Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
Malicious RDP Tunneling (via rdp)
This rule detects uses RDP tunneling to redirect traffic to a C&C target.
HuntRule TeamWindowsrdpHigh40Premium2026-08-31Malicious Service Permissions Hijacked for Privileges Abuse - Reg via PowerShell (via powershell)
This rule detects modify the permissions of a service using native PowerShell commands in order to abuse its privileges. Note that it requires PowerShell 7 or higher.
HuntRule TeamWindowspowershellHigh30Premium2026-08-31Malicious Windows Native Backup Deletion (via process_creation)
This rule detects delete existing Windows native backup (only available on Windows Server).
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Malicious Credentials (protected by DPAPI) Dump via Network Share (via security)
This rule detects attempt to dump DPAPI credentials (Windows Vault, Chrome, RDP, WiFi, Emails, ...) or registry hives via network share via tools like DonPAPI.
HuntRule TeamWindowssecurityHigh30Premium2026-08-30Malicious Stickey Key IFEO Registry Changed - Reg via Sysmon (via registry_event)
This rule detects changed the IFEO settings related to sethc.
HuntRule TeamWindowsregistry_eventHigh50Premium2026-08-30Malicious Mimispool Printer Driver Installation - PrintNightmare Vulnerability - CVE-2021-36958 (via printservice)
This rule detects help to detect scenarios where an attacker exploit the Mimispool print driver to escalate privileges.
HuntRule TeamWindowsprintserviceHigh70Premium2026-08-30Malicious Kerberos TGS Ticket Request Related to a Potential Golden Ticket (via security)
This rule detects request a potential Golden ticket. Findings returned by this rule may not confirm at 100% that a Golden ticket was generated and further investigations would be required to confirm it. Another indicator (in case of a lazy Golden ticket) to check would be to check if the TargetUserName refers to an existing user in the domain.
HuntRule TeamWindowssecurityHigh90Premium2026-08-30Malicious Command Injection via SyncAppvPublishingServer VBS LOLBin (via process_creation)
This rule detects abuse of the SyncAppvPublishingServer.vbs living-off-the-land script to inject PowerShell after a semicolon separator, the ClickFix delivery behavior ClearFake uses to launch a hidden PowerShell downloader from a clipboard-pasted Run command. Adversaries proxy execution through this signed script to evade script-host controls, making early detection critical for catching the infection at the first execution stage.
HuntRule TeamWindowsprocess_creationHigh110Premium2026-08-30FortiClient Binary Executed from LocalAppData Compliance Directory (via process_creation)
This rule detects a FortiClientCompliance.exe process running from a LocalAppData FortiClient compliance directory, an unusual user-writable location for endpoint software that in this intrusion was a renamed Greenshot binary used as a signed malware loader. Adversaries place trusted-looking binaries in AppData to masquerade legitimate software while executing sideloaded payloads, making early detection critical for catching the loader before shellcode execution.
HuntRule TeamWindowsprocess_creationHigh120Premium2026-08-30Operator Bloopers Cobalt Strike Modules
Detects use of Cobalt Strike module commands accidentally entered in the CMD shell
HuntRule TeamWindowsprocess_creationHigh90Premium2026-08-30Malicious Scheduled Task ForceNetbirdRestart for Remote Access Persistence (via process_creation)
This rule detects creation of a scheduled task named ForceNetbirdRestart that restarts the NetBird agent after boot, a persistence behavior used by MuddyWater to keep its remote-access tunnel available. Adversaries leverage the task to guarantee the covert NetBird channel reconnects on every reboot.
HuntRule TeamWindowsprocess_creationHigh110Premium2026-08-30ESET Security Service Disabling via sc.exe (via process_creation)
This rule detects sc.exe being used to stop or disable ESET endpoint protection services such as ekrn and EraAgentSvc, a defense-evasion behavior performed by the EtherRAT deployment script before payload execution. Adversaries leverage service control to blind endpoint protection ahead of credential theft and lateral movement.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-08-30ToneShell Backdoor Persistence via dokanctl Scheduled Task (via process_creation)
This rule detects creation of the dokanctl scheduled task that the Frankenstein ToneShell variant registers to re-launch its AppData-based svchosts.exe payload every minute. The distinctive task name combined with schtasks creation reflects the backdoor installing minute-interval persistence on the host.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-30Masquerading Edge Update Masquerade Executed From AppData (via process_creation)
This rule detects a process named MicrosoftEdgeUpdateCore.exe running from a user AppData path rather than a legitimate Microsoft Edge install location, the self-copy used by the LeakyStealer payload to run under a trusted-looking name. Adversaries name their loader after Edge update binaries to evade casual inspection while injecting into Explorer and harvesting wallet and browser data.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-30Masquerading SSLoad PhantomLoader DLL Execution via Regsvr32 Silent Load from AppData (via process_creation)
This rule detects regsvr32.exe silently registering the MenuEx.dll PhantomLoader component that masquerades as a 360 Total Security module in the SSLoad infection chain launched from an MSI installer. Adversaries use regsvr32 as a trusted LOLBin to load the first-stage loader without a visible window, making this command pattern a strong indicator of the delivery stage.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-08-30