Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
94 rules
Phobos 8Base Ransomware Encrypted File Extension Created
This rule detects files being renamed with the .8base extension appended by Phobos ransomware operated by the 8Base group. Phobos appends an extension containing a victim ID and contact email ending in .8base to each encrypted file. A wave of these file events signals active ransomware encryption on the host.
HuntRule TeamWindowsfile_eventHigh40Premium2026-09-10Rhysida Ransomware Encrypted File Extension Created
This rule detects files being renamed with the .rhysida extension appended by Rhysida ransomware during encryption. Rhysida uses ChaCha20 to encrypt victim files and marks each with this extension. A burst of such file events indicates active mass encryption on the host.
HuntRule TeamWindowsfile_eventHigh50Premium2026-09-10Rhysida Ransomware Note CriticalBreachDetected.pdf Created
This rule detects the creation of a file named CriticalBreachDetected.pdf, the fixed ransom note dropped by Rhysida ransomware. Rhysida writes this note across affected directories after encrypting files. Detecting the note filename provides a high-confidence indicator that Rhysida encryption has already occurred on the host.
HuntRule TeamWindowsfile_eventHigh40Premium2026-09-09Possible Akira Ransomware VM Shutdown via vim-cmd
This rule detects use of vim-cmd to power off virtual machines on an ESXi host, a step the Akira Rust ransomware performs before encrypting VM files. The encryptor enumerates guests with getallvms and forces them off to release locked disks. Detecting it can stop the attack before mass encryption begins.
HuntRule TeamLinuxprocess_creationHigh50Premium2026-09-09Possible Ransomware Pre-Encryption VM Termination via esxcli
This rule detects use of esxcli to force kill running virtual machines, a step ransomware performs on ESXi hosts to unlock VM disk files before encryption. Multiple studied families run vm process kill with type force to stop guests prior to mass encryption. Detecting it can interrupt the attack before data is locked.
HuntRule TeamLinuxprocess_creationHigh50Premium2026-09-09Possible Akira Ransomware Note or Encrypted Extension Creation
This rule detects creation of files with the akiranew extension or the akiranew.txt ransom note produced by the Akira Rust ransomware variant. Both artifacts appear only after files have been encrypted on the host. Detecting them confirms an active Akira encryption event for rapid isolation.
HuntRule TeamLinuxfile_eventHigh100Premium2026-09-09Possible Ransomware Note or Encrypted File Extension Creation
This rule detects creation of ransom note files or files renamed with encrypted extensions used by the ransomware families compared in this research. The specific note names and extensions appear only after data has been encrypted on the victim host. Detecting them confirms an active encryption event so responders can isolate the machine.
HuntRule TeamWindowsfile_eventHigh80Premium2026-09-08Suspicious Windows Defender Real-Time Protection Disabled via Policy Registry by Cephalus Ransomware
This rule detects registry changes under the Windows Defender Real-Time Protection policy key that disable on-access and real-time scanning, a defense evasion step used by Cephalus ransomware. Turning off these protections lets the encryptor run without interference.
HuntRule TeamWindowsregistry_setMedium280Premium2026-09-08Suspicious AutoAdminLogon Enabled via Winlogon Registry by RansomHub Ransomware
This rule detects the Winlogon AutoAdminLogon value being enabled, configuring automatic logon of an account without credentials. RansomHub sets this value to maintain access and ensure its payload runs after reboot.
HuntRule TeamWindowsregistry_setMedium190Premium2026-09-08Suspicious PowerShell Hidden Web Download via Invoke-WebRequest by CatB Ransomware
This rule detects a hidden PowerShell or cmd invocation combining Invoke-WebRequest with DownloadData to retrieve a payload, matching the ingress tool transfer behavior emulated for CatB ransomware. Running the download in a hidden window is a common defense evasion tactic for staging follow-on malware.
HuntRule TeamWindowsprocess_creationHigh390Premium2026-09-08Suspicious Symbolic Link Evaluation Enabled via fsutil by RansomHub Ransomware
This rule detects fsutil enabling remote-to-local and remote-to-remote symbolic link evaluation, a configuration change RansomHub uses to reach and encrypt files across redirected paths. Enabling these symlink behaviors is uncommon in normal administration.
HuntRule TeamWindowsprocess_creationMedium80Premium2026-09-08Suspicious Volume Shadow Copy Deletion via PowerShell WMI by Akira Ransomware
This rule detects PowerShell deleting Volume Shadow Copies through the Win32_ShadowCopy WMI class, an inhibit-recovery step used by Akira ransomware before encryption. Removing shadow copies prevents victims from restoring files without paying.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-08Malicious Anubis Ransomware Cloudflare Tunnel via cloudflared (via process_creation)
This rule detects execution of the cloudflared client establishing an outbound Cloudflare Tunnel. Operators behind the Anubis ransomware campaign dropped cloudflared to Windows and NAS hosts and ran it with tunnel and token arguments to create a persistent encrypted command and control channel that bypasses inbound firewall controls.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-07FunkSec Ransomware Encryption Artifacts via funksec Extension and Markdown Ransom Note (via file_event)
This rule detects the on-disk artifacts of FunkSec ransomware, namely files renamed with the funksec extension and the dropped README markdown ransom note. Adversaries append a unique extension and write a ransom note during mass encryption, so these artifacts confirm active data-encryption for impact.
HuntRule TeamWindowsfile_eventHigh90Premium2026-09-01DragonForce Ransomware Volume Shadow Copy Deletion via WMIC ShadowCopy Where Delete (via process_creation)
This rule detects abuse of WMIC to enumerate and delete a specific volume shadow copy by ID, the inhibit-recovery behavior DragonForce ransomware performs through cmd.exe before file encryption. Adversaries delete shadow copies so victims cannot restore encrypted files, making early detection critical for interrupting the intrusion before data becomes unrecoverable.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-30