Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,291 rules
Malicious Ladon PowerShell Attack Framework Import (via process_creation)
This rule detects PowerShell importing the Ladon attack framework module and invoking its modules such as SweetPotato, Runas, or MssqlCmd as observed in the MeshAgent and SuperShell intrusion. Ladon provides scanning, privilege escalation, and lateral movement capabilities.
—Windowsprocess_creationHigh90Premium2026-09-05Suspicious CRAT Injection Named Pipe ChromeUpdatePipe (via pipe_created)
This rule detects the creation of the named pipe ChromeUpdatePipe used by the CRAT payload to transmit injected code between processes. The pipe masquerades as a Chrome update channel and is a stable indicator of this backdoor family.
—Windowspipe_createdHigh40Premium2026-09-05Malicious Privileged Container Creation in Kubernetes (via audit)
This rule detects a Kubernetes API request that creates a pod with a privileged security context, which grants the container near-host capabilities and is a primary path for escaping to the underlying node. Container escape and privileged workloads are emerging techniques in the Red Canary Threat Detection Report as adversaries target cloud-native environments. Detecting privileged pod creation surfaces a high-risk configuration that enables host compromise.
HuntRule TeamKubernetesauditHigh40Premium2026-09-05Malicious Assignment of a Privileged Azure AD Role (via auditlogs)
This rule detects an account being added to a privileged Azure AD directory role such as Global Administrator or Privileged Role Administrator, an account-manipulation technique used to escalate and entrench control of a tenant. Privileged role assignment is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting this operation surfaces privilege escalation in the identity plane.
HuntRule TeamAzureauditlogsHigh30Premium2026-09-05Malicious User Password Change Using Current Hash Password - ChangeNTLM - Mimikatz (via security)
This rule detects resets a user account by using the compromised NTLM password hash. The newly clear text password defined by the attacker can be then used in order to login into services like Outlook Web Access (OWA), RDP, SharePoint... As ID 4723 refers to user changing is own password, the SubjectSid and TargetSid should be equal. However in a change initiated by Mimikatz, they will be different. Correlate the event ID 4723, 4624 and 5145 using the "SubjectLogonId" field to identify the source of the reset.
HuntRule TeamWindowssecurityHigh30Premium2026-09-05Malicious Cluster-Admin Role Binding Creation (via audit)
This rule detects creation of a ClusterRoleBinding or RoleBinding, which can grant an attacker cluster-admin privileges over a Kubernetes cluster, a privilege-escalation and persistence technique in cloud-native environments. Abusive role binding is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting these requests surfaces an attempt to entrench elevated access.
HuntRule TeamKubernetesauditHigh10Premium2026-09-05Malicious Modification of a Computer Account SPN (via security)
This rule detects update the Service Principal Name (SPN) of a computer account in order to perform "Kerberos redirection" and escalate privileges.
HuntRule TeamWindowssecurityHigh30Premium2026-09-05Malicious Mailbox Audit Bypass Association in Exchange Online (via exchange)
This rule detects an account being added to the mailbox audit bypass list, which stops Exchange from logging that account's mailbox actions, a defense-evasion technique used to hide mailbox access and rule creation. Mailbox audit bypass is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting this operation surfaces an attacker suppressing mailbox telemetry.
HuntRule TeamM365exchangeHigh10Premium2026-09-05Malicious High Risk Active Directory Group Membership Change (via security)
This rule detects scenarios where a suspicious group membership is changed.
HuntRule TeamWindowssecurityHigh60Premium2026-09-05Malicious Account Marked as Sensitive and Cannot Be Delegated Had Its Protection Removed (via security)
This rule detects removes security protection from a sensitive account to escalate privileges.
HuntRule TeamWindowssecurityHigh60Premium2026-09-05Malicious Active Directory Enumeration via SharpHound or BloodHound (via process_creation)
This rule detects execution of the SharpHound collector or the Invoke-BloodHound cmdlet using its characteristic collection-method arguments, which harvest Active Directory objects, sessions and access-control relationships to map attack paths to Domain Admin. Large-scale AD discovery like this is a common pre-lateral-movement step seen across intrusions in the Red Canary Threat Detection Report. Detecting the collector's invocation surfaces reconnaissance before the adversary pivots.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-05Malicious Host Constrained Delegation Settings Changed for Potential Abuse (Rubeus) - Kerberos Only (via security)
This rule detects modifies host delegation settings for privilege escalation.
HuntRule TeamWindowssecurityHigh40Premium2026-09-05Malicious Host Set with Unconstrained Delegation (via security)
This rule detects modifies host delegation settings for privilege escalation.
HuntRule TeamWindowssecurityHigh30Premium2026-09-05Malicious Host Set with Constrained Delegation (via security)
This rule detects modifies host delegation settings for privilege escalation.
HuntRule TeamWindowssecurityHigh40Premium2026-09-05Masquerading Computer Account Manipulation for Delegation - RBCD (via security)
This rule detects manipulate a computer object and updates its attribute 'msDS-AllowedToActOnBehalfOfOtherIdentity' to enable a resource to impersonate and authenticate any domain user.
HuntRule TeamWindowssecurityHigh70Premium2026-09-05