Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
141 rules
Suspicious PowMix Scheduled Task Launching LNK via Explorer
This rule detects creation of a scheduled task that runs explorer.exe against a shortcut file, matching the PowMix botnet persistence that fires a daily task at 11:00 to relaunch its malicious LNK through Explorer. Abusing explorer.exe to open an attacker LNK on a schedule masks the loader chain as ordinary shell activity. This persistence pattern indicates a PowMix foothold on the host.
HuntRule TeamWindowsprocess_creationHigh328Premium2026-05-21Malicious Remote XSL Script Execution via WMIC Squiblytwo Technique
This rule detects WMIC invoking a remote XSL stylesheet via the format switch which is the squiblytwo technique used by the Lazarus chain to execute attacker script content as analysed by NCC Group. Loading a remote XSL through a signed system binary evades application control and downloads code from adversary infrastructure.
HuntRule TeamWindowsprocess_creationHigh151Premium2026-05-21Suspicious tapiperf.dll Load by WMI Provider Host via Image Load
This rule detects wmiprvse.exe loading tapiperf.dll, which the Lunar toolset abuses through DLL replacement to gain execution inside a trusted Windows process. Legitimately tapiperf.dll is a TAPI performance counter library and is not loaded by the WMI provider host. This anomalous load points to DLL hijacking used for stealthy persistence and code execution.
HuntRule TeamWindowsimage_loadHigh142Premium2026-05-21Malicious Volgmer Payload Storage in WMI Security Registry Key
This rule detects creation of specific named values under the WMI Security registry key used by the Hidden Cobra Volgmer backdoor to hide its encoded configuration and payload. Writing data to this rarely used registry location under these hardcoded GUID value names is a high-confidence indicator of a Volgmer infection.
HuntRule TeamWindowsregistry_setHigh223Premium2026-05-12Malicious Remote Process Creation via wmic node call create
This rule detects wmic invoking process call create against a remote node. The CloudComputating group used this WMI technique to execute commands on remote hosts for lateral movement across the network, which is uncommon in routine administration.
HuntRule TeamWindowsprocess_creationHigh407Premium2026-05-05Malicious Impacket WMIexec Execution via SMB Admin Share (via security)
This rule detects remotely execute WMIexec via SMB admin share in order to escalate privileges.
HuntRule TeamWindowssecurityHigh73Premium2026-05-02Malicious Impacket wmiexec Output Redirection via ADMIN Share
This rule detects the characteristic Impacket wmiexec command line that redirects command output to a temporary file on the local admin share over the loopback address as described in the WithSecure WMI lab. This redirection pattern is highly specific to semi interactive Impacket WMI execution and is a strong indicator of remote lateral movement by an attacker toolkit.
HuntRule TeamWindowsprocess_creationHigh385Premium2026-05-02Windows: WMIC service ChangeStartMode sets Manual or Disabled startup type
Detects wmic.exe commands changing a Windows service startup type to Manual or Disabled via ChangeStartMode.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium438Free2026-04-27Windows: Detect NetExec (nxc.exe) Process Execution with Network Service Commands
Flags Windows execution of NetExec (nxc.exe) when command lines include SMB/RDP/SSH/WinRM/WMI and other protocol keywords.
Chirag Damani, Huntrule TeamWindowsprocess_creationHigh175Free2026-03-29Windows Process Creation: Registry Modification to Disable ETW AutoLogger via reg.exe or PowerShell
Flags reg.exe or PowerShell registry changes aimed at disabling WMI AutoLogger EventLog session components.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh247Free2025-12-25Windows RDP Enable/Disable via Win32_TerminalServiceSetting WMI Tool Commands
Flags WMIC/PowerShell command lines that reference Win32_TerminalServiceSetting SetAllowTSConnections to change RDP.
Daniel Koifman (KoifSec), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium482Free2025-11-15Windows WMIC Registry Changes via WMI StdRegProv Write Methods
Flags wmic.exe commands invoking WMI StdRegProv to create/delete keys or set registry values.
Daniel Koifman (KoifSec), Huntrule TeamWindowsprocess_creationMedium263Free2025-07-30Windows WMI StdRegProv Registry Enumeration via wmic.exe
Flags wmic.exe usage invoking WMI StdRegProv registry read/enumeration methods for discovery.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium432Free2025-07-30Windows WMI (wmic.exe) Sets User Password to Never Expire
Detects wmic.exe commands that set a Windows account password to never expire via WMI.
Daniel Koifman (KoifSec), Huntrule TeamWindowsprocess_creationMedium101Free2025-07-30Windows reg.exe disables Defender WMI Autologger sessions by setting Start to 0
Flags reg.exe changing WMI Autologger Start for DefenderApiLogger/DefenderAuditLogger to 0, impairing ETW security logging.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationHigh141Free2025-07-09