Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,118 rules
SynkLoader Python Stager Execution from AppData via pythonw (via process_creation)
This rule detects the SynkLoader Python stager launched by pythonw.exe from a randomly named AppData subdirectory using the fl\ang\ss.py path layout observed after a Microsoft Teams phishing lure. Adversaries run the loader silently to decrypt and inject follow-on modules while evading command-line script inspection, making early detection critical for stopping module deployment before credential theft.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-08-30Malicious Command Injection via SyncAppvPublishingServer VBS LOLBin (via process_creation)
This rule detects abuse of the SyncAppvPublishingServer.vbs living-off-the-land script to inject PowerShell after a semicolon separator, the ClickFix delivery behavior ClearFake uses to launch a hidden PowerShell downloader from a clipboard-pasted Run command. Adversaries proxy execution through this signed script to evade script-host controls, making early detection critical for catching the infection at the first execution stage.
HuntRule TeamWindowsprocess_creationHigh90Premium2026-08-30FortiClient Binary Executed from LocalAppData Compliance Directory (via process_creation)
This rule detects a FortiClientCompliance.exe process running from a LocalAppData FortiClient compliance directory, an unusual user-writable location for endpoint software that in this intrusion was a renamed Greenshot binary used as a signed malware loader. Adversaries place trusted-looking binaries in AppData to masquerade legitimate software while executing sideloaded payloads, making early detection critical for catching the loader before shellcode execution.
HuntRule TeamWindowsprocess_creationHigh120Premium2026-08-30Operator Bloopers Cobalt Strike Modules
Detects use of Cobalt Strike module commands accidentally entered in the CMD shell
HuntRule TeamWindowsprocess_creationHigh70Premium2026-08-30Suspicious Cobalt Strike Loader C2 Traffic via Forged MSIE yie9 User-Agent (via proxy)
This rule detects command-and-control traffic using the forged Internet Explorer 9 user-agent carrying the yie9 token observed with the Cobalt Strike PowerShell loader across Chinese and Russian infrastructure. Adversaries leverage a spoofed legacy browser user-agent to blend beacon traffic into normal web requests.
HuntRule TeamWebproxyMedium80Premium2026-08-30Malicious Scheduled Task ForceNetbirdRestart for Remote Access Persistence (via process_creation)
This rule detects creation of a scheduled task named ForceNetbirdRestart that restarts the NetBird agent after boot, a persistence behavior used by MuddyWater to keep its remote-access tunnel available. Adversaries leverage the task to guarantee the covert NetBird channel reconnects on every reboot.
HuntRule TeamWindowsprocess_creationHigh110Premium2026-08-30TinyLoader USB Propagation via Double-Extension Executables (via file_event)
This rule detects creation of double-extension executables such as Photo.jpg.exe and Document.pdf.exe used by TinyLoader to spread across removable media. Adversaries leverage deceptive filenames that appear to be images or documents so users execute the loader from infected USB drives.
HuntRule TeamWindowsfile_eventMedium20Premium2026-08-30ESET Security Service Disabling via sc.exe (via process_creation)
This rule detects sc.exe being used to stop or disable ESET endpoint protection services such as ekrn and EraAgentSvc, a defense-evasion behavior performed by the EtherRAT deployment script before payload execution. Adversaries leverage service control to blind endpoint protection ahead of credential theft and lateral movement.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-08-30ToneShell Backdoor Persistence via dokanctl Scheduled Task (via process_creation)
This rule detects creation of the dokanctl scheduled task that the Frankenstein ToneShell variant registers to re-launch its AppData-based svchosts.exe payload every minute. The distinctive task name combined with schtasks creation reflects the backdoor installing minute-interval persistence on the host.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-08-30Suspicious Remote Utilities RuRAT Host Deployment via Fake Crypto Wallet Installer (via process_creation)
This rule detects execution of Remote Utilities host and client binaries used as a remote access backdoor after a fake cryptocurrency wallet installer campaign attributed to a suspected Russian threat actor. Adversaries deploy the legitimate Remote Utilities RMM under attacker control to gain persistent hands-on access to victim hosts, so its execution outside sanctioned administration warrants investigation.
HuntRule TeamWindowsprocess_creationMedium10Premium2026-08-30Masquerading Edge Update Masquerade Executed From AppData (via process_creation)
This rule detects a process named MicrosoftEdgeUpdateCore.exe running from a user AppData path rather than a legitimate Microsoft Edge install location, the self-copy used by the LeakyStealer payload to run under a trusted-looking name. Adversaries name their loader after Edge update binaries to evade casual inspection while injecting into Explorer and harvesting wallet and browser data.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-30Suspicious Hardware Inventory Discovery via WMIC Device Class Queries (via process_creation)
This rule detects WMIC queries against keyboard, pointing device and monitor WMI classes used by the SHUYAL stealer to fingerprint the host and detect analysis environments before stealing credentials. Adversaries enumerate attached hardware to build a victim profile and to evade sandboxes that lack real peripherals.
HuntRule TeamWindowsprocess_creationMedium30Premium2026-08-30Masquerading SSLoad PhantomLoader DLL Execution via Regsvr32 Silent Load from AppData (via process_creation)
This rule detects regsvr32.exe silently registering the MenuEx.dll PhantomLoader component that masquerades as a 360 Total Security module in the SSLoad infection chain launched from an MSI installer. Adversaries use regsvr32 as a trusted LOLBin to load the first-stage loader without a visible window, making this command pattern a strong indicator of the delivery stage.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-08-30HamsaUpdate Linux Payload Download via Wget Piped to Bash (via process_creation)
This rule detects the Operation HamsaUpdate Linux stage retrieving update.sh with wget and piping it directly into bash for immediate execution. Downloading a remote script and executing it inline without touching disk is the delivery behavior used to run the multi-layer wiper loader on Linux hosts.
HuntRule TeamLinuxprocess_creationMedium10Premium2026-08-30Masquerading PNGPlug DLL Sideloading of libcef Into down.exe Host Binary (via image_load)
This rule detects the down.exe host binary loading a libcef.dll from the PNGPlug delivery archive, a DLL sideloading step that decrypts and injects the ValleyRAT payload hidden inside PNG-masqueraded files. Pairing this common legitimate application name with the CEF library load surfaces the sideloading behavior at the point of second-stage execution.
HuntRule TeamWindowsimage_loadMedium10Premium2026-08-30