Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,188 rules
Malicious Stickey Key IFEO - Reg via Command (via process_creation)
This rule detects enable the Image File Execution Options (IFEO) debugger for sethc.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-08-04Suspicious AWS Federated Console Login From Programmatic Credentials
This rule detects an AWS Management Console sign-in performed by a federated user identity which indicates a session created from long-term or temporary programmatic credentials rather than an IAM user or SSO login. Wiz shows attackers exchange stolen keys for a federated console session to obfuscate their real identity and break session traceability. This matters because it lets an adversary operate interactively in the console while evading the account owner attribution normally provided by ConsoleLogin.
HuntRule TeamAwscloudtrailMedium93Premium2026-08-04Suspicious Ngrok Tunnel Using svchost Masqueraded Config
This rule detects execution referencing an ngrok configuration file named svchost.yml. The Twelve group ran ngrok with a config masqueraded as a system component to tunnel internal services out to attacker infrastructure while evading casual inspection.
HuntRule TeamWindowsprocess_creationHigh102Premium2026-08-04Malicious UAC Bypass via DllHost ICMLuaUtil Elevated COM Interface in ValleyRat Campaign (via process_creation)
This rule detects DllHost.exe launched with the ICMLuaUtil elevated COM CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7, the auto-elevation interface abused by the Silver Fox ValleyRat loader to bypass User Account Control. Adversaries leverage this elevated COM object to obtain administrator rights without a prompt, making detection valuable for catching privilege escalation during the intrusion.
HuntRule TeamWindowsprocess_creationHigh297Premium2026-08-04Suspicious GCP Service Account Key Creation for Persistence (via gcp.audit)
This rule detects the CreateServiceAccountKey method in GCP audit logs, the persistence technique Red Canary described where a service account creates a new key for itself to survive key-deletion remediation. Because these tokens are not revokable, key creation where the requesting principal matches the target service account is a strong sign of an actor establishing durable access.
HuntRule TeamGcpgcp.auditMedium92Premium2026-08-04Suspicious DenoGate Run Key Persistence Launching Headless Deno Backdoor
This rule detects a Run key value named Deno_AutoRun created for persistence by the DenoGate backdoor delivered through Microsoft Teams IT impersonation. The value silently relaunches the Deno runtime under a headless conhost wrapper at logon. This fixed autostart name reestablishes the backdoor and its WebSocket command and control after reboot.
HuntRule TeamWindowsregistry_setHigh123Premium2026-08-04Malicious Web Browser Spawning Command or Script Interpreter
This rule detects a web browser process such as chrome.exe, msedge.exe or iexplore.exe spawning a command shell or scripting interpreter, the core signal of the FileFix social-engineering technique that tricks users into pasting an obfuscated PowerShell command into the File Explorer address bar. A browser has no legitimate reason to launch cmd, PowerShell, wscript or python. This parent-child chain indicates code execution from the KongTuke web-inject cluster.
HuntRule TeamWindowsprocess_creationHigh72Premium2026-08-04Suspicious Gatekeeper Quarantine Database Query via sqlite3
This rule detects sqlite3 querying the LSQuarantineEvents database, an anti-analysis check used by macOS Shlayer and Bundlore to inspect how a sample was downloaded and whether Gatekeeper flagged it. Reading this quarantine store helps the adware tailor its behavior and evade detonation environments.
HuntRule TeamMacosprocess_creationHigh61Premium2026-08-04Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
This rule detects creation or modification of Exchange Online inbox rules that filter messages from myworkday.com and delete or move them to obscure folders. This behavior is associated with payroll pirate campaigns against US universities where attackers hide Workday payroll and direct deposit change notifications from compromised victims. Concealing these alerts lets attackers reroute salary payments without the victim noticing, making early detection critical.
HuntRule TeamM365exchangeHigh142Premium2026-08-04Suspicious Device Registration Following OAuth Token Theft
This rule detects Entra ID device registration and Primary Refresh Token acquisition activity consistent with the ROADtools tradecraft used after OAuth phishing. Registering an attacker-controlled device lets the adversary obtain a PRT and maintain durable access to the tenant beyond the stolen refresh token.
HuntRule TeamAzureauditlogsMedium83Premium2026-08-04Suspicious EBS Snapshot Shared With External Account via CloudTrail
This rule detects ModifySnapshotAttribute events that add CREATE_VOLUME_PERMISSION for a specific external AWS account, sharing an EBS snapshot outside the owner account. Adversaries share a snapshot they created with an attacker-controlled account so they can restore the volume elsewhere and exfiltrate its data. Externally sharing a snapshot bypasses direct data reads and is a known cloud exfiltration technique.
HuntRule TeamAwscloudtrailMedium171Premium2026-08-04Possible VMware Workspace ONE Access Authentication Bypass via Embedded Auth Broker Callback (CVE-2022-22972) (via webserver)
This rule detects POST requests to the Workspace ONE Access embedded auth broker callback endpoint used in the CVE-2022-22972 host header authentication bypass. This maps to exploitation where an attacker supplies a crafted Host header to trick the internal auth broker into issuing a valid session. Successful abuse grants unauthenticated administrative access to the appliance.
HuntRule TeamWebwebserverMedium62Premium2026-08-04Malicious Stealth Soldier C2 User-Agent (via proxy)
This rule detects outbound web requests carrying the hardcoded Stealth Soldier user-agent string used by the Stealth Soldier backdoor in espionage attacks across North Africa. This static, tool-specific user-agent is a distinctive command-and-control fingerprint that legitimate clients do not present.
HuntRule TeamWebproxyHigh181Premium2026-08-04Suspicious Rogue WordPress REST Route morning/v1 (via webserver)
This rule detects requests to a rogue REST route morning/v1 registered by the wp2shell web shell to execute commands via a base64 parameter passed to passthru. Access to this attacker-defined route indicates an active web shell on the WordPress host. The specific route name is characteristic of this implant.
HuntRule TeamWebwebserverHigh163Premium2026-08-04Malicious User Browser Credentials Dump via Network Share - DonPapi, Lazagne (via security)
This rule detects attempt to dump browser credentials (Firefox, Google Chrome, ...) via network share.
HuntRule TeamWindowssecurityHigh354Premium2026-08-04