Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,140 rules
Suspicious Discovery Command Spawned by Java Process
This rule detects the Cleo Java runtime spawning Windows discovery utilities such as nltest, whoami, and ipconfig, the hands-on-keyboard reconnaissance seen after exploitation of Cleo file transfer software and the Malichus malware. A Java service process launching domain and host enumeration is not part of normal operation. This lineage indicates active post-exploitation of an internet-facing Cleo server.
HuntRule TeamWindowsprocess_creationHigh213Premium2026-08-20Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
This rule detects Microsoft 365 sign-in events blocked by Conditional Access after a valid password was supplied, which can indicate credential stuffing or password spraying against accounts protected only by MFA. Huntress observed adversaries validating stolen credentials from VPN, Tor, and proxy sources before attempting session takeover. A spike of these blocks from anomalous geographies surfaces pre-MFA account compromise that would otherwise be silent.
HuntRule TeamAzuresigninlogsMedium346Premium2026-08-20Suspicious Persistence via pcalua Launching rundll32 Control_RunDLL
This rule detects the Program Compatibility Assistant pcalua being abused to launch rundll32 with the Control_RunDLL export against a user profile DLL. RedCurl uses this scheduled task chain to persist its BrowserSpec loader while masking the parent process.
HuntRule TeamWindowsprocess_creationHigh74Premium2026-08-20Possible Log4Shell JNDI Exploitation Attempt in Web Request
This rule detects Log4Shell (CVE-2021-44228) exploitation strings such as JNDI LDAP/RMI/DNS lookups and Log4j lookup obfuscation appearing in web request URIs and User-Agent headers. Attackers embed these expressions to force vulnerable Log4j2 loggers into resolving attacker-controlled JNDI references, leading to remote code execution.
HuntRule TeamWebwebserverHigh278Premium2026-08-20Suspicious PowerShell Invoke-WebRequest Piped to Invoke-Expression via FakeBat Loader
This rule detects PowerShell downloading a remote payload with Invoke-WebRequest using a custom User-Agent and piping the response straight into Invoke-Expression. FakeBat, also tracked as EugenLoader, delivers this one liner through malvertising and fake software sites to stage its next component in memory. Fileless download and execute cradles like this bypass disk based controls and warrant investigation.
HuntRule TeamWindowsps_scriptMedium111Premium2026-08-20Suspicious macOS SSH Loopback Connection for TCC Bypass
This rule detects an SSH client connecting to the local loopback address on macOS. It maps to a technique where an attacker uses ssh to localhost so the spawned session inherits full disk access granted to the SSH daemon, bypassing the TCC privacy prompt. Detecting loopback SSH can surface abuse of remote services for privacy control evasion.
HuntRule TeamMacosprocess_creationLow123Premium2026-08-20Malicious Lazarus SIGNBT DLL Side-Loading via PCHealthCheck Host (via image_load)
This rule detects the Microsoft PC Health Check binary PCHealthCheck.exe loading a PCHealthCheck.dll from outside standard program directories, the DLL side-loading technique the Lazarus SIGNBT cluster uses to execute malicious code under a signed utility. Restricting to non-program paths separates the abuse from the legitimately installed application.
HuntRule TeamWindowsimage_loadHigh188Premium2026-08-20Suspicious DLL Side-Loading from Non-Standard winsystem Directory
This rule detects a module being loaded from the non-standard C:\winsystem directory used by the STARKVEIL chain to stage side-loaded DLLs alongside a legitimate signed executable. Attackers rely on this masquerading path to run malicious code under a trusted process while evading directory-based allowlists.
HuntRule TeamWindowsimage_loadHigh379Premium2026-08-20ClickFix Pastejacking via Script Interpreter Command in Run Dialog MRU (via registry_set)
This rule detects ClickFix pastejacking where a clipboard-injected download-and-execute command is entered through the Windows Run dialog and recorded in the Explorer RunMRU key. Adversaries leverage the Run dialog to have the victim manually launch a script interpreter, so PowerShell or download utilities appearing in RunMRU history is a strong user-assisted execution indicator.
HuntRule TeamWindowsregistry_setHigh295Premium2026-08-20Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
This rule detects browsercore.exe launched by a process other than a known browser or task host, a pattern used to request a PRT cookie for cloud authentication abuse. The cloud lateral-movement research shows attackers invoke browsercore outside its normal browser context to obtain single sign-on artifacts. An unexpected parent for this binary is a heuristic sign of token theft.
HuntRule TeamWindowsprocess_creationMedium262Premium2026-08-20Malicious DLL Sideloading via WSPrint and BugSplatRc64 by UAT-9244
This rule detects the WSPrint executable loading BugSplatRc64.dll from its ProgramData directory. UAT-9244 sideloads this DLL to execute follow-on implants under a benign-looking process. Loading a payload DLL from ProgramData through a planted executable is a hallmark of DLL search-order hijacking.
HuntRule TeamWindowsimage_loadHigh91Premium2026-08-20OpenSSH Server Firewall Configuration on Windows - Firewall (via firewall-as)
This rule detects configure the Windows firewall to allow incoming connections to perform stealthy lateral movement.
HuntRule TeamWindowsfirewall-asHigh369Premium2026-08-20Malicious Stickey Key Called CMD via Command Execution (via process_creation)
This rule detects calls the stickey key and execute CMD.
HuntRule TeamWindowsprocess_creationHigh351Premium2026-08-20SIP or Trust Provider Registration (via registry_set)
This rule detects register a SIP or trust provider in order to mislead signature validation checks.
HuntRule TeamWindowsregistry_setHigh3310Premium2026-08-20Malicious BRICKSTORM Backdoor Execution via Masqueraded Binary Path
This rule detects execution of the BRICKSTORM backdoor from masqueraded system paths used by the VerdantBamboo intrusion set. The malware was deployed as /usr/sbin/luserput and as a blacklist binary under the IPSec libexec directory on pfSense firewalls to blend with legitimate appliance components. Detecting these hardcoded drop locations exposes an active foothold on network edge devices used for long-term espionage.
HuntRule TeamLinuxprocess_creationHigh382Premium2026-08-20