Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,292 rules
Malicious Remote Script Piped to a Shell on macOS (via process_creation)
This rule detects a macOS command line that downloads remote content with curl and pipes it straight into a shell or osascript, the paste-and-run delivery behavior behind macOS stealers such as Atomic and Odyssey that trick users into running a one-liner in Terminal. macOS paste-and-run stealer campaigns are called out in the Red Canary Threat Detection Report. Detecting the download-and-execute pipe surfaces infostealer installation at the execution stage.
HuntRule TeamMacosprocess_creationHigh60Premium2026-09-03Uncommon macOS Keychain Credential Access via Security Utility (via process_creation)
This rule detects use of the built-in security utility to dump the keychain or extract stored generic and internet passwords, a credential-access behavior used by macOS stealers to harvest saved secrets. Credential theft from the keychain supports the infostealer activity documented in the Red Canary Threat Detection Report. Because interactive keychain dumping is uncommon, detecting these security-command patterns surfaces credential harvesting.
HuntRule TeamMacosprocess_creationHigh30Premium2026-09-03PowerShell Storing an Encoded Payload in the Registry (via process_creation)
This rule detects PowerShell writing a base64 or byte-array value into an HKCU registry key, the fileless persistence and staging behavior seen in Solarmarker and Yellow Cockatoo intrusions. Storing an encoded payload in the registry is a defense-evasion and persistence technique tracked in the Red Canary Threat Detection Report. Detecting this write surfaces a fileless payload being cached for later execution.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-03Malicious Shared Library Preload Persistence via ld.so.preload (via process_creation)
This rule detects modification of /etc/ld.so.preload, which forces a shared library to load into every dynamically linked process, a stealthy persistence and privilege-escalation technique used by Linux rootkits. Ld.so.preload hijacking is tracked in the Red Canary Threat Detection Report. Detecting the change surfaces a system-wide library hijack.
HuntRule TeamLinuxprocess_creationHigh20Premium2026-09-03Malicious Scheduled Persistent Task with SYSTEM Privileges Creation (via process_creation)
This rule detects creates a privileged task to establish persistence.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-03VSS Backup Deletion or Resize (via process_creation)
This rule detects delete or resize existing VSS backup.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-03Malicious Wdigest Authentication Enabled - Reg via Command (via process_creation)
This rule detects enable Wdgiest authention so passwords are stored in clear text and can be dumped.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-03Malicious Boot Recovery Tampering via Bcdedit (via process_creation)
This rule detects bcdedit disabling automatic recovery or forcing the boot status policy to ignore failures, an inhibit-system-recovery step ransomware runs so victims cannot restore Windows after encryption. Boot-configuration tampering is an impact technique tracked in the Red Canary Threat Detection Report. Detecting these commands surfaces recovery being sabotaged ahead of encryption.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-03Malicious Task Manager Used for LSASS Dump - Kernel (via security)
This rule detects attempt to dump the LSASS process via the Task Manager.
HuntRule TeamWindowssecurityHigh00Premium2026-09-03Malicious Compiled HTML Help Process Spawning a Script Interpreter (via process_creation)
This rule detects the Windows help viewer hh.exe spawning a command shell or script interpreter, which happens when a weaponized compiled HTML help (.chm) file executes embedded script for proxy execution. Compiled HTML File abuse is a System Binary Proxy Execution technique in the Red Canary Threat Detection Report used to run code under a trusted binary and evade allowlisting. Detecting interpreter children of hh.exe surfaces malicious CHM execution.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-03Malicious Winlogon Process Contact to C2 - Blacklotus - Sysmon (via process_creation)
This rule detects blacklotus HTTP downloader injection into winlogon.exe process.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-03Malicious Event Log Clear Attempt - Wmi (via process_creation)
This rule detects clear the event logs.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-03Malicious Interactive Privileged Shell Triggered by Schedule Task - Deprecated (via process_creation)
This rule detects abuse the at command to elevate privilages. Note that at command is deprecated since Windows 8 and replaced by schtask.
HuntRule TeamWindowsprocess_creationHigh100Premium2026-09-03Malicious Brutforce Enumeration with Non Existing Users - Login (via security)
This rule detects enumerate potential existing users, resulting in failed logins with unexisting or invalid accounts.
HuntRule TeamWindowssecurityHigh80Premium2026-09-03Malicious Host Constrained Delegation Settings Changed for Potential Abuse (Rubeus) - Any Protocol (via security)
This rule detects modifies host delegation settings for privilege escalation.
HuntRule TeamWindowssecurityHigh80Premium2026-09-03