Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,120 rules
SplashTop Network
Detects use of SplashTop
HuntRule TeamWindowsdns_queryHigh60Premium2026-08-30JavaScript Execution Using MSDOS 8.3 File Notation
Detects script execution using MSDOS 8.3 File names
HuntRule TeamWindowsprocess_creationMedium50Premium2026-08-30FlawedGrace spawning threat injection target
Detecting the command FlawedGrace is using for the purpose of injecting into it the spawned process, in this case the cmd.exe process.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-30Hiding local user accounts
Detects the use reg.exe to hide users from listed in the logon screen. This is possible by changing the registry key value to 0 for a specific user.
HuntRule TeamWindowsprocess_creationMedium50Premium2026-08-30Custom Cobalt Strike Command Execution
Detects the execution of a specific OneLiner to Invoke PowerShell commands.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-30Suspicious Khmer Shadow Scheduled Task VMwareNamespace Creation (via process_creation)
This rule detects creation of the VMwareNamespace scheduled task with a ten-minute repeat that maintains execution of the Khmer Shadow loader against Cambodian targets. Adversaries register this task to relaunch the sideloaded VMware binary from the local AppData persistence directory. The task name paired with the ten-minute interval is a distinctive persistence marker.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-08-30SparkRAT Scheduled Task TaskHandler Running as SYSTEM from C Drivers (via process_creation)
This rule detects schtasks creating the TaskHandler task set to run at startup as SYSTEM with highest privileges from the C Drivers directory in the Cambodia-focused SparkRAT chain. Adversaries register a SYSTEM-level onstart task to relaunch their sideloading host under maximum privilege. The task name combined with the SYSTEM run context and C Drivers path is distinctive.
HuntRule TeamWindowsprocess_creationMedium60Premium2026-08-30FileFix Browser Spawning Script Interpreter Child Process (via process_creation)
This rule detects a web browser spawning PowerShell, cmd, mshta or wscript, the highest-fidelity signal of the FileFix social-engineering attack that tricks users into pasting a command into the File Explorer address bar. Adversaries deliver a fragmented PowerShell one-liner through a fake upload dialog that then pulls a steganographic payload. Browsers do not normally launch script interpreters as children.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-30Untrusted Makop Ransomware Vulnerable Driver hlpdrv Drop for EDR Kill (via file_event)
This rule detects the Makop intrusion set dropping the hlpdrv vulnerable driver used to terminate endpoint protection at the kernel level before encryption. Adversaries deploy this abusable driver to disable defenses through bring-your-own-vulnerable-driver. Appearance of this specific driver filename on disk indicates staging for defense evasion.
HuntRule TeamWindowsfile_eventMedium90Premium2026-08-30INC Ransomware Ransom Note INC-README Written to Disk (via file_event)
This rule detects the INC ransomware dropping its INC-README ransom note across directories during encryption in the ransomware-as-a-service operation tracked by Acronis. Adversaries write the note to every touched folder alongside appending the .INC extension to encrypted files. The fixed note filename is a strong post-impact detection anchor.
HuntRule TeamWindowsfile_eventHigh70Premium2026-08-30PureHVNC Process Hollowing into RegAsm Spawned by PowerShell (via process_creation)
This rule detects RegAsm being spawned by PowerShell, the process-hollowing target used to run the PureHVNC RAT after a trojanized ScreenConnect installer downloads NvContainerRecovery.ps1. Adversaries inject PureHVNC into the .NET RegAsm host to hide under a trusted binary. RegAsm launched from PowerShell rather than build tooling is highly anomalous.
HuntRule TeamWindowsprocess_creationMedium70Premium2026-08-29Uncommon Browser Launched with Remote Debugging Port for Cookie Theft (via process_creation)
This rule detects a Chromium-based browser started with a remote debugging port flag, the technique Electron-based gaming stealers use to attach to the browser and dump cookies directly from a debugged instance. Adversaries launch the browser in debug mode to bypass cookie encryption and harvest session tokens. Debug-mode browser launches are rare outside developer tooling.
HuntRule TeamWindowsprocess_creationMedium120Premium2026-08-29Suspicious Shadow Vector Persistence via Schtasks OnLogon Highest from AppData (via process_creation)
This rule detects schtasks creating an onlogon task at highest run level pointing at an executable in AppData Roaming, the persistence used by the Shadow Vector campaign delivering AsyncRAT through court-themed SVG decoys to Colombian users. Adversaries register a high-privilege logon task that relaunches their payload from a user-writable path. An onlogon highest task targeting Roaming is a strong persistence indicator.
HuntRule TeamWindowsprocess_creationMedium90Premium2026-08-29PATCHCORD Beacon C2 Tasking via api.jsp clientId Poll (via proxy)
This rule detects the PATCHCORD implant polling its command channel with the hardcoded Beacon user-agent and the api.jsp clientId tasking URI observed in the Afghan telecom intrusion set. Adversaries use this fixed user-agent and endpoint to fetch operator commands over HTTP. The distinctive agent string and URI make this beacon reliably separable from normal web traffic.
HuntRule TeamWebproxyHigh70Premium2026-08-29In-Memory Ramnit Process Injection Target Spawned by WmiPrvSE in drIBAN Fraud Operation (via process_creation)
This rule detects the WMI provider host WmiPrvSE.exe spawning ImagingDevices.exe, Wab.exe, or Wabmig.exe, the seldom-executed signed Windows binaries that Ramnit uses as injection hosts after sLoad delivery in the drIBAN banking-fraud operation. Adversaries launch these low-noise processes from WMI to host injected banking-trojan code under a trusted image, making early detection critical for surfacing the intrusion before man-in-the-browser fraud.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-29