Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,161 rules
Suspicious type Command Piping Encoded Log to Renamed git Binary (via process_creation)
This rule detects a command line that pipes the contents of glog.txt via the type command into the renamed git binary, the staging technique used by APT-C-60 to feed an encoded payload to its execution proxy. Reading a benign-looking log file and piping it into a proxied binary conceals the true payload source.
HuntRule TeamWindowsprocess_creationMedium325Premium2026-08-14Suspicious Run Key Masquerading as GoogleUpdate From Wrong Path via Registry Set (via registry_set)
This rule detects a Run key autostart entry masquerading as GoogleUpdate but pointing to a payload outside the legitimate Google update directory, a persistence and masquerading technique used by malware from MSIX installers per Red Canary. A trusted-looking name paired with the wrong file path is a high-confidence indicator of a malicious autorun disguised as software updater.
HuntRule TeamWindowsregistry_setHigh317Premium2026-08-14Suspicious HTTP POST to Local AI Malware Exfil Endpoint (via proxy)
This rule detects HTTP POST requests to the /crypto-data endpoint used by AI-assisted malware to transmit collected cryptocurrency and victim data. The specific exfiltration path combined with the POST method reflects the malware sending stolen data to its collection service.
HuntRule TeamWebproxyLow121Premium2026-08-14PowerShell Remote Download From Bunny CDN Host
This rule detects PowerShell download activity referencing a b-cdn.net Bunny CDN host, an abused delivery infrastructure in the LummaStealer campaign. Attackers stage payloads on legitimate CDN domains to blend malicious downloads with normal traffic.
HuntRule TeamWindowsps_scriptMedium103Premium2026-08-14Suspicious Interpreter Spawned by launchd from Application Bundle
This rule detects the macOS launchd process directly spawning a shell or script interpreter that executes a payload located inside an application bundle Contents/MacOS path. This behavior corresponds to the CVE-2021-30657 Gatekeeper bypass where an app lacking an Info.plist is launched without notarization checks. It lets attackers run arbitrary code while evading Gatekeeper.
HuntRule TeamMacosprocess_creationHigh52Premium2026-08-14Suspicious Lateral Movement Detection - Based on "special Groups" Feature (via security)
This rule detects scenarios where a user of a predefined set of group(s) logs on a target machine.
HuntRule TeamWindowssecurityMedium207Premium2026-08-14Suspicious prt-scan Campaign Credential Harvesting via proc environ Scan (via process_creation)
This rule detects processes reading other processes environment blocks through /proc/*/environ which the prt-scan background daemon uses to sweep memory for AWS Cloudflare Netlify and NPM tokens on CI runners. Broad scanning of /proc environ files is uncommon in normal build activity and suggests credential harvesting.
HuntRule TeamLinuxprocess_creationMedium112Premium2026-08-14Malicious IFEO Debugger Hijack of vds.exe by FishMonger
This rule detects registration of an Image File Execution Options Debugger value for vds.exe, a persistence and defense-evasion technique used by the FishMonger group deploying SprySOCKS. The activity abuses the IFEO mechanism so that a malicious binary is launched whenever the Virtual Disk Service is invoked. Detecting this key is important because it silently redirects execution of a legitimate system component to attacker-controlled code.
HuntRule TeamWindowsregistry_setHigh71Premium2026-08-14Suspicious Stately Taurus Visual Studio Code Tunnel Abuse via VSCode CLI (via process_creation)
This rule detects execution of the Visual Studio Code command line binary with the tunnel argument, which creates a remote-access tunnel back to a VSCode account. The Stately Taurus espionage group abused this feature to obtain interactive reverse-shell access to government hosts in Southeast Asia while blending in with legitimate developer traffic. Abuse of a trusted developer tool for command and control lets the actor evade network controls and persist covertly.
HuntRule TeamWindowsprocess_creationMedium102Premium2026-08-14Malicious kagent RAT Delivery via HuggingFace Space Download (via process_creation)
This rule detects a shell downloading and executing an installer script hosted on a HuggingFace Space on Linux hosts. The marimo blockchain botnet campaign delivered the kagent NKN based remote access trojan through an install-linux.sh script pulled from a HuggingFace Space domain. Piping a remote Space installer into a shell indicates malware delivery.
HuntRule TeamLinuxprocess_creationHigh153Premium2026-08-14Possible Ngrok RDP Tunnel Exposure via TCP 3389
This rule detects command lines that tunnel TCP port 3389 which exposes internal Remote Desktop Protocol to the internet. The BlackJack group used ngrok tcp 3389 to reach RDP on compromised hosts, and such tunneling enables covert lateral movement and remote interactive access.
HuntRule TeamWindowsprocess_creationMedium188Premium2026-08-14Malicious TCP Session Hijacking via rshijack
This rule detects execution of the rshijack tool used to inject data into established TCP sessions. Wiz Research observed rshijack abused inside a shared Replicate environment to hijack traffic to a central Redis instance, so its use strongly indicates adversary in the middle or lateral movement activity.
HuntRule TeamLinuxprocess_creationHigh121Premium2026-08-14Malicious Vulnerable Driver HwRwDrv Loaded for BYOVD
This rule detects loading of the HwRwDrv vulnerable driver, a bring-your-own-vulnerable-driver component observed in a Huntress-tracked Tiflux RMM malspam campaign to gain privileged kernel access. Attackers load this signed but vulnerable driver to tamper with protected processes and security tooling. Presence of this driver name is a strong indicator of BYOVD privilege escalation.
HuntRule TeamWindowsdriver_loadHigh138Premium2026-08-14Suspicious HDUtil Loader Execution with NoUac Arguments via process_creation
This rule detects the OkoBot HDUtil.exe loader running with its distinctive nouac and noattach arguments to launch further payloads. These custom flags are specific to the OkoBot framework targeting cryptocurrency wallet users. The unusual argument set is a reliable execution fingerprint for the loader.
HuntRule TeamWindowsprocess_creationHigh205Premium2026-08-14Suspicious PerfWatson2 Execution from Local AppData
This rule detects a process named PerfWatson2.exe running from a user LocalAppData directory, where the genuine Visual Studio telemetry helper never lives. CL-STA-1062 stages a masqueraded PerfWatson2.exe in LOCALAPPDATA as part of its backdoor toolset. Flagging the trusted name in this unexpected location reveals an implant impersonating a developer utility.
HuntRule TeamWindowsprocess_creationMedium131Premium2026-08-14