Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,121 rules
In-Memory Ramnit Process Injection Target Spawned by WmiPrvSE in drIBAN Fraud Operation (via process_creation)
This rule detects the WMI provider host WmiPrvSE.exe spawning ImagingDevices.exe, Wab.exe, or Wabmig.exe, the seldom-executed signed Windows binaries that Ramnit uses as injection hosts after sLoad delivery in the drIBAN banking-fraud operation. Adversaries launch these low-noise processes from WMI to host injected banking-trojan code under a trusted image, making early detection critical for surfacing the intrusion before man-in-the-browser fraud.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-29Suspicious DLL Sideloading via NtHandleCallback Loading log.dll for Winos RAT (via image_load)
This rule detects the signed white file NtHandleCallback.exe loading a log.dll from outside trusted system directories, a DLL sideloading chain used by the SwimSnake (Silver Fox) group to decrypt and inject the Winos remote access trojan. Adversaries pair a legitimately signed executable with a malicious companion DLL to run code under a trusted process, making early detection critical for surfacing the loader before RAT injection.
HuntRule TeamWindowsimage_loadMedium60Premium2026-08-29Malicious DBatLoader DLL Sideloading via easinvoker.exe Loading netutils.dll (via image_load)
This rule detects the auto-elevating binary easinvoker.exe loading a netutils.dll from outside System32, the DLL hijacking and UAC bypass chain DBatLoader uses to run malicious code with elevated privileges. Adversaries place the legitimate signed executable alongside a rogue netutils.dll to inherit auto-elevation, making early detection critical for catching privilege escalation before injection into SndVol.exe or iexpress.exe.
HuntRule TeamWindowsimage_loadHigh70Premium2026-08-29Suspicious Timestomping of PHP Webshell in Ivanti CSA Webroot via touch (via process_creation)
This rule detects use of touch with an explicit date argument to backdate a PHP file inside the Ivanti Cloud Service Appliance LANDesk broker webroot, the timestomping behavior used by the Houken intrusion set to blend planted webshells with legitimate appliance files. Adversaries leverage timestamp manipulation to frustrate forensic triage, making this a strong signal of an attacker actively concealing webshell drops on the appliance.
HuntRule TeamLinuxprocess_creationMedium110Premium2026-08-29Malicious JSP Webshell Deployment in Ivanti EPMM Tomcat (via file_event)
This rule detects creation of JSP files under the Ivanti EPMM Tomcat mifs webapps directory, where exploitation of CVE-2026-1281 and CVE-2026-1340 plants webshells such as 401.jsp and 403.jsp. A webshell in this application path gives attackers persistent authenticated command execution on the appliance.
HuntRule TeamLinuxfile_eventHigh102Premium2026-08-28Malicious EtherRAT SSH authorized_keys Backdoor Injection via Shell (via process_creation)
This rule detects the injection of an SSH public key carrying the root@vps identifier into an authorized_keys file on Linux hosts. This activity is performed by the EtherRAT React2Shell implant to establish persistent root access over SSH. Writing an attacker controlled key into authorized_keys grants durable remote access and should be treated as a compromise.
HuntRule TeamLinuxprocess_creationHigh61Premium2026-08-28Malicious DEVMAN Ransomware Encrypted File and Note Artifacts
This rule detects files encrypted by DEVMAN ransomware, identified by the .DEVMAN extension and the deterministically renamed ransom note e47qfsnz2trbkhnt.devman. DEVMAN is a DragonForce variant that encrypts its own note, producing this fixed filename.
HuntRule TeamWindowsfile_eventHigh132Premium2026-08-28Malicious TeamPCP systemd User Unit Dropper via sysmon.py Persistence (via file_event)
This rule detects creation of a Python dropper named sysmon.py inside the per-user systemd unit directory which the TeamPCP compromise of Trivy writes on developer machines to gain persistent execution. The dropper polls an attacker C2 and downloads a follow-on payload so its presence indicates an active supply-chain implant that harvests cloud and SSH credentials.
HuntRule TeamLinuxfile_eventHigh274Premium2026-08-28DoT (DNS Over TLS) Activation - PowerShell (via powershell)
This rule detects enable DNS over TLS in order to evade detection for command and control purposes.
HuntRule TeamWindowspowershellMedium168Premium2026-08-28Malicious TeamPCP durabletask Payload python3 managed.pyz from tmp (via process_creation)
This rule detects execution of python3 against /tmp/managed.pyz which is the primary payload dropped by the trojanized durabletask PyPI releases from the TeamPCP campaign. Running a zipapp from /tmp under python3 in this exact form indicates the supply-chain implant is active and harvesting cloud and Kubernetes credentials.
HuntRule TeamLinuxprocess_creationHigh133Premium2026-08-28Suspicious DLL Load from Public Directory by svchost (via image_load)
This rule detects svchost.exe loading a DLL from the C:\Users\Public staging directory, an abnormal side-loading pattern used by the Ashen Lepus AshTag suite with modules such as netutils.dll and wtsapi32.dll. Legitimate svchost service DLLs load from System32, so a load out of a world-writable staging path indicates side-loaded malware.
HuntRule TeamWindowsimage_loadHigh71Premium2026-08-28In-Memory AMSI Bypass via amsiInitFailed Field Manipulation in PowerShell (via ps_script)
This rule detects a PowerShell script block that sets the amsiInitFailed field to True, the in-memory AMSI bypass used by the agent1.ps1 stage of an Azorult campaign smuggled through Google Sites. Forcing amsiInitFailed disables Antimalware Scan Interface inspection so later stages run unscanned, making this a high-confidence defense-evasion signal.
HuntRule TeamWindowsps_scriptHigh93Premium2026-08-28Suspicious Outbound Firewall Block Rule Added via Netsh Advfirewall
This rule detects netsh advfirewall being used to add a rule that blocks outbound traffic, a technique observed in the ESXi intrusion to sever host communication with external security or management services. Attackers block outbound connections to prevent EDR telemetry and updates from reaching the network. An added block rule targeting outbound direction on a server is an atypical administrative action worth reviewing.
HuntRule TeamWindowsprocess_creationMedium112Premium2026-08-28Suspicious CTFMON Masqueraded Binary Execution (via process_creation)
This rule detects execution of CTFM0N.exe, a filename crafted to impersonate the legitimate Windows ctfmon.exe by replacing the letter O with a zero. SugarGh0st deployed this binary as its persistent RAT component.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-08-28Suspicious Cisco ASA WebVPN Login Scanning with Spoofed Chrome User-Agent
This rule detects inbound requests to Cisco ASA web login endpoints /+CSCOE+/logon.html and /+webvpn+/index.html that carry the single spoofed browser identifier Chrome/102.0.5005.63 used across a coordinated scanning botnet. The activity mapped a surge of 25,000 IPs probing Cisco ASA devices, frequently a precursor to a newly disclosed vulnerability being weaponized for initial access.
HuntRule TeamWebwebserverMedium375Premium2026-08-28