Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,105 rules
PATCHCORD SHEETCORD Startup Folder VBScript Persistence (via file_event)
This rule detects the SHEETCORD backdoor dropping SystemHelper.vbs into the user Startup folder to gain logon persistence during the PATCHCORD campaign against Afghan telecom targets. Adversaries place a VBScript launcher in the Startup directory so wscript executes their implant at every logon. Detecting the drop exposes persistence before the Google Sheets tasking channel activates.
HuntRule TeamWindowsfile_eventHigh70Premium2026-09-01Nullsoft Scriptable Installer Script (NSIS) execution
Detects the loading of the NSIS System plugin library, indicative of an NSIS script execution.
HuntRule TeamWindowsimage_loadLow50Premium2026-09-01Malicious PHP Code Injection in URL via CraftCMS CVE-2025-32432 Exploitation (via webserver)
This rule detects inline PHP code appearing in a request URL, the code-injection technique used after CraftCMS CVE-2025-32432 exploitation to write a file manager webshell to the web root via file_put_contents and file_get_contents. Adversaries embed PHP tags and file functions in the request so the vulnerable application stores and executes attacker-controlled code.
HuntRule TeamWebwebserverHigh80Premium2026-09-01Malicious Houken sysinitd Rootkit Kernel Module Load via insmod (via process_creation)
This rule detects loading of the Houken sysinitd rootkit kernel module via insmod, the persistence and defense-evasion behavior deployed on compromised Ivanti Cloud Service Appliance devices to hook the kernel and hide the intrusion. Adversaries leverage a loadable kernel module to survive reboots and conceal processes and network activity, making detection critical because the rootkit blinds most higher-level telemetry once loaded.
HuntRule TeamLinuxprocess_creationHigh60Premium2026-09-01Malicious Kimsuky Remote HTA Execution via URL Shortener (via process_creation)
This rule detects mshta.exe launching a remote payload through a Korean URL shortener domain, the delivery behavior of the Kimsuky KimJongRAT campaign that hides its staging server behind link24 and buly redirects. Adversaries leverage mshta as a trusted scripting host to fetch and run remote HTA content while evading download controls, making early detection critical for catching execution at the initial access stage.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-01Possible DNS Queries to Public Ethereum RPC Endpoints for EtherHiding Payload Retrieval (via dns_query)
This rule detects DNS resolution of public Ethereum RPC provider domains queried by EtherRAT to read its command and control configuration from a smart contract using the EtherHiding technique. Adversaries leverage blockchain RPC endpoints as a resilient dead drop that resists takedown while blending with legitimate crypto traffic, making this a heuristic signal worth reviewing on hosts with no expected blockchain activity.
HuntRule TeamWindowsdns_queryLow30Premium2026-09-01Masquerading Kimsuky Scheduled Task Persistence Executing VBE via Wscript (via process_creation)
This rule detects creation of a scheduled task that repeatedly launches wscript.exe against a VBScript encoded file, the persistence behavior used by a Kimsuky campaign to keep its bot.vbe beacon running at short intervals. Adversaries leverage the Task Scheduler to survive reboots and maintain access while masquerading as a browser update task, making early detection critical for surfacing persistence before further payload deployment.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-01Masquerading sLoad Ramnit Loader Execution via PowerShell Running a Masqueraded Log Script (via process_creation)
This rule detects PowerShell launching with an execution-policy bypass to run a script masqueraded as a .log file, the loader behavior used by the sLoad downloader to execute the encrypted Ramnit payload in the drIBAN banking-fraud operation. Adversaries rename PowerShell scripts to log extensions so the interpreter runs untrusted code while evading extension-based controls, making early detection critical for catching the loader before Ramnit injection.
HuntRule TeamWindowsprocess_creationMedium40Premium2026-09-01Malicious Browser Master Key Decryption Artifacts Written by Katz Stealer (via file_event)
This rule detects creation of the decrypted browser master-key text files written by Katz Stealer after it extracts and decrypts Chrome, Edge, and Brave application-bound encryption keys. Adversaries leverage these staged key files to decrypt saved credentials and cookies offline, making detection valuable for catching browser credential theft in progress.
HuntRule TeamWindowsfile_eventHigh60Premium2026-09-01Renamed DLL Sideloading of TOTPGuard via Renamed Setup Binary in Nimbus Manticore Chain (via image_load)
This rule detects a setup.exe process loading TOTPGuard.dll, the AppDomain-hijacking DLL sideloading pair used by Nimbus Manticore to run a decrypted native implant from a renamed Microsoft Visual Studio host binary. Adversaries leverage sideloading through a signed executable to execute malicious code under a trusted process, making early detection critical for surfacing the infection chain before beacon establishment.
HuntRule TeamWindowsimage_loadHigh40Premium2026-09-01In-Memory Matanbuchus Loader DLL Sideloading via Notepad++ GenericUpdater Loading libcurl (via image_load)
This rule detects the legitimate Notepad++ GUP updater GenericUpdater.exe loading libcurl.dll from a user-writable location, the DLL sideloading behavior used by the Matanbuchus 3.0 loader after delivery through a fake Notepad++ update. Adversaries leverage sideloading against a signed updater to execute the loader under a trusted process while evading process-based detection, making early detection critical for stopping the chain before regsvr32 persistence and process hollowing deploy.
HuntRule TeamWindowsimage_loadHigh50Premium2026-09-01Masquerading Certificate Services Outbound LDAP or SMB Connection via Certighost Coercion (via network_connection)
This rule detects the Certificate Services process certsrv.exe initiating outbound connections to LDAP or SMB destination ports, the coerced-authentication behavior abused in the Certighost CVE-2026-54121 attack chain to force a Certificate Authority to authenticate against attacker-controlled infrastructure. Adversaries leverage this to relay CA credentials and impersonate Domain Controllers, making early detection critical for stopping certificate-based domain takeover.
HuntRule TeamWindowsnetwork_connectionMedium30Premium2026-09-01PowerShell Spawned by SharePoint Worker Process After ToolShell Exploitation (via process_creation)
This rule detects the SharePoint worker process w3wp.exe spawning PowerShell, the post-exploitation execution pattern seen after ToolShell CVE-2025-53770 web shell deployment where decoded payloads are written to disk. Adversaries leverage the worker process to run commands under IIS context, making early detection critical for catching hands-on-keyboard activity following server compromise.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-01NailaoLoader DLL Sideloading via usysdiag.exe Loading sensapi.dll (via image_load)
This rule detects the signed Huorong binary usysdiag.exe loading a sensapi.dll from outside the Windows system directories, the DLL side-loading behavior used to launch NailaoLoader and decrypt the NailaoLocker ransomware in intrusions following CVE-2024-24919 exploitation of Check Point gateways. Adversaries abuse a trusted signed binary to run the loader under a legitimate process while evading detection.
HuntRule TeamWindowsimage_loadHigh50Premium2026-09-01ClickFix NetSupport RAT Staging via Password-Protected 7-Zip Extraction (via process_creation)
This rule detects extraction of the password-protected ClickFix archive at.7z with 7-Zip, which unpacks the NetSupport RAT binary neservice.exe onto the host. Adversaries leverage password-protected archives to smuggle the RAT past content inspection, making extraction of this campaign-specific archive a useful post-delivery indicator.
HuntRule TeamWindowsprocess_creationMedium10Premium2026-09-01