Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
Uncommon Mustang Panda pcl2bmp Sideloading Host Executed from Public Documents (via process_creation)
This rule detects the legitimate pcl2bmp binary launched from the Public Documents directory, the DLL side-loading host used to load the malicious ctxmui.dll in the Mustang Panda ZOHOMURK operation against Indian government and energy sectors. Adversaries relocate a signed executable to a world-writable path so it sideloads their loader under a trusted process. Execution of this printer utility from Public Documents is highly anomalous.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-02Enabling restricted admin mode
Detects the registry modification to enable restricted admin mode using reg.exe
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-02Malicious Inhibition of System Recovery via Shadow Copy or Backup Deletion (via process_creation)
This rule detects command lines that delete volume shadow copies or backups or disable boot-time recovery, using vssadmin, wmic shadowcopy, wbadmin or bcdedit. Inhibiting system recovery is a high-impact technique in the Red Canary Threat Detection Report and a hallmark of ransomware preparing to prevent victims from restoring encrypted data. Detecting these destructive commands provides a critical, high-fidelity signal immediately before or during encryption.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-02Malicious IIS Application Pool Credential Dumping (via process_creation)
This rule detects scenarios where an attacker.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-02Malicious RDP BlueeKeep Connection Closed - CVE-2019-0708 (via rdp)
This rule detects exploit the BlueKeep vulnerability.
HuntRule TeamWindowsrdpHigh70Premium2026-09-02Malicious Impacket DCOMexec Process Abuse via MMC (via process_creation)
This rule detects execute the Impacket DCOMexec tool in order to abuse DCOM services.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-02Malicious Anonymous Login - Domain Specified (via security)
This rule detects scenarios where a suspicious anonymous login is performed during discovery phases.
HuntRule TeamWindowssecurityHigh30Premium2026-09-02Malicious SQL Server Dedicated Admin Connection (DAC) Suspicious Activity (via application)
This rule detects enabled the DAC mode in order to bypass access controls, logon triggers, perform brute force attacks or run unauthorized queries.
HuntRule TeamMssqlapplicationHigh50Premium2026-09-02Malicious Service Deactivation - Command (via process_creation)
This rule detects disable.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-02BitLocker Feature Activation on Multiple Hosts - Native (via bitlocker)
This rule detects enable or reconfigure BitLocker on multiple hosts for ransomware purposes.
HuntRule TeamWindowsbitlockerHigh50Premium2026-09-02Malicious Brutforce Enumeration on Windows OpenSSH Server with Non Existing User (via security)
This rule detects sSH brutforce a Windows OpenSSH server with non existing users.
HuntRule TeamWindowssecurityHigh50Premium2026-09-02Malicious Massive Remote Service Creation via Named Pipes - Tchopper (via security)
This rule detects uses the Tchopper tool by remotely creating multiple services via named pipes.
HuntRule TeamWindowssecurityHigh30Premium2026-09-01Malicious Audit Policy Disabled by Command Line (via process_creation)
This rule detects disbale or clear the audit policy for defense evasion purposes.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-01Malicious Shared Folder Access with Forged Golden Ticket (via security)
This rule detects used a forged Golden ticket to login on a remote shared folder. Per default or if specified, the ticket will be forged using the builtin administrator account (SID *-500). However, and it frequent cases, a non suspicious user name will be specificied during the forge in order to evade security monitoring. The rule works based on this trick.
HuntRule TeamWindowssecurityHigh50Premium2026-09-01Malicious User Files Dump via Network Share - DonPapi, Lazagne (via security)
This rule detects attempt to dump user profile information via network share.
HuntRule TeamWindowssecurityHigh40Premium2026-09-01