Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,148 rules
Suspicious PowerShell Download to Disk Then Execute (via process_creation)
This rule detects PowerShell downloading a remote file and saving it to disk with an output path, a common precursor to executing a staged payload. AresLoader retrieves its DLL over HTTP with an OutFile parameter before starting the process. Download-to-disk followed by local execution is a recurring ingress-tool-transfer behavior.
HuntRule TeamWindowsprocess_creationMedium299Premium2026-08-19Suspicious mstsc Launch of RDP File From User Download or Temp Path (via process_creation)
This rule detects the Remote Desktop client mstsc.exe opening a .rdp configuration file from a Downloads, Temp or AppData location, the delivery pattern of the rogue RDP campaign that phished malicious .rdp files enabling remote application mode and drive redirection. Executing an attacker-supplied RDP file connects victims to actor-controlled servers with resource redirection.
HuntRule TeamWindowsprocess_creationMedium201Premium2026-08-19KrbRelayUp Service Installation - Native (via system)
This rule detects escalate privileges while abusing KrbRelayUp attack.
HuntRule TeamWindowssystemHigh398Premium2026-08-19Suspicious AppleScript Payload Execution via osascript (macOS)
This rule detects osascript executing a compiled AppleScript (.scpt) file, matching AppleScript payload delivery observed in fake macOS application installers distributing infostealers. Adversaries use .scpt files dropped from mounted DMG images to run malicious logic and harvest credentials. AppleScript execution of on-disk .scpt files outside trusted automation workflows is unusual and warrants review.
HuntRule TeamMacosprocess_creationMedium3210Premium2026-08-19Suspicious IAM AdministratorAccess Policy Attachment via CloudTrail (via cloudtrail)
This rule detects the Shai Hulud privilege escalation in AWS where a freshly created IAM user is granted the AdministratorAccess managed policy through an AttachUserPolicy call. Attaching full administrator rights to a user is a high impact action that is rare in normal operations. It followed the creation of a cloudops-monitor identity.
HuntRule TeamAwscloudtrailMedium121Premium2026-08-19Suspicious DarkVNC vncdll64.dll Hidden VNC Module Load
This rule detects loading of vncdll64.dll, the hidden VNC module used by DarkVNC to create a covert desktop session inside explorer.exe for interactive remote control. This named module is specific to the DarkVNC toolset and its load indicates hands on keyboard access hidden from the victim.
HuntRule TeamWindowsimage_loadMedium102Premium2026-08-19Suspicious Service Installation Masquerading as winupd
This rule detects installation of a Windows service named winupd, a masquerade used by the INC Ransom group to run a renamed PsExec binary under a plausible Windows-update name. Service creation with this deceptive name is not expected from legitimate software and indicates hands-on-keyboard execution and lateral movement.
HuntRule TeamWindowssystemHigh435Premium2026-08-19Suspicious NSPX30 DLL Side-Loading of comx3 via RsStub (via image_load)
This rule detects the RsStub.exe binary loading comx3.dll, the DLL side-loading chain that launches the NSPX30 implant by abusing a legitimate executable. Loading this attacker-supplied DLL into a trusted process delivers the AitM-enabled backdoor while evading signature checks.
HuntRule TeamWindowsimage_loadMedium92Premium2026-08-19Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
This rule detects HTTP requests to the sneakylog license verification endpoint used by the Sneaky 2FA Phishing-as-a-Service platform. Each deployed phishing kit calls the api key path on the operator infrastructure to validate its license before serving the AiTM page. Observing this callback identifies hosts interacting with the Sneaky 2FA kit infrastructure.
HuntRule TeamWebproxyLow218Premium2026-08-19Suspicious Payload Execution From systemd-private Temporary Directory on Linux
This rule detects a process executing from the per-service private temporary path /tmp/systemd-private- which Wiz observed attackers abusing to hide XMRig Sliver and Mirai payloads after exploiting the Aviatrix Controller RCE CVE-2024-50603. This is important because binaries running out of a systemd private tmp namespace are almost always malware staged to evade detection so execution from this location signals post-exploitation deployment of miners and implants.
HuntRule TeamLinuxprocess_creationHigh121Premium2026-08-19Suspicious Security Software Discovery via PowerShell SecurityCenter2 AntivirusProduct Query (via process_creation)
This rule detects PowerShell querying the root/SecurityCenter2 AntivirusProduct WMI class, the security-software discovery step Troll Stealer runs while profiling a victim before credential theft. Adversaries enumerate installed antivirus to tailor evasion, so this query outside of administrative inventory tooling is a meaningful reconnaissance indicator.
HuntRule TeamWindowsprocess_creationMedium62Premium2026-08-19Malicious Credential Hive Copy from Volume Shadow Copy
This rule detects a copy command referencing a HarddiskVolumeShadowCopy path together with a credential store name such as SAM, SYSTEM, or ntds.dit, a technique Huntress observed for extracting locked hives from a shadow copy. Attackers duplicate credential databases from the snapshot to bypass file locks before offline cracking. Copying hive files out of a shadow copy is a strong credential-access indicator.
HuntRule TeamWindowsprocess_creationHigh131Premium2026-08-19Malicious Curl to Shell Dropper from Paste Site via Command Line
This rule detects a shell command that downloads a script from a public paste site such as rentry.co or glot.io and pipes it directly into a shell interpreter. This one-line fetch-and-execute pattern is used by the OpenClaw AI skill marketplace supply chain campaign to deliver macOS stealer payloads. Detecting it exposes ingress tool transfer that bypasses on-disk staging and gives the attacker immediate code execution.
HuntRule TeamWindowsprocess_creationHigh153Premium2026-08-19Suspicious PAN-OS Exploit User-Agent for CVE-2024-0012
This rule detects HTTP requests carrying the malformed User-Agent string used in exploitation of PAN-OS CVE-2024-0012 and CVE-2024-9474. This behavior matches Operation Lunar Peek where attackers chained authentication bypass and privilege escalation against management interfaces. The distinctive rv 11.0 token differs from legitimate browsers and provides a reliable signature for exploit traffic against exposed firewalls.
HuntRule TeamWebwebserverMedium296Premium2026-08-18NitrogenLoader Sideloading via Renamed Setup Binary Loading python312.dll (via image_load)
This rule detects a setup.exe process loading python312.dll, the DLL sideloading pair used by the Nitrogen campaign where a renamed python.exe host loads a malicious NitrogenLoader DLL mirroring the exports of a genuine Python runtime. Adversaries leverage this trojanized installer bundle delivered through malvertising to stage Cobalt Strike, making detection valuable for catching the loader before beacon injection.
HuntRule TeamWindowsimage_loadMedium194Premium2026-08-18