Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,395 rules
Suspicious WARMCOOKIE Scheduled Task for rundll32 Persistence via process_creation
This rule detects creation of a scheduled task that runs rundll32 against the WARMCOOKIE loader RtlUpd at a short recurring interval to maintain persistence. The backdoor registers a task firing every ten minutes to ensure continuous execution. The combination of a minute-based recurrence with rundll32 loading this DLL is characteristic of WARMCOOKIE.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-07-11Malicious Audit Policy Disabled by Command Line (via security)
This rule detects attempts disbaled the audit policy for defense evasion purposes.
HuntRule TeamWindowssecurityHigh123Premium2026-07-11NetSupport Manager RAT Execution From a User-Writable Path (via process_creation)
This rule detects the NetSupport Manager remote-control client (client32.exe) running from a user-writable directory such as AppData, ProgramData or Temp, where adversaries deploy the otherwise-legitimate RMM tool as a covert remote access trojan. Abuse of remote monitoring and management software is a leading access technique in the Red Canary Threat Detection Report. Because sanctioned installs live in Program Files, execution from user paths is a strong indicator of malicious NetSupport deployment.
HuntRule TeamWindowsprocess_creationHigh188Premium2026-07-11Malicious Active Directory Replication Request Indicating DCSync
This rule detects a directory service access event granting the replicating directory changes right which the ALPHV actor exercised through a credential tool to perform DCSync and pull domain hashes and this matters because outside of domain controllers and a small set of sync services the request for the replication extended right is a high fidelity indicator of DCSync credential theft.
HuntRule TeamWindowssecurityHigh121Premium2026-07-11Suspicious UAC Bypass via iscsicpl Auto-Elevation in Operation TrueChaos
This rule detects iscsicpl.exe spawning a command interpreter or script host child process, an auto-elevation UAC bypass abused in Operation TrueChaos against Southeast Asian government targets. iscsicpl launching cmd, powershell or a temporary binary indicates privilege escalation ahead of Havoc C2 deployment.
HuntRule TeamWindowsprocess_creationHigh221Premium2026-07-11Malicious Keychain Credential Theft via security find-generic-password by ClickLock macOS Stealer (via process_creation)
This rule detects the macOS security utility invoked with find-generic-password to dump the Chrome keychain secret, the exact command ClickLock stealer runs to extract stored browser credentials. Reading the keychain password non-interactively reveals credential theft. Detecting it exposes ClickLock harvesting saved secrets.
HuntRule TeamMacosprocess_creationHigh267Premium2026-07-11Malicious GPO Permission Abuse via SharpGPOAbuse
This rule detects execution of SharpGPOAbuse, a tool CrazyHunter operators use to weaponize edit rights over a Group Policy Object for domain-wide code execution. Abusing GPO permissions lets an attacker push tasks or scripts to every host in scope. Presence of this tooling indicates active privilege abuse against Active Directory.
HuntRule TeamWindowsprocess_creationHigh112Premium2026-07-11Malicious Cobalt Strike Default Named Pipe Creation (via pipe_created)
This rule detects creation of named pipes matching Cobalt Strike default and post-exploitation patterns such as msagent_, postex_ and status_ pipes used for beacon inter-process communication and privilege escalation. Cobalt Strike is among the most prevalent adversary tools in the Red Canary Threat Detection Report, used across ransomware and espionage intrusions for command and control. Detecting its characteristic named pipes surfaces beacon activity that often evades network-based controls.
HuntRule TeamWindowspipe_createdHigh52Premium2026-07-11Suspicious Registry Run Key Persistence Masquerading as Microsoft Updater (via process_creation)
This rule detects reg.exe adding a CurrentVersion Run value named updater that points to a Microsoft Updater directory. Maranhao Stealer establishes persistence with this masqueraded autorun entry in the user AppData path.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-07-11Possible GCleaner Loader C2 Check-in via cpa ping php Endpoint via proxy
This rule detects GCleaner loader command and control check-ins that request the /cpa/ping.php endpoint carrying a substr parameter. GCleaner is a pay per install loader that pulls follow on payloads after beaconing to its panel. The distinctive URI and query structure identifies the loader control channel independent of the rotating C2 IP addresses.
HuntRule TeamWebproxyHigh366Premium2026-07-11Deleting Windows Defender scheduled tasks
Detects the deletion of scheduled tasks related to Windows Defender.
HuntRule TeamWindowsprocess_creationHigh63Premium2026-07-11Malicious Backup and Shadow Copy Destruction via Native Utilities
This rule detects the deletion of volume shadow copies, backup catalogs, and recovery configuration through native Windows utilities, a recovery-inhibition step performed by Hunters International affiliates before encryption. Destroying backups to prevent restoration is a hallmark of ransomware impact activity and should be treated as high priority.
HuntRule TeamWindowsprocess_creationHigh182Premium2026-07-11Suspicious Finger Client Execution for Command and Control
This rule detects execution of the legacy finger.exe client, which adversaries abuse to reach external hosts and exfiltrate command output over the finger protocol. Huntress observed finger used to contact an attacker IP following OWASSRF exploitation of Exchange. Because finger is effectively obsolete on modern networks, any execution warrants investigation.
HuntRule TeamWindowsprocess_creationHigh4210Premium2026-07-11Suspicious Cgroup release_agent Abuse for Container Escape
This rule detects command activity referencing the cgroup release_agent and notify_on_release mechanism used to break out of a container and execute code on the host. Writing a release_agent path that runs on cgroup teardown is a classic privileged container escape. Detecting this reference exposes an attempted breakout to the underlying node.
HuntRule TeamWindowsprocess_creationHigh405Premium2026-07-11Suspicious Microsoft Defender Real-Time Protection Disabled via Registry
This rule detects registry modifications that disable Microsoft Defender real-time monitoring under the Windows Defender policy keys. Microsoft observed services.exe abused to disable Defender via registry during post-exploitation of SharePoint before deploying Warlock ransomware. Turning off antivirus through policy keys clears the way for credential theft and encryption, so this change warrants immediate review.
HuntRule TeamWindowsregistry_setHigh348Premium2026-07-11