Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,144 rules
OpenSSH Server Firewall Configuration on Windows - Firewall (via firewall-as)
This rule detects configure the Windows firewall to allow incoming connections to perform stealthy lateral movement.
HuntRule TeamWindowsfirewall-asHigh369Premium2026-08-20Malicious Stickey Key Called CMD via Command Execution (via process_creation)
This rule detects calls the stickey key and execute CMD.
HuntRule TeamWindowsprocess_creationHigh351Premium2026-08-20SIP or Trust Provider Registration (via registry_set)
This rule detects register a SIP or trust provider in order to mislead signature validation checks.
HuntRule TeamWindowsregistry_setHigh3310Premium2026-08-20Malicious BRICKSTORM Backdoor Execution via Masqueraded Binary Path
This rule detects execution of the BRICKSTORM backdoor from masqueraded system paths used by the VerdantBamboo intrusion set. The malware was deployed as /usr/sbin/luserput and as a blacklist binary under the IPSec libexec directory on pfSense firewalls to blend with legitimate appliance components. Detecting these hardcoded drop locations exposes an active foothold on network edge devices used for long-term espionage.
HuntRule TeamLinuxprocess_creationHigh382Premium2026-08-20Suspicious Caret Obfuscated Command Execution via Process Creation
This rule detects caret-escaped command strings such as caret-broken curl and mshta invocations used by Scarlet Goldfinch ClickFix lures inside cmd.exe. Attackers insert carets between characters to evade signature matching and casual inspection, so heavily caret-broken tokens on the command line indicate deliberate obfuscation of a malicious download.
HuntRule TeamWindowsprocess_creationHigh83Premium2026-08-20Malicious Keenadu Android Backdoor C2 Registration and Task Polling URIs
This rule detects HTTP requests to the command-and-control URI paths used by the Keenadu Android backdoor including its client registration and task polling endpoints. Kaspersky tied these structured paths to Keenadu infrastructure linking several major Android botnets. Traffic matching these endpoints indicates an infected device beaconing to its operator to receive tasking and exfiltrate data.
HuntRule TeamWebproxyMedium215Premium2026-08-20Malicious Tool Execution from inetpub Web Root Directory
This rule detects execution of binaries from the inetpub pub directory, where the DynoWiper actor staged scheduling and update tools such as schtask.exe and update executables after web-server compromise. Legitimate processes rarely execute from inside the IIS web root, so a running binary there points to post-exploitation tooling.
HuntRule TeamWindowsprocess_creationHigh82Premium2026-08-20Malicious Office 365 Email Rule Breach - On Behalf (via office365)
This rule detects attempt to hide emails in order to perform phishing attacks by replacing, for example, financial information from the original email with another email containing attacker's financial information. This technique may also be used to avoid specific email notification to be received by end users in case, for example, of an ongoing breach.
HuntRule TeamAzureoffice365High71Premium2026-08-20Malicious regsvcs LOLBin Loading Ransomware DLL from UNC Path
This rule detects the regsvcs.exe living-off-the-land binary being used to load and install a DLL from a UNC network path, matching SafePay ransomware deployment via regsvcs proxy execution. Attackers abuse regsvcs to run their encryptor DLL while bypassing application controls. Loading a DLL over UNC through regsvcs is not a legitimate developer workflow.
HuntRule TeamWindowsprocess_creationHigh145Premium2026-08-20Suspicious Active Directory Subnet Enumeration via ADFind Subnets Query (via process_creation)
This rule detects ADFind querying the configuration Subnets container with the subnets switch, the network-topology reconnaissance run in this multi-gang intrusion to map site subnets before lateral movement. Adversaries use ADFind to enumerate the directory Subnets object and understand the network layout for targeting, so this specific subnets query is a strong discovery indicator.
HuntRule TeamWindowsprocess_creationMedium121Premium2026-08-20Suspicious Rundll32 Executing DLL Start Export With Control Flags
This rule detects rundll32.exe calling a DLL Start export together with WarmCookie control flags such as /p /u or /update. WarmCookie also known as BadSpace was launched through rundll32 invoking its Start export with these command switches. The Start export paired with these operational flags is a distinctive WarmCookie loader signature for proxied malicious DLL execution.
HuntRule TeamWindowsprocess_creationHigh163Premium2026-08-20Malicious Reverse Shell Spawned by Web Server User (via process_creation)
This rule detects the web server account www-data launching an interactive reverse shell, as seen in the compromised-container forensics case following web application exploitation. A shell with a network redirect running as the web user indicates active remote control. This behavior is rarely legitimate for a service account.
HuntRule TeamLinuxprocess_creationHigh449Premium2026-08-20Suspicious DERO Cryptojacking Dropper Script Execution
This rule detects execution of the ddns.sh dropper script associated with the DERO cryptojacking campaign. Wiz Research observed this script deployed through malicious Kubernetes deployments to fetch and launch the miner, so references to it indicate an ingress tool transfer and staging on a compromised node.
HuntRule TeamLinuxprocess_creationMedium182Premium2026-08-20Malicious NetSupport RAT Execution From Public Folder via Process Creation
This rule detects the NetSupport client32.exe running with its client32.ini configuration from the Users Public directory, a placement pattern characteristic of NetSupport Manager abused as a remote access trojan. Attackers deploy the legitimate remote control tool from world-writable locations to gain hands-on-keyboard access while blending in with sanctioned software, so this path is a strong indicator of RAT abuse.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-08-19Suspicious Firewall Rule Added Using PowerShell or CMD (via firewall-as)
This rule detects scenarios where a firewall rule is added using PowerShell or CMD.
HuntRule TeamWindowsfirewall-asMedium406Premium2026-08-19