Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,395 rules
Malicious WannaCry Run Key Persistence to tasksche via registry_set
This rule detects the creation of a Run key registry value pointing to the WannaCry payload tasksche.exe, establishing persistence at user logon. The malware writes this value under the CurrentVersion Run key to survive reboots. Presence of a tasksche.exe reference in an autostart location is a high-confidence indicator of WannaCry infection.
HuntRule TeamWindowsregistry_setHigh61Premium2026-07-17Suspicious File Created in Startup Folder by WinRAR via CVE-2025-8088
This rule detects WinRAR or its extraction binaries writing a file into a user Startup folder which indicates exploitation of the CVE-2025-8088 alternate data stream path traversal flaw. Attackers drop LNK HTA or BAT payloads into Startup to gain logon persistence when a user opens a crafted archive.
HuntRule TeamWindowsfile_eventHigh163Premium2026-07-17Malicious ESXi Secure Boot Bypass via execInstalledOnly Disable
This rule detects an esxcli command disabling the execInstalledOnly kernel setting on an ESXi host, matching UNC3944 tampering that allows unsigned binaries to run so the actor can deploy ransomware and offline tooling. Turning off this protection removes a core defense against untrusted code on the hypervisor.
HuntRule TeamWindowsprocess_creationHigh241Premium2026-07-17Malicious Docker Socket Access via Curl Unix Socket
This rule detects curl invocations that talk directly to the Docker daemon Unix socket, the technique an AI agent-driven actor used to create a privileged container and escape onto the host orchestration plane. Direct API calls to the docker.sock allow spawning containers that mount the host filesystem. This behavior is a strong container escape indicator.
HuntRule TeamLinuxprocess_creationHigh143Premium2026-07-17Malicious Payload Download and Execution via certutil urlcache (via process_creation)
This rule detects certutil being used with the urlcache option to download a remote executable to disk, a living off the land technique used by a ransomware actor after exploiting an unsupported ColdFusion server to fetch and launch beacon payloads into the Windows temp directory. Legitimate use of certutil to download arbitrary executables over HTTP is rare.
HuntRule TeamWindowsprocess_creationHigh214Premium2026-07-17Malicious Keyhunter Worker Systemd Unit File Creation
This rule detects creation of the keyhunter-worker systemd unit file dropped by the NATS-as-C2 credential harvesting campaign. The unit establishes persistence for a worker that connects to an attacker NATS broker and exfiltrates cloud and AI API keys. A unit file with this name is a strong indicator of compromise.
HuntRule TeamLinuxfile_eventHigh289Premium2026-07-17Suspicious Scheduled Task Masquerading as Realtek Audio Service (via process_creation)
This rule detects the AsyncRAT campaign registering scheduled tasks that impersonate Realtek audio maintenance to launch its batch and AutoHotkey loaders. The tasks use names such as CheckRealtekAudioVersion and execute dropped RealtekAudioService64 components. Creation of these named tasks indicates persistence by the loader.
HuntRule TeamWindowsprocess_creationHigh421Premium2026-07-17Malicious TALONITE FlowCloud Renamed HTML Help Workshop Binary (via process_creation)
This rule detects a process whose original file name is the legitimate HTML Help Workshop binary hhw.exe but which runs under a different image name. TALONITE FlowCloud executes a renamed copy of hhw.exe to store harvested host data in database files while evading name-based detection. A mismatch between the embedded original name and the on-disk name is a strong masquerading signal.
HuntRule TeamWindowsprocess_creationHigh404Premium2026-07-16Malicious Mimikatz LSASS Credential Dumping via Command Line
This rule detects Mimikatz command modules such as sekurlsa logonpasswords or lsadump on the process command line, the credential harvesting method TrickBot uses through its Mimikatz-based module to dump LSASS memory. These module strings are distinctive to Mimikatz regardless of the binary name. Their presence indicates active credential theft supporting lateral movement.
HuntRule TeamWindowsprocess_creationHigh102Premium2026-07-16Masquerading Noodlophile Payload Execution via Video File Double Extension (via process_creation)
This rule detects execution of an image named with a video double extension such as .mp4.exe, the masquerading technique used by the Noodlophile stealer campaign delivered through fake AI video-generation platforms. Adversaries leverage a video-looking filename so users who expect a rendered clip instead launch the wrapper binary, making early detection critical for catching the intrusion at first execution before the CapCut loader and XWorm injection proceed.
HuntRule TeamWindowsprocess_creationHigh436Premium2026-07-16Suspicious Windows Event Log Clearing via wevtutil
This rule detects clearing of Windows event logs using wevtutil cl. Ransomware operators covered in this report chain wevtutil cl commands against the Security, System and Application logs to erase forensic evidence around encryption. Bulk event-log clearing is a strong indicator of anti-forensic activity.
HuntRule TeamWindowsprocess_creationHigh154Premium2026-07-16Malicious Sparkling Pisces Backdoor C2 URI Pattern (via proxy)
This rule detects web requests to the fixed command-and-control URIs used by the Sparkling Pisces KLogEXE keylogger and FPSpy backdoor, which encode operator index parameters in PHP endpoints. These structured request patterns are specific to the toolset and indicate an infected host communicating with its controller.
HuntRule TeamWebproxyHigh163Premium2026-07-16ValleyRat Beacon Sideloading via NtHandleCallback Loading log.dll (via image_load)
This rule detects the NtHandleCallback.exe process loading log.dll from its working directory, the DLL sideloading pair used to launch the ValleyRat beacon in the Silver Fox campaign. Adversaries leverage a masqueraded executable and a co-located malicious DLL to run the beacon under a benign-looking process, making detection valuable for surfacing command-and-control staging.
HuntRule TeamWindowsimage_loadHigh202Premium2026-07-16Malicious Microsoft Defender Service Components Status Disabled - Registry via Sysmon (via process_creation)
This rule detects disable Defender security features by modifying service configuration in registry.
HuntRule TeamWindowsprocess_creationHigh259Premium2026-07-16Malicious GachiLoader C2 Beacon via X-Secret gachifamily Header
This rule detects HTTP traffic carrying the custom header value gachifamily or the GachiLoader C2 URI patterns /log and /richfamily, structural markers of the malware's command-and-control channel. These fixed protocol artifacts identify GachiLoader beaconing and tasking regardless of the C2 host in use.
HuntRule TeamWebproxyHigh3010Premium2026-07-16