Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,138 rules
SwimSnake Driver Execution Persistence via Session Manager PlatformExecute (via registry_set)
This rule detects writes to the Session Manager PlatformExecute registry value, an unusual boot-time execution key the fake FinalShell SwimSnake campaign abuses to trigger a released driver (BEB.exe) for security-software tampering. Adversaries plant execution entries under Session Manager to run code very early and outside common autostart monitoring, making early detection critical for catching driver-based defense evasion before shellcode injection into explorer.exe.
HuntRule TeamWindowsregistry_setHigh102Premium2026-08-21FireWood Backdoor Persistence Files in Hidden kde-root Directory (via file_event)
This rule detects creation of the FireWood backdoor working files inside a hidden .kde-root directory, where the Linux implant stores its loader and PID artifacts under either a system library path or a user home directory. The masquerade as KDE runtime files combined with the hidden directory reflects the backdoor establishing itself on the host.
HuntRule TeamLinuxfile_eventHigh93Premium2026-08-21Suspicious Scheduled Task Creation for Efimer Controller (via process_creation)
This rule detects schtasks.exe registering a task that references controller.xml the scheduled-task definition used by the Efimer Trojan for persistence. Efimer establishes a recurring task to keep its clipboard clipper and Tor-based command channel running. A task built from an XML file named controller in user-writable space is an indicator of this infection.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-08-21Suspicious File Immutability Manipulation via chattr
This rule detects use of chattr to set or clear the immutable attribute on files, an anti-removal technique used by Kinsing and similar Log4Shell payloads to protect malicious binaries and persistence entries from deletion. Setting the immutable bit prevents defenders and cleanup tooling from removing the implanted files.
HuntRule TeamLinuxprocess_creationMedium156Premium2026-08-21Malicious Windows Firewall Disable via Netsh
This rule detects netsh disabling the Windows firewall, removing host network restrictions to ease lateral movement and remote access. This was observed during KawaLocker ransomware deployment together with RDP enablement. Turning off the firewall exposes services and undermines network segmentation defenses.
HuntRule TeamWindowsprocess_creationMedium112Premium2026-08-21Obfuscated Certutil Payload Download - Command (via process_creation)
This rule detects abuse certutil command to download obfuscated malicious payload.
HuntRule TeamWindowsprocess_creationHigh3110Premium2026-08-21Possible IcedID C2 Communication via HTTP Parameters (via proxy)
This rule detects HTTP requests carrying the analytics mimicking parameter set combined with the __io token used by IcedID command and control traffic. The malware disguises beacons as web analytics requests to blend into normal browsing traffic while relaying host data.
HuntRule TeamWebproxyMedium383Premium2026-08-21Suspicious macOS Hardware Identifier Reconnaissance via ioreg (via process_creation)
This rule detects execution of ioreg querying IOPlatformExpertDevice to harvest the hardware UUID as performed by trojanized text editor malware targeting Chinese users during victim fingerprinting which precedes second-stage payload delivery.
HuntRule TeamMacosprocess_creationMedium81Premium2026-08-21Suspicious OpenSSH Reverse Tunnel Establishment via ssh.exe
This rule detects ssh.exe launched with the -R remote-forwarding switch to establish a reverse tunnel. In Talos IR ransomware engagements operators used OpenSSH reverse tunnels to proxy traffic back into the victim network for persistent access, so this is a protocol-tunneling indicator that should be correlated with the tunnel destination.
HuntRule TeamWindowsprocess_creationMedium236Premium2026-08-21Suspicious TransferLoader Temporary File Creation in Windows Temp (via file_event)
This rule detects creation of the defender.user.tmp staging file in the Windows temporary directory that TransferLoader writes during execution. The masquerading filename mimics Microsoft Defender while residing in a temp path.
HuntRule TeamWindowsfile_eventMedium72Premium2026-08-21Suspicious SoftEther VPN Hamcore Config Written to ProgramData (via file_event)
This rule detects the creation of the SoftEther VPN hamcore.se2 archive or vpn_server.config under ProgramData as used by the Larva-26010 campaign to install a covert VPN tunnel on compromised web servers. These SoftEther artifacts in ProgramData indicate unauthorized remote access setup.
—Windowsfile_eventMedium339Premium2026-08-21Suspicious TransferLoader Configuration Storage in Phone Config Registry Key (via registry_set)
This rule detects creation of registry values under the Windows Phone Config key that TransferLoader abuses to store its C2 server, sleep timeout, encryption key and in-memory PE payload. Legitimate software rarely writes rmi, to, id or md values under this path.
HuntRule TeamWindowsregistry_setHigh404Premium2026-08-21Malicious OilRig Solar and Mango C2 URI Pattern via Proxy (via proxy)
This rule detects outbound HTTP requests matching the Solar and Mango command-and-control URI pattern used by OilRig, where template.aspx is queried with the rt=d and sun= parameters. This structured URI encodes tasking and exfiltration for the group's downloaders and marks active C2 traffic.
HuntRule TeamWebproxyHigh136Premium2026-08-21Suspicious Discovery Command Spawned by Java Process
This rule detects the Cleo Java runtime spawning Windows discovery utilities such as nltest, whoami, and ipconfig, the hands-on-keyboard reconnaissance seen after exploitation of Cleo file transfer software and the Malichus malware. A Java service process launching domain and host enumeration is not part of normal operation. This lineage indicates active post-exploitation of an internet-facing Cleo server.
HuntRule TeamWindowsprocess_creationHigh213Premium2026-08-20Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
This rule detects Microsoft 365 sign-in events blocked by Conditional Access after a valid password was supplied, which can indicate credential stuffing or password spraying against accounts protected only by MFA. Huntress observed adversaries validating stolen credentials from VPN, Tor, and proxy sources before attempting session takeover. A spike of these blocks from anomalous geographies surfaces pre-MFA account compromise that would otherwise be silent.
HuntRule TeamAzuresigninlogsMedium346Premium2026-08-20