Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
System Time Lookup
Detects use of time to look up the system time as part of host discovery
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-30Malicious Kimsuky AlphaSeed Payload Execution via Regsvr32 Loading edge dat (via process_creation)
This rule detects regsvr32 silently loading a .dat payload from the hidden .edge directory in the user profile, the proxy-execution behavior Kimsuky AlphaSeed uses to run its powermgmt.dat backdoor DLL. Regsvr32 registering a data-extension file from a hidden per-user folder is a strong signed-binary-proxy execution indicator for this loader.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-30DragonForce Ransomware Volume Shadow Copy Deletion via WMIC ShadowCopy Where Delete (via process_creation)
This rule detects abuse of WMIC to enumerate and delete a specific volume shadow copy by ID, the inhibit-recovery behavior DragonForce ransomware performs through cmd.exe before file encryption. Adversaries delete shadow copies so victims cannot restore encrypted files, making early detection critical for interrupting the intrusion before data becomes unrecoverable.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-30Renamed Mimikatz Credential Theft Command Indicators (via process_creation)
This rule detects command lines containing Mimikatz module and function names such as sekurlsa::logonpasswords, lsadump::sam or kerberos::golden, which reveal use of the credential-theft toolkit regardless of the executable's filename. Mimikatz is one of the most common credential-access tools in the Red Canary Threat Detection Report, harvesting plaintext passwords, hashes and Kerberos tickets to enable lateral movement and privilege escalation. Detecting its distinctive module syntax surfaces the tool even when it has been renamed or embedded in scripts.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-30Uncommon Executable Written to Startup Folder by WinRAR via CVE-2025-8088 Path Traversal (via file_event)
This rule detects WinRAR writing an executable into the user Startup folder, the persistence outcome of the CVE-2025-8088 alternate-data-stream path-traversal flaw abused in the Paper Werewolf campaign to auto-run its payload at logon. A decompression tool dropping a binary into a logon-autostart location is highly abnormal and indicates exploitation of the extractor.
HuntRule TeamWindowsfile_eventHigh80Premium2026-08-30Malicious Accessibility Feature Backdoor via Image File Execution Options Debugger (via registry_set)
This rule detects a Debugger value being set on an accessibility binary (sethc.exe, utilman.exe, osk.exe, magnify.exe, narrator.exe or displayswitch.exe) under Image File Execution Options, which lets an attacker launch a command shell from the logon screen without credentials. This accessibility-feature hijack is a persistence and privilege-escalation technique tracked in the Red Canary Threat Detection Report. Detecting the registry modification catches the backdoor before it is triggered at the lock screen.
HuntRule TeamWindowsregistry_setHigh30Premium2026-08-30Malicious alexantr File Manager Webshell Access after CraftCMS Compromise (via webserver)
This rule detects requests to a filemanager.php webshell with its upload and delete parameters, the open-source alexantr file manager dropped to the web root following CraftCMS CVE-2025-32432 exploitation. Adversaries use this webshell to browse, upload and remove files on the compromised server for hands-on-keyboard actions.
HuntRule TeamWebwebserverHigh80Premium2026-08-30SplashTop Network
Detects use of SplashTop
HuntRule TeamWindowsdns_queryHigh60Premium2026-08-30FlawedGrace spawning threat injection target
Detecting the command FlawedGrace is using for the purpose of injecting into it the spawned process, in this case the cmd.exe process.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-30Custom Cobalt Strike Command Execution
Detects the execution of a specific OneLiner to Invoke PowerShell commands.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-30FileFix Browser Spawning Script Interpreter Child Process (via process_creation)
This rule detects a web browser spawning PowerShell, cmd, mshta or wscript, the highest-fidelity signal of the FileFix social-engineering attack that tricks users into pasting a command into the File Explorer address bar. Adversaries deliver a fragmented PowerShell one-liner through a fake upload dialog that then pulls a steganographic payload. Browsers do not normally launch script interpreters as children.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-30INC Ransomware Ransom Note INC-README Written to Disk (via file_event)
This rule detects the INC ransomware dropping its INC-README ransom note across directories during encryption in the ransomware-as-a-service operation tracked by Acronis. Adversaries write the note to every touched folder alongside appending the .INC extension to encrypted files. The fixed note filename is a strong post-impact detection anchor.
HuntRule TeamWindowsfile_eventHigh70Premium2026-08-30PATCHCORD Beacon C2 Tasking via api.jsp clientId Poll (via proxy)
This rule detects the PATCHCORD implant polling its command channel with the hardcoded Beacon user-agent and the api.jsp clientId tasking URI observed in the Afghan telecom intrusion set. Adversaries use this fixed user-agent and endpoint to fetch operator commands over HTTP. The distinctive agent string and URI make this beacon reliably separable from normal web traffic.
HuntRule TeamWebproxyHigh80Premium2026-08-29In-Memory Ramnit Process Injection Target Spawned by WmiPrvSE in drIBAN Fraud Operation (via process_creation)
This rule detects the WMI provider host WmiPrvSE.exe spawning ImagingDevices.exe, Wab.exe, or Wabmig.exe, the seldom-executed signed Windows binaries that Ramnit uses as injection hosts after sLoad delivery in the drIBAN banking-fraud operation. Adversaries launch these low-noise processes from WMI to host injected banking-trojan code under a trusted image, making early detection critical for surfacing the intrusion before man-in-the-browser fraud.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-29Malicious DBatLoader DLL Sideloading via easinvoker.exe Loading netutils.dll (via image_load)
This rule detects the auto-elevating binary easinvoker.exe loading a netutils.dll from outside System32, the DLL hijacking and UAC bypass chain DBatLoader uses to run malicious code with elevated privileges. Adversaries place the legitimate signed executable alongside a rogue netutils.dll to inherit auto-elevation, making early detection critical for catching privilege escalation before injection into SndVol.exe or iexpress.exe.
HuntRule TeamWindowsimage_loadHigh80Premium2026-08-29