Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,172 rules
Malicious Payload Assembly via MZ Header Prepend and copy Concatenation (via process_creation)
This rule detects the technique of writing an MZ header and concatenating it with a downloaded blob using copy to reconstruct an executable, used by Bitter APT against PTCL to rebuild the WmRAT payload. The disguised binary is downloaded as a PNG then reassembled on disk. This MZ-prepend and copy pattern is a distinctive evasion behavior.
HuntRule TeamWindowsprocess_creationHigh52Premium2026-08-10Malicious Mini Shai-Hulud TanStack C2 git-tanstack and getsession (via dns_query)
This rule detects DNS lookups for the git-tanstack.com payload host and getsession.org session channels used by the Mini Shai-Hulud TanStack npm compromise to fetch its Bun payload and exfiltrate stolen tokens. A resolution indicates the preinstall dropper has executed on a developer or CI host.
HuntRule TeamNetworkdns_queryHigh133Premium2026-08-10Suspicious VBScript Execution From ProgramData Microsoft Subfolder
This rule detects wscript or cscript executing a .vbs file from a subfolder under C:\ProgramData\Microsoft, a persistence and staging path used by Banana RAT. Legitimate scripts rarely run from these attacker-created directories.
HuntRule TeamWindowsprocess_creationMedium385Premium2026-08-10Malicious Exchange Group Membership Change to Perform DCsync Attack (via security)
This rule detects adds its account into a sensitive Exchange group to obtain "Replicating Directory Changes /all" and perform DCsync attack.
HuntRule TeamWindowssecurityHigh351Premium2026-08-10Suspicious Rundll32 Execution of WebDAV-Hosted DLL via Entry Export (via process_creation)
This rule detects rundll32.exe loading a DLL from a WebDAV UNC path and calling the exported function named Entry. Strela Stealer uses this technique to execute a fileless DLL payload delivered over WebDAV.
HuntRule TeamWindowsprocess_creationHigh93Premium2026-08-10Suspicious Kubernetes Secret Enumeration via kubectl
This rule detects kubectl commands that list or read Kubernetes secrets. Wiz Research observed attackers who gained code execution in a pod running kubectl get secrets to harvest cluster credentials, so secret enumeration from unexpected contexts can signal credential access and lateral movement preparation.
HuntRule TeamLinuxprocess_creationMedium3710Premium2026-08-10Suspicious Windows Defender Tamper Protection Disabled via Registry by Nova Ransomware
This rule detects the Windows Defender TamperProtection value being set to zero under the Defender Features key, disabling tamper protection so security tooling can be altered. Nova ransomware performs this change as part of multi-layered Defender evasion.
HuntRule TeamWindowsregistry_setMedium123Premium2026-08-10Malicious Cobalt Strike Malleable C2 URI Beacon via Proxy
This rule detects HTTP requests to the Cobalt Strike malleable profile URI /1/events/com.amazon.csm.csa.prod observed in the Nitrogen 2.0 campaign. This fixed path masquerades as Amazon telemetry to blend with normal traffic. Detecting it identifies beaconing to Cobalt Strike infrastructure.
HuntRule TeamWebproxyHigh3810Premium2026-08-10Suspicious Attrib Hiding of Stealer Artifacts (via process_creation)
This rule detects attrib.exe applying hidden and system attributes to Maranhao Stealer artifacts such as infoprocess.exe, crypto.key, or the Microsoft Updater directory. This hides malicious files from the user.
HuntRule TeamWindowsprocess_creationMedium61Premium2026-08-10Suspicious Bitdefender Binary Sideloading log.dll Loader
This rule detects the legitimate Bitdefender bds.exe loading a malicious log.dll from its directory, a DLL sideloading loader used by the Billbug espionage group to decrypt and run its backdoor payload.
HuntRule TeamWindowsimage_loadHigh447Premium2026-08-10Suspicious Azure CLI Enumeration of Roles and Logic Apps
This rule detects Azure CLI discovery commands that enumerate role assignments and Logic App workflows in a tenant. It reflects post-authentication cloud reconnaissance where an attacker maps permissions and automation to find escalation paths. Detecting it can surface hands-on enumeration after a service principal compromise.
HuntRule TeamWindowsprocess_creationMedium353Premium2026-08-09Suspicious Account Set with Password Not Required - Weakness Introduction (via security)
This rule detects set an account with password not required to perform privilege escalation attack.
HuntRule TeamWindowssecurityMedium111Premium2026-08-09Suspicious Double Base64 Decoded Payload Piped to Shell in CI (reviewdog Supply Chain)
This rule detects a base64 decoded payload being piped directly into a shell, the execution pattern of the injected reviewdog/action-setup install.sh that dumped CI runner memory. It matters because decode into shell in a build step is a common way supply chain payloads execute credential theft code without touching disk.
HuntRule TeamLinuxprocess_creationMedium143Premium2026-08-09Suspicious Unattended AnyDesk Silent Install with Auto-Start
This rule detects a silent unattended AnyDesk installation configured to start with Windows, a remote-access-tool deployment pattern abused by threat actors to establish persistent covert remote control of a compromised host. The combination of silent install and auto-start flags indicates non-interactive attacker-driven deployment rather than a normal user setup.
HuntRule TeamWindowsprocess_creationHigh298Premium2026-08-09Suspicious Java Process Spawning Reconnaissance Commands via Cleo MFT (via process_creation)
This rule detects a Java process spawning a shell that runs host and domain reconnaissance commands. The Cleopatra Java backdoor, delivered by exploiting Cleo managed file transfer software, executed discovery utilities such as nltest, net view and systeminfo through child shells.
HuntRule TeamWindowsprocess_creationMedium423Premium2026-08-09