Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,424 rules
Malicious Tool Execution from inetpub Web Root Directory
This rule detects execution of binaries from the inetpub pub directory, where the DynoWiper actor staged scheduling and update tools such as schtask.exe and update executables after web-server compromise. Legitimate processes rarely execute from inside the IIS web root, so a running binary there points to post-exploitation tooling.
HuntRule TeamWindowsprocess_creationHigh112Premium2026-08-20Malicious Office 365 Email Rule Breach - On Behalf (via office365)
This rule detects attempt to hide emails in order to perform phishing attacks by replacing, for example, financial information from the original email with another email containing attacker's financial information. This technique may also be used to avoid specific email notification to be received by end users in case, for example, of an ongoing breach.
HuntRule TeamAzureoffice365High81Premium2026-08-20Malicious regsvcs LOLBin Loading Ransomware DLL from UNC Path
This rule detects the regsvcs.exe living-off-the-land binary being used to load and install a DLL from a UNC network path, matching SafePay ransomware deployment via regsvcs proxy execution. Attackers abuse regsvcs to run their encryptor DLL while bypassing application controls. Loading a DLL over UNC through regsvcs is not a legitimate developer workflow.
HuntRule TeamWindowsprocess_creationHigh175Premium2026-08-20Suspicious Rundll32 Executing DLL Start Export With Control Flags
This rule detects rundll32.exe calling a DLL Start export together with WarmCookie control flags such as /p /u or /update. WarmCookie also known as BadSpace was launched through rundll32 invoking its Start export with these command switches. The Start export paired with these operational flags is a distinctive WarmCookie loader signature for proxied malicious DLL execution.
HuntRule TeamWindowsprocess_creationHigh223Premium2026-08-20Malicious Reverse Shell Spawned by Web Server User (via process_creation)
This rule detects the web server account www-data launching an interactive reverse shell, as seen in the compromised-container forensics case following web application exploitation. A shell with a network redirect running as the web user indicates active remote control. This behavior is rarely legitimate for a service account.
HuntRule TeamLinuxprocess_creationHigh449Premium2026-08-20Malicious NetSupport RAT Execution From Public Folder via Process Creation
This rule detects the NetSupport client32.exe running with its client32.ini configuration from the Users Public directory, a placement pattern characteristic of NetSupport Manager abused as a remote access trojan. Attackers deploy the legitimate remote control tool from world-writable locations to gain hands-on-keyboard access while blending in with sanctioned software, so this path is a strong indicator of RAT abuse.
HuntRule TeamWindowsprocess_creationHigh123Premium2026-08-19Masquerading Konni Registry Run Key Launching Wscript JavaScript from ProgramData (via registry_set)
This rule detects a CurrentVersion Run autorun value whose command runs wscript with the JavaScript engine against a script staged in ProgramData, the persistence behavior of a Konni AsyncRAT chain registered as GUpdate2 or SUpdate. Adversaries leverage the run key with the scripting host to relaunch their JavaScript loader at logon while masquerading as an updater, making early detection critical for surfacing persistence before AsyncRAT reconnects.
HuntRule TeamWindowsregistry_setHigh361Premium2026-08-19Obfuscated XE Group Reflective Loader via PowerShell Spawned by IIS Worker Process (via process_creation)
This rule detects the IIS worker process w3wp.exe spawning a hidden PowerShell that runs a base64-encoded reflective loader, the in-memory execution step XE Group used after webshell access to launch Meterpreter. A web server process launching an obfuscated hidden PowerShell is a strong indicator of post-exploitation code execution.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-08-19Malicious Sticky Key Sethc Command for Replacement by CMD (via process_creation)
This rule detects replace the original sethc.exe file by cmd.exe.
HuntRule TeamWindowsprocess_creationHigh438Premium2026-08-19Malicious Lynx Ransomware Encrypted File Extension Creation (via file_event)
This rule detects creation of files carrying the .LYNX extension appended by the Lynx ransomware encryptor as reported by Group-IB. Adversaries rename encrypted files with this extension during impact, so a burst of these writes indicates active ransomware encryption on the host.
HuntRule TeamWindowsfile_eventHigh163Premium2026-08-19Suspicious DLL Sideloading via Fake ApowerREC.exe Loading lastbld2Base.dll via Winos (via image_load)
This rule detects the Winos 4.0 loader using a fake ApowerREC.exe to side load the malicious lastbld2Base.dll through its DllMain during initial execution. The pairing of this screen recorder binary with that DLL name is specific to the campaign. It launches the in memory implant.
HuntRule TeamWindowsimage_loadHigh329Premium2026-08-19Possible Sitecore Experience Platform Pre-Auth RCE via TypeConfuseDelegate Gadget (via webserver)
This rule detects POST requests to the Sitecore Reporting Report.ashx handler carrying a parameters XML body with NetDataContractSerializer and TypeConfuseDelegate gadget markers. This is the pre-auth deserialization RCE CVE-2021-42237 that reaches Process.Start on the server. Detecting it exposes code-execution attempts against internet-facing Sitecore Experience Platform instances.
HuntRule TeamWebwebserverHigh4310Premium2026-08-19KrbRelayUp Service Installation - Native (via system)
This rule detects escalate privileges while abusing KrbRelayUp attack.
HuntRule TeamWindowssystemHigh398Premium2026-08-19Suspicious Service Installation Masquerading as winupd
This rule detects installation of a Windows service named winupd, a masquerade used by the INC Ransom group to run a renamed PsExec binary under a plausible Windows-update name. Service creation with this deceptive name is not expected from legitimate software and indicates hands-on-keyboard execution and lateral movement.
HuntRule TeamWindowssystemHigh475Premium2026-08-19Suspicious Payload Execution From systemd-private Temporary Directory on Linux
This rule detects a process executing from the per-service private temporary path /tmp/systemd-private- which Wiz observed attackers abusing to hide XMRig Sliver and Mirai payloads after exploiting the Aviatrix Controller RCE CVE-2024-50603. This is important because binaries running out of a systemd private tmp namespace are almost always malware staged to evade detection so execution from this location signals post-exploitation deployment of miners and implants.
HuntRule TeamLinuxprocess_creationHigh151Premium2026-08-19