Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Antivirus signatures matching APT malware naming patterns
Flags Antivirus alerts when malware signatures reference APT-style naming patterns and family name substrings.
Arnim Rupp (Nextron Systems), Huntrule Team—antivirusCritical234Free2026-06-15Malicious SharePoint spinstall Web Shell Access Leaking Machine Keys
This rule detects web requests to the spinstall web shell dropped during on-premises SharePoint exploitation. Microsoft observed spinstall0.aspx and its variants deployed to leak the server MachineKey via GET requests. Retrieval of the ASP.NET machine key enables forged payloads and full compromise, so any access to this web shell is a critical finding.
HuntRule TeamWebwebserverCritical142Premium2026-06-11Malicious Cloud PRT Theft via Mimikatz cloudap (via process_creation)
This rule detects Mimikatz cloudap and cloudapkd module usage that extracts the Primary Refresh Token key material used for cloud single sign-on. The cloud lateral-movement research shows this yields tokens for pivoting from a compromised host to cloud identity. These module names are tool-specific and indicate active credential theft.
HuntRule TeamWindowsprocess_creationCritical3710Premium2026-06-05Malicious Backdoored liblzma Loaded by sshd (CVE-2024-3094)
This rule detects the sshd process loading the backdoored liblzma shared object versions 5.6.0 or 5.6.1 associated with the XZ Utils supply chain compromise. Wiz Research described how this library hooks RSA_public_decrypt to grant remote code execution, so loading these specific versions indicates a compromised host.
HuntRule TeamLinuximage_loadCritical163Premium2026-05-17Malicious Active Directory Database (NTDS.dit) Extraction (via process_creation)
This rule detects extraction of the Active Directory database via ntdsutil Install-From-Media snapshots or shadow-copy access to ntds.dit, which yields every domain credential hash for offline cracking and forging. NTDS credential access is a high-impact technique in the Red Canary Threat Detection Report and a common precursor to domain-wide compromise. Detecting these extraction commands surfaces a domain-controller-level credential theft.
HuntRule TeamWindowsprocess_creationCritical246Premium2026-05-06Malicious Jamf Pro SSRF Targeting Cloud Metadata via imageUrl (via webserver)
This rule detects requests to the Jamf Pro eduFeatureSettingsTest endpoint whose imageUrl parameter references the cloud instance metadata address 169.254.169.254. This is the full-read SSRF CVE-2021-39303 and CVE-2021-40809 aimed at stealing AWS instance credentials from the metadata service. Detecting it surfaces active theft of cloud IAM credentials through the vulnerable server.
HuntRule TeamWebwebserverCritical113Premium2026-05-05Windows Defender windefend Event 1119 flags RedSun TieringEngineService.exe EICAR test file
Alerts on WinDefend 1119 remediation failures involving TieringEngineService.exe marked with EICAR content or triggered by RedSun.exe.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowswindefendCritical256Free2026-04-17Windows Named Pipe Created with Name "REDSUN"
Flags creation of the named pipe \REDSUN on Windows, consistent with RedSun-style IPC used during exploitation.
Swachchhanda Shrawan Poudel (Nextron Systems), @unresolvedhost, Huntrule TeamWindowspipe_createdCritical151Free2026-04-17Windows File Creation: TieringEngineService.exe in RS- prefixed Temp Directory
Detects creation of TieringEngineService.exe under an RS-{GUID}-prefixed directory in %TEMP% on Windows.
Swachchhanda Shrawan Poudel (Nextron Systems), @unresolvedhost, Huntrule TeamWindowsfile_eventCritical183Free2026-04-17Windows File Creation in SharePoint Web Server Extensions Suggesting ToolShell Drop
Alerts on Windows file creations within SharePoint Web Server Extensions that match suspicious spinstall/debug artifacts linked to CVE-2025-53770.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventCritical391Free2025-07-21Bitbucket Audit: Unauthorized Full Data Export Triggered (Data Pipeline)
Flags Bitbucket audit events indicating an unauthorized user attempted a full data export.
Muhammad Faisal (@faisalusuf), Huntrule TeamBitbucketauditCritical3710Free2024-02-25Bitbucket Audit: Unauthorized Access to a Resource
Flags Bitbucket audit events reporting unauthorized access attempts to a resource.
Muhammad Faisal (@faisalusuf), Huntrule TeamBitbucketauditCritical152Free2024-02-25Webserver Path Scan for ScreenConnect SetupWizard Authentication Bypass (CVE-2024-1709)
Alerts on web requests to '/SetupWizard.aspx/' that match exploitation patterns for ScreenConnect authentication bypass CVE-2024-1709.
Matt Anderson, Huntress, Huntrule Team—webserverCritical196Free2024-02-20Windows Security Event 4698 Scheduled Task Creation for TeamCity UI
Flags Windows scheduled task creation events where the task name is TeamCity Settings UI and content contains a specific marker.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityCritical301Free2023-10-24Proxy HTTP GET Pattern Matching /MSHTML_C7/ with IPv4 Query Parameters
Alerts on proxy HTTP GET requests to /MSHTML_C7/ with an IPv4-like query parameter pattern.
X__Junior, Huntrule Team—proxyCritical120Free2023-07-12