Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,512 rules
Possible Progress WhatsUp Gold SSRF via core render baseUrl (via webserver)
This rule detects PUT requests to the Progress WhatsUp Gold NmConsole core render API, abused as a server-side request forgery primitive through its baseUrl parameter. Attackers chained this SSRF to reach internal services and escalate impact on WhatsUp Gold deployments. Detecting it surfaces attempts to pivot into internal infrastructure via the monitoring server.
HuntRule TeamWebwebserverMedium332Premium2026-05-05Malicious Remote Process Creation via wmic node call create
This rule detects wmic invoking process call create against a remote node. The CloudComputating group used this WMI technique to execute commands on remote hosts for lateral movement across the network, which is uncommon in routine administration.
HuntRule TeamWindowsprocess_creationHigh427Premium2026-05-05Suspicious Scheduled Task Running rundll32 DllRegisterServer Every Minute
This rule detects creation of a scheduled task that repeatedly invokes rundll32 against the DllRegisterServer export on a per-minute trigger. OysterLoader uses this technique to persist a malicious DLL dropped into the user profile. A minute interval task launching rundll32 with DllRegisterServer is rarely legitimate and typically indicates loader persistence.
HuntRule TeamWindowsprocess_creationHigh182Premium2026-05-05Malicious Service Abuse with Malicious ImagePath - Reg via PowerShell (via powershell)
This rule detects modify the original service executable path with a malicious one.
HuntRule TeamWindowspowershellHigh123Premium2026-05-05Suspicious Dero Miner Binaries nginx and cloud Execution
This rule detects execution of the Dero campaign binaries planted as usr bin nginx for propagation and usr bin cloud as the Dero miner. Naming the miner and worm after benign system tools hides them from operators reviewing running processes inside containers. The specific paths combined with these names are strong campaign indicators.
HuntRule TeamLinuxprocess_creationMedium195Premium2026-05-05Suspicious Toshiba Binary Sideloading toshdpapi.dll
This rule detects the legitimate Toshiba toshdpdb.exe loading a malicious toshdpapi.dll from its directory, a DLL sideloading chain used to run a PlugX variant in China-linked espionage intrusions that also deployed RA World ransomware.
HuntRule TeamWindowsimage_loadHigh408Premium2026-05-05Possible DLL Search Order Hijack of httpapi.dll Outside System32 (via image_load)
This rule detects the Windows httpapi.dll being loaded from a directory other than System32 or SysWOW64 which indicates DLL search order hijacking. Abuse of a writable agent directory to plant httpapi.dll was used to escalate privileges to SYSTEM against the Delinea Privilege Manager agent.
HuntRule TeamWindowsimage_loadHigh3410Premium2026-05-05Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)
This rule detects the SimpleHelp Remote Access client spawning a command shell that runs account and domain enumeration utilities. Following exploitation of SimpleHelp RMM for initial access, operators used the persisted client to run net and nltest reconnaissance.
HuntRule TeamWindowsprocess_creationMedium141Premium2026-05-04Suspicious Headless Browser Automation with Anti-Detection Flags via Astaroth (via process_creation)
This rule detects a browser launched in headless automation mode with flags that suppress automation indicators. The Astaroth spambot drives Chrome or Edge with headless, disable-infobars, and excludeSwitches settings to abuse authenticated web sessions without user awareness. This flag combination is unusual on endpoint hosts.
HuntRule TeamWindowsprocess_creationMedium258Premium2026-05-04Suspicious Permissions Changed on a Group Policy - GPO (via security)
This rule detects will attempt to take control over a group policy.
HuntRule TeamWindowssecurityMedium392Premium2026-05-04Suspicious Member Added to Privileged Directory Role in Entra ID
This rule detects Entra ID audit events adding a member to a directory role such as Global Administrator. Wiz Research observed Midnight Blizzard elevating principals into privileged roles to broaden access, so unexpected role membership changes can indicate an account manipulation and privilege escalation attempt.
HuntRule TeamAzureauditlogsMedium1810Premium2026-05-04Suspicious chmod 777 on Dropped Payload in Temp Directory
This rule detects a process granting world-writable and executable permissions to a file staged under /tmp, a step used to make a downloaded exploit payload runnable. During React2Shell exploitation the actor dropped an architecture-specific binary into /tmp and made it executable before running it. Broad chmod 777 on temp payloads is a common post-compromise action that precedes execution of second-stage tooling.
HuntRule TeamLinuxprocess_creationMedium82Premium2026-05-04Suspicious Browser Launch With Remote Debugging for Cookie Theft (via process_creation)
This rule detects a Chromium-based browser launched with both a remote debugging port and a custom user data directory. Phantom Goblin abuses this to extract cookies and session data directly from the browser.
HuntRule TeamWindowsprocess_creationMedium221Premium2026-05-04Suspicious MOTD Or Git Hook Script Creation For Linux Persistence
This rule detects creation of executable scripts in the dynamic message-of-the-day directory or a git hooks directory which are persistence locations abused to run attacker code on login or developer workflow events. Adversaries drop scripts into update-motd.d or git hooks so their payload executes automatically with the privileges of the triggering process.
HuntRule TeamLinuxfile_eventLow387Premium2026-05-04Suspicious Service DLL Registration via regsvr32 Silent
This rule detects regsvr32.exe silently registering a DLL as part of the RONINGLOADER service installation chain that loads goldendays.dll. Adversaries use the silent flag to register malicious DLLs without user-visible prompts while establishing service-based persistence.
HuntRule TeamWindowsprocess_creationMedium458Premium2026-05-04