Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,184 rules
Suspicious User Home Directory Modification via dscl Process Creation
This rule detects use of dscl to change a user account home directory, the core step of the macOS HM Surf technique that relocates the home path to tamper with Safari privacy preference files and bypass TCC protections. Modifying NFSHomeDirectory lets an attacker point sensitive Safari config to a controlled location and grant itself camera, microphone or location access.
HuntRule TeamMacosprocess_creationMedium81Premium2026-08-07Malicious Recovery Environment Tampering via Bcdedit
This rule detects bcdedit being used to disable Windows automatic recovery, a boot-configuration change ransomware performs to block system restoration after encryption. It is associated with REvil ransomware-as-a-service affiliate operations that pair this step with shadow copy deletion. Detecting recovery tampering flags impending or in-progress impact activity.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-08-07Malicious SQL Server Database Auditing Deactivated (via application)
This rule detects deactivates SQL Server database auditing capacities. SQL auditing requires previous configuration on each SQL instance.
HuntRule TeamMssqlapplicationHigh51Premium2026-08-07Suspicious AutoIt3 Script Execution from User Directory (via process_creation)
This rule detects AutoIt3.exe executing a script from a user-writable directory, the loader behavior used in the LATAM Google Cloud Run campaigns where a Startup LNK launches PowerShell and AutoIt. AutoIt is abused to run compiled loader logic that injects the final banking trojan payload.
HuntRule TeamWindowsprocess_creationMedium208Premium2026-08-06Suspicious Kerberoasting via setspn Service Principal Query
This rule detects setspn.exe querying all service principal names in a domain, a reconnaissance step for Kerberoasting used by China-linked actors to identify service accounts for credential extraction.
HuntRule TeamWindowsprocess_creationMedium232Premium2026-08-06JanaWare Ransomware Ransom Note _ONEMLI_NOT_ Written to Disk (via file_event)
This rule detects the JanaWare ransomware writing its _ONEMLI_NOT_ ransom note across folders as it completes encryption in attacks against Turkish organizations. Adversaries drop this hardcoded Turkish-language note filename in every encrypted directory. The fixed prefix is a reliable post-impact detection anchor.
HuntRule TeamWindowsfile_eventHigh161Premium2026-08-06Malicious Mini Shai-Hulud gh-token-monitor Persistence Service (via file_event)
This rule detects creation of the gh-token-monitor LaunchAgent plist or systemd user service dropped by the Mini Shai-Hulud TanStack npm compromise to poll for GitHub tokens every 60 seconds. This fixed persistence artifact indicates the trojanized package has installed its credential-monitoring daemon.
HuntRule TeamLinuxfile_eventHigh163Premium2026-08-06Suspicious Execution of Temporary dfae Command Script by Careto
This rule detects cmd.exe executing a temporary batch file matching the ~dfae naming pattern used by the Careto APT. The malware drops a short-lived command script alongside its scheduled task to stage subsequent payloads. Execution of a hidden temporary command file with this prefix indicates malicious staging activity.
HuntRule TeamWindowsprocess_creationMedium228Premium2026-08-06Suspicious LNK Launch of WebDAV Batch via TryCloudflare Tunnel
This rule detects command lines referencing a trycloudflare tunnel host serving a batch script over WebDAV. The Quartet campaign shipped a zipped lnk that pulled new or startup batch files from a TryCloudflare share to stage Python payloads. Fetching executables from an ephemeral trycloudflare tunnel is a delivery pattern used to bypass domain reputation controls.
HuntRule TeamWindowsprocess_creationHigh41Premium2026-08-06Malicious rundll32 Loading dat Payload via afunix Export
This rule detects rundll32.exe loading a file with a .dat extension and invoking the afunix export with a key argument. This loader pattern is used by the Lazarus group during Operation SyncHole watering-hole attacks to execute the ThreatNeedle and related malware via a trusted signed binary. The non-DLL extension plus specific export name distinguishes it from normal rundll32 usage.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-08-06Suspicious WMIC Execution from Anomalous Parent Process (via process_creation)
This rule detects wmic being spawned by an anomalous parent such as an Office application, browser or scripting host. Legitimate WMIC use rarely originates from these processes, so this parent-child relationship points to WMI being abused for execution or discovery following initial access.
HuntRule TeamWindowsprocess_creationMedium91Premium2026-08-06Possible Process Injection into Attrib via Mispadu AutoIt Loader (via process_creation)
This rule detects attrib.exe being spawned by the AutoIt3 interpreter, which corresponds to the Mispadu loader injecting its payload into an attrib.exe process. A legitimate AutoIt application launching attrib in this way is not expected.
HuntRule TeamWindowsprocess_creationHigh73Premium2026-08-06Malicious TeamTNT Silentbob Cryptominer Setup Script Execution (via process_creation)
This rule detects execution of the setup_c3pool_miner.sh script that the TeamTNT Silentbob campaign drops inside compromised containers to install a Monero cryptominer after discovering misconfigured Docker APIs and JupyterLab instances. Deployment of this miner setup script on a server workload indicates cryptojacking.
HuntRule TeamLinuxprocess_creationMedium112Premium2026-08-06Suspicious perfctl Hidden IPC Directory Creation in tmp (via file_event)
This rule detects the perfctl malware creating its hidden inter process communication directory /tmp/.xdiag which holds a Unix socket and state files such as the victim IP, event log and TOR data. The hidden dot prefixed directory under tmp is used to coordinate the cryptominer and rootkit and is unique to this threat.
HuntRule TeamLinuxfile_eventHigh439Premium2026-08-06Suspicious Reconnaissance Commands Spawned by Samsung MagicINFO Server
This rule detects the Samsung MagicINFO application spawning cmd.exe to run reconnaissance commands such as whoami or arp, observed by Huntress following exploitation of the MagicINFO 9 server flaw. Attackers run host and network discovery immediately after gaining code execution through the vulnerable web application. Reconnaissance shells parented by the MagicINFO service indicate active post-exploitation.
HuntRule TeamWindowsprocess_creationHigh143Premium2026-08-06