Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,147 rules
Suspicious DERO Cryptojacking Dropper Script Execution
This rule detects execution of the ddns.sh dropper script associated with the DERO cryptojacking campaign. Wiz Research observed this script deployed through malicious Kubernetes deployments to fetch and launch the miner, so references to it indicate an ingress tool transfer and staging on a compromised node.
HuntRule TeamLinuxprocess_creationMedium182Premium2026-08-20Malicious NetSupport RAT Execution From Public Folder via Process Creation
This rule detects the NetSupport client32.exe running with its client32.ini configuration from the Users Public directory, a placement pattern characteristic of NetSupport Manager abused as a remote access trojan. Attackers deploy the legitimate remote control tool from world-writable locations to gain hands-on-keyboard access while blending in with sanctioned software, so this path is a strong indicator of RAT abuse.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-08-19Suspicious Firewall Rule Added Using PowerShell or CMD (via firewall-as)
This rule detects scenarios where a firewall rule is added using PowerShell or CMD.
HuntRule TeamWindowsfirewall-asMedium406Premium2026-08-19Suspicious Firewall Rule Masquerading as CloudExperienceHost via netsh
This rule detects creation of a Windows firewall rule via netsh whose name impersonates Microsoft.Windows.CloudExperienceHost, a defense evasion step used by the GigaWiper backdoor. Naming a malicious firewall rule after a trusted Windows component hides attacker network allowances from casual review.
HuntRule TeamWindowsprocess_creationMedium63Premium2026-08-19Masquerading Konni Registry Run Key Launching Wscript JavaScript from ProgramData (via registry_set)
This rule detects a CurrentVersion Run autorun value whose command runs wscript with the JavaScript engine against a script staged in ProgramData, the persistence behavior of a Konni AsyncRAT chain registered as GUpdate2 or SUpdate. Adversaries leverage the run key with the scripting host to relaunch their JavaScript loader at logon while masquerading as an updater, making early detection critical for surfacing persistence before AsyncRAT reconnects.
HuntRule TeamWindowsregistry_setHigh361Premium2026-08-19Suspicious GAM OAuth Token Enumeration via Process Creation
This rule detects use of the GAM command line tool to print or delete OAuth tokens across a Google Workspace tenant, activity observed both during attacker reconnaissance of consented apps and legitimate administrative cleanup. Because token enumeration reveals which third-party apps hold access, unexpected GAM token operations outside change windows can indicate an attacker mapping or pruning OAuth grants.
HuntRule TeamWindowsprocess_creationLow2910Premium2026-08-19Suspicious Hidden Local Account Creation via Dscl (via process_creation)
This rule detects dscl creating a user record together with hidden-account or UID attributes, a persistence technique used to add a stealthy admin account that does not appear on the macOS login window. Hidden account creation is tracked in the Red Canary Threat Detection Report macOS coverage. Detecting this surfaces a covert local account being planted.
HuntRule TeamMacosprocess_creationMedium363Premium2026-08-19Obfuscated XE Group Reflective Loader via PowerShell Spawned by IIS Worker Process (via process_creation)
This rule detects the IIS worker process w3wp.exe spawning a hidden PowerShell that runs a base64-encoded reflective loader, the in-memory execution step XE Group used after webshell access to launch Meterpreter. A web server process launching an obfuscated hidden PowerShell is a strong indicator of post-exploitation code execution.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-08-19Malicious XMRig Cryptominer Execution with NiceHash Pool Arguments
This rule detects launch of the XMRig cryptocurrency miner with its characteristic pool and NiceHash command-line flags. The BeatBanker dual-mode Android trojan runs XMRig against an attacker pool over TLS to abuse device resources for Monero mining as reported by Kaspersky. This flag combination is specific to covert mining and indicates resource hijacking on the host.
HuntRule TeamWindowsprocess_creationMedium234Premium2026-08-19Malicious Sticky Key Sethc Command for Replacement by CMD (via process_creation)
This rule detects replace the original sethc.exe file by cmd.exe.
HuntRule TeamWindowsprocess_creationHigh438Premium2026-08-19Malicious Lynx Ransomware Encrypted File Extension Creation (via file_event)
This rule detects creation of files carrying the .LYNX extension appended by the Lynx ransomware encryptor as reported by Group-IB. Adversaries rename encrypted files with this extension during impact, so a burst of these writes indicates active ransomware encryption on the host.
HuntRule TeamWindowsfile_eventHigh153Premium2026-08-19Suspicious winrm.vbs LOLBAS Script Execution for Code Proxying
This rule detects cscript or wscript executing the built in winrm.vbs script, a living-off-the-land binary abused in the OnlyDcRatFans campaign to proxy execution of a DcRat payload retrieved from paste.ee. winrm.vbs is normally used interactively by administrators, so its invocation by a script host to run additional code indicates abuse.
HuntRule TeamWindowsprocess_creationMedium52Premium2026-08-19Suspicious DLL Sideloading via Fake ApowerREC.exe Loading lastbld2Base.dll via Winos (via image_load)
This rule detects the Winos 4.0 loader using a fake ApowerREC.exe to side load the malicious lastbld2Base.dll through its DllMain during initial execution. The pairing of this screen recorder binary with that DLL name is specific to the campaign. It launches the in memory implant.
HuntRule TeamWindowsimage_loadHigh299Premium2026-08-19Possible Sitecore Experience Platform Pre-Auth RCE via TypeConfuseDelegate Gadget (via webserver)
This rule detects POST requests to the Sitecore Reporting Report.ashx handler carrying a parameters XML body with NetDataContractSerializer and TypeConfuseDelegate gadget markers. This is the pre-auth deserialization RCE CVE-2021-42237 that reaches Process.Start on the server. Detecting it exposes code-execution attempts against internet-facing Sitecore Experience Platform instances.
HuntRule TeamWebwebserverHigh4210Premium2026-08-19Suspicious PowerShell Download to Disk Then Execute (via process_creation)
This rule detects PowerShell downloading a remote file and saving it to disk with an output path, a common precursor to executing a staged payload. AresLoader retrieves its DLL over HTTP with an OutFile parameter before starting the process. Download-to-disk followed by local execution is a recurring ingress-tool-transfer behavior.
HuntRule TeamWindowsprocess_creationMedium299Premium2026-08-19