Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,279 rules
Malicious Enabling of Restricted Admin Mode via Registry by UAT-8837
This rule detects setting the DisableRestrictedAdmin value to zero under the Lsa key which enables Restricted Admin mode for RDP. UAT-8837 modifies this setting to enable pass-the-hash style network logons over Remote Desktop. Enabling Restricted Admin mode lets an actor authenticate with stolen hashes without knowing plaintext credentials.
HuntRule TeamWindowsregistry_setHigh50Premium2026-09-12Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
This rule detects modification of the fDenyTSConnections value to zero which enables inbound Remote Desktop connections. The DeadLock ransomware operators enable RDP and open the firewall to facilitate lateral movement. Enabling remote desktop on compromised hosts expands attacker access across the environment.
HuntRule TeamWindowsregistry_setHigh50Premium2026-09-12Suspicious Hidden Account Creation via Winlogon SpecialAccounts UserList Registry
This rule detects modification of the Winlogon SpecialAccounts UserList registry key to hide a local account from the Windows logon screen. The Chaos ransomware-as-a-service group sets a user value to 0 under this key to conceal accounts created for persistent access. Hiding accounts from the logon interface is a defense-evasion technique used to maintain covert access.
HuntRule TeamWindowsregistry_setHigh20Premium2026-09-12Malicious Service DLL Hijack for Persistence via Lotus Blossom
This rule detects modification of the ServiceDll parameter of the legitimate TapiSrv swprv or AppMgmt services which the Lotus Blossom espionage group abuses to load its Sagerunex backdoor under a trusted service host process. Rewriting the ServiceDll of these built in services is a stealthy persistence and defense evasion technique.
HuntRule TeamWindowsregistry_setHigh50Premium2026-09-12Suspicious Autorun Registry Persistence via sausageLoop Run Key
This rule detects creation of a Run key value named sausageLoop or pointing to ffUpdaar.exe as used by the lumuiUpdater loader dropped through copyright infringement phishing lures. Attackers abuse HKCU autorun keys to persist the infostealer loader across reboots which makes this an early foothold indicator worth investigating.
HuntRule TeamWindowsregistry_setHigh50Premium2026-09-12Suspicious COM Hijack Via InprocServer32 Modification
This rule detects modification of a CLSID InprocServer32 registry value that points to a DLL in a user-writable directory. UAT-5647 hijacked COM objects by rewriting InprocServer32 CLSID keys to load RomCom components for persistence. Redirecting an InprocServer32 default value to an attacker DLL causes trusted applications to load malicious code providing stealthy persistence and execution.
HuntRule TeamWindowsregistry_setHigh20Premium2026-09-12Malicious BabyLockerKZ Run Key Persistence
This rule detects creation of a CurrentVersion Run value named BabyLockerKZ. This MedusaLocker variant registered a BabyLockerKZ autorun entry to persist across reboots. A Run key carrying the malware family name is a direct persistence indicator tying host activity to this ransomware operation.
HuntRule TeamWindowsregistry_setHigh00Premium2026-09-12Malicious Defender Disable And Executable Exclusion Via Registry
This rule detects registry modifications that disable Microsoft Defender or add a broad executable-file exclusion. BlackByte tampered with Defender policy keys to disable protection and exclude all .exe files before deploying its ransomware. Disabling antivirus and whitelisting entire file types via the registry is a defense-evasion step that clears the way for payload execution.
HuntRule TeamWindowsregistry_setHigh20Premium2026-09-12Malicious FodHelper UAC Bypass via ms-settings Shell Command Hijack (via registry_set)
This rule detects creation of the HKCU ms-settings shell open command key which the CoralRaider intrusion uses together with FodHelper to bypass User Account Control and run code with elevated privileges. This fileless UAC bypass abuses auto-elevating trusted binaries and is a reliable privilege escalation and defense evasion technique.
HuntRule TeamWindowsregistry_setHigh30Premium2026-09-12Malicious Ctrlpanel Run Key Autostart Persistence (via registry_set)
This rule detects creation of a Run key value named Ctrlpanel pointing at the OfflRouter dropper which the virus uses to survive reboot and re-infect the host. Autostart Run key persistence with an attacker-controlled binary is a core mechanism for maintaining foothold on Windows endpoints.
HuntRule TeamWindowsregistry_setHigh30Premium2026-09-12Malicious TinyTurla ServiceDll Registration via svchost Group (via registry_set)
This rule detects the sdm service ServiceDll parameter being pointed at dcmd.dll, the loader DLL for the TinyTurla backdoor executed through a custom svchost group. Setting ServiceDll to the malicious module completes the service-based persistence used in the full kill chain.
HuntRule TeamWindowsregistry_setHigh40Premium2026-09-12Malicious COM Hijacking via TinyTurla CLSID InprocServer32 (via registry_set)
This rule detects registration of the TinyTurla-NG CLSID {C2796011-...} InprocServer32 under the current user Classes hive, a COM hijacking persistence mechanism used by Turla. Loading the backdoor DLL through a hijacked COM object survives reboots and runs under a trusted host process.
HuntRule TeamWindowsregistry_setHigh00Premium2026-09-12Malicious WDigest Credential Caching Enabled via Registry (via registry_set)
This rule detects the WDigest UseLogonCredential value being set to 1, forcing plaintext credentials back into LSASS memory, as done by Lazarus in Operation Blacksmith. Re-enabling WDigest caching prepares the host for subsequent LSASS memory theft of cleartext passwords.
HuntRule TeamWindowsregistry_setHigh20Premium2026-09-12Malicious UAC Disable via EnableLUA Registry Modification (via registry_set)
This rule detects the EnableLUA registry value being set to 0, which disables User Account Control, as performed by Phobos ransomware affiliates. Disabling UAC removes elevation prompts and eases silent execution of privileged operations during the intrusion.
HuntRule TeamWindowsregistry_setHigh00Premium2026-09-12Persistence Run Key Pointing to svchost.exe in AppData Roaming
This rule detects a Run key autostart entry whose value references svchost.exe located under a user AppData Roaming path. The Yashma ransomware established persistence through a Run key pointing at its dropped svchost.exe masquerade copy. This lets the ransomware survive reboots by abusing a trusted process name from an illegitimate location.
HuntRule TeamWindowsregistry_setHigh40Premium2026-09-12