Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
94 rules
RedCurl QWCrypt Ransomware Execution with Hyper-V Targeting Flags
This rule detects the QWCrypt ransomware binary launched with its distinctive command line flags that target Hyper-V virtual machines while excluding gateway hosts and disabling shadow copies during encryption.
HuntRule TeamWindowsprocess_creationHigh236Premium2026-07-06Suspicious DeadLock Ransomware C2 Proxy Request to prrq.php Endpoint (via proxy)
This rule detects HTTP requests to the /prrq.php proxy endpoint used by DeadLock ransomware to reach C2 proxy servers whose addresses are rotated through Polygon smart contracts per Group-IB. Adversaries route control and ransom-negotiation traffic through these proxy PHP endpoints, so requests to this path signal DeadLock C2 activity.
HuntRule TeamWebproxyMedium202Premium2026-06-26Suspicious Vulnerable Driver Load for BYOVD Abuse by DragonForce Ransomware (via driver_load)
This rule detects loading of the TrueSight.sys or RentDrv.sys vulnerable drivers that DragonForce abuses in a bring-your-own-vulnerable-driver technique to call ZwTerminateProcess and disable endpoint protection. Attackers exploit these signed drivers to kill security agents from kernel space. Flagging their load exposes tampering with defensive tooling.
HuntRule TeamWindowsdriver_loadMedium3710Premium2026-06-25Malicious NTDS Database Dump via NTDSUtil in BlackSuit Ransomware
This rule detects ntdsutil being used to create an installation from media (IFM) copy of the Active Directory database, a credential-access technique observed in BlackSuit ransomware intrusions. Dumping NTDS.dit gives operators every domain hash for offline cracking and full domain compromise, making this a critical detection.
HuntRule TeamWindowsprocess_creationHigh403Premium2026-06-19Suspicious Password-Protected Archive Extraction of Everything64.dll by Elpaco Ransomware
This rule detects 7-Zip command-line extraction of a password-protected archive that deploys the Everything64.dll component. Elpaco ransomware, a Mimic variant, abuses the legitimate Everything search library for fast file enumeration prior to encryption. Password-protected extraction of this specific payload indicates staging of ransomware tooling on the host.
HuntRule TeamWindowsprocess_creationHigh393Premium2026-06-17Malicious Chaos Ransomware Ransom Note and Encrypted Extension (via file_event)
This rule detects Chaos C++ ransomware writing the ransom note READ_IT.txt into the AppData folder and appending the .chaos extension to encrypted files. Creation of these artifacts indicates active encryption by the locker. The malware also drops debug logs under the temp folder.
HuntRule TeamWindowsfile_eventHigh229Premium2026-06-12Malicious Ransomware Encryptor Execution with Password Gate (via process_creation)
This rule detects a binary launched with password and no-admin arguments characteristic of the Qilin ransomware encryptor. Operators executed the encryptor with a long password and a no-admin flag to skip UAC prompts during mass encryption.
HuntRule TeamWindowsprocess_creationHigh296Premium2026-06-12Suspicious Run Key Persistence via Masqueraded svhostss Value by Elpaco Ransomware
This rule detects creation of a Run key value named svhostss which masquerades as the legitimate Windows svchost process. Elpaco ransomware, a Mimic variant, uses this autorun entry to persist across reboots. The deceptive naming combined with an autorun context indicates persistence for a ransomware payload.
HuntRule TeamWindowsregistry_setHigh93Premium2026-06-12Malicious Akira Ransomware Encryption Execution (via process_creation)
This rule detects the Akira ransomware encryptor invoked with its characteristic path and share targeting switches. These combined command-line flags drive selective encryption across local and network locations. Detection here indicates active encryption and imminent impact on the environment.
HuntRule TeamWindowsprocess_creationHigh3710Premium2026-06-07Malicious Event Log Tampering via wevtutil Channel Disable by FunkSec Ransomware (via process_creation)
This rule detects use of wevtutil to disable the Security and Application event log channels, a defense-evasion action performed by FunkSec ransomware to blind logging before encryption. Adversaries turn off event channels so their tampering, service termination and encryption activity is not recorded for responders.
HuntRule TeamWindowsprocess_creationHigh133Premium2026-06-03Malicious Akira Ransomware Encryptor Execution (via process_creation)
This rule detects execution of the Akira ransomware encryptor invoked with its characteristic path, share and encryption-percentage arguments. Operators launched akira.exe and locker.exe with the -n, -p and -s flags to encrypt local drives and network shares.
HuntRule TeamWindowsprocess_creationHigh173Premium2026-05-29Suspicious LocalAccountTokenFilterPolicy Enabled via Registry by BlackByte Ransomware
This rule detects the LocalAccountTokenFilterPolicy registry value being set to one, which disables remote UAC filtering and grants full administrative access for local accounts over the network. BlackByte ransomware sets this value to ease lateral movement.
HuntRule TeamWindowsregistry_setMedium132Premium2026-05-25Malicious Ransomware Self-Deletion via Ping Loopback and Del
This rule detects a command line that pings the unusual loopback address 127.0.0.7 and then deletes a file, a self-removal and timing-delay technique used by Mamona ransomware after encryption. The non-standard loopback octet combined with a delete command is a strong anti-forensic indicator.
HuntRule TeamWindowsprocess_creationHigh172Premium2026-05-24Suspicious Windows Firewall Disabled via netsh by BlackByte Ransomware
This rule detects netsh disabling all Windows Firewall profiles, a defense evasion action used by BlackByte ransomware to remove network restrictions before spreading. Turning off all firewall profiles is rarely legitimate on managed endpoints.
HuntRule TeamWindowsprocess_creationMedium83Premium2026-05-22Malicious Windows Defender Service Disable via sc.exe by Nova Ransomware
This rule detects sc.exe being used to disable the WinDefend service by setting its start type to disabled, a defense evasion step performed by Nova ransomware before encryption. Disabling the Defender service removes real-time protection from the host.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-05-18