Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,420 rules
Suspicious Novaservice Binary Executing From Public User Directory (via process_creation)
This rule detects execution of novaservice.exe from within the public user profile Documents or Downloads directories, a masquerade used by Boggy Serpens to run implant components from a world-writable location. A service-like binary executing from a user data path rather than a protected system directory indicates a planted payload.
HuntRule TeamWindowsprocess_creationHigh344Premium2026-08-05Malicious NTDS Extraction via NetExec (via process_creation)
This rule detects the NetExec nxc binary invoking its NTDS module over SMB to extract the Active Directory database. This was used to steal domain credential hashes en masse before ransomware deployment. Bulk NTDS extraction provides every domain account hash and enables full domain takeover.
HuntRule TeamWindowsprocess_creationHigh153Premium2026-08-05Possible FortiOS Authentication Bypass via local_access_token on WebSocket CLI Endpoint (via webserver)
This rule detects exploitation of FortiOS and FortiProxy CVE-2024-55591 where an unauthenticated request to the Node.js websocket CLI endpoint supplies a local_access_token to bypass session validation and gain super_admin access. The combination of the ws cli path and the token parameter is not seen in normal administration.
HuntRule TeamWebwebserverHigh142Premium2026-08-05Malicious VoidLink Rootkit Dropper Artifacts via Filesystem (via file_event)
This rule detects the creation of VoidLink dropper artifacts prefixed with vl in temporary and shared memory directories on Linux hosts. The VoidLink rootkit stages its components as hidden vl_ files under /tmp and /dev/shm before loading its kernel module. Files matching this naming pattern indicate rootkit staging activity.
HuntRule TeamLinuxfile_eventHigh131Premium2026-08-05Suspicious msxsl Execution with Text Script Dropper
This rule detects the msxsl utility being used to process a txt file as a script transformation. More_eggs operators abused msxsl with txt hosted JScript droppers to execute code outside normal script interpreters. This LOLBIN abuse bypasses application controls that only watch common scripting hosts.
HuntRule TeamWindowsprocess_creationHigh172Premium2026-08-05Malicious Mirage Kitten C2 Communication via Keyboard-Walk URIs (via proxy)
This rule detects HTTP requests to the distinctive keyboard-walk URI paths used by Mirage Kitten malware for command-and-control against Middle East and Africa targets. These fixed, non-dictionary URI stems are strong C2 indicators and their presence in web traffic points to active beaconing from a compromised host.
HuntRule TeamWebproxyHigh161Premium2026-08-05Suspicious VBScript Launcher Execution via Wscript for Mining Operation (via process_creation)
This rule detects wscript executing the sysdata.vbs launcher used by the Monero mining operation to stage its payload and injection routine. Observed in the Elastic Security Labs fake-installer campaign where sysdata.vbs kicks off process injection into conhost or explorer to run the XMRig miner covertly.
HuntRule TeamWindowsprocess_creationHigh82Premium2026-08-05Suspicious Service Persistence via InstallUtil with Masqueraded Service Name
This rule detects InstallUtil.exe referencing the nhdService or WinDefUpd service names used by the ShellClient RAT in Operation GhostShell for persistence. Attackers install these masqueraded services so the RAT survives reboots and blends in with legitimate update services. The pairing of the InstallUtil proxy binary with these specific service names is a strong GhostShell indicator.
HuntRule TeamWindowsprocess_creationHigh133Premium2026-08-04Malicious Stickey Key IFEO - Reg via Command (via process_creation)
This rule detects enable the Image File Execution Options (IFEO) debugger for sethc.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-08-04Suspicious Ngrok Tunnel Using svchost Masqueraded Config
This rule detects execution referencing an ngrok configuration file named svchost.yml. The Twelve group ran ngrok with a config masqueraded as a system component to tunnel internal services out to attacker infrastructure while evading casual inspection.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-08-04Malicious UAC Bypass via DllHost ICMLuaUtil Elevated COM Interface in ValleyRat Campaign (via process_creation)
This rule detects DllHost.exe launched with the ICMLuaUtil elevated COM CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7, the auto-elevation interface abused by the Silver Fox ValleyRat loader to bypass User Account Control. Adversaries leverage this elevated COM object to obtain administrator rights without a prompt, making detection valuable for catching privilege escalation during the intrusion.
HuntRule TeamWindowsprocess_creationHigh297Premium2026-08-04Suspicious DenoGate Run Key Persistence Launching Headless Deno Backdoor
This rule detects a Run key value named Deno_AutoRun created for persistence by the DenoGate backdoor delivered through Microsoft Teams IT impersonation. The value silently relaunches the Deno runtime under a headless conhost wrapper at logon. This fixed autostart name reestablishes the backdoor and its WebSocket command and control after reboot.
HuntRule TeamWindowsregistry_setHigh133Premium2026-08-04Malicious Web Browser Spawning Command or Script Interpreter
This rule detects a web browser process such as chrome.exe, msedge.exe or iexplore.exe spawning a command shell or scripting interpreter, the core signal of the FileFix social-engineering technique that tricks users into pasting an obfuscated PowerShell command into the File Explorer address bar. A browser has no legitimate reason to launch cmd, PowerShell, wscript or python. This parent-child chain indicates code execution from the KongTuke web-inject cluster.
HuntRule TeamWindowsprocess_creationHigh72Premium2026-08-04Suspicious Gatekeeper Quarantine Database Query via sqlite3
This rule detects sqlite3 querying the LSQuarantineEvents database, an anti-analysis check used by macOS Shlayer and Bundlore to inspect how a sample was downloaded and whether Gatekeeper flagged it. Reading this quarantine store helps the adware tailor its behavior and evade detonation environments.
HuntRule TeamMacosprocess_creationHigh71Premium2026-08-04Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
This rule detects creation or modification of Exchange Online inbox rules that filter messages from myworkday.com and delete or move them to obscure folders. This behavior is associated with payroll pirate campaigns against US universities where attackers hide Workday payroll and direct deposit change notifications from compromised victims. Concealing these alerts lets attackers reroute salary payments without the victim noticing, making early detection critical.
HuntRule TeamM365exchangeHigh162Premium2026-08-04