Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,421 rules
Malicious Exchange or SharePoint Worker Process Spawning Command Shell from Web Shell (via process_creation)
This rule detects the IIS worker process w3wp.exe spawning command shells or the net utility on on-premises Exchange or SharePoint servers, the web-shell execution behavior these attacks use after deploying pages such as getidtoken.aspx or signout.aspx. Adversaries drop web shells into OWA auth and LAYOUTS directories to run commands in the server context, so command interpreters descending from w3wp indicate server-side compromise.
HuntRule TeamWindowsprocess_creationHigh187Premium2026-08-13Malicious BLOODALCHEMY DLL Side-Loading via BrDifxapi Executable
This rule detects DLL side-loading where the BrDifxapi executable loads a BrLogAPI DLL which is the loading chain the BLOODALCHEMY backdoor abuses to execute its payload. Pairing this specific host binary with this specific module name reflects a known malicious side-loading combination rather than legitimate Brother software behavior.
HuntRule TeamWindowsimage_loadHigh411Premium2026-08-12BitLocker Feature Configuration - Reg via Command (via process_creation)
This rule detects configures BitLocker for ransomware purposes.
HuntRule TeamWindowsprocess_creationHigh269Premium2026-08-12Malicious Bring-Your-Own-Vulnerable-Driver Load for EDR Killing
This rule detects loading of vulnerable signed drivers abused by EDR-killer tooling including BdApiUtil.sys, TfSysMon.sys, K7RKScan.sys, ThrottleStop.sys and HwRwDrv.sys. Attackers load these drivers to gain kernel primitives for terminating security processes via DeviceIoControl, so their presence signals an imminent defense-disabling attempt.
HuntRule TeamWindowsdriver_loadHigh142Premium2026-08-12Suspicious RegAsm or RegSvcs Spawned by Script Host (via process_creation)
This rule detects RegAsm.exe or RegSvcs.exe launched by a script host such as PowerShell, wscript, or cscript, the injection target abused in the Cascading Shadows phishing chain. The actor hollows these signed .NET utilities to run Agent Tesla, Remcos, or XLoader while evading defenses through trusted binary proxy execution.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-08-12Suspicious Scheduled Task Masquerading as Edge Update Running as SYSTEM via schtasks
This rule detects creation of a scheduled task that masquerades as a Microsoft Edge update while running as SYSTEM. This technique was observed in a DLL hijacking campaign analyzed by Kaspersky where attackers created a task named \Microsoft\Windows\Edge\Edgeupdates to gain persistent SYSTEM-level execution. Abusing a legitimate-looking task name in the wrong namespace lets an adversary blend malicious persistence with benign updater activity.
HuntRule TeamWindowsprocess_creationHigh131Premium2026-08-12Suspicious Bootkitty Rootkit Component Drop under opt via File System
This rule detects creation of the Bootkitty user-space and kernel components /opt/injector.so, /opt/observer, and /opt/rootkit_loader.ko. These fixed paths are dropped by the first known UEFI bootkit for Linux to load a kernel module and inject a shared object through the boot process. Their presence indicates a UEFI bootkit compromise.
HuntRule TeamLinuxfile_eventHigh452Premium2026-08-12Malicious PowerShell Exfiltration to webhook.site Following WSUS Exploitation
This rule detects PowerShell using Invoke-WebRequest to PUT data to the webhook.site service, the exfiltration channel observed after Windows Server Update Services remote code execution. Attackers stage discovery output and upload it to a disposable webhook endpoint for collection. Outbound PUT requests to webhook.site from PowerShell are a strong exfiltration indicator.
HuntRule TeamWindowsps_scriptHigh131Premium2026-08-12Malicious Scheduled Task Deploying DYNOWIPER Payload (via process_creation)
This rule detects scheduled task creation referencing the DYNOWIPER wiper payload filenames used against Poland's energy sector. Observed in Elastic Security Labs telemetry where schtask.exe creates tasks running dynacom_update.exe or Source.exe to launch destructive file-corruption routines, enabling persistence and destructive execution.
HuntRule TeamWindowsprocess_creationHigh425Premium2026-08-12ValleyRAT DLL Sideloading via Douyin Loading Non-Standard DLL (via image_load)
This rule detects the legitimate Douyin (TikTok) binary loading a tier0.dll or sscronet.dll, the DLL sideloading behavior used by ValleyRAT to run its loader from the Common Files System directory under a signed application. Adversaries leverage sideloading against a trusted binary to execute shellcode that injects into svchost.exe, making early detection critical for surfacing the intrusion before keylogging and remote-control commands begin.
HuntRule TeamWindowsimage_loadHigh183Premium2026-08-11Suspicious Scheduled Task Creation for HijackLoader Persistence (via process_creation)
This rule detects the creation of a scheduled task named mlt_Archive through schtasks, the persistence mechanism observed in the IObit side-loading intrusion delivering AsyncRAT. This task name is not associated with legitimate software.
HuntRule TeamWindowsprocess_creationHigh172Premium2026-08-11Malicious Stopping of Security or Backup Services Before Impact (via process_creation)
This rule detects service-control commands (net stop, sc stop or Stop-Service) targeting antivirus, EDR, SQL or backup services, a defense-impairment step ransomware operators run to disable protection and free locked files before encryption. Stopping security and backup services is an impact-precursor technique in the Red Canary Threat Detection Report. Detecting these commands surfaces the final staging move before data is encrypted.
HuntRule TeamWindowsprocess_creationHigh61Premium2026-08-11Malicious SCMBanker ClickFix Payload Fetch via Curl Piped to Cmd
This rule detects a curl download of a remote resource piped directly into a cmd.exe interpreter which is the ClickFix delivery step of the SCMBanker Mexican banking-fraud toolkit. Adversaries trick victims into pasting a clipboard command that fetches and runs a staged validation script. Catching this pipe-to-interpreter pattern exposes the initial foothold before the wider toolkit is pulled.
HuntRule TeamWindowsprocess_creationHigh82Premium2026-08-11Suspicious BadIIS Service Persistence Masquerading as System Services
This rule detects creation of Windows services under the BadIIS masquerading names Winlogin, FaxService or AudiosService, which imitate legitimate system service names through subtle misspellings. The commodity BadIIS ecosystem installs services under these deceptive names to persist and blend into service inventories. Creation of a service with these typo-squatted names indicates BadIIS persistence.
HuntRule TeamWindowsprocess_creationHigh349Premium2026-08-11Malicious Panamorfi DDoS JAR Execution via Java (via process_creation)
This rule detects the Panamorfi campaign running its Java payloads conn.jar and mineping.jar after compromising an exposed Jupyter notebook. conn.jar connects to a Discord channel for command and control while mineping.jar launches TCP flood denial of service attacks. These jar names are unique to the campaign.
HuntRule TeamLinuxprocess_creationHigh146Premium2026-08-11