Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,419 rules
AsyncRAT C2 Check-in via Structured Verify Query Parameters (via proxy)
This rule detects AsyncRAT command-and-control check-ins carrying the structured verify query parameters observed in the ScreenConnect campaign, including the verify host, Support and Guest markers. Adversaries leverage these fixed request parameters to register infected hosts with the controller over web traffic.
HuntRule TeamWebproxyHigh133Premium2026-07-29Malicious EDR Termination via rundll32 Loading polers.dll Targeting Fortinet Processes (via process_creation)
This rule detects the Interlock EDR killer which uses rundll32.exe to invoke the exported start routine of polers.dll and terminate security processes matching the Forti pattern through a vulnerable anti cheat driver. The watchdog repeatedly relaunches to keep defenses down. This command line is unique to the tooling.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-07-29CraftCMS Yii Object Injection via generate-transform Endpoint (via webserver)
This rule detects requests to the CraftCMS asset generate-transform endpoint carrying Yii gadget class markers, the object-injection primitive exploited in CVE-2025-32432 to reach PhpManager and execute attacker code from a session file. Adversaries send crafted class references such as FnStream and PhpManager to trigger unauthenticated remote code execution.
HuntRule TeamWebwebserverHigh81Premium2026-07-29Malicious Azure WireServer Access Impersonating WALinuxAgent (via process_creation)
This rule detects a process contacting the Azure WireServer host address while presenting the WALinuxAgent identity, a technique used in the ChaosDB walkthrough to steal certificates and goal-state data. A non-agent process impersonating the Linux guest agent to reach WireServer is a strong sign of credential theft. Legitimate agent traffic originates from the agent binary itself, not ad-hoc curl commands.
HuntRule TeamLinuxprocess_creationHigh409Premium2026-07-29Suspicious Lazarus queue.bat Persistence Dropped in Startup Folder
This rule detects the creation of a file named queue.bat inside a Windows Startup folder which is the persistence mechanism used by the Lazarus DeceptiveDevelopment and Contagious Interview campaigns. The batch file relaunches the malicious Node.js and Python loader chain at every logon. Attackers use it to maintain foothold on developer machines targeted through fake job interviews.
HuntRule TeamWindowsfile_eventHigh125Premium2026-07-29Suspicious svchost Masquerading Executed Outside System Directory
This rule detects a process named svchost.exe running from any location other than the System32 or SysWOW64 directories, matching the GopherWhisper JabGopher component that spawns a fake svchost.exe host for LaxGopher injection. The legitimate service host only executes from System, so a copy elsewhere reveals masquerading and process injection.
HuntRule TeamWindowsprocess_creationHigh131Premium2026-07-29Malicious Self-Deletion Via Fsutil SetZeroData
This rule detects fsutil.exe being used with the setZeroData operation to overwrite file contents with zeros. BlackByte used fsutil setZeroData to zero out and self-delete its own binary after execution to hinder forensic recovery. Zeroing file data through fsutil is an anti-forensic indicator removal action rarely performed by legitimate administration.
HuntRule TeamWindowsprocess_creationHigh319Premium2026-07-29Possible SharePoint ToolShell Exploitation via ToolPane Edit POST With Spoofed Referer (CVE-2025-53770)
This rule detects a POST to the SharePoint ToolPane page in edit display mode with a Referer spoofing SignOut.aspx, the exploitation request of the ToolShell CVE-2025-53770 and CVE-2025-53771 chain. It matters because this unauthenticated request is the entry point for deserialization based remote code execution.
HuntRule TeamWebwebserverHigh254Premium2026-07-29Suspicious Execution From var tmp Masquerading as apt via GRIDTIDE
This rule detects a binary named xapt executing from the var tmp directory as used by the GRIDTIDE espionage campaign to masquerade as the legitimate apt package manager. Attackers run this payload with root privileges to spawn shells and establish backdoor access.
HuntRule TeamLinuxprocess_creationHigh123Premium2026-07-29Malicious Credential Added to an Azure AD Application (via auditlogs)
This rule detects a password or key credential being added to an Azure AD application or service principal, an account-manipulation technique that grants an attacker persistent, app-based access to a tenant. Adding application credentials is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting this operation surfaces a stealthy tenant backdoor being created.
HuntRule TeamAzureauditlogsHigh102Premium2026-07-29Possible SSTI Remote Command Execution from Web Application Process
This rule detects a web application runtime spawning reconnaissance or download shell commands, the hallmark of server side template injection reaching remote code execution. Template engines such as Jinja2 or FreeMarker are abused to run os.popen against system utilities. Detecting the abnormal child process exposes exploitation of the exposed web application.
HuntRule TeamLinuxprocess_creationHigh357Premium2026-07-29Malicious Script Execution from WinRAR Extraction Directory via CVE-2023-38831
This rule detects a command interpreter executing a script staged in a WinRAR temporary extraction directory named Rar$DIa. CVE-2023-38831 abuses a filename spoofing flaw so that opening a decoy document triggers execution of an adjacent script from the Rar$ temp path. This yields attacker code execution when the victim merely opens a crafted archive.
HuntRule TeamWindowsprocess_creationHigh278Premium2026-07-28Suspicious Botnet Payload Drop to Hidden Xdiag Temp Path
This rule detects references to the hidden staging directory /tmp/.xdiag and the /tmp/httpd artifact used to drop React2Shell follow-on payloads. Attackers stage Mirai and Gafgyt mipsel botnet binaries in these locations after exploiting affected hosts for command-and-control enrollment.
HuntRule TeamLinuxprocess_creationHigh142Premium2026-07-28Suspicious calc.exe Execution From Non-System Directory via DLL Side-Loading
This rule detects the Windows Calculator binary calc.exe running from a directory other than System32 or SysWOW64. The revived Qbot banking trojan copies a legitimate calc.exe alongside a malicious WindowsCodecs.dll so the trusted binary side-loads attacker code. Running a signed system binary from an unexpected path is a common evasion that lets malware execute under a benign process name.
HuntRule TeamWindowsprocess_creationHigh229Premium2026-07-28Possible Atlassian Confluence CVE-2023-22515 Setup Recovery Exploitation via Webserver (via webserver)
This rule detects HTTP requests that re-enable the Confluence setup workflow by toggling setupComplete to false and then hitting the setup administrator and finish-setup actions, matching exploitation of the broken access control flaw CVE-2023-22515. It is associated with attacks against internet-facing Atlassian Confluence servers to create rogue administrator accounts. Because these endpoints should never be reachable on a configured instance, this pattern strongly indicates active exploitation.
HuntRule TeamWebwebserverHigh322Premium2026-07-28