Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,395 rules
Malicious Nova Ransomware Note and Encrypted File Extension via File Event
This rule detects creation of the Nova ransomware note README_NOVA.me alongside files bearing the .xgWLckNV extension appended during encryption. These artifacts are dropped as Nova encrypts a host and demands ransom.
HuntRule TeamWindowsfile_eventHigh164Premium2026-07-14Malicious Defender Behavior Monitoring Disable via Set-MpPreference
This rule detects commands that disable Microsoft Defender behavior monitoring through Set-MpPreference or the MpPreference registry path. A fake KMSPico installer delivering Vidar Stealer used a javaw hosted stage to switch off behavior monitoring before running AutoIt. Turning off behavior monitoring lets the loader execute without real-time detection.
HuntRule TeamWindowsps_scriptHigh83Premium2026-07-14Malicious Scheduled Task Masquerading as Google Updater via Schtasks
This rule detects creation of a scheduled task named after the Google updater with the highest run level triggered on user logon. The CL-STA-1062 actor deploying the TinyRCT backdoor against Southeast Asian governments registers a task called GoogleUpdaterTaskSystem to blend with legitimate Chrome update tasks. Detecting this masqueraded persistence surfaces an elevated logon-triggered foothold hiding behind a trusted name.
HuntRule TeamWindowsprocess_creationHigh298Premium2026-07-14Malicious Recovery Disablement via bcdedit
This rule detects bcdedit disabling Windows recovery, used by the hacktivist ransomware operators to block system restoration before encryption. Turning off automatic recovery removes a victim safety net. Combined with shadow deletion this is a strong pre-encryption impact signal.
HuntRule TeamWindowsprocess_creationHigh101Premium2026-07-14Rogue Privileged Account Names on Cisco IOS XE
This rule detects references to the rogue privilege-15 account names created during active exploitation of the Cisco IOS XE Web UI vulnerability. Attackers created local accounts named cisco_tac_admin, cisco_support and cisco_sys_manager to maintain administrative access. These specific usernames are attacker-chosen masquerade artifacts and should never exist in a normal configuration.
HuntRule TeamCiscoaaaHigh72Premium2026-07-14Malicious Node.js Execution of test.js from .vscode Folder in Lazarus Lure (via process_creation)
This rule detects the Node.js runtime running a script named test.js located inside a .vscode project folder, the exact loader pattern used by the Lazarus BeaverTail campaign after a victim runs npm install. The hidden .vscode directory disguises the malicious bootstrap among normal editor files. This execution kicks off the download of the follow-on Python infostealer.
HuntRule TeamWindowsprocess_creationHigh243Premium2026-07-14Suspicious Regsvr32 Loading DLL from Remote WebDAV Location via Strela Stealer (via process_creation)
This rule detects regsvr32 executing a DLL from a remote WebDAV or HTTP location without writing it to disk, the fileless second stage delivery technique used by Strela Stealer.
HuntRule TeamWindowsprocess_creationHigh302Premium2026-07-14Malicious OMI Server Spawning Shell as Root via OMIGOD SCX Provider (via process_creation)
This rule detects the OMI server or engine process spawning a shell or command interpreter, which the OMIGOD CVE-2021-38647 and CVE-2021-38648 flaws abuse to execute attacker commands as root through the SCX provider on Azure Linux virtual machines. Such child processes indicate unauthenticated remote code execution or local privilege escalation and should be investigated as an active intrusion.
HuntRule TeamLinuxprocess_creationHigh253Premium2026-07-14Suspicious Lateral Movement via Invoke-WMIExec or Invoke-SMBExec (via ps_script)
This rule detects PowerShell use of the Invoke-WMIExec or Invoke-SMBExec pass-the-hash tooling observed alongside the ThrottleStop AV-killer intrusion. These functions authenticate to remote hosts with an NTLM hash and run commands such as local account creation without a plaintext password. Their presence indicates hands-on lateral movement using stolen credential material.
HuntRule TeamWindowsps_scriptHigh3810Premium2026-07-14Malicious Update Orchestrator Service Reconfiguration for Privilege Escalation
This rule detects reconfiguration of the Update Orchestrator Service binary path via sc.exe, the abuse chain behind CVE-2019-1322 that runs an attacker command as SYSTEM. Repointing UsoSvc to an arbitrary command lets a low-privileged user escalate to SYSTEM when the service restarts.
HuntRule TeamWindowsprocess_creationHigh111Premium2026-07-14Suspicious Command Prompt Spawned by Winlogon
This rule detects winlogon.exe spawning cmd.exe, an anomalous parent-child relationship used by Backdoor.Stupig to run a SYSTEM command prompt on the secure logon desktop. Winlogon rarely launches an interactive shell.
HuntRule TeamWindowsprocess_creationHigh374Premium2026-07-14Possible UAC Bypass via ms-settings Shell Open Command Hijack (via registry_set)
This rule detects modification of the ms-settings shell open command registry value under HKCU which is the fodhelper.exe auto-elevation UAC bypass. Lunar Spider used this technique to elevate privileges without a consent prompt. The registry hijack redirects a trusted auto-elevating binary to run an attacker-controlled command with high integrity.
HuntRule TeamWindowsregistry_setHigh81Premium2026-07-13OpenSSH Server Firewall Configuration on Windows - PowerShell (via powershell)
This rule detects configure the Windows firewall to allow incoming connections to perform stealthy lateral movement.
HuntRule TeamWindowspowershellHigh103Premium2026-07-13Malicious Unsigned libConfigurer64 Dylib Side-Loading via Image Load
This rule detects loading of the libConfigurer64 dylib which pirated macOS applications side-load to execute the bundled Khepri implant. This uniquely named unsigned library is the loading mechanism of the campaign so its appearance indicates a trojanized pirated app running malicious code.
HuntRule TeamMacosimage_loadHigh181Premium2026-07-13Malicious BlackByte Ransomware Host Marker via Control Panel Registry
This rule detects the international control panel values s1159 and s2359 being set to BLACKBYTE, a distinctive host-marking artifact created by BlackByte ransomware. BlackByte writes this value to tag infected systems.
HuntRule TeamWindowsregistry_setHigh82Premium2026-07-13