Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,116 rules
Malicious Microsoft Defender Critical Security Components Disabled - PowerShell (via powershell)
This rule detects disable Defender security features in PowerShell.
HuntRule TeamWindowspowershellHigh80Premium2026-08-31Malicious Rubeus Kerberos Constrained Delegation Abuse - S4U2Proxy (via security)
This rule detects abuse Kerberos constrained delegation in order to escalate privileges.
HuntRule TeamWindowssecurityHigh50Premium2026-08-31Renamed Procdump Tool Used for Dumping LSASS Process (via process_creation)
This rule detects dump the LSASS process content using a renamed version of the Procdump tool.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Malicious Impacket SMBexec Service Creation - Registry (via registry_event)
This rule detects register the SMBexec service to estasblish persistence.
HuntRule TeamWindowsregistry_eventHigh00Premium2026-08-31Malicious User Creation via Commandline (via process_creation)
This rule detects create a user via commandline.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-08-31Malicious Network Share Discovery And/or Connection via Commandline (via process_creation)
This rule detects enumerate or to establish a connection to a network share.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-31Malicious RDP Tunneling (via rdp)
This rule detects uses RDP tunneling to redirect traffic to a C&C target.
HuntRule TeamWindowsrdpHigh30Premium2026-08-31Malicious Service Permissions Hijacked for Privileges Abuse - Reg via PowerShell (via powershell)
This rule detects modify the permissions of a service using native PowerShell commands in order to abuse its privileges. Note that it requires PowerShell 7 or higher.
HuntRule TeamWindowspowershellHigh30Premium2026-08-31Malicious Windows Native Backup Deletion (via process_creation)
This rule detects delete existing Windows native backup (only available on Windows Server).
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-31Malicious Credentials (protected by DPAPI) Dump via Network Share (via security)
This rule detects attempt to dump DPAPI credentials (Windows Vault, Chrome, RDP, WiFi, Emails, ...) or registry hives via network share via tools like DonPAPI.
HuntRule TeamWindowssecurityHigh20Premium2026-08-30Malicious Stickey Key IFEO Registry Changed - Reg via Sysmon (via registry_event)
This rule detects changed the IFEO settings related to sethc.
HuntRule TeamWindowsregistry_eventHigh50Premium2026-08-30Malicious Mimispool Printer Driver Installation - PrintNightmare Vulnerability - CVE-2021-36958 (via printservice)
This rule detects help to detect scenarios where an attacker exploit the Mimispool print driver to escalate privileges.
HuntRule TeamWindowsprintserviceHigh60Premium2026-08-30Malicious Kerberos TGS Ticket Request Related to a Potential Golden Ticket (via security)
This rule detects request a potential Golden ticket. Findings returned by this rule may not confirm at 100% that a Golden ticket was generated and further investigations would be required to confirm it. Another indicator (in case of a lazy Golden ticket) to check would be to check if the TargetUserName refers to an existing user in the domain.
HuntRule TeamWindowssecurityHigh80Premium2026-08-30SynkLoader Python Stager Execution from AppData via pythonw (via process_creation)
This rule detects the SynkLoader Python stager launched by pythonw.exe from a randomly named AppData subdirectory using the fl\ang\ss.py path layout observed after a Microsoft Teams phishing lure. Adversaries run the loader silently to decrypt and inject follow-on modules while evading command-line script inspection, making early detection critical for stopping module deployment before credential theft.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-08-30Malicious Command Injection via SyncAppvPublishingServer VBS LOLBin (via process_creation)
This rule detects abuse of the SyncAppvPublishingServer.vbs living-off-the-land script to inject PowerShell after a semicolon separator, the ClickFix delivery behavior ClearFake uses to launch a hidden PowerShell downloader from a clipboard-pasted Run command. Adversaries proxy execution through this signed script to evade script-host controls, making early detection critical for catching the infection at the first execution stage.
HuntRule TeamWindowsprocess_creationHigh90Premium2026-08-30