Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,425 rules
Suspicious Scheduled Task Creation for Efimer Controller (via process_creation)
This rule detects schtasks.exe registering a task that references controller.xml the scheduled-task definition used by the Efimer Trojan for persistence. Efimer establishes a recurring task to keep its clipboard clipper and Tor-based command channel running. A task built from an XML file named controller in user-writable space is an indicator of this infection.
HuntRule TeamWindowsprocess_creationHigh162Premium2026-08-21Obfuscated Certutil Payload Download - Command (via process_creation)
This rule detects abuse certutil command to download obfuscated malicious payload.
HuntRule TeamWindowsprocess_creationHigh3510Premium2026-08-21Suspicious TransferLoader Configuration Storage in Phone Config Registry Key (via registry_set)
This rule detects creation of registry values under the Windows Phone Config key that TransferLoader abuses to store its C2 server, sleep timeout, encryption key and in-memory PE payload. Legitimate software rarely writes rmi, to, id or md values under this path.
HuntRule TeamWindowsregistry_setHigh454Premium2026-08-21Malicious OilRig Solar and Mango C2 URI Pattern via Proxy (via proxy)
This rule detects outbound HTTP requests matching the Solar and Mango command-and-control URI pattern used by OilRig, where template.aspx is queried with the rt=d and sun= parameters. This structured URI encodes tasking and exfiltration for the group's downloaders and marks active C2 traffic.
HuntRule TeamWebproxyHigh166Premium2026-08-21Suspicious Discovery Command Spawned by Java Process
This rule detects the Cleo Java runtime spawning Windows discovery utilities such as nltest, whoami, and ipconfig, the hands-on-keyboard reconnaissance seen after exploitation of Cleo file transfer software and the Malichus malware. A Java service process launching domain and host enumeration is not part of normal operation. This lineage indicates active post-exploitation of an internet-facing Cleo server.
HuntRule TeamWindowsprocess_creationHigh243Premium2026-08-20Suspicious Persistence via pcalua Launching rundll32 Control_RunDLL
This rule detects the Program Compatibility Assistant pcalua being abused to launch rundll32 with the Control_RunDLL export against a user profile DLL. RedCurl uses this scheduled task chain to persist its BrowserSpec loader while masking the parent process.
HuntRule TeamWindowsprocess_creationHigh104Premium2026-08-20Possible Log4Shell JNDI Exploitation Attempt in Web Request
This rule detects Log4Shell (CVE-2021-44228) exploitation strings such as JNDI LDAP/RMI/DNS lookups and Log4j lookup obfuscation appearing in web request URIs and User-Agent headers. Attackers embed these expressions to force vulnerable Log4j2 loggers into resolving attacker-controlled JNDI references, leading to remote code execution.
HuntRule TeamWebwebserverHigh288Premium2026-08-20Malicious Lazarus SIGNBT DLL Side-Loading via PCHealthCheck Host (via image_load)
This rule detects the Microsoft PC Health Check binary PCHealthCheck.exe loading a PCHealthCheck.dll from outside standard program directories, the DLL side-loading technique the Lazarus SIGNBT cluster uses to execute malicious code under a signed utility. Restricting to non-program paths separates the abuse from the legitimately installed application.
HuntRule TeamWindowsimage_loadHigh208Premium2026-08-20Suspicious DLL Side-Loading from Non-Standard winsystem Directory
This rule detects a module being loaded from the non-standard C:\winsystem directory used by the STARKVEIL chain to stage side-loaded DLLs alongside a legitimate signed executable. Attackers rely on this masquerading path to run malicious code under a trusted process while evading directory-based allowlists.
HuntRule TeamWindowsimage_loadHigh389Premium2026-08-20ClickFix Pastejacking via Script Interpreter Command in Run Dialog MRU (via registry_set)
This rule detects ClickFix pastejacking where a clipboard-injected download-and-execute command is entered through the Windows Run dialog and recorded in the Explorer RunMRU key. Adversaries leverage the Run dialog to have the victim manually launch a script interpreter, so PowerShell or download utilities appearing in RunMRU history is a strong user-assisted execution indicator.
HuntRule TeamWindowsregistry_setHigh295Premium2026-08-20Malicious DLL Sideloading via WSPrint and BugSplatRc64 by UAT-9244
This rule detects the WSPrint executable loading BugSplatRc64.dll from its ProgramData directory. UAT-9244 sideloads this DLL to execute follow-on implants under a benign-looking process. Loading a payload DLL from ProgramData through a planted executable is a hallmark of DLL search-order hijacking.
HuntRule TeamWindowsimage_loadHigh131Premium2026-08-20OpenSSH Server Firewall Configuration on Windows - Firewall (via firewall-as)
This rule detects configure the Windows firewall to allow incoming connections to perform stealthy lateral movement.
HuntRule TeamWindowsfirewall-asHigh369Premium2026-08-20Malicious Stickey Key Called CMD via Command Execution (via process_creation)
This rule detects calls the stickey key and execute CMD.
HuntRule TeamWindowsprocess_creationHigh351Premium2026-08-20SIP or Trust Provider Registration (via registry_set)
This rule detects register a SIP or trust provider in order to mislead signature validation checks.
HuntRule TeamWindowsregistry_setHigh3310Premium2026-08-20Malicious BRICKSTORM Backdoor Execution via Masqueraded Binary Path
This rule detects execution of the BRICKSTORM backdoor from masqueraded system paths used by the VerdantBamboo intrusion set. The malware was deployed as /usr/sbin/luserput and as a blacklist binary under the IPSec libexec directory on pfSense firewalls to blend with legitimate appliance components. Detecting these hardcoded drop locations exposes an active foothold on network edge devices used for long-term espionage.
HuntRule TeamLinuxprocess_creationHigh412Premium2026-08-20