Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,164 rules
Suspicious RegAsm or RegSvcs Spawned by Script Host (via process_creation)
This rule detects RegAsm.exe or RegSvcs.exe launched by a script host such as PowerShell, wscript, or cscript, the injection target abused in the Cascading Shadows phishing chain. The actor hollows these signed .NET utilities to run Agent Tesla, Remcos, or XLoader while evading defenses through trusted binary proxy execution.
HuntRule TeamWindowsprocess_creationHigh61Premium2026-08-12Suspicious Exposed Ollama API Service Connection
This rule detects network connections to the default Ollama LLM service port, exposure that attackers abuse to hijack local AI inference in the evolved LLMjacking campaign. An internet-reachable Ollama endpoint allows unauthenticated model access and resource theft. Connections from untrusted sources to this port warrant review of the exposed service.
HuntRule TeamLinuxnetwork_connectionLow128Premium2026-08-12Suspicious Scheduled Task Masquerading as Edge Update Running as SYSTEM via schtasks
This rule detects creation of a scheduled task that masquerades as a Microsoft Edge update while running as SYSTEM. This technique was observed in a DLL hijacking campaign analyzed by Kaspersky where attackers created a task named \Microsoft\Windows\Edge\Edgeupdates to gain persistent SYSTEM-level execution. Abusing a legitimate-looking task name in the wrong namespace lets an adversary blend malicious persistence with benign updater activity.
HuntRule TeamWindowsprocess_creationHigh111Premium2026-08-12Suspicious DNS Query for TryCloudflare Tunnel Abused for Malware Delivery (via dns_query)
This rule detects DNS resolution of trycloudflare.com subdomains, which threat actors abused as disposable tunnels to host WebDAV shares delivering AsyncRAT and XWorm. TryCloudflare is a legitimate developer service so correlate with script or LNK activity.
HuntRule TeamWindowsdns_queryMedium142Premium2026-08-12Possible CopyFail Root Exploitation via Python Spawning SUID Shell (via process_creation)
This rule detects a Python interpreter spawning a shell that invokes SUID privileged binaries, a behavior consistent with exploitation of the CopyFail vulnerability to gain root on modern Linux distributions. The child shell abuses setuid utilities to elevate an unprivileged process. Detecting this chain surfaces local privilege escalation attempts.
HuntRule TeamLinuxprocess_creationMedium103Premium2026-08-12Suspicious Windows Security Spoofing via pin Executable Writing output.txt via process_creation
This rule detects execution of pin.exe with an output.txt argument. In the rogue RMM campaign this binary spoofs the Windows Security interface while writing harvested data to output.txt, so its presence indicates a fake security prompt used to capture credentials or user input in support of the intrusion.
HuntRule TeamWindowsprocess_creationMedium84Premium2026-08-12Suspicious Typosquatted Apple User-Agent Beaconing from Ivanti Implant (via proxy)
This rule detects HTTP requests bearing a typosquatted Apple user-agent string that substitutes look-alike characters for the letter l. Implants deployed against Ivanti Connect Secure used App1e and AppIe user-agents during their dormancy and beaconing. A user-agent forging the Apple brand with homoglyphs is a distinctive command-and-control fingerprint.
HuntRule TeamWebproxyMedium401Premium2026-08-12Suspicious Autorun Persistence Masquerading as VMware NAT Service
This rule detects a Run key value named VMware NAT Service being created under the current user hive, a persistence method used by Gh0stBins RAT to masquerade as the legitimate VMware NAT service. The genuine VMware service does not register user-level Run key persistence.
HuntRule TeamWindowsregistry_setMedium93Premium2026-08-12Suspicious Bootkitty Rootkit Component Drop under opt via File System
This rule detects creation of the Bootkitty user-space and kernel components /opt/injector.so, /opt/observer, and /opt/rootkit_loader.ko. These fixed paths are dropped by the first known UEFI bootkit for Linux to load a kernel module and inject a shared object through the boot process. Their presence indicates a UEFI bootkit compromise.
HuntRule TeamLinuxfile_eventHigh422Premium2026-08-12Malicious PowerShell Exfiltration to webhook.site Following WSUS Exploitation
This rule detects PowerShell using Invoke-WebRequest to PUT data to the webhook.site service, the exfiltration channel observed after Windows Server Update Services remote code execution. Attackers stage discovery output and upload it to a disposable webhook endpoint for collection. Outbound PUT requests to webhook.site from PowerShell are a strong exfiltration indicator.
HuntRule TeamWindowsps_scriptHigh101Premium2026-08-12Malicious Scheduled Task Deploying DYNOWIPER Payload (via process_creation)
This rule detects scheduled task creation referencing the DYNOWIPER wiper payload filenames used against Poland's energy sector. Observed in Elastic Security Labs telemetry where schtask.exe creates tasks running dynacom_update.exe or Source.exe to launch destructive file-corruption routines, enabling persistence and destructive execution.
HuntRule TeamWindowsprocess_creationHigh395Premium2026-08-12ValleyRAT DLL Sideloading via Douyin Loading Non-Standard DLL (via image_load)
This rule detects the legitimate Douyin (TikTok) binary loading a tier0.dll or sscronet.dll, the DLL sideloading behavior used by ValleyRAT to run its loader from the Common Files System directory under a signed application. Adversaries leverage sideloading against a trusted binary to execute shellcode that injects into svchost.exe, making early detection critical for surfacing the intrusion before keylogging and remote-control commands begin.
HuntRule TeamWindowsimage_loadHigh183Premium2026-08-11Suspicious Scheduled Task Creation for HijackLoader Persistence (via process_creation)
This rule detects the creation of a scheduled task named mlt_Archive through schtasks, the persistence mechanism observed in the IObit side-loading intrusion delivering AsyncRAT. This task name is not associated with legitimate software.
HuntRule TeamWindowsprocess_creationHigh92Premium2026-08-11Suspicious Credential Prompt Phishing via osascript (via process_creation)
This rule detects osascript invoking an AppleScript dialog box that prompts the user for a password, a technique used by macOS stealers such as Cthulhu and Atomic to socially engineer credentials. Attackers use fake authentication dialogs to capture the local account password for privilege escalation and keychain access.
HuntRule TeamMacosprocess_creationMedium319Premium2026-08-11Possible AntSword Webshell Access on Ivanti EPMM 403.jsp
This rule detects HTTP POST requests to the 403.jsp resource on Ivanti EPMM carrying the AntSword webshell parameter k. It is tied to a Java webshell appended to the legitimate 403.jsp error page during EPMM exploitation to provide operators remote command execution. Detecting these requests reveals interaction with the deployed webshell.
HuntRule TeamWebwebserverMedium116Premium2026-08-11