Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,516 rules
Suspicious Payload Drop to Public User Directory by Gladinet Exploit
This rule detects the files d3d11.dll or Centre.exe being written under the Public user directory, a payload staging behavior observed by Huntress following CVE-2025-30406 exploitation of Gladinet CentreStack. Attackers drop a DLL sideloading component and secondary executable into a world-writable directory to establish execution and persistence. Placement of these named binaries in the Public directory is anomalous and indicates post-exploitation staging.
HuntRule TeamWindowsfile_eventMedium113Premium2026-05-04Malicious Equation Editor Child Process Execution via process_creation
This rule detects the Microsoft Equation Editor EQNEDT32.EXE spawning any child process which almost always indicates exploitation of the CVE-2017-11882 memory corruption vulnerability. SideWinder delivered RTF documents that exploited Equation Editor to launch mshta.exe and fetch a remote HTA payload against maritime and nuclear targets. Equation Editor never legitimately creates child processes so this is a high confidence exploitation signal.
HuntRule TeamWindowsprocess_creationHigh112Premium2026-05-03Suspicious awk Character Generation Piped to Shell on VMware ESXi (via process_creation)
This rule detects awk being used to assemble command strings from numeric character codes on VMware ESXi. Actors abuse awk BEGIN blocks with printf and percent-c formatting to build obfuscated commands that are then piped into a shell. This construct rarely appears in legitimate ESXi administration.
HuntRule TeamLinuxprocess_creationMedium91Premium2026-05-03Suspicious Defender Exclusion Added via Set-MpPreference
This rule detects use of Set-MpPreference with an exclusion path parameter to exempt a directory from Windows Defender scanning, a defense-evasion step performed by the PureCrypter loader. Adding broad exclusions is rarely a legitimate interactive action.
HuntRule TeamWindowsprocess_creationMedium173Premium2026-05-03Suspicious Subtitle File Parsing for Staged Command Execution
This rule detects a command that reads a subtitle srt file and pipes selected lines through findstr and more to extract and run embedded script code. This is the first stage of a fake movie torrent that delivers Agent Tesla through a layered PowerShell chain.
HuntRule TeamWindowsprocess_creationMedium71Premium2026-05-03Suspicious Shared Printer Creation - PrintNightmare Vulnerability - CVE-2021-36958 (via security)
This rule detects exploit the PrintNightmare vulnerability by exposing a vulnerable shared printer. At any case, any new printer share creation should be carefully monitored.
HuntRule TeamWindowssecurityMedium122Premium2026-05-03Suspicious WindowServer Binary Masquerade in Application Support (via file_event)
This rule detects creation of a file named WindowServer under ~/Library/Application Support/ on macOS. The Trojan-Proxy drops its main executable using the name of a legitimate system service in this user directory to blend in, so a WindowServer binary written to Application Support rather than the OS location indicates masquerading malware.
HuntRule TeamMacosfile_eventMedium169Premium2026-05-03Suspicious Quick Format of Drive with Auto-Confirmation
This rule detects the format command running a quick format with automatic yes confirmation, matching the SyncFuture helpformat routine that wiped a drive. The batch tooling formatted a non-system volume with /Q and /Y to destroy data without user interaction. Unattended quick formatting of a drive is a destructive action that can indicate data-destruction or anti-forensic intent.
HuntRule TeamWindowsprocess_creationMedium41Premium2026-05-03Malicious secur32.dll Sideload From Color Profile Directory (via image_load)
This rule detects a secur32.dll being loaded from the printer spool color drivers directory rather than System32. ShadowPad was deployed via DLL sideloading using signed hosts such as WindowsUpdate.exe loading a malicious secur32.dll from spool drivers color. A trusted system DLL name loaded from an unexpected writable path indicates search-order hijacking and stealthy backdoor execution.
HuntRule TeamWindowsimage_loadHigh142Premium2026-05-03Suspicious CoinMiner KillProc Termination of Competing Miners (via process_creation)
This rule detects termination of competing mining processes such as phoenixminer, ethdcrminer64, or geekminer which the T-Rex CoinMiner campaign performs to monopolize GPU resources. Killing rival miner executables is a distinctive impact stage behavior.
—Windowsprocess_creationMedium91Premium2026-05-03Suspicious DynamicWrapperX Registration via regsvr32 (via process_creation)
This rule detects regsvr32.exe silently registering libeay32.dll, the loading vector for the DynamicWrapperX component used by the SugarGh0st RAT. Abusing regsvr32 to register a renamed helper DLL provides script-driven Windows API access while evading application controls.
HuntRule TeamWindowsprocess_creationMedium185Premium2026-05-03Nullsoft Scriptable Installer Script (NSIS) file creation
Detects the creation of the NSIS System plugin library, indicative of an NSIS script execution.
HuntRule TeamWindowsfile_eventLow91Premium2026-05-03Malicious Microsoft Defender Tampering via PowerShell MpPreference
This rule detects PowerShell disabling Microsoft Defender real-time monitoring or adding scan exclusions, the defense-evasion step performed by The Gentlemen ransomware before deploying its payload. Tampering with Defender protection settings is a high-confidence indicator of an adversary preparing to run malware unhindered.
HuntRule TeamWindowsprocess_creationHigh113Premium2026-05-03Suspicious Lazarus SIGNBT Loader Configuration Artifacts wpd Files (via file_event)
This rule detects creation of the external configuration and payload container files wpd.ini, wpd.mmf and wpd.bin that the Lazarus SIGNBT loader drops beside its side-loaded DLLs to hold AES-encrypted C2 proxy lists and payloads. These distinctively named artifacts accompany the loader on disk, making their appearance a useful indicator of a SIGNBT deployment.
HuntRule TeamWindowsfile_eventMedium72Premium2026-05-03Malicious Cryptominer Payload Retrieval into Temporary Directory
This rule detects a shell changing into a writable temporary directory before downloading a secondary payload, a staging pattern used by the Log4j XMRig campaign to fetch shell droppers such as 8UsA.sh. This behavior stages miner components in non-persistent locations to evade inspection and hijack compute resources.
HuntRule TeamLinuxprocess_creationMedium1810Premium2026-05-03