Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,293 rules
Malicious Medium Risk Local/domain Local Group Membership Change (via security)
This rule detects scenarios where a suspicious group membership is changed.
HuntRule TeamWindowssecurityHigh60Premium2026-09-02Malicious Massive Processes Termination Burst (via process_creation)
This rule detects kill multiples services on a host. Attacker may target services related to databases, security products or backups (Veeam, Symantec, Acronis ...).
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-02GateDoor DLL Search Order Hijacking via WebView2Loader from MicrosoftEdging (via image_load)
This rule detects WebViewHost.exe loading a WebView2Loader.dll from the roaming MicrosoftEdging directory, the DLL search-order hijack GateDoor uses to run malicious code under a WebView2 host name. Because the legitimate loader ships inside vendor install paths, a WebView2Loader.dll executing from the user roaming profile is a reliable side-loading indicator.
HuntRule TeamWindowsimage_loadHigh40Premium2026-09-02Malicious Firewall Deactivation - PowerShell (via powershell)
This rule detects disabled the Windows Firewall to evade defense.
HuntRule TeamWindowspowershellHigh170Premium2026-09-02Masquerading Administrator Login Impersonation with Forged Golden Ticket (via security)
This rule detects used a forged Golden ticket to login on a remote host. Per default or if specified, the ticket will be forged using the builtin administrator account (SID *-500). However, and it frequent cases, a non suspicious user name will be specificied during the forge in order to evade security monitoring. The rule works based on this trick.
HuntRule TeamWindowssecurityHigh60Premium2026-09-02Malicious Kerberos proxiable/S4U2self Ticket - CVE-2021-42278/42287 (via security)
This rule detects request a proxiable ticket. This action may trigger while attempting to identify a vulnerable target or using some offsensive Kerberos tools like Kerbrute, Impacket...
HuntRule TeamWindowssecurityHigh00Premium2026-09-02Malicious Service Creation - PowerShell (via powershell)
This rule detects create a service for persistence.
HuntRule TeamWindowspowershellHigh20Premium2026-09-02Malicious UAC Bypass via ms-settings Handler Hijack (via registry_set)
This rule detects creation of a command under HKCU ms-settings\shell\open\command, the registry hijack that fodhelper.exe and computerdefaults.exe follow to auto-elevate an attacker command without a UAC prompt. This ms-settings handler hijack is a privilege-escalation technique tracked in the Red Canary Threat Detection Report. Detecting the key modification surfaces a UAC-bypass being staged.
HuntRule TeamWindowsregistry_setHigh30Premium2026-09-02Malicious Event Log Clear Attempt - Command (via process_creation)
This rule detects clear the event logs.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-02Malicious Massive Remote Service Creation via Named Pipes - TChopper, CME (via security)
This rule detects remotely creates a service over named pipes. Tools like Tchopper or CrackMapExec can trigger this rule.
HuntRule TeamWindowssecurityHigh60Premium2026-09-02Malicious Kerberos Ticket File Creation Indicating Credential Theft (via file_event)
This rule detects creation of .kirbi files, the on-disk format Mimikatz and similar tools use when exporting stolen Kerberos tickets for pass-the-ticket and Kerberoasting attacks. Kerberos ticket theft tied to LSASS and credential abuse features in the Red Canary Threat Detection Report as a path to lateral movement and domain compromise. Because legitimate software rarely writes .kirbi files, their appearance is a high-fidelity indicator of credential theft.
HuntRule TeamWindowsfile_eventHigh90Premium2026-09-02Renamed Regsvr32 or Rundll32 Loading a DLL With a Non-Standard Extension (via process_creation)
This rule detects regsvr32 or rundll32 loading a module that carries a disguised or non-standard extension such as .dat, .tmp, .png or .log from a user-writable directory, a masquerading pattern used by loaders like Qbot to hide their DLL payload. Proxy execution of renamed DLLs is documented in the Red Canary Threat Detection Report as a way to defeat extension-based controls. Detecting these disguised module loads surfaces the payload execution.
HuntRule TeamWindowsprocess_creationHigh80Premium2026-09-02Malicious Event Log Deactivation or Size Reduction - Command (via process_creation)
This rule detects disable or reduce the size of an event log.
HuntRule TeamWindowsprocess_creationHigh80Premium2026-09-02Malicious Kimsuky VBE Payload Download via Curl to AppData and Execution (via process_creation)
This rule detects a command shell chain that uses curl to download a remote payload into the user AppData Roaming directory as a VBScript encoded file and then executes it, the delivery behavior of a Kimsuky LNK campaign abusing remote control tools across Northeast Asia. Adversaries leverage curl as a trusted utility to stage a bot.vbe beacon while blending with normal traffic, making early detection critical for catching the intrusion at the delivery stage.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-02Uncommon Mustang Panda pcl2bmp Sideloading Host Executed from Public Documents (via process_creation)
This rule detects the legitimate pcl2bmp binary launched from the Public Documents directory, the DLL side-loading host used to load the malicious ctxmui.dll in the Mustang Panda ZOHOMURK operation against Indian government and energy sectors. Adversaries relocate a signed executable to a world-writable path so it sideloads their loader under a trusted process. Execution of this printer utility from Public Documents is highly anomalous.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-02