Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,420 rules
Malicious ClickFix Execution Chain Spawning MSHTA via Pcalua on EtherRAT Infection
This rule detects the Program Compatibility Assistant launcher pcalua.exe being abused to proxy execution of mshta.exe against an HTML application. This living-off-the-land chain is a ClickFix step in the EtherRAT SYS_INFO campaign that fetches command and control from an Ethereum contract. Using pcalua to break the parent-child chain evades detections keyed on direct mshta launches.
HuntRule TeamWindowsprocess_creationHigh395Premium2026-08-01Suspicious PowerShell With Reversed HTTP String (via process_creation)
This rule detects PowerShell command lines containing the reversed HTTP string used to hide C2 URLs. This steganography spam campaign reverses download URLs before reconstructing them at runtime.
HuntRule TeamWindowsprocess_creationHigh341Premium2026-07-31Malicious ShadowPad DLL Sideloading via TosBtKbd by Knife Framework
This rule detects the legitimate Toshiba TosBtKbd executable loading the TosBtKbdLayer DLL used to sideload ShadowPad. The China-nexus Knife framework abuses this signed binary to execute its ShadowPad implant through search-order hijacking. Sideloading through a trusted executable lets the implant run under the cover of a legitimate process.
HuntRule TeamWindowsimage_loadHigh82Premium2026-07-31Malicious Exploitation of Confluence setup-restore Endpoint
This rule detects POST requests to the Confluence setup-restore action, the endpoint abused in CVE-2023-22518 to reset the instance and gain administrative control before Cerber ransomware deployment. Requests to this administrative restore endpoint from untrusted sources indicate active exploitation of the vulnerability.
HuntRule TeamWebwebserverHigh3310Premium2026-07-31Suspicious Child Process Spawned by IIS Worker w3wp
This rule detects the IIS worker process w3wp.exe spawning PowerShell, cmd, or certutil, the webshell execution pattern seen in WS_FTP exploitation. The IIS worker should serve web content, not launch interactive shells or download tools, so these children indicate server-side code execution through a web application compromise.
HuntRule TeamWindowsprocess_creationHigh111Premium2026-07-31Suspicious RegAsm MSBuild or AutoIt Accessing Browser Credential Stores
This rule detects RegAsm, MSBuild, RegSvcs, or AutoIt3 processes referencing browser credential and cookie stores such as Login Data, key4.db, and cookies.sqlite. Microsoft observed injected Lumma Stealer code inside these hosts harvesting DPAPI-protected browser secrets. These .NET and scripting hosts have no legitimate reason to read browser credential databases, making the combination a strong credential theft indicator.
HuntRule TeamWindowsprocess_creationHigh388Premium2026-07-31Malicious Shadow Copy Deletion via Vssadmin (via process_creation)
This rule detects vssadmin deleting all volume shadow copies quietly. DarkWatchMan RAT removes shadow copies to inhibit recovery and hide its activity on the host.
HuntRule TeamWindowsprocess_creationHigh133Premium2026-07-31FortiOS WebSocket CLI Authentication Bypass via Node.js Exploit Tooling (via webserver)
This rule detects requests to the FortiOS websocket CLI endpoints ws cli open and ws newcli open originating from a Node.js user-agent, matching the KeyPlug-linked exploit tooling for CVE-2024-23108 and CVE-2024-23109. Adversaries leverage these websocket CLI paths to bypass authentication and reach the Fortinet command interface.
HuntRule TeamWebwebserverHigh51Premium2026-07-31Suspicious FL Studio Executable Side-Loading flengine DLL From Non-Standard Path
This rule detects the legitimate FL Studio binary fl.exe loading flengine.dll from a directory outside its normal installation path which is the DLL side-loading technique used to launch the BITSLOTH backdoor. Adversaries abuse this trusted signed executable to proxy execution of malicious code and evade defenses.
HuntRule TeamWindowsimage_loadHigh402Premium2026-07-31Malicious Cobalt Strike Post Exploitation Named Pipe
This rule detects creation of Cobalt Strike post exploitation named pipes following the postex prefix convention observed during the IcedID intrusion where the beacon spawned post exploitation jobs over SMB named pipes and this matters because the postex pipe pattern is a high fidelity signal of an active Cobalt Strike beacon performing credential and command tasks.
HuntRule TeamWindowspipe_createdHigh133Premium2026-07-31Malicious Konni PowerShell Loader Reading Script from ProgramData via Invoke-Expression (via process_creation)
This rule detects PowerShell launched with an execution policy bypass that reads a script from the ProgramData directory and runs it through Invoke-Expression, the loader behavior of a Konni AsyncRAT LNK infection that drops d.ps1 into ProgramData. Adversaries leverage Get-Content piped into Invoke-Expression to execute a staged script while hiding the payload from the command line, making early detection critical for catching the loader before AsyncRAT deploys.
HuntRule TeamWindowsprocess_creationHigh249Premium2026-07-30Malicious Mailbox Forwarding Rule Creation (via exchange)
This rule detects creation or modification of a mailbox rule that auto-forwards or redirects mail to an external address, a collection-and-exfiltration technique adversaries use after compromising an account to silently siphon correspondence. Malicious email rules are a recurring identity threat in the Red Canary Threat Detection Report, often following business email compromise. Detecting forwarding-rule creation surfaces data theft that victims rarely notice.
HuntRule TeamM365exchangeHigh193Premium2026-07-30Suspicious Windows Event Log Clearing via wevtutil on EC2 Host
This rule detects the wevtutil utility being used to clear Windows event logs which destroys host forensic evidence. In the Wiz hybrid cloud response the attacker deleted local operating system logs on compromised EC2 Windows instances to frustrate investigation. This is important because clearing event logs is a deliberate anti-forensic action that almost never occurs during normal administration and hides earlier attacker activity.
HuntRule TeamWindowsprocess_creationHigh288Premium2026-07-30Malicious Axios npm Compromise Windows Payload Artifacts wt.exe and 6202033 (via process_creation)
This rule detects execution of the wt.exe payload dropped in ProgramData and the numbered staging scripts 6202033.vbs 6202033.ps1 and system.bat used by the compromised axios npm package to deploy its RAT on Windows. These fixed artifact names run during or shortly after npm install and indicate an active infection beaconing every 60 seconds.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-07-30Malicious Windows Defender Exclusion of System32 via Registry (via registry_set)
This rule detects a Windows Defender path exclusion being registered for the System32 directory, a defense-evasion step in the full TinyTurla kill chain. Excluding System32 lets Turla stage and run its service DLL from a trusted location without antivirus inspection.
HuntRule TeamWindowsregistry_setHigh101Premium2026-07-30