Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,420 rules
Malicious LummaC2 Stealer C2 Endpoint Beacon via Proxy
This rule detects HTTP requests to the LummaC2 command-and-control endpoints /c2conf and /c2sock used by version 4.0 of the stealer. These fixed URI paths handle configuration retrieval and data exfiltration. Detecting them identifies infected hosts communicating with LummaC2 infrastructure.
HuntRule TeamWebproxyHigh166Premium2026-08-02Malicious Volt Typhoon Port Proxy Configuration via Netsh (via process_creation)
This rule detects netsh being used to add an IPv4 to IPv4 port proxy rule, a living off the land relay technique Volt Typhoon uses to tunnel traffic through compromised network devices and hosts. This intrusion set targets critical infrastructure for stealthy lateral movement, so an interactive portproxy add almost always reflects adversary staged pivoting rather than administration.
HuntRule TeamWindowsprocess_creationHigh61Premium2026-08-02Malicious ShadowPad DLL Sideloading via imecmnt.exe (via image_load)
This rule detects the Microsoft IME binary imecmnt.exe loading imjp14k.dll from a non-system directory, a DLL search-order sideloading chain used by Stately Taurus to launch the ShadowPad backdoor. The loaded DLL subsequently injects into wmplayer.exe or dllhost.exe to run in memory. Sideloading a malicious DLL through a signed IME component lets the actor evade allowlisting and defeat image-integrity checks.
HuntRule TeamWindowsimage_loadHigh92Premium2026-08-02Malicious Powerfun Reverse Shell Script via Script Block (via ps_script)
This rule detects execution of the powerfun PowerShell reverse shell, the interactive backdoor deployed over port 443 after FortiClientEMS exploitation as documented by Red Canary. Powerfun is a publicly available offensive script with no legitimate use, so any script block referencing it indicates hands-on-keyboard remote access.
HuntRule TeamWindowsps_scriptHigh133Premium2026-08-02Malicious LSASS Credential Dumping via Mimikatz sekurlsa and lsadump Commands (via process_creation)
This rule detects Mimikatz command modules such as sekurlsa logonPasswords and lsadump sam being passed on the command line, the credential-access step in the ELPACO-team Confluence intrusion where logon passwords and SAM secrets were harvested to a results log. Adversaries run these Mimikatz modules to extract plaintext and hashed credentials from memory and the registry, so these module strings are a high-confidence dumping indicator regardless of the binary name.
HuntRule TeamWindowsprocess_creationHigh92Premium2026-08-02Possible Local File Inclusion Path Traversal Targeting CentreStack Web.config
This rule detects web requests to the CentreStack storage handler containing directory traversal sequences that reference Web.config, matching the local file inclusion exploitation of Gladinet CentreStack and Triofox. Attackers read Web.config to steal machine keys and secrets enabling deserialization attacks. Successful traversal to configuration files precedes full remote code execution and warrants investigation.
HuntRule TeamWebwebserverHigh103Premium2026-08-02Suspicious VietCredCare Stealer Persistence via Startup Folder Drop
This rule detects the VietCredCare stealer binary crsysys.exe being written into the Windows Startup folder for persistence. The malware copies itself here so it relaunches at every user logon. This autostart behavior maintains attacker access for continued credential theft.
HuntRule TeamWindowsfile_eventHigh51Premium2026-08-02Masquerading Scheduled Task Masquerading as Windows Defender via Typosquatted Name (via process_creation)
This rule detects creation of a scheduled task named to impersonate Windows Defender using the misspelled Windos Defende form observed in the CylindricalCanine intrusion linked to the DigiCert incident. Adversaries name persistence tasks after trusted security tooling to blend in during casual review, making early detection critical for removing the backdoor's autostart before it re-runs.
HuntRule TeamWindowsprocess_creationHigh286Premium2026-08-02Malicious RDP Discovery Performed on Multiple Hosts (via rdp)
This rule detects discover active RDP services via tools like Hydra. Note that this event doesn't provide any information about login outcome (success or failure) as well as user information. For further correlation, ID 4624/4625 (logon type 3, 7 or 10) as well as ID 1149 should be used.
HuntRule TeamWindowsrdpHigh203Premium2026-08-01Malicious PowerShell Spawned by IIS Worker Process via OWASSRF Exchange Exploitation (via process_creation)
This rule detects the IIS worker process w3wp.exe spawning PowerShell, a post-exploitation pattern seen in the OWASSRF exploitation of Exchange CVE-2022-41080 and CVE-2022-41082 through Outlook Web Access. Attackers use this server-side execution to run reconnaissance and drop tooling after bypassing ProxyNotShell mitigations, so PowerShell descended from an Exchange web process is a strong compromise signal.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-08-01OneNote Spawning Script Interpreter for AsyncRAT Delivery (via process_creation)
This rule detects Microsoft OneNote spawning a command shell, script host, or mshta process, the initial-execution behavior of the AsyncRAT chain that embeds a malicious HTA or script inside a OneNote document. Adversaries leverage OneNote attachments to bypass macro controls and launch a loader, making early detection critical for stopping the delivery chain before the RAT is decrypted.
HuntRule TeamWindowsprocess_creationHigh93Premium2026-08-01Suspicious Obfuscated PowerShell Spawned by explorer via Run Dialog
This rule detects powershell launched directly by explorer with obfuscation indicators which matches the paste and run or ClickFix technique used by Mocha Manakin to trick users into pasting a malicious command into the Run dialog. This user driven execution delivers a NodeJS backdoor while bypassing many download based defenses. Detecting explorer spawned obfuscated PowerShell surfaces the initial foothold.
HuntRule TeamWindowsprocess_creationHigh151Premium2026-08-01Possible Atlassian Confluence CVE-2023-22518 Setup-Restore Exploitation via Webserver (via webserver)
This rule detects unauthenticated HTTP POST requests to the Confluence setup-restore endpoints used to exploit the improper authorization vulnerability CVE-2023-22518. It is associated with attacks against Atlassian Confluence Data Center and Server that abuse the restore functionality to import a malicious ZIP. Successful exploitation lets an attacker reset the instance and create administrative access, so this activity should be triaged as a potential compromise.
HuntRule TeamWebwebserverHigh417Premium2026-08-01Suspicious Phishing URL with Unrendered Template Placeholder (via proxy)
This rule detects web requests whose URL path contains the unrendered phishing-kit template placeholder sf_rand_string_lowercase6, a literal artifact left in links from a large refresh-header phishing campaign. The presence of this build-time placeholder in a live URL is a strong indicator of the credential-harvesting kit and its automatic redirect landing pages.
HuntRule TeamWebproxyHigh92Premium2026-08-01Suspicious Tomcat Manager WAR Deployment via HTTP PUT by UNC6201
This rule detects an HTTP PUT to the Tomcat manager text deploy endpoint with update set to true which UNC6201 used to upload a WAR web shell after abusing default manager credentials. Attackers deploy the GRIMBOLT backdoor as a running web application to gain root on Dell RecoverPoint appliances.
HuntRule TeamWebwebserverHigh2310Premium2026-08-01