Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
94 rules
Malicious Shadow Copy and Backup Deletion for Ransomware Recovery Inhibition
This rule detects deletion of volume shadow copies and backup catalogs through vssadmin wmic and wbadmin which Phobos ransomware runs before encryption to prevent victims from restoring their files. Inhibiting system recovery is a common precursor to file encryption and warrants immediate response.
HuntRule TeamWindowsprocess_creationHigh133Premium2026-08-18Suspicious Event Log Clearing via wevtutil During Ransomware Activity
This rule detects wevtutil clearing Windows event logs which ransomware operators perform to destroy evidence of intrusion and lateral movement. Clearing logs immediately before or after encryption impairs incident response and timeline reconstruction.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-08-14Malicious Cactus Ransomware Ransom Note Creation (via file_event)
This rule detects creation of Cactus ransomware ransom notes, which embed the fixed C.A.c_T.U-S-R.e-a_D.m-e marker between randomized prefixes and postfixes in the note filename. Adversaries leverage mass note deployment during the encryption stage, making detection of this distinctive embedded string a reliable late-stage indicator of a Cactus impact event.
HuntRule TeamWindowsfile_eventHigh427Premium2026-08-13Suspicious Windows Defender Tamper Protection Disabled via Registry by Nova Ransomware
This rule detects the Windows Defender TamperProtection value being set to zero under the Defender Features key, disabling tamper protection so security tooling can be altered. Nova ransomware performs this change as part of multi-layered Defender evasion.
HuntRule TeamWindowsregistry_setMedium153Premium2026-08-10Malicious SQL Server Spawning Command Interpreter via Mallox Ransomware
This rule detects the MS SQL Server process sqlservr.exe spawning a command interpreter such as cmd, PowerShell, or sqlps, the initial code-execution step in Mallox ransomware intrusions following database compromise. A database engine launching shells almost always reflects abuse of SQL for command execution and should be treated as an active intrusion.
HuntRule TeamWindowsprocess_creationHigh321Premium2026-08-09JanaWare Ransomware Ransom Note _ONEMLI_NOT_ Written to Disk (via file_event)
This rule detects the JanaWare ransomware writing its _ONEMLI_NOT_ ransom note across folders as it completes encryption in attacks against Turkish organizations. Adversaries drop this hardcoded Turkish-language note filename in every encrypted directory. The fixed prefix is a reliable post-impact detection anchor.
HuntRule TeamWindowsfile_eventHigh161Premium2026-08-06Malicious Ransomware Extension Class Registration for ELPACO-team by Elpaco Ransomware
This rule detects registration of the .ELPACO-team file extension class under HKLM Classes. Elpaco ransomware, a Mimic variant, registers its own encrypted-file extension to associate the ransom note handler after encryption. Presence of this class key indicates ransomware has executed and modified file associations on the host.
HuntRule TeamWindowsregistry_setCritical91Premium2026-08-01Malicious Mamona Ransomware Note and Encrypted File Extension
This rule detects creation of the Mamona ransomware note README.HAes.txt or files bearing the .HAes encrypted extension. These artifacts are written recursively across directories once Mamona completes its offline encryption.
HuntRule TeamWindowsfile_eventHigh289Premium2026-07-28Suspicious Silent AnyDesk Installation for Remote Access by DeadLock Ransomware
This rule detects silent unattended installation of AnyDesk configured to start with Windows. The DeadLock ransomware operators deploy AnyDesk as a covert remote access tool for persistence and hands-on control. Silent installation with automatic startup indicates the tool is being planted rather than installed by a user.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-07-26Malicious Volume Shadow Copy Deletion via vssadmin by Medusa Ransomware
This rule detects use of vssadmin to delete all volume shadow copies quietly, matching the inhibit-recovery step performed by Medusa ransomware before encryption per Unit 42. Ransomware wipes shadow copies to prevent victims from restoring files which is a strong pre-encryption indicator of an active ransomware attack.
HuntRule TeamWindowsprocess_creationHigh143Premium2026-07-25Suspicious Windows Event Log Clearing via Dire Wolf Ransomware (via process_creation)
This rule detects use of wevtutil to clear Windows event logs, an indicator removal step performed by Dire Wolf ransomware across the Application, System, Security and Setup logs.
HuntRule TeamWindowsprocess_creationMedium133Premium2026-07-21Malicious Nova Ransomware Note and Encrypted File Extension via File Event
This rule detects creation of the Nova ransomware note README_NOVA.me alongside files bearing the .xgWLckNV extension appended during encryption. These artifacts are dropped as Nova encrypts a host and demands ransom.
HuntRule TeamWindowsfile_eventHigh164Premium2026-07-14Malicious BlackByte Ransomware Host Marker via Control Panel Registry
This rule detects the international control panel values s1159 and s2359 being set to BLACKBYTE, a distinctive host-marking artifact created by BlackByte ransomware. BlackByte writes this value to tag infected systems.
HuntRule TeamWindowsregistry_setHigh82Premium2026-07-13Malicious Cicada3301 Ransomware Locker Execution via Command Line Key (via process_creation)
This rule detects execution of the Cicada3301 ransomware locker binary with its command-line decryption key argument, which the Repellent Scorpius affiliate launched remotely through PsExec to encrypt hosts. Passing the encryption key on the command line is characteristic of this Rust-based locker and indicates active ransomware deployment.
HuntRule TeamWindowsprocess_creationHigh93Premium2026-07-11Malicious Akira Ransomware Encryptor Command Line Flags
This rule detects execution of a binary using the stopvm and vmonly flags characteristic of the Akira Rust ransomware encryptor targeting ESXi. These flags instruct the tool to shut down and encrypt only virtual machines. Detecting the flag combination exposes the ransomware payload at runtime.
HuntRule TeamLinuxprocess_creationHigh121Premium2026-07-08