Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
94 rules
Malicious Shadow Copy Deletion and Recovery Tampering by BabLock Ransomware
This rule detects deletion of volume shadow copies and disabling of Windows recovery, hallmarks of BabLock ransomware pre-encryption activity. The operators run vssadmin Delete Shadows and bcdedit recoveryenabled No to prevent victims restoring their data. This inhibits recovery and maximizes the impact of the encryption stage.
HuntRule TeamWindowsprocess_creationHigh52Premium2026-05-16Malicious File Encryption via Kraken Ransomware Encryptor Binary
This rule detects execution of the Kraken ransomware encryptor with its characteristic key, path, timeout and directory command-line switches. The binary encrypts victim files and appends the .zpsc extension while dropping a ransom note. Detecting the encryptor invocation provides a late-stage indicator of active ransomware deployment.
HuntRule TeamWindowsprocess_creationHigh122Premium2026-05-11Malicious Ransomware Ransom Note README-RECOVER File Creation
This rule detects creation of README-RECOVER ransom note text files, the note naming convention dropped during the Qilin ransomware encryption stage. These notes appear across directories once mass file encryption completes. Their creation is a definitive indicator that ransomware impact has already occurred and requires immediate response.
HuntRule TeamWindowsfile_eventHigh437Premium2026-05-10Malicious Eldorado Ransomware Ransom Note Creation
This rule detects the creation of the HOW_RETURN_YOUR_DATA.TXT ransom note dropped by Eldorado ransomware across encrypted directories. The note appears once encryption completes and delivers the extortion demand. It matters because its widespread creation confirms an active Eldorado impact event on the host or shares.
HuntRule TeamWindowsfile_eventHigh454Premium2026-05-07Malicious Interlock Ransomware Ransom Note File Creation
This rule detects creation of ransom note files named README that Interlock ransomware writes across encrypted directories using the distinctive filename bang README bang txt. The unique note filename indicates active ransomware deployment and data encryption on the host.
HuntRule TeamWindowsfile_eventHigh73Premium2026-04-30Windows: BlueSky ransomware-related file and share access events
Alerts on Windows file/share access involving .bluesky and "DECRYPT FILES BLUESKY" artifact naming tied to BlueSky activity.
j4son, Huntrule TeamWindowssecurityHigh141Free2023-05-23Windows: Rorschach execution indicator via critical command-line pattern
Windows process creation events with certain system utilities and a "11111111" command-line marker are flagged as ransomware execution activity.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical203Free2023-04-04Windows Registry Ransom Note Keyword Changes in LegalNoticeCaption/Text
Alerts on registry changes to Windows legal notice caption/text containing ransomware-style keywords.
frack113, Huntrule TeamWindowsregistry_setHigh133Free2022-12-11Antivirus ransomware signature match (Babuk, Lockbit, Ryuk, WannaCry)
Flags antivirus ransomware detections when the alert signature contains known ransomware family name strings.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusCritical409Free2022-05-12Windows Process Command-Line Indicators of BlackByte Ransomware Activity
Flags Windows process creation command-line patterns consistent with BlackByte ransomware techniques.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3210Free2022-02-25BlackByte ransomware Registry Set Persistence and Privilege Changes (Windows)
Alerts on BlackByte-specific Windows registry value changes to DWORD 1 across three predefined keys.
frack113, Huntrule TeamWindowsregistry_setHigh131Free2022-01-24Windows: .txt Created on User Desktop via cmd.exe
Flags cmd.exe creating .txt files under user Desktop, a common ransomware-style artifact placement pattern.
frack113, Huntrule TeamWindowsfile_eventMedium100Free2021-12-26Microsoft 365 Cloud App Security - Potential Ransomware Activity Alerts on File Upload
Flags successful Microsoft Cloud App Security reports of potential ransomware-related file uploads in Microsoft 365.
austinsonger, Huntrule TeamM365threat_managementMedium422Free2021-08-19Windows process creation patterns associated with DarkSide ransomware helpers
Detects Windows process creation consistent with DarkSide ransomware helper execution using encoded command-line content.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical163Free2021-05-14LockerGoga Ransomware Indicators in Windows Process Command Line
Flags Windows processes with a specific LockerGoga-style command-line argument pattern.
Vasiliy Burov, oscd.community, Huntrule TeamWindowsprocess_creationCritical192Free2020-10-18