Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
NailaoLoader DLL Sideloading via usysdiag.exe Loading sensapi.dll (via image_load)
This rule detects the signed Huorong binary usysdiag.exe loading a sensapi.dll from outside the Windows system directories, the DLL side-loading behavior used to launch NailaoLoader and decrypt the NailaoLocker ransomware in intrusions following CVE-2024-24919 exploitation of Check Point gateways. Adversaries abuse a trusted signed binary to run the loader under a legitimate process while evading detection.
HuntRule TeamWindowsimage_loadHigh70Premium2026-09-01Obfuscated IIS Worker Spawning Encoded PowerShell after SharePoint ToolShell (via process_creation)
This rule detects the IIS worker process w3wp.exe spawning a command shell or PowerShell with a Base64-encoded command, the post-exploitation behavior observed after SharePoint ToolShell exploitation of CVE-2025-53770. Adversaries run encoded PowerShell from the web server context to install webshells and stage further tooling.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-01TerraStealerV2 Data Staging in Bay0NsQIzx Package Directory (via file_event)
This rule detects TerraStealerV2 staging collected browser and wallet data inside the hardcoded Bay0NsQIzx package directory under LocalAppData before archiving it for exfiltration. Adversaries leverage a fixed staging folder to consolidate stolen artifacts, making file writes into this named directory a high-confidence collection indicator.
HuntRule TeamWindowsfile_eventHigh40Premium2026-09-01Malicious XWorm Persistence via Minute-Interval Scheduled Task Named XClient (via process_creation)
This rule detects creation of a highly privileged scheduled task named XClient that runs every minute, the persistence mechanism used by recent XWorm infection chains to relaunch the RAT payload continuously. Adversaries leverage minute-interval tasks to survive reboots and process termination, making early detection of the XClient task critical for removing the implant before further tasking.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-08-31Malicious Wdigest Authentication Enabled - Registry (via registry_set)
This rule detects enable Wdgiest authention so passwords are stored in clear text and can be dumped.
HuntRule TeamWindowsregistry_setHigh30Premium2026-08-31RedDelta PlugX DLL Sideloading via Legitimate Utilities Loading Planted DLLs (via image_load)
This rule detects RedDelta PlugX DLL search-order hijacking in which signed utilities such as ONENOTEM.exe, inkform.exe, and LDeviceDetectionHelper.exe load attacker-planted DLLs from outside the Windows system directories. Adversaries leverage sideloading against trusted binaries to run the PlugX loader under a legitimate process, making these host-and-module pairings a strong defense-evasion indicator.
HuntRule TeamWindowsimage_loadHigh30Premium2026-08-31ClickFix Paste-Jacking Execution of mshta Retrieving Remote Payload (via process_creation)
This rule detects mshta.exe launched from the Windows Explorer Run dialog to fetch a remote payload over HTTP, the paste-jacking or ClickFix execution pattern in which a user is tricked into pasting a clipboard-injected command. Adversaries use this to run remote HTA or XLL content and stage stealer malware, making detection of Explorer-spawned mshta with a URL a strong signal of social-engineering-driven execution.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-31Malicious RDP Shadow Session Configuration Enabled - Registry (via registry_event)
This rule detects would enable shadow configuratin via registry. Note that this alert does not report the created Key and that further verification on hosts will be required to confirm the behavior.
HuntRule TeamWindowsregistry_eventHigh50Premium2026-08-31IFM Creation Detected from Commandline - Installation from Media (via process_creation)
This rule detects create an IFM image (usually used for deploying domain controllers to reduce replication traffic) for dumping credentials.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Malicious Impacket DCOMexec Privilege Abuse via MMC (via security)
This rule detects execute the Impacket DCOMexec tool in order to abuse DCOM services.
HuntRule TeamWindowssecurityHigh60Premium2026-08-31Obfuscated Encoded PowerShell Payload Deployed via Process Execution (via process_creation)
This rule detects deployed an encoded PowerShell payload via a process execution. Some parameters are commented in case you would like to reduce false positives or make the rule more precise.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Malicious WMI Spwaning PowerShell Process - WMImplant (via process_creation)
This rule detects wMIimplant.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Obfuscated Encoded PowerShell Payload Deployed - PowerShell (via powershell)
This rule detects deployed a service pointing to a hidden and encoded PowerShell payload.
HuntRule TeamWindowspowershellHigh50Premium2026-08-31Malicious Scheduled Task Created and Deleted Fastly - ATexec.py (via security)
This rule detects abuse task scheduler capacities to execute commands or elevate privileges.
HuntRule TeamWindowssecurityHigh30Premium2026-08-31Malicious Event Log Cleared Using Diagnostics - Via PowerShell (via powershell)
This rule detects clear the event logs.
HuntRule TeamWindowspowershellHigh60Premium2026-08-31