Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,120 rules
HamsaUpdate Linux Payload Download via Wget Piped to Bash (via process_creation)
This rule detects the Operation HamsaUpdate Linux stage retrieving update.sh with wget and piping it directly into bash for immediate execution. Downloading a remote script and executing it inline without touching disk is the delivery behavior used to run the multi-layer wiper loader on Linux hosts.
HuntRule TeamLinuxprocess_creationMedium10Premium2026-08-30Masquerading PNGPlug DLL Sideloading of libcef Into down.exe Host Binary (via image_load)
This rule detects the down.exe host binary loading a libcef.dll from the PNGPlug delivery archive, a DLL sideloading step that decrypts and injects the ValleyRAT payload hidden inside PNG-masqueraded files. Pairing this common legitimate application name with the CEF library load surfaces the sideloading behavior at the point of second-stage execution.
HuntRule TeamWindowsimage_loadMedium10Premium2026-08-30IMEEX Framework DLL Execution via Rundll32 Loading imaadp (via process_creation)
This rule detects rundll32.exe loading the imaadp.dll module used by the IMEEX framework to run its 64-bit backdoor while masquerading under a trusted host process. Invocation of this specific module name through rundll32 indicates the implant executing on the host.
HuntRule TeamWindowsprocess_creationMedium00Premium2026-08-30System Time Lookup
Detects use of time to look up the system time as part of host discovery
HuntRule TeamWindowsprocess_creationHigh30Premium2026-08-30Malicious Kimsuky AlphaSeed Payload Execution via Regsvr32 Loading edge dat (via process_creation)
This rule detects regsvr32 silently loading a .dat payload from the hidden .edge directory in the user profile, the proxy-execution behavior Kimsuky AlphaSeed uses to run its powermgmt.dat backdoor DLL. Regsvr32 registering a data-extension file from a hidden per-user folder is a strong signed-binary-proxy execution indicator for this loader.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-30DragonForce Ransomware Volume Shadow Copy Deletion via WMIC ShadowCopy Where Delete (via process_creation)
This rule detects abuse of WMIC to enumerate and delete a specific volume shadow copy by ID, the inhibit-recovery behavior DragonForce ransomware performs through cmd.exe before file encryption. Adversaries delete shadow copies so victims cannot restore encrypted files, making early detection critical for interrupting the intrusion before data becomes unrecoverable.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-30Renamed Mimikatz Credential Theft Command Indicators (via process_creation)
This rule detects command lines containing Mimikatz module and function names such as sekurlsa::logonpasswords, lsadump::sam or kerberos::golden, which reveal use of the credential-theft toolkit regardless of the executable's filename. Mimikatz is one of the most common credential-access tools in the Red Canary Threat Detection Report, harvesting plaintext passwords, hashes and Kerberos tickets to enable lateral movement and privilege escalation. Detecting its distinctive module syntax surfaces the tool even when it has been renamed or embedded in scripts.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-30GateDoor Command-and-Control via gateway REST Endpoints (via proxy)
This rule detects outbound HTTP requests to the Django REST command-and-control endpoints used by GateDoor and RustDoor, including gateway register, gateway report and gateway future_task for device registration and command polling. Matching these fixed URI paths in proxy logs can reveal an infected host beaconing to the backdoor infrastructure.
HuntRule TeamWebproxyMedium50Premium2026-08-30Uncommon Executable Written to Startup Folder by WinRAR via CVE-2025-8088 Path Traversal (via file_event)
This rule detects WinRAR writing an executable into the user Startup folder, the persistence outcome of the CVE-2025-8088 alternate-data-stream path-traversal flaw abused in the Paper Werewolf campaign to auto-run its payload at logon. A decompression tool dropping a binary into a logon-autostart location is highly abnormal and indicates exploitation of the extractor.
HuntRule TeamWindowsfile_eventHigh80Premium2026-08-30Suspicious Local Account Creation and Privileged Group Addition via Net.EXE (via process_creation)
This rule detects creation of a local user account or addition of an account to a privileged local group through net.exe or net1.exe. Account manipulation for persistence and privilege escalation features in the Red Canary Threat Detection Report, letting adversaries establish durable, legitimate-looking access. Detecting local account and administrators-group changes at the command line surfaces backdoor-account activity.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-08-30Malicious Accessibility Feature Backdoor via Image File Execution Options Debugger (via registry_set)
This rule detects a Debugger value being set on an accessibility binary (sethc.exe, utilman.exe, osk.exe, magnify.exe, narrator.exe or displayswitch.exe) under Image File Execution Options, which lets an attacker launch a command shell from the logon screen without credentials. This accessibility-feature hijack is a persistence and privilege-escalation technique tracked in the Red Canary Threat Detection Report. Detecting the registry modification catches the backdoor before it is triggered at the lock screen.
HuntRule TeamWindowsregistry_setHigh30Premium2026-08-30Malicious alexantr File Manager Webshell Access after CraftCMS Compromise (via webserver)
This rule detects requests to a filemanager.php webshell with its upload and delete parameters, the open-source alexantr file manager dropped to the web root following CraftCMS CVE-2025-32432 exploitation. Adversaries use this webshell to browse, upload and remove files on the compromised server for hands-on-keyboard actions.
HuntRule TeamWebwebserverHigh50Premium2026-08-30Suspicious VERSION.dll Proxy Sideloading from User AppData Directory (via image_load)
This rule detects the Windows library VERSION.dll being loaded from a user AppData location rather than the system directories, the DLL proxying step of the browser cache smuggling technique that hijacks Microsoft Teams or OneDrive startup to run a beacon. Adversaries place a proxy VERSION.dll beside a trusted application so it loads ahead of the genuine system copy.
HuntRule TeamWindowsimage_loadMedium40Premium2026-08-30SilentMare Updater Execution from User AppData Directory (via process_creation)
This rule detects execution of the SilentMare updater binaries dropped into per-user AppData product folders by fake file-conversion and archive utilities delivered through malicious search ads. These updaters run on scheduled-task intervals to contact C2 and fetch in-memory .NET payloads, so their launch from a user profile directory is an early sign of the loader operating on the host.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-08-30Rclone SMB Share Exfiltration
Detection of a exfiltration activity using rclone from Windows network shares using SMB.
HuntRule TeamZeeksmb_filesMedium40Premium2026-08-30