Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,519 rules
Suspicious Fileless PowerShell Execution via Invoke-RestMethod Piped to IEX (via process_creation)
This rule detects PowerShell fetching remote content with Invoke-RestMethod and piping it straight into Invoke-Expression, the fileless delivery used by the SEO poisoning campaign impersonating Gemini and Claude Code installers. This pattern executes attacker-hosted script without touching disk. Some tooling uses irm iex legitimately, so review the target domain.
HuntRule TeamWindowsprocess_creationMedium377Premium2026-05-02Microsoft Defender SpyNet Reporting Disabled via Registry
This rule detects the Microsoft Defender SpyNetReporting registry value being set to 0, disabling cloud-delivered protection telemetry so malware runs with reduced detection. Huntress observed BlackCat affiliates degrading Defender before payload deployment. Turning off SpyNet reporting is a deliberate defense-evasion action rarely performed by legitimate administration.
HuntRule TeamWindowsregistry_setHigh3610Premium2026-05-02Suspicious New Rights Granted to an Account for Privilege Escalation (via security)
This rule detects grants new rights to an account in order to escalate privileges.
HuntRule TeamWindowssecurityMedium72Premium2026-05-02Malicious Mimikatz Driver Deployed via Service (via security)
This rule detects installs the Mimikatz driver to bypass the LSA protected mode (RunAsPPL) and dump LSASS process content.
HuntRule TeamWindowssecurityHigh1410Premium2026-05-02Possible PowerShell Empire Default User-Agent In HTTP Traffic
This rule detects outbound HTTP traffic carrying the default user-agent string shipped with the PowerShell Empire C2 framework. In the WithSecure C2 and Exfiltration Lab 1 the Empire agent beacons out with an unmodified Mozilla compatible MSIE user-agent that is characteristic of the framework default profile. Attackers rely on this static header for their staging and command channel unless an operator customizes it.
HuntRule TeamWebproxyLow111Premium2026-05-02Malicious Impacket WMIexec Execution via SMB Admin Share (via security)
This rule detects remotely execute WMIexec via SMB admin share in order to escalate privileges.
HuntRule TeamWindowssecurityHigh73Premium2026-05-02Suspicious Reverse Shell via socat EXEC Redirection
This rule detects socat invoked with an EXEC or SYSTEM redirection to a shell, a reverse shell pattern shown in Elastic Linux persistence research. Attackers pair a socat TCP endpoint with EXEC to pipe an interactive shell back to a listener for command and control. Socat spawning a shell process is uncommon in normal administration and points to remote-access tooling.
HuntRule TeamLinuxprocess_creationHigh82Premium2026-05-02Malicious Microsoft Defender Threat Exclusion Added - PowerShell (via powershell)
This rule detects scenarios where a threat exclusion is added to the antivirus in order to bypass its detection capacities.
HuntRule TeamWindowspowershellHigh173Premium2026-05-02Suspicious Windows Service ImagePath Pointing to AppData Directory
This rule detects creation or modification of a Windows service whose ImagePath references a user AppData directory. Legitimate services rarely execute from per-user AppData paths, so this pattern commonly indicates malware establishing persistence as a service. Reviewing such services helps surface service-based persistence.
HuntRule TeamWindowsregistry_setMedium102Premium2026-05-02Suspicious Daxin Backdoor Driver srt64.sys Loaded
This rule detects loading of a kernel driver named srt64.sys, associated with the Backdoor.Daxin espionage implant that hijacks legitimate network connections for covert command and control against hardened networks.
HuntRule TeamWindowsdriver_loadHigh121Premium2026-05-02Suspicious SNS Publish to Phone Number for Smishing
This rule detects an SNS Publish call that targets a phone number directly, a smishing abuse pattern in the AWS SNS research by Elastic. Adversaries who compromise credentials use SNS to send SMS phishing messages at scale from the victim account. Direct phone number publishes outside of known messaging workflows can indicate account abuse and outbound phishing.
HuntRule TeamAwscloudtrailMedium123Premium2026-05-02Malicious Impacket wmiexec Output Redirection via ADMIN Share
This rule detects the characteristic Impacket wmiexec command line that redirects command output to a temporary file on the local admin share over the loopback address as described in the WithSecure WMI lab. This redirection pattern is highly specific to semi interactive Impacket WMI execution and is a strong indicator of remote lateral movement by an attacker toolkit.
HuntRule TeamWindowsprocess_creationHigh385Premium2026-05-02Suspicious Control Panel File Execution via control.exe with CPL Argument
This rule detects control.exe launching a Control Panel file, a proxy-execution technique observed in a martial-law-themed APT campaign where a disguised hwp.cpl was executed through control.exe to trigger CPlApplet and side-load a malicious DLL. It captures the abuse of the Control Panel host to run attacker code. Detecting this is important because control.exe invoking .cpl payloads outside settings interfaces is a recognized malware execution and DLL side-loading vector.
HuntRule TeamWindowsprocess_creationMedium132Premium2026-05-02Suspicious Side-Loaded DLL Loaded by SSH Agent for Lazarus ServiceChanger
This rule detects the ssh-agent binary loading a libcrypto.dll from a non-standard path, a side-loading chain abused by the Lazarus ServiceChanger tool. The attackers convert ssh-agent into a persistent service and hijack its DLL dependency to run malicious code. A libcrypto.dll loaded by ssh-agent outside trusted install paths indicates side-loading.
HuntRule TeamWindowsimage_loadHigh268Premium2026-05-02Malicious Modification of a Fake Domain Controller SPN (DCshadow) - Directory Services (via security)
This rule detects update the Service Principal Name (SPN) of a computer account in order to perform "Kerberos redirection" and escalate privileges.
HuntRule TeamWindowssecurityHigh171Premium2026-05-02