Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,395 rules
Malicious ClickFix PowerShell DownloadFile Loader with Hidden Window
This rule detects a hidden-window PowerShell process using DownloadFile to fetch a script from a remote host, the NetSupport RAT ClickFix loader pattern. Victims pasted a command that ran PowerShell with hidden window and no-profile flags to download and then execute a follow-on .ps1 payload. Hidden PowerShell combined with a remote file download is a classic first-stage loader behavior.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-07-19Suspicious MSHTA Execution of Polyglot PDF File Spawned by cmd (via process_creation)
This rule detects mshta.exe launched by cmd.exe with a PDF file argument, matching the UNK_CraftyCamel chain where an LNK ran cmd then mshta to execute a PDF and HTA polyglot. Legitimate mshta rarely processes files with a .pdf extension.
HuntRule TeamWindowsprocess_creationHigh153Premium2026-07-19SSH over port 443 with known Server and Client Strings
Will detect the presence of known SSH client and SSH server strings that have been used for SSH tunneling.
HuntRule TeamZeeksshHigh91Premium2026-07-19Suspicious InvisibleFerret C2 Endpoints over Port 1224 (via proxy)
This rule detects HTTP requests to the InvisibleFerret command and control server that exposes payload, browser, clipboard and key exfiltration endpoints over TCP port 1224. The Lazarus backdoor cycles through fixed URI paths such as payload, brow, mclip and keys on this port. The pairing of the non-standard port with these named resources reveals the backdoor traffic.
HuntRule TeamWebproxyHigh93Premium2026-07-19Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
This rule detects non-interactive Microsoft 365 sign-ins using the BAV2ROPC legacy authentication client. In the Railway PaaS token replay campaign, operators used BAV2ROPC to silently refresh stolen tokens and access mailboxes without triggering interactive MFA, so this client string on sign-ins indicates likely token abuse and legacy protocol exploitation.
HuntRule TeamM365signinlogsHigh92Premium2026-07-19Suspicious Masqueraded Zemana Driver Written to Disk via updatedrv (via file_event)
This rule detects the vulnerable Zemana driver being written to disk under the masqueraded name updatedrv.sys, a staging step used by the Terminator tool before creating a service and loading the driver to disable endpoint protection. The file is typically dropped into the system drivers directory or a ProgramData usoshared path.
HuntRule TeamWindowsfile_eventHigh215Premium2026-07-19Malicious Lazarus Rundll32 Execution of Sup ETL Privilege Escalation Loader (via process_creation)
This rule detects rundll32.exe executing a sup.etl file from the USOShared directory using the SerializeMarketTable export as observed in the Lazarus attack on Windows web servers. Loading an etl file as a DLL through an unusual export is a strong indicator of this loader.
—Windowsprocess_creationHigh152Premium2026-07-19IFM Detected - ESENT - Installation from Media (via application)
This rule detects create an IFM image (usually used for deploying domain controllers to reduce replication traffic) for dumping credentials.
HuntRule TeamWindowsapplicationHigh417Premium2026-07-19WordPress wp2shell PoC User-Agent HTTP Requests
Alerts on web requests with User-Agent exactly equal to "wp2shell", matching wp2shell PoC behavior.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverHigh13210Free2026-07-19Malicious GitHub Repository Creation With s1ngularity Exfiltration Name
This rule detects a GitHub audit repo create event where the repository name contains s1ngularity, the naming convention of the exfiltration repositories used to publish stolen secrets. It matters because these attacker created repositories are the exfiltration destination in the nx supply chain attack.
HuntRule TeamGithubauditHigh206Premium2026-07-18Malicious PowerShell Download Cradle via Invoke-WebRequest and IEX
This rule detects PowerShell run with an execution policy bypass that downloads content and pipes it directly to Invoke-Expression. Stealerium uses powershell -eP Bypass with Invoke-WebRequest to pull an atom feed from a blogspot dead drop and execute it in memory with IEX. This download-and-execute cradle is a widely abused fileless staging technique.
HuntRule TeamWindowsprocess_creationHigh139Premium2026-07-18Suspicious Scheduled Task Masquerading as Edge Update Telemetry (via process_creation)
This rule detects creation of a scheduled task using the distinctive name CoreEdgeUpdateServicesTelemetry FallBack. The FLUX#CONSOLE campaign registered this task to run its sideloading Dism binary every five minutes for persistence.
HuntRule TeamWindowsprocess_creationHigh141Premium2026-07-18Driverquery Lookup
Detects use of driverquery to look up the installed and configured drivers as part of host discovery
HuntRule TeamWindowsprocess_creationHigh2910Premium2026-07-17Suspicious CoffeeLoader Execution via Armoury Crate DLL Side-Loading (via process_creation)
This rule detects rundll32 executing the ArmouryAIOSDK.dll with the Post_EntrypointReturn export that CoffeeLoader uses to run its stager through DLL side-loading of ASUS Armoury Crate. Legitimate Armoury Crate components are not invoked this way from user writable paths.
HuntRule TeamWindowsprocess_creationHigh343Premium2026-07-17Malicious Metasploit PsExec Named Pipe Command Execution
This rule detects a command shell echoing data into a local named pipe, the service-based execution pattern produced by the Metasploit PsExec module when it installs a service that writes command output back through a pipe. This is used for remote code execution and lateral movement from a compromised host. Legitimate software does not echo into a raw named pipe from cmd.exe in this way.
HuntRule TeamWindowsprocess_creationHigh1910Premium2026-07-17