Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,396 rules
Suspicious Hidden PowerShell Download and Archive Expansion
This rule detects hidden-window PowerShell that downloads content with Invoke-WebRequest and expands an archive in the same command. This chain was used to retrieve and unpack the XWorm loader, combining ingress tool transfer with a hidden window to evade user awareness.
HuntRule TeamWindowsprocess_creationHigh113Premium2026-07-24Malicious LSASS Credentials Dump via Task Manager - File (via file_creation)
This rule detects provides an indicator of a user accessing the task manager in order to eventually dump the LSASS process content using the "Details" tab > right click on "lsass.exe" > Create a dump file.
HuntRule TeamWindowsfile_creationHigh168Premium2026-07-24Malicious Regsvr32 Registration of DynamicWrapperX (via process_creation)
This rule detects regsvr32 registering the dynwrapx ActiveX component. DarkWatchMan RAT registers DynamicWrapperX to invoke Windows API calls from its JavaScript payload.
HuntRule TeamWindowsprocess_creationHigh355Premium2026-07-24Suspicious Scheduled Task Masquerading As System Process
This rule detects schtasks creating a task named after a core Windows process such as winlogon csrss or dllhost. The PowerRAT and DCRAT campaign registered scheduled tasks impersonating winlogon csrss and dllhost triggered at logon or on a minute interval. Naming a scheduled task after a trusted system process combines persistence with masquerading to evade casual task review.
HuntRule TeamWindowsprocess_creationHigh388Premium2026-07-24Malicious Security Service Tampering via wmic PathName Query (via process_creation)
This rule detects the use of wmic to enumerate services by their executable path and delete or stop those belonging to Sophos endpoint protection, a technique used by Terminator and its variants to disable security tooling before deploying ransomware or a cryptominer. The command selects services whose PathName matches a security vendor string and invokes delete or stopservice.
HuntRule TeamWindowsprocess_creationHigh102Premium2026-07-24Malicious New Member Added to a "OCS/Lync/Skype for Business" Administration Group - Medium Risk (via security)
This rule detects scenarios where a new member is added to a sensitive administration group related to OCS/Lync/Skype for Business in order to scan topology, infiltrate servers and move laterally.
HuntRule TeamWindowssecurityHigh123Premium2026-07-24Malicious DNS Query To ClickFix Infostealer C2 Domain
This rule detects DNS resolution of apposx.com, the fake Cloudflare verification and staging domain used in the ClickFix infostealer campaign. The domain fronts the social-engineering lure that leads macOS users to install the Odyssey and ACR stealers. Alerting on the hardcoded C2 domain surfaces hosts that reached the delivery infrastructure regardless of the payload used.
HuntRule TeamNetworkdns_queryHigh216Premium2026-07-24Suspicious Duke Malware DLLs Written to Windows Tasks Directory (via file_event)
This rule detects the Duke malware support DLLs being written into the Windows Tasks directory during the APT29 German Embassy campaign side-loading chain. Dropping Mso.dll and AppVIsvSubsystems64.dll into C:\Windows\Tasks stages the side-loading pair for msoev execution. DLL creation in this task directory is abnormal and indicates payload staging.
HuntRule TeamWindowsfile_eventHigh128Premium2026-07-24SplashTop Process
Detects use of SplashTop
HuntRule TeamWindowsprocess_creationHigh101Premium2026-07-23Suspicious EC2 Serial Console SSH Public Key Push (via cloudtrail)
This rule detects the SendSerialConsoleSSHPublicKey call used to push an SSH key to an instance serial console, an uncommon access path adversaries leverage to reach hosts that block normal network SSH. Legitimate serial console use is rare, so this event strongly suggests an attacker seeking out of band interactive access to a cloud instance.
HuntRule TeamAwscloudtrailHigh133Premium2026-07-23Malicious Webshell Written to Citrix NetScaler VPN Theme Directory (via file_event)
This rule detects the post-exploitation stage of Citrix NetScaler CVE-2026-8452 where a php webshell is dropped into the vpn theme directory after a pre-auth heap overflow. A php file in this template directory indicates appliance compromise.
HuntRule TeamLinuxfile_eventHigh111Premium2026-07-23Malicious Simps Botnet Infection Marker File Creation (via file_event)
This rule detects creation of the keksec.infected.you.log marker file dropped by the Simps botnet to flag a compromised host. The presence of this Keksec group artifact indicates the device has been enrolled into Mirai and Gafgyt based DDoS operations.
HuntRule TeamLinuxfile_eventHigh248Premium2026-07-23Malicious NTDS.dit Extraction via ntdsutil IFM Snapshot (via process_creation)
This rule detects use of ntdsutil to create an install-from-media snapshot, the technique Storm-1175 uses to extract the NTDS.dit Active Directory database and steal domain credential hashes during Medusa ransomware operations. Adversaries dump NTDS.dit to obtain every domain account hash for offline cracking and mass lateral movement, so this command on a domain controller is a critical credential-access alert.
HuntRule TeamWindowsprocess_creationHigh111Premium2026-07-23Malicious DcRAT Payload Masquerading as Mixed Reality.exe via process_creation
This rule detects execution of a binary named Mixed Reality.exe from the Windows Media Player directory, a masquerading trick used by Operation DragonReturn to stage its multi-stage DcRAT loader. The China-nexus actor placed the payload under a trusted vendor folder to blend with legitimate software while conducting espionage against Indian tax infrastructure, so early detection exposes the loader before injection and C2.
HuntRule TeamWindowsprocess_creationHigh92Premium2026-07-23Suspicious WScript Execution Spawned by Microsoft Word (via process_creation)
This rule detects wscript.exe spawned as a child of Microsoft Word, indicating macro-driven script execution. The returning Bumblebee campaign used a macro-enabled document that dropped a temp script and ran it via wscript to fetch the loader.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-07-23