Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
Malicious LSASS Credential Dump with LSASSY - Kernel Access (via security)
This rule detects remotely dump LSASS credentials using the LSASSY tool.
HuntRule TeamWindowssecurityHigh70Premium2026-09-01SystemNightmare by GentilKiwi - External Printer Mapped - CVE-2021-1675 / CVE-2021-34527 (via security)
This rule detects exploit the PrintNightmare vulnerability by abusing the Windows print spooler using the service exposed by Gentilkiwi.
HuntRule TeamWindowssecurityHigh60Premium2026-09-01Obfuscated RDP Tunneling Configuration Enabled for Port Forwarding (via process_creation)
This rule detects configure port forwarding on a host to redirect traffic to a C&C target.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-01Malicious Metasploit Reverse Shell Injection in SQL Server (via process_creation)
This rule detects inject a payload into SQL Server in order to obtain a remote shell.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-01Malicious Impacket WMIexec Process Execution (via process_creation)
This rule detects execute WMIexec in order to escalate privileges.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-01Malicious Fortinet APT Group Abuse on Windows - User (via security)
This rule detects scenarios where APT actors exploits Fortinet vulnerabilities to gain access into Windows infrastructure.
HuntRule TeamWindowssecurityHigh60Premium2026-09-01Malicious Service Abuse with Backdoored "command Failure" - Reg via PowerShell (via powershell)
This rule detects modify the configuration of a service to trigger an action when the service is crashed.
HuntRule TeamWindowspowershellHigh80Premium2026-09-01Malicious Rubeus Kerberos Unconstrained Delegation Abuse (via security)
This rule detects abuse Kerberos unconstrained delegation for domain persistence.
HuntRule TeamWindowssecurityHigh60Premium2026-09-01Malicious Stickey Key Called CMD via Command Execution - Hash Detection (via process_creation)
This rule detects calls the stickey key and execute CMD.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-01MuddyWater NetBird Deployment via Hardcoded Setup Key (via process_creation)
This rule detects NetBird being configured with the hardcoded setup key reused across MuddyWater samples targeting CFOs, a remote-access persistence behavior. Adversaries leverage a known setup key to silently enroll compromised hosts into their NetBird overlay network for hands-on access.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-01Malicious Firewall Deactivation - Firewall (via firewall-as)
This rule detects disabled the Windows Firewall to evade defense.
HuntRule TeamWindowsfirewall-asHigh70Premium2026-09-01Malicious Microsoft Defender Threat Exclusion Added - Native (via windefend)
This rule detects scenarios where a threat exclusion is added to the antivirus in order to bypass its detection capacities.
HuntRule TeamWindowswindefendHigh90Premium2026-09-01FunkSec Ransomware Encryption Artifacts via funksec Extension and Markdown Ransom Note (via file_event)
This rule detects the on-disk artifacts of FunkSec ransomware, namely files renamed with the funksec extension and the dropped README markdown ransom note. Adversaries append a unique extension and write a ransom note during mass encryption, so these artifacts confirm active data-encryption for impact.
HuntRule TeamWindowsfile_eventHigh90Premium2026-09-01Malicious XE Group Webshell Upload via VeraCore UploadImage CVE-2024-57968 (via webserver)
This rule detects abuse of the VeraCore UploadImage handler to upload an ASP or ASPX webshell through the CVE-2024-57968 unrestricted-upload flaw exploited by XE Group. The request combines the PMA upload controller with a script-file filename parameter, reflecting the point at which the actor plants a persistent webshell on the server.
HuntRule TeamWebwebserverHigh120Premium2026-09-01HamsaUpdate Wiper Trigger via F5UPDATER ConfirmDeleteFiles Argument (via process_creation)
This rule detects execution of the F5UPDATER wiper masquerading as an F5 update tool with the ConfirmDeleteFiles argument that triggers destructive file deletion without a confirmation prompt in Operation HamsaUpdate against Israeli infrastructure. The specific loader name paired with this argument marks the transition from staging to data destruction.
HuntRule TeamWindowsprocess_creationHigh120Premium2026-09-01