Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,420 rules
Malicious ESX Admins Domain Group Creation via Process Creation
This rule detects creation of or membership changes to a domain group named ESX Admins using net.exe, the core exploitation step for CVE-2024-37085 in which ESXi hypervisors grant full administrative access to any member of that group. Multiple ransomware operators created this group to obtain hypervisor admin rights and mass-encrypt virtual machines.
HuntRule TeamWindowsprocess_creationHigh123Premium2026-08-11Malicious Secretdump Password Dumping via SMB Admin Share (via security)
This rule detects execute Secretdump in order to remotely dump credentials over SMB.
HuntRule TeamWindowssecurityHigh103Premium2026-08-11WezRat Command and Control HTTP URI Pattern
This rule detects HTTP requests matching the WezRat command and control URI scheme including the distinctive wez Agent InsMch endpoint. The backdoor tasks and reads data through these fixed URI paths while spoofing a firefox user agent. Detecting the URI pattern reveals active command and control traffic.
HuntRule TeamWebproxyHigh329Premium2026-08-11Malicious LSASS Process Dump by a Non System Account (via security)
This rule detects will dump the LSASS memory content using tools like Mimikatz, ProcDump, TaskMgr, ...
HuntRule TeamWindowssecurityHigh162Premium2026-08-11Suspicious AWS Inline Policy Granting Full S3 Access
This rule detects a PutUserPolicy call that attaches an inline IAM policy granting s3 wildcard permissions to a user. It maps to privilege escalation observed in S3 attack chains where an operator self-grants full bucket access before collection. Detecting it exposes IAM policy tampering aimed at cloud data theft.
HuntRule TeamAwscloudtrailHigh416Premium2026-08-10Malicious Arkanix Stealer C2 Communication via Custom User-Agent
This rule detects outbound HTTP traffic carrying the hardcoded User-Agent string used by the Arkanix C++ and Python infostealer. Kaspersky observed Arkanix identifying itself to its panel with the ArkanixStealer client string while requesting stealer and hidden VNC modules. This distinctive agent is a reliable indicator of an infected host communicating with the stealer backend to receive payloads and exfiltrate credentials.
HuntRule TeamWebproxyHigh102Premium2026-08-10Malicious Payload Assembly via MZ Header Prepend and copy Concatenation (via process_creation)
This rule detects the technique of writing an MZ header and concatenating it with a downloaded blob using copy to reconstruct an executable, used by Bitter APT against PTCL to rebuild the WmRAT payload. The disguised binary is downloaded as a PNG then reassembled on disk. This MZ-prepend and copy pattern is a distinctive evasion behavior.
HuntRule TeamWindowsprocess_creationHigh82Premium2026-08-10Malicious Mini Shai-Hulud TanStack C2 git-tanstack and getsession (via dns_query)
This rule detects DNS lookups for the git-tanstack.com payload host and getsession.org session channels used by the Mini Shai-Hulud TanStack npm compromise to fetch its Bun payload and exfiltrate stolen tokens. A resolution indicates the preinstall dropper has executed on a developer or CI host.
HuntRule TeamNetworkdns_queryHigh133Premium2026-08-10Malicious Exchange Group Membership Change to Perform DCsync Attack (via security)
This rule detects adds its account into a sensitive Exchange group to obtain "Replicating Directory Changes /all" and perform DCsync attack.
HuntRule TeamWindowssecurityHigh351Premium2026-08-10Suspicious Rundll32 Execution of WebDAV-Hosted DLL via Entry Export (via process_creation)
This rule detects rundll32.exe loading a DLL from a WebDAV UNC path and calling the exported function named Entry. Strela Stealer uses this technique to execute a fileless DLL payload delivered over WebDAV.
HuntRule TeamWindowsprocess_creationHigh123Premium2026-08-10Malicious Cobalt Strike Malleable C2 URI Beacon via Proxy
This rule detects HTTP requests to the Cobalt Strike malleable profile URI /1/events/com.amazon.csm.csa.prod observed in the Nitrogen 2.0 campaign. This fixed path masquerades as Amazon telemetry to blend with normal traffic. Detecting it identifies beaconing to Cobalt Strike infrastructure.
HuntRule TeamWebproxyHigh4010Premium2026-08-10Suspicious Bitdefender Binary Sideloading log.dll Loader
This rule detects the legitimate Bitdefender bds.exe loading a malicious log.dll from its directory, a DLL sideloading loader used by the Billbug espionage group to decrypt and run its backdoor payload.
HuntRule TeamWindowsimage_loadHigh577Premium2026-08-10Suspicious Unattended AnyDesk Silent Install with Auto-Start
This rule detects a silent unattended AnyDesk installation configured to start with Windows, a remote-access-tool deployment pattern abused by threat actors to establish persistent covert remote control of a compromised host. The combination of silent install and auto-start flags indicates non-interactive attacker-driven deployment rather than a normal user setup.
HuntRule TeamWindowsprocess_creationHigh328Premium2026-08-09Malicious Tpwinprn DLL Loaded via Renamed rundll32 by Diplomatic Specter
This rule detects execution referencing the Tpwinprn.dll payload run through a renamed copy of rundll32 from SysWOW64, a loader behavior tied to the Operation Diplomatic Specter Chinese cyberespionage campaign. Renaming a signed system binary to proxy DLL execution helps the actor evade image-name detections. Detecting this reveals masqueraded loader activity delivering the espionage toolkit.
HuntRule TeamWindowsprocess_creationHigh152Premium2026-08-09Suspicious Script Host Spawning PowerShell Or Cmd via Gootloader
This rule detects wscript.exe or cscript.exe launching PowerShell or cmd, matching the Gootloader chain where a malicious .JS extracted from a ZIP hands off to a shell. Gootloader delivers this JavaScript through SEO-poisoned search results posing as document templates. A Windows script host spawning a command interpreter is rarely benign on endpoints.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-08-09