Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,296 rules
Malicious PPL Abuse via ClipUp Protected Process Launch
This rule detects the ClipUp.exe utility launched with a protected process light argument, the technique RONINGLOADER uses to spawn a signed binary as a PPL and disable Microsoft Defender. Abusing ClipUp to obtain a protected process lets the loader tamper with security services that normally block it.
HuntRule TeamWindowsprocess_creationHigh92Premium2026-08-25Suspicious Host.exe In Windows Directory Running As Service
This rule detects execution of host.exe from the Windows directory with a service-style command line switch. BlackByte ransomware operators deployed C:\Windows\host.exe run with an -s flag and an eight-digit token to register itself as a service. A generically named binary placed in the Windows root and launched as a service is a masquerading and persistence pattern used to blend malicious execution into the OS.
HuntRule TeamWindowsprocess_creationHigh123Premium2026-08-25Malicious Command Execution Spawned by Apache Tomcat
This rule detects the Tomcat service process spawning command interpreters or administrative utilities, indicating web application remote code execution such as the Samsung MagicINFO exploitation observed by eSentire. A Java web server launching cmd, PowerShell, or account management binaries is a strong sign of server-side exploitation leading to cryptomining deployment.
HuntRule TeamWindowsprocess_creationHigh152Premium2026-08-25Malicious In-Memory Payload Execution via PowerShell DownloadString (via process_creation)
This rule detects PowerShell downloading a script from a remote host and immediately executing it in memory using DownloadString together with Invoke-Expression, a fileless technique used by a ransomware actor after ColdFusion exploitation to run Cobalt Strike beacons and reverse shells. Combining a web download with immediate expression evaluation is a common malicious loader pattern.
HuntRule TeamWindowsprocess_creationHigh267Premium2026-08-24Suspicious DNS Zone Export via dnscmd for Reconnaissance
This rule detects use of dnscmd with the zone export option to dump an Active Directory DNS zone to a file, a reconnaissance technique used by the Karakurt extortion actor to enumerate internal hosts and services. A full zone export gives an attacker a map of the environment to plan lateral movement and target high-value systems.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-08-24Suspicious DLL Sideloading via Renamed fixmapi Swom.exe Loading Mapistub.dll via Confucius (via image_load)
This rule detects Confucius persistence in which the legitimate fixmapi.exe is copied to Swom.exe in AppData and side loads a malicious Mapistub.dll from LocalAppData. The genuine Mapistub.dll is a system component so loading it beside a renamed fixmapi binary indicates the loader. This chain establishes the backdoor.
HuntRule TeamWindowsimage_loadHigh122Premium2026-08-24Untrusted Disabling of macOS System Integrity Protection (via process_creation)
This rule detects csrutil disable, which turns off System Integrity Protection so an attacker can modify protected system locations and load unsigned kernel code on macOS. Disabling SIP is a defense-evasion technique tracked in the Red Canary Threat Detection Report macOS coverage. Detecting this command surfaces removal of a core macOS protection.
HuntRule TeamMacosprocess_creationHigh102Premium2026-08-24Malicious User Account Control Bypass via Auto-Elevating Binary Hijack (via process_creation)
This rule detects a known auto-elevating Windows binary such as fodhelper, computerdefaults, eventvwr or sdclt spawning a command shell or script interpreter, the tell-tale child-process pattern of a User Account Control bypass. UAC bypasses are a recurring privilege-escalation and defense-evasion technique in the Red Canary Threat Detection Report, letting adversaries obtain a high-integrity process without a prompt. Detecting these parent-child pairs surfaces the elevation attempt.
HuntRule TeamWindowsprocess_creationHigh2010Premium2026-08-24Suspicious Execution of agent.exe From WinSyncDefender AppData Directory (via process_creation)
This rule detects execution of agent.exe from the Microsoft WinSyncDefender folder under AppData Roaming, the staging path used by Operation ShadowRecruit to host its SheetAgent RAT payload. Running a generically named binary from a fake Microsoft directory in a user-writable location is a wrong-context indicator of the recruitment-themed campaign against Indian job seekers, exposing the malware between delivery and Google Sheets C2.
HuntRule TeamWindowsprocess_creationHigh193Premium2026-08-24Malicious DLL Side-Loading of vcomp100 via converter.exe
This rule detects the ImageMagick converter.exe loading vcomp100.dll from outside the Windows system directories. The IDAT loader chain delivering Vidar and ACR stealers abused this signed binary to side-load a malicious vcomp100.dll and execute stager code under a trusted process.
HuntRule TeamWindowsimage_loadHigh201Premium2026-08-24DLL Side-Loading of NvSmartMax via NvSmart Host Process
This rule detects the nvSmartEx.exe host loading NvSmartMax.dll from outside the legitimate NVIDIA program directory, the DLL side-loading pair used by DeadRinger actors to run implant code. A trusted NVIDIA binary loading its companion DLL from an unexpected path indicates search-order hijacking.
HuntRule TeamWindowsimage_loadHigh393Premium2026-08-24Malicious Microsoft Defender Default Action Changed to Allow Any Threat - Command (via process_creation)
This rule detects change Defender default action to allow any threats.
HuntRule TeamWindowsprocess_creationHigh91Premium2026-08-24Malicious DNS Hosts File Accessed via Network Share (via security)
This rule detects attempt read the Hosts file content via network share.
HuntRule TeamWindowssecurityHigh419Premium2026-08-23Malicious Akira Ransomware Execution via Encryption Command-Line Parameters
This rule detects process execution using the distinctive encryption command-line parameters of the Akira ransomware encryptor, matching intrusions where a renamed akira.exe is run against mounted network shares. The switches control encryption scope and percentage across targeted paths and shares. Detecting these parameters catches the encryptor even when the binary is renamed to evade name-based controls.
HuntRule TeamWindowsprocess_creationHigh101Premium2026-08-23Malicious Windows Defender Disabling via DC.exe Defender Control by Elpaco Ransomware
This rule detects execution of the Defender Control utility (DC.exe) with a disable switch to turn off Windows Defender. This behavior is used by the Elpaco ransomware, a Mimic variant, to blind endpoint protection before encryption. Disabling defenses removes the primary barrier to file encryption and lateral movement, making early detection critical.
HuntRule TeamWindowsprocess_creationHigh447Premium2026-08-23