Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,151 rules
Malicious Curl to Shell Dropper from Paste Site via Command Line
This rule detects a shell command that downloads a script from a public paste site such as rentry.co or glot.io and pipes it directly into a shell interpreter. This one-line fetch-and-execute pattern is used by the OpenClaw AI skill marketplace supply chain campaign to deliver macOS stealer payloads. Detecting it exposes ingress tool transfer that bypasses on-disk staging and gives the attacker immediate code execution.
HuntRule TeamWindowsprocess_creationHigh153Premium2026-08-19Suspicious PAN-OS Exploit User-Agent for CVE-2024-0012
This rule detects HTTP requests carrying the malformed User-Agent string used in exploitation of PAN-OS CVE-2024-0012 and CVE-2024-9474. This behavior matches Operation Lunar Peek where attackers chained authentication bypass and privilege escalation against management interfaces. The distinctive rv 11.0 token differs from legitimate browsers and provides a reliable signature for exploit traffic against exposed firewalls.
HuntRule TeamWebwebserverMedium296Premium2026-08-18NitrogenLoader Sideloading via Renamed Setup Binary Loading python312.dll (via image_load)
This rule detects a setup.exe process loading python312.dll, the DLL sideloading pair used by the Nitrogen campaign where a renamed python.exe host loads a malicious NitrogenLoader DLL mirroring the exports of a genuine Python runtime. Adversaries leverage this trojanized installer bundle delivered through malvertising to stage Cobalt Strike, making detection valuable for catching the loader before beacon injection.
HuntRule TeamWindowsimage_loadMedium194Premium2026-08-18Suspicious SMB DLL Lateral Movement
Detection of potential us of SMB to transfer DLL's into the ProgramData folder of hosts for purposes of lateral movement.
HuntRule TeamZeeksmb_filesMedium96Premium2026-08-18Suspicious Python or uv Execution Spawned by AI CLI Assistant
This rule detects the python or uv interpreter launched as a child of an AI command line assistant such as the Claude or Gemini CLI which reflects adversaries directing these agents to run local code during hands on abuse. Because AI CLI tools can execute arbitrary commands on behalf of a user they can be steered into running attacker supplied scripts. Detecting unexpected interpreter children of AI assistants supports hunting for this emerging abuse.
HuntRule TeamWindowsprocess_creationLow163Premium2026-08-18Suspicious RegSvcs Reflective .NET Load from Fake Update Chain
This rule detects PowerShell spawning RegSvcs.exe which is abused as an injection target for reflectively loaded .NET payloads decoded from disguised png files. This behavior was seen in fake browser update campaigns delivering BitRAT and Lumma Stealer. Attackers pick RegSvcs as a signed host to execute malicious code under a trusted image name.
HuntRule TeamWindowsprocess_creationHigh397Premium2026-08-18Suspicious HelloNet SSH Reverse Tunnel via frontpage.exe (via process_creation)
This rule detects execution of frontpage.exe with an SSH reverse port-forwarding argument, a renamed SSH client used by the HelloNet campaign to establish an outbound reverse tunnel on port 8443. Attackers use such tunnels to expose internal services and maintain covert remote access to compromised hosts.
HuntRule TeamWindowsprocess_creationHigh399Premium2026-08-18Malicious Credential Harvesting via LaZagne (via process_creation)
This rule detects command lines invoking the LaZagne credential-recovery tool, which extracts passwords from browsers, mail clients, Wi-Fi and dozens of other stores in one pass. LaZagne is a credential-access tool observed in intrusions profiled in the Red Canary Threat Detection Report. Detecting its execution surfaces bulk credential theft on the host.
HuntRule TeamWindowsprocess_creationHigh82Premium2026-08-18Suspicious AppleScript Execution Spawning a Shell via Osascript
This rule detects osascript running an AppleScript that invokes do shell script to launch shell commands, a bridge XCSSET v4.0 uses to run in-memory modules and shell payloads on macOS. This pattern lets the malware execute code while presenting as ordinary automation. Detecting the AppleScript to shell bridge exposes scripted execution used to run the stealer components.
HuntRule TeamMacosprocess_creationMedium197Premium2026-08-18Suspicious AWS Administrator Policy Attachment via CloudTrail (via aws)
This rule detects the attachment of the administrator access managed policy to an IAM user in CloudTrail. During the intrusion the attacker created a backdoor admin user and attached administrator access to retain full control of the account. Administrator policy attachments should be reconciled against approved access change requests.
HuntRule TeamAwscloudtrailMedium112Premium2026-08-18Malicious Shadow Copy and Backup Deletion for Ransomware Recovery Inhibition
This rule detects deletion of volume shadow copies and backup catalogs through vssadmin wmic and wbadmin which Phobos ransomware runs before encryption to prevent victims from restoring their files. Inhibiting system recovery is a common precursor to file encryption and warrants immediate response.
HuntRule TeamWindowsprocess_creationHigh133Premium2026-08-18Suspicious mshta Execution of Remote HTA Payload
This rule detects mshta fetching and executing an HTA from a remote URL, a proxy execution step in ACR Stealer intrusion chains that leads to PowerShell staging. Running a remote HTML application through a trusted Windows binary evades application controls and initiates the infostealer delivery chain.
HuntRule TeamWindowsprocess_creationHigh351Premium2026-08-18Suspicious Startup Folder Redirection via User Shell Folders by MuddyWater (via registry_set)
This rule detects modification of the Startup value under the Explorer User Shell Folders registry key, a persistence technique MuddyWater uses to redirect the startup directory so its payload autoruns at logon. Tampering with this key silently changes where Windows looks for startup items. Detecting the change exposes stealthy persistence.
HuntRule TeamWindowsregistry_setMedium102Premium2026-08-18Malicious Octo Tempest Credential Theft Tooling (via process_creation)
This rule detects execution of credential theft tools including LaZagne gosecretsdump and ADFSDump. Octo Tempest used these utilities to harvest local secrets and AD FS token-signing material for federation abuse.
HuntRule TeamWindowsprocess_creationHigh397Premium2026-08-18Masquerading Cuckoo Stealer LaunchAgent Masquerading as Homebrew Updater (via file_event)
This rule detects creation of a LaunchAgent plist named com.homebrew.brewupdater used by Cuckoo Stealer to persist on macOS after a fake Homebrew ClickFix lure. Adversaries leverage a Homebrew-themed LaunchAgent label so the stealer relaunches at login while appearing to be a legitimate package updater.
HuntRule TeamMacosfile_eventHigh2510Premium2026-08-18