Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
94 rules
Untrusted Makop Ransomware Vulnerable Driver hlpdrv Drop for EDR Kill (via file_event)
This rule detects the Makop intrusion set dropping the hlpdrv vulnerable driver used to terminate endpoint protection at the kernel level before encryption. Adversaries deploy this abusable driver to disable defenses through bring-your-own-vulnerable-driver. Appearance of this specific driver filename on disk indicates staging for defense evasion.
HuntRule TeamWindowsfile_eventMedium90Premium2026-08-30INC Ransomware Ransom Note INC-README Written to Disk (via file_event)
This rule detects the INC ransomware dropping its INC-README ransom note across directories during encryption in the ransomware-as-a-service operation tracked by Acronis. Adversaries write the note to every touched folder alongside appending the .INC extension to encrypted files. The fixed note filename is a strong post-impact detection anchor.
HuntRule TeamWindowsfile_eventHigh70Premium2026-08-30Malicious DEVMAN Ransomware Encrypted File and Note Artifacts
This rule detects files encrypted by DEVMAN ransomware, identified by the .DEVMAN extension and the deterministically renamed ransom note e47qfsnz2trbkhnt.devman. DEVMAN is a DragonForce variant that encrypts its own note, producing this fixed filename.
HuntRule TeamWindowsfile_eventHigh152Premium2026-08-28Malicious Akira Ransomware Encrypted File Extension via File Event
This rule detects files being renamed with the .akira extension appended during encryption by Akira ransomware. Mass creation of .akira files indicates active encryption of the host.
HuntRule TeamWindowsfile_eventHigh72Premium2026-08-27Malicious BitLocker Abuse for Ransomware via PowerShell (via ps_script)
This rule detects PowerShell that enables BitLocker while removing the key protectors which the ShrinkLocker ransomware does to encrypt drives and lock out the legitimate owner without leaving a recovery key.
HuntRule TeamWindowsps_scriptMedium143Premium2026-08-26Malicious WeaXor Ransomware Encryption Artifacts on Disk (via file_event)
This rule detects file system artifacts left by WeaXor ransomware, namely files renamed with the wex extension and the dropped RECOVERY INFO note. It indicates active encryption on the host.
HuntRule TeamWindowsfile_eventHigh153Premium2026-08-25Malicious Akira Ransomware Execution via Encryption Command-Line Parameters
This rule detects process execution using the distinctive encryption command-line parameters of the Akira ransomware encryptor, matching intrusions where a renamed akira.exe is run against mounted network shares. The switches control encryption scope and percentage across targeted paths and shares. Detecting these parameters catches the encryptor even when the binary is renamed to evade name-based controls.
HuntRule TeamWindowsprocess_creationHigh101Premium2026-08-23Malicious Windows Defender Disabling via DC.exe Defender Control by Elpaco Ransomware
This rule detects execution of the Defender Control utility (DC.exe) with a disable switch to turn off Windows Defender. This behavior is used by the Elpaco ransomware, a Mimic variant, to blind endpoint protection before encryption. Disabling defenses removes the primary barrier to file encryption and lateral movement, making early detection critical.
HuntRule TeamWindowsprocess_creationHigh447Premium2026-08-23Malicious DeadLock Ransomware Encrypted File Extension Creation (via file_event)
This rule detects creation of files carrying the .dlock extension appended by the DeadLock ransomware encryptor as reported by Group-IB. Adversaries rename encrypted files with this extension during impact, so these writes indicate active DeadLock encryption on the host.
HuntRule TeamWindowsfile_eventHigh143Premium2026-08-23Malicious DeadBolt Ransomware Note and Encrypted File Artifacts
This rule detects the creation of the DeadBolt ransom note or files bearing the .deadbolt extension which mark encrypted data on compromised QNAP network attached storage devices. The note and extension appear as the ransomware finishes encrypting shares. It is important because their presence confirms an active DeadBolt impact event requiring immediate response.
HuntRule TeamLinuxfile_eventHigh61Premium2026-08-23DragonForce Ransomware File Association Registration for Encrypted Extension (via registry_set)
This rule detects registration of a DefaultIcon association for the .dragonforce_encrypted file extension, an impact behavior DragonForce ransomware performs so all encrypted files display an attacker-supplied icon dropped under the public profile. Registering an icon for a novel encrypted extension is a strong post-encryption indicator, making detection useful for scoping ransomware impact across a host.
HuntRule TeamWindowsregistry_setHigh82Premium2026-08-22Malicious DragonForce Ransomware Encrypted File Extension (via file_event)
This rule detects creation of files bearing the .dragonforce_encrypted extension written by the DragonForce ransomware payload during mass file encryption. Presence of this extension confirms active data-encryption impact on the host. Rapid detection enables containment before encryption spreads across shares.
HuntRule TeamWindowsfile_eventHigh237Premium2026-08-22Suspicious Fog Ransomware File Artifacts (via file_event)
This rule detects creation of the Fog ransomware DbgLog.sys operational log or files bearing the .fog and .flocked encrypted extensions. These artifacts are dropped during Fog ransomware encryption on compromised hosts.
HuntRule TeamWindowsfile_eventHigh239Premium2026-08-21Malicious regsvcs LOLBin Loading Ransomware DLL from UNC Path
This rule detects the regsvcs.exe living-off-the-land binary being used to load and install a DLL from a UNC network path, matching SafePay ransomware deployment via regsvcs proxy execution. Attackers abuse regsvcs to run their encryptor DLL while bypassing application controls. Loading a DLL over UNC through regsvcs is not a legitimate developer workflow.
HuntRule TeamWindowsprocess_creationHigh165Premium2026-08-20Malicious Lynx Ransomware Encrypted File Extension Creation (via file_event)
This rule detects creation of files carrying the .LYNX extension appended by the Lynx ransomware encryptor as reported by Group-IB. Adversaries rename encrypted files with this extension during impact, so a burst of these writes indicates active ransomware encryption on the host.
HuntRule TeamWindowsfile_eventHigh153Premium2026-08-19