Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,109 rules
Masquerading Certificate Services Outbound LDAP or SMB Connection via Certighost Coercion (via network_connection)
This rule detects the Certificate Services process certsrv.exe initiating outbound connections to LDAP or SMB destination ports, the coerced-authentication behavior abused in the Certighost CVE-2026-54121 attack chain to force a Certificate Authority to authenticate against attacker-controlled infrastructure. Adversaries leverage this to relay CA credentials and impersonate Domain Controllers, making early detection critical for stopping certificate-based domain takeover.
HuntRule TeamWindowsnetwork_connectionMedium30Premium2026-09-01PowerShell Spawned by SharePoint Worker Process After ToolShell Exploitation (via process_creation)
This rule detects the SharePoint worker process w3wp.exe spawning PowerShell, the post-exploitation execution pattern seen after ToolShell CVE-2025-53770 web shell deployment where decoded payloads are written to disk. Adversaries leverage the worker process to run commands under IIS context, making early detection critical for catching hands-on-keyboard activity following server compromise.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-01NailaoLoader DLL Sideloading via usysdiag.exe Loading sensapi.dll (via image_load)
This rule detects the signed Huorong binary usysdiag.exe loading a sensapi.dll from outside the Windows system directories, the DLL side-loading behavior used to launch NailaoLoader and decrypt the NailaoLocker ransomware in intrusions following CVE-2024-24919 exploitation of Check Point gateways. Adversaries abuse a trusted signed binary to run the loader under a legitimate process while evading detection.
HuntRule TeamWindowsimage_loadHigh50Premium2026-09-01ClickFix NetSupport RAT Staging via Password-Protected 7-Zip Extraction (via process_creation)
This rule detects extraction of the password-protected ClickFix archive at.7z with 7-Zip, which unpacks the NetSupport RAT binary neservice.exe onto the host. Adversaries leverage password-protected archives to smuggle the RAT past content inspection, making extraction of this campaign-specific archive a useful post-delivery indicator.
HuntRule TeamWindowsprocess_creationMedium10Premium2026-09-01Obfuscated IIS Worker Spawning Encoded PowerShell after SharePoint ToolShell (via process_creation)
This rule detects the IIS worker process w3wp.exe spawning a command shell or PowerShell with a Base64-encoded command, the post-exploitation behavior observed after SharePoint ToolShell exploitation of CVE-2025-53770. Adversaries run encoded PowerShell from the web server context to install webshells and stage further tooling.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-01TerraStealerV2 Data Staging in Bay0NsQIzx Package Directory (via file_event)
This rule detects TerraStealerV2 staging collected browser and wallet data inside the hardcoded Bay0NsQIzx package directory under LocalAppData before archiving it for exfiltration. Adversaries leverage a fixed staging folder to consolidate stolen artifacts, making file writes into this named directory a high-confidence collection indicator.
HuntRule TeamWindowsfile_eventHigh40Premium2026-09-01Malicious XWorm Persistence via Minute-Interval Scheduled Task Named XClient (via process_creation)
This rule detects creation of a highly privileged scheduled task named XClient that runs every minute, the persistence mechanism used by recent XWorm infection chains to relaunch the RAT payload continuously. Adversaries leverage minute-interval tasks to survive reboots and process termination, making early detection of the XClient task critical for removing the implant before further tasking.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-08-31APT28 Scheduled Task Named OneDriveHealth (via process_creation)
This rule detects creation of a scheduled task named OneDriveHealth via schtasks, the transient persistence APT28 registers and later deletes to establish its foothold while masquerading as a legitimate OneDrive maintenance job. Adversaries leverage benign-sounding task names to evade review, making detection of this specific task name useful for surfacing the intrusion.
HuntRule TeamWindowsprocess_creationMedium10Premium2026-08-31Malicious Wdigest Authentication Enabled - Registry (via registry_set)
This rule detects enable Wdgiest authention so passwords are stored in clear text and can be dumped.
HuntRule TeamWindowsregistry_setHigh30Premium2026-08-31RedDelta PlugX DLL Sideloading via Legitimate Utilities Loading Planted DLLs (via image_load)
This rule detects RedDelta PlugX DLL search-order hijacking in which signed utilities such as ONENOTEM.exe, inkform.exe, and LDeviceDetectionHelper.exe load attacker-planted DLLs from outside the Windows system directories. Adversaries leverage sideloading against trusted binaries to run the PlugX loader under a legitimate process, making these host-and-module pairings a strong defense-evasion indicator.
HuntRule TeamWindowsimage_loadHigh30Premium2026-08-31ClickFix Paste-Jacking Execution of mshta Retrieving Remote Payload (via process_creation)
This rule detects mshta.exe launched from the Windows Explorer Run dialog to fetch a remote payload over HTTP, the paste-jacking or ClickFix execution pattern in which a user is tricked into pasting a clipboard-injected command. Adversaries use this to run remote HTA or XLL content and stage stealer malware, making detection of Explorer-spawned mshta with a URL a strong signal of social-engineering-driven execution.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-08-31Malicious RDP Shadow Session Configuration Enabled - Registry (via registry_event)
This rule detects would enable shadow configuratin via registry. Note that this alert does not report the created Key and that further verification on hosts will be required to confirm the behavior.
HuntRule TeamWindowsregistry_eventHigh40Premium2026-08-31IFM Creation Detected from Commandline - Installation from Media (via process_creation)
This rule detects create an IFM image (usually used for deploying domain controllers to reduce replication traffic) for dumping credentials.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-31Suspicious Lateral Movement by Mounting a Network Share - Net Use - Command (via security)
This rule detects move laterally by mounting a network share using compromised user credentials.
HuntRule TeamWindowssecurityMedium30Premium2026-08-31Malicious Impacket DCOMexec Privilege Abuse via MMC (via security)
This rule detects execute the Impacket DCOMexec tool in order to abuse DCOM services.
HuntRule TeamWindowssecurityHigh50Premium2026-08-31