Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,096 rules
Malicious Kerberos Ticket File Creation Indicating Credential Theft (via file_event)
This rule detects creation of .kirbi files, the on-disk format Mimikatz and similar tools use when exporting stolen Kerberos tickets for pass-the-ticket and Kerberoasting attacks. Kerberos ticket theft tied to LSASS and credential abuse features in the Red Canary Threat Detection Report as a path to lateral movement and domain compromise. Because legitimate software rarely writes .kirbi files, their appearance is a high-fidelity indicator of credential theft.
HuntRule TeamWindowsfile_eventHigh60Premium2026-09-02Suspicious System Reconnaissance via WMI Command-Line Queries (via process_creation)
This rule detects wmic.exe being used to enumerate host security and system information, such as querying installed antivirus products, operating-system details or running processes for situational awareness. WMI-based discovery is called out in the Red Canary Threat Detection Report as an early hands-on-keyboard step that informs an adversary's next moves. Detecting these reconnaissance queries surfaces post-compromise triage before escalation.
HuntRule TeamWindowsprocess_creationMedium40Premium2026-09-02Renamed Regsvr32 or Rundll32 Loading a DLL With a Non-Standard Extension (via process_creation)
This rule detects regsvr32 or rundll32 loading a module that carries a disguised or non-standard extension such as .dat, .tmp, .png or .log from a user-writable directory, a masquerading pattern used by loaders like Qbot to hide their DLL payload. Proxy execution of renamed DLLs is documented in the Red Canary Threat Detection Report as a way to defeat extension-based controls. Detecting these disguised module loads surfaces the payload execution.
HuntRule TeamWindowsprocess_creationHigh80Premium2026-09-02Malicious Event Log Deactivation or Size Reduction - Command (via process_creation)
This rule detects disable or reduce the size of an event log.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-02Malicious Kimsuky VBE Payload Download via Curl to AppData and Execution (via process_creation)
This rule detects a command shell chain that uses curl to download a remote payload into the user AppData Roaming directory as a VBScript encoded file and then executes it, the delivery behavior of a Kimsuky LNK campaign abusing remote control tools across Northeast Asia. Adversaries leverage curl as a trusted utility to stage a bot.vbe beacon while blending with normal traffic, making early detection critical for catching the intrusion at the delivery stage.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-02Uncommon Mustang Panda pcl2bmp Sideloading Host Executed from Public Documents (via process_creation)
This rule detects the legitimate pcl2bmp binary launched from the Public Documents directory, the DLL side-loading host used to load the malicious ctxmui.dll in the Mustang Panda ZOHOMURK operation against Indian government and energy sectors. Adversaries relocate a signed executable to a world-writable path so it sideloads their loader under a trusted process. Execution of this printer utility from Public Documents is highly anomalous.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-02Enabling restricted admin mode
Detects the registry modification to enable restricted admin mode using reg.exe
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-02Malicious Inhibition of System Recovery via Shadow Copy or Backup Deletion (via process_creation)
This rule detects command lines that delete volume shadow copies or backups or disable boot-time recovery, using vssadmin, wmic shadowcopy, wbadmin or bcdedit. Inhibiting system recovery is a high-impact technique in the Red Canary Threat Detection Report and a hallmark of ransomware preparing to prevent victims from restoring encrypted data. Detecting these destructive commands provides a critical, high-fidelity signal immediately before or during encryption.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-02Suspicious Scheduled Task Enumerated (via process_creation)
This rule detects enumerates scheduled task configuration.
HuntRule TeamWindowsprocess_creationMedium40Premium2026-09-02Malicious IIS Application Pool Credential Dumping (via process_creation)
This rule detects scenarios where an attacker.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-02ClickFix PowerShell In-Memory Execution via Invoke-RestMethod Piped to Invoke-Expression (via process_creation)
This rule detects the ClickFix golden pattern in which PowerShell retrieves a remote payload with Invoke-RestMethod and immediately runs it through Invoke-Expression, executing code entirely in memory. Adversaries leverage this download-and-run one-liner delivered through pastejacking overlays, making the paired cmdlets a reliable ClickFix execution indicator.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-09-02Malicious RDP BlueeKeep Connection Closed - CVE-2019-0708 (via rdp)
This rule detects exploit the BlueKeep vulnerability.
HuntRule TeamWindowsrdpHigh40Premium2026-09-02OpenSSH Native Server Feature Installation (via powershell)
This rule detects enables the native OpenSSH server feature on Windows to perform stealthy lateral movement.
HuntRule TeamWindowspowershellMedium50Premium2026-09-02Malicious Impacket DCOMexec Process Abuse via MMC (via process_creation)
This rule detects execute the Impacket DCOMexec tool in order to abuse DCOM services.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-09-02Malicious Anonymous Login - Domain Specified (via security)
This rule detects scenarios where a suspicious anonymous login is performed during discovery phases.
HuntRule TeamWindowssecurityHigh20Premium2026-09-02