Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,522 rules
Malicious PowerShell DownloadFile to AppData Executable
This rule detects PowerShell using the WebClient DownloadFile method to fetch an executable into the AppData directory. Warzone RAT runs obfuscated PowerShell that downloads gm.exe into %appdata% before establishing persistence and UAC bypass. Downloading executables into AppData via PowerShell DownloadFile is a common malware retrieval and staging behavior.
HuntRule TeamWindowsprocess_creationHigh101Premium2026-05-01Malicious LOLBin Spawned by Outlook via MonikerLink CVE-2024-21413
This rule detects Microsoft Outlook spawning script interpreters or living off the land binaries such as mshta which is a hallmark of the MonikerLink CVE-2024-21413 exploitation chain. Successful exploitation lets an attacker bypass the Protected View warning and achieve code execution from a crafted email which makes any such child process highly suspicious.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-05-01Malicious CRYPTBASE.dll Side-Loading Outside System32
This rule detects CRYPTBASE.dll being loaded from a directory outside the Windows System32 folder. The CPU-Z and HWMonitor watering-hole campaign side-loaded a malicious CRYPTBASE.dll next to a trusted binary to hijack execution as reported by Kaspersky. Because the genuine CRYPTBASE.dll ships only in System32, loading it from any other path is a reliable DLL search-order hijack indicator.
HuntRule TeamWindowsimage_loadHigh173Premium2026-05-01Suspicious BitLocker FVE Policy Modification via Registry (via registry_set)
This rule detects writes to the HKLM SOFTWARE Policies Microsoft FVE registry policy keys which the ShrinkLocker ransomware sets to force BitLocker encryption behavior and enable drive locking against the victim.
HuntRule TeamWindowsregistry_setMedium241Premium2026-05-01Possible Shadow Credentials Abuse via msDS-KeyCredentialLink Modification
This rule detects modification of the msDS-KeyCredentialLink attribute on a directory object. Adversaries write key credentials to this attribute to perform certificate-based authentication as the target account, a technique known as Shadow Credentials used for persistence and credential theft.
HuntRule TeamWindowssecurityHigh299Premium2026-05-01Suspicious Cron Persistence File Created in System Cron Directories
This rule detects creation of a file named 0anacron inside the system cron directories which the DripDropper Linux malware uses to masquerade as a trusted periodic job and establish scheduled task persistence. Placing a script among legitimate cron jobs lets the malware re execute and survive reboots. Detecting this file write surfaces persistence establishment on compromised Linux hosts.
HuntRule TeamLinuxfile_eventLow331Premium2026-04-30Malicious Interlock Ransomware Ransom Note File Creation
This rule detects creation of ransom note files named README that Interlock ransomware writes across encrypted directories using the distinctive filename bang README bang txt. The unique note filename indicates active ransomware deployment and data encryption on the host.
HuntRule TeamWindowsfile_eventHigh83Premium2026-04-30Malicious Backup Catalog Deletion via Wbadmin (via process_creation)
This rule detects wbadmin being used to delete the backup catalog or system state backups. Ransomware destroys Windows Backup data so that administrators cannot restore files or system state after encryption. Deletion of backup catalogs is a deliberate recovery-inhibition step and rarely part of legitimate maintenance.
HuntRule TeamWindowsprocess_creationHigh82Premium2026-04-30Suspicious AWS SES Production Access Request via PutAccountDetails (Cloud Email Abuse)
This rule detects SES PutAccountDetails CloudTrail events that request production sending access to escape the SES sandbox, a burst of which was central to the cloud email service takeover campaign. It matters because attackers using leaked keys raise sending limits before launching large phishing campaigns.
HuntRule TeamAwscloudtrailMedium153Premium2026-04-30Webserver Alerts for libredtail-http User-Agent HTTP Requests
Alerts on web requests carrying the "libredtail-http" User-Agent, indicating likely automated malicious probing.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule Team—webserverMedium151Free2026-04-30Linux auditd: Detect AF_ALG socket() syscall (address family 38) for crypto API abuse
Flags AF_ALG (38) socket() creations from Linux auditd while filtering common legitimate crypt/VPN tools.
Gene Kazimiarovich, Huntrule TeamLinuxauditdHigh143Free2026-04-30Windows Print.EXE Sensitive File Dump for Credential Access
Alerts when Print.EXE is executed with arguments targeting ntds.dit, SAM, SECURITY, and SYSTEM files for credential access.
Ayush Anand (Securityinbits), Huntrule TeamWindowsprocess_creationHigh121Free2026-04-28Cisco Network Device 802.1X (dot1x) Disabled via port-control Force-Authorized
Alerts on Cisco configuration changes that disable 802.1X on a port (force-authorized or no dot1x port-control).
Luc Génaux, Huntrule TeamCiscoaaaMedium715Free2026-04-28GCP Google Workspace Suspicious Login Events (Google Classified)
Alerts on Google Workspace login audit events classified by Google as suspicious, including less secure app and programmatic login types.
Tom Kluter, Huntrule TeamGcpgoogle_workspace.loginMedium143Free2026-04-28Google Workspace login activity: Out-of-domain email forwarding
Flags Google Workspace out-of-domain email forwarding events from audit logs on login.googleapis.com.
Tom kluter, Huntrule TeamGcpgoogle_workspace.loginMedium112Free2026-04-28