Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,093 rules
Malicious DLL ServerLevelPluginDll Registration - Reg via Sysmon (via registry_set)
This rule detects scenarios where a DLL is loaded by the DNS server in order to escalate privileges or initiate a remote shell.
HuntRule TeamWindowsregistry_setCritical30Premium2026-09-02Registry Query for WDigest
Rule to detect discovery activity for WDigest registry settings
HuntRule TeamWindowsprocess_creationMedium30Premium2026-09-02Malicious Registry Hive Dump of SAM or SYSTEM via Reg Save (via process_creation)
This rule detects reg.exe saving the SAM, SYSTEM or SECURITY registry hive to disk, which lets an attacker extract local credential material and boot keys for offline hash recovery. Registry hive dumping is a credential-access technique documented in the Red Canary Threat Detection Report. Detecting these save commands surfaces local credential theft in progress.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-09-02Suspicious Code Execution via InstallUtil LOLBIN (via process_creation)
This rule detects InstallUtil.exe run with uninstall or log-suppression flags used to trigger attacker code in a .NET assembly's Uninstall method while avoiding console output, a signed-binary proxy technique. InstallUtil abuse is a defense-evasion technique tracked in the Red Canary Threat Detection Report. Detecting these command lines surfaces code execution under a trusted Microsoft utility.
HuntRule TeamWindowsprocess_creationMedium20Premium2026-09-02Malicious Read Access to the Linux Shadow Password File (via process_creation)
This rule detects a shell or file utility reading /etc/shadow, the file holding Linux password hashes, which adversaries copy to crack credentials offline. OS credential access on Linux hosts supports the lateral movement and escalation documented in the Red Canary Threat Detection Report. Because /etc/shadow is normally accessed only by system authentication components, ad-hoc reads by cat, cp or editors are a strong credential-theft indicator.
HuntRule TeamLinuxprocess_creationHigh40Premium2026-09-02Malicious UAC Bypass via sdclt Handler Hijack (via registry_set)
This rule detects modification of the HKCU exefile runas isolatedCommand or Folder shell open command keys that sdclt.exe consults, a registry hijack used to auto-elevate an attacker command without a UAC prompt. This sdclt handler hijack is a privilege-escalation technique tracked in the Red Canary Threat Detection Report. Detecting the key change surfaces a UAC-bypass being staged.
HuntRule TeamWindowsregistry_setHigh20Premium2026-09-02Malicious Winlogon Shell or Userinit Persistence Modification (via registry_set)
This rule detects modification of the Winlogon Shell or Userinit values, which are executed at every interactive logon and are abused to launch a payload persistently with the user's session. Winlogon helper persistence is a technique tracked in the Red Canary Threat Detection Report. Detecting changes to these keys surfaces a logon-triggered persistence foothold.
HuntRule TeamWindowsregistry_setHigh30Premium2026-09-02Malicious Bulk Data Exfiltration via Rclone (via process_creation)
This rule detects rclone being run with copy, sync or move operations to a cloud remote, the staging-and-exfiltration tool ransomware crews use to bulk-transfer stolen data before encryption. Data exfiltration over cloud storage is documented in the Red Canary Threat Detection Report as a hallmark of double-extortion intrusions. Detecting rclone transfer commands surfaces exfiltration during the critical window before impact.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-09-02Malicious Diskshadow Command Abuse to Expose VSS Backup (via process_creation)
This rule detects attemps to create an IFM for dumping credentials.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-02Malicious Houken PHP Webshell Written into Ivanti CSA Webroot via Shell Redirection (via process_creation)
This rule detects a shell dropping a PHP webshell into the Ivanti Cloud Service Appliance LANDesk broker webroot by echoing PHP code that invokes system() or eval() on request parameters, the initial-access behavior used by the Houken intrusion set after exploiting Ivanti CSA zero-days. Adversaries leverage this to obtain a persistent command channel on the appliance, making early detection critical for catching perimeter compromise before rootkit deployment and lateral movement.
HuntRule TeamLinuxprocess_creationHigh20Premium2026-09-02Suspicious RDP Shadow Session Started - Native (via rdp)
This rule detects has initiated a RDP shadow session.
HuntRule TeamWindowsrdpMedium10Premium2026-09-02Malicious Tampering With Windows Defender Protection (via process_creation)
This rule detects command-line attempts to disable core Microsoft Defender protections, such as turning off real-time monitoring through Set-MpPreference or adding broad exclusions, or stopping and disabling the WinDefend service. Impairing endpoint defenses is a common defense-evasion step in the Red Canary Threat Detection Report, clearing the way for follow-on tooling to run undetected. Detecting these tamper commands surfaces the adversary weakening the host before further action.
HuntRule TeamWindowsprocess_creationHigh00Premium2026-09-02Suspicious LSASS Credential Dump with LSASSY - PowerShell (via powershell)
This rule detects remotely dump LSASS credentials using the LSASSY tool.
HuntRule TeamWindowspowershellMedium50Premium2026-09-02Malicious Medium Risk Local/domain Local Group Membership Change (via security)
This rule detects scenarios where a suspicious group membership is changed.
HuntRule TeamWindowssecurityHigh30Premium2026-09-02Suspicious Brutforce with Denied Access Due to Account Restrictions Policies (via security)
This rule detects attemps to use a comprimised account but failed to login due to account restrictions policies (permissions, time restrictions, workstation, logon type, ...).
HuntRule TeamWindowssecurityMedium10Premium2026-09-02