Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,194 rules
Malicious Ransomware Extension Class Registration for ELPACO-team by Elpaco Ransomware
This rule detects registration of the .ELPACO-team file extension class under HKLM Classes. Elpaco ransomware, a Mimic variant, registers its own encrypted-file extension to associate the ransom note handler after encryption. Presence of this class key indicates ransomware has executed and modified file associations on the host.
HuntRule TeamWindowsregistry_setCritical81Premium2026-08-01Possible Atlassian Confluence CVE-2023-22518 Setup-Restore Exploitation via Webserver (via webserver)
This rule detects unauthenticated HTTP POST requests to the Confluence setup-restore endpoints used to exploit the improper authorization vulnerability CVE-2023-22518. It is associated with attacks against Atlassian Confluence Data Center and Server that abuse the restore functionality to import a malicious ZIP. Successful exploitation lets an attacker reset the instance and create administrative access, so this activity should be triaged as a potential compromise.
HuntRule TeamWebwebserverHigh397Premium2026-08-01Suspicious Phishing URL with Unrendered Template Placeholder (via proxy)
This rule detects web requests whose URL path contains the unrendered phishing-kit template placeholder sf_rand_string_lowercase6, a literal artifact left in links from a large refresh-header phishing campaign. The presence of this build-time placeholder in a live URL is a strong indicator of the credential-harvesting kit and its automatic redirect landing pages.
HuntRule TeamWebproxyHigh82Premium2026-08-01Suspicious SolarWinds Web Help Desk Java Process Spawning Command Shell (via process_creation)
This rule detects the SolarWinds Web Help Desk java runtime spawning a command shell through its wrapper process, a chain indicative of post-exploitation following CVE abuse of Web Help Desk. Observed in Elastic Security Labs telemetry where wrapper.exe to java.exe to cmd.exe signals remote code execution against an exposed application server.
HuntRule TeamWindowsprocess_creationMedium163Premium2026-08-01Suspicious Tomcat Manager WAR Deployment via HTTP PUT by UNC6201
This rule detects an HTTP PUT to the Tomcat manager text deploy endpoint with update set to true which UNC6201 used to upload a WAR web shell after abusing default manager credentials. Attackers deploy the GRIMBOLT backdoor as a running web application to gain root on Dell RecoverPoint appliances.
HuntRule TeamWebwebserverHigh2310Premium2026-08-01Malicious ClickFix Execution Chain Spawning MSHTA via Pcalua on EtherRAT Infection
This rule detects the Program Compatibility Assistant launcher pcalua.exe being abused to proxy execution of mshta.exe against an HTML application. This living-off-the-land chain is a ClickFix step in the EtherRAT SYS_INFO campaign that fetches command and control from an Ethereum contract. Using pcalua to break the parent-child chain evades detections keyed on direct mshta launches.
HuntRule TeamWindowsprocess_creationHigh395Premium2026-08-01Suspicious PowerShell With Reversed HTTP String (via process_creation)
This rule detects PowerShell command lines containing the reversed HTTP string used to hide C2 URLs. This steganography spam campaign reverses download URLs before reconstructing them at runtime.
HuntRule TeamWindowsprocess_creationHigh301Premium2026-07-31Malicious ShadowPad DLL Sideloading via TosBtKbd by Knife Framework
This rule detects the legitimate Toshiba TosBtKbd executable loading the TosBtKbdLayer DLL used to sideload ShadowPad. The China-nexus Knife framework abuses this signed binary to execute its ShadowPad implant through search-order hijacking. Sideloading through a trusted executable lets the implant run under the cover of a legitimate process.
HuntRule TeamWindowsimage_loadHigh72Premium2026-07-31Suspicious Bruteforce via Password Reset (via security)
This rule detects if a attacker attempts to reset multiple times a user password to perform a bruteforce attack.
HuntRule TeamWindowssecurityInformational355Premium2026-07-31Suspicious Oversized Numeric X-Forwarded-For Header Targeting Ivanti Connect Secure (via proxy)
This rule detects the network signature of Ivanti Connect Secure CVE-2025-22457 where an extremely long X-Forwarded-For header consisting only of digits and periods is used to overflow a stack buffer in the web process. Legitimate proxy chains do not produce headers of this length.
HuntRule TeamWebproxyLow3410Premium2026-07-31Suspicious Curl Download to Public User Directory
This rule detects curl being used to download a file into the C:\\Users\\Public directory, the staging behavior of the Snake Python infostealer delivered through messaging services. Attackers stage a ZIP payload in this world-writable location before unpacking and executing it. The combination of a download utility writing to Public is a strong sign of malware staging.
HuntRule TeamWindowsprocess_creationMedium141Premium2026-07-31Malicious Exploitation of Confluence setup-restore Endpoint
This rule detects POST requests to the Confluence setup-restore action, the endpoint abused in CVE-2023-22518 to reset the instance and gain administrative control before Cerber ransomware deployment. Requests to this administrative restore endpoint from untrusted sources indicate active exploitation of the vulnerability.
HuntRule TeamWebwebserverHigh3010Premium2026-07-31Suspicious Microsoft Edge Unpacked Extension Load via UNC6692 Edgecution
This rule detects Microsoft Edge being launched with the load-extension flag pointing at an unpacked extension directory. UNC6692 abuses this Edgecution technique to sideload a malicious browser extension for persistence and data access after Quick Assist intrusion. Command-line loading of unpacked extensions is rare outside development and warrants review.
HuntRule TeamWindowsprocess_creationMedium133Premium2026-07-31Suspicious Child Process Spawned by IIS Worker w3wp
This rule detects the IIS worker process w3wp.exe spawning PowerShell, cmd, or certutil, the webshell execution pattern seen in WS_FTP exploitation. The IIS worker should serve web content, not launch interactive shells or download tools, so these children indicate server-side code execution through a web application compromise.
HuntRule TeamWindowsprocess_creationHigh111Premium2026-07-31Suspicious Application Shim Database Installation via sdbinst
This rule detects sdbinst.exe installing a custom application-compatibility shim database (.sdb) file, a technique used to inject code and persist by intercepting API calls to a target application. Legitimate shim installs are rare on endpoints, making a non-standard .sdb install worth review.
HuntRule TeamWindowsprocess_creationMedium73Premium2026-07-31