09-03Malicious Compiled HTML Help Process Spawning a Script Interpreter (via process_creation)
This rule detects the Windows help viewer hh.exe spawning a command shell or script interpreter, which happens when a weaponized compiled HTML help (.chm) file executes embedded script for proxy execution. Compiled HTML File abuse is a System Binary Proxy Execution technique in the Red Canary Threat Detection Report used to run code under a trusted binary and evade allowlisting. Detecting interpreter children of hh.exe surfaces malicious CHM execution.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-03Suspicious Data Staging via Password-Protected Archive Utility (via process_creation)
This rule detects command-line archive tools (rar, 7z, WinRAR) creating password-protected or split archives, a collection-and-staging step attackers use to bundle stolen data before exfiltration. Archiving collected data is a technique tracked in the Red Canary Threat Detection Report. Detecting these invocations surfaces data being packaged for theft.
HuntRule TeamWindowsprocess_creationMedium30Premium2026-09-03Malicious Winlogon Process Contact to C2 - Blacklotus - Sysmon (via process_creation)
This rule detects blacklotus HTTP downloader injection into winlogon.exe process.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-03Suspicious Kernel Extension Load on macOS (via process_creation)
This rule detects kextload, kextutil or kmutil loading a kernel extension, a technique that can install a persistent, high-privilege driver on macOS and is abused by rootkits and stalkerware. Kernel extension abuse is tracked in the Red Canary Threat Detection Report macOS coverage. Detecting the load surfaces kernel-level code being introduced.
HuntRule TeamMacosprocess_creationMedium10Premium2026-09-03Malicious Event Log Clear Attempt - Wmi (via process_creation)
This rule detects clear the event logs.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-03Suspicious File Permission Grant to Everyone via Icacls (via process_creation)
This rule detects icacls granting the Everyone principal full control of files or directories, a file-permission-modification step attackers use to make payloads world-writable or to weaken protected paths. Broad permission grants are tracked in the Red Canary Threat Detection Report. Detecting these commands surfaces tampering with access controls.
HuntRule TeamWindowsprocess_creationMedium10Premium2026-09-03Malicious Interactive Privileged Shell Triggered by Schedule Task - Deprecated (via process_creation)
This rule detects abuse the at command to elevate privilages. Note that at command is deprecated since Windows 8 and replaced by schtask.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-03AppleScript do-shell-script Abuse via Osascript (via process_creation)
This rule detects osascript running an AppleScript do-shell-script clause that also invokes curl, base64, python or a shell in temp, a pattern macOS malware and post-exploitation tooling use to stage and run second-stage code. AppleScript-driven shell execution is a scripting-abuse technique noted in the Red Canary Threat Detection Report macOS coverage. Detecting this combination surfaces script-based execution on macOS endpoints.
HuntRule TeamMacosprocess_creationMedium20Premium2026-09-03Malicious Brutforce Enumeration with Non Existing Users - Login (via security)
This rule detects enumerate potential existing users, resulting in failed logins with unexisting or invalid accounts.
HuntRule TeamWindowssecurityHigh30Premium2026-09-03