Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,198 rules
Suspicious XZ Utils Backdoor Kill-Switch Environment String via process_creation
This rule detects the hardcoded kill-switch string used by the XZ Utils liblzma backdoor (CVE-2024-3094) appearing in process command lines or environment variables. The backdoor checks for this specific token to disable itself, and its presence in telemetry indicates interaction with the implanted malicious code. Investigating hosts exhibiting this string helps identify systems affected by the supply chain attack.
HuntRule TeamLinuxprocess_creationMedium123Premium2026-07-30Suspicious Windows Event Log Clearing via wevtutil on EC2 Host
This rule detects the wevtutil utility being used to clear Windows event logs which destroys host forensic evidence. In the Wiz hybrid cloud response the attacker deleted local operating system logs on compromised EC2 Windows instances to frustrate investigation. This is important because clearing event logs is a deliberate anti-forensic action that almost never occurs during normal administration and hides earlier attacker activity.
HuntRule TeamWindowsprocess_creationHigh268Premium2026-07-30Malicious Axios npm Compromise Windows Payload Artifacts wt.exe and 6202033 (via process_creation)
This rule detects execution of the wt.exe payload dropped in ProgramData and the numbered staging scripts 6202033.vbs 6202033.ps1 and system.bat used by the compromised axios npm package to deploy its RAT on Windows. These fixed artifact names run during or shortly after npm install and indicate an active infection beaconing every 60 seconds.
HuntRule TeamWindowsprocess_creationHigh131Premium2026-07-30Suspicious Kubernetes API Exposure via kubectl proxy
This rule detects kubectl proxy being launched with a listening port which exposes the Kubernetes API server through an unauthenticated local proxy. Wiz identifies this as a control plane initial access vector because the proxy forwards requests using the operator credentials without further authentication. This is important because binding the proxy to a reachable interface can hand full authenticated API access to anyone who can connect to that port.
HuntRule TeamLinuxprocess_creationMedium72Premium2026-07-30Malicious Windows Defender Exclusion of System32 via Registry (via registry_set)
This rule detects a Windows Defender path exclusion being registered for the System32 directory, a defense-evasion step in the full TinyTurla kill chain. Excluding System32 lets Turla stage and run its service DLL from a trusted location without antivirus inspection.
HuntRule TeamWindowsregistry_setHigh91Premium2026-07-30Malicious Print Spooler Privilege Escalation via Printer Added - CVE-2020-1048 (via powershell)
This rule detects abuse the printer spooler features to load a DLL. The attack is composed by 4 steps > 1) create a printer that points to a missing DLL 2) print to that port 3) crash the printer spool 4) have his original DLL registered for privilege escalation.
HuntRule TeamWindowspowershellHigh73Premium2026-07-30Malicious WARMCOOKIE DLL Execution from RtlUpd Path via rundll32
This rule detects rundll32.exe executing a DLL from the C:\ProgramData\RtlUpd directory, the fixed drop path and loader behavior of the WARMCOOKIE backdoor. The malware writes RtlUpd.dll to this ProgramData location and runs it via rundll32 to establish its foothold.
HuntRule TeamWindowsprocess_creationHigh237Premium2026-07-30Suspicious Workday Payment Election Change via Compromised Account (via workday)
This rule surfaces Workday audit events where an account modifies payment elections or core account details. This activity matches payroll pirate operations in which attackers who phished university credentials register their own MFA device and reroute direct deposit to attacker-controlled bank accounts. Correlating payment element changes with recent device enrollment helps surface payroll fraud before funds are lost.
HuntRule TeamWorkdayauditLow111Premium2026-07-30Malicious DLL Sideloading of BrMod104.dll by Stately Taurus (via image_load)
This rule detects the loading of BrMod104.dll, a malicious module sideloaded by the Stately Taurus (Mustang Panda) group to deploy the Bookworm and PubLoad malware families. DLL sideloading via a signed host executable lets the actor execute code while evading application controls and blending with legitimate processes.
HuntRule TeamWindowsimage_loadHigh419Premium2026-07-30Malicious SesameOp Netapi64 Artifact Files Written to Windows Temp (via file_event)
This rule detects creation of SesameOp working files such as Netapi64.start and Netapi64.Exception in Windows Temp along with files carrying the .Netapi64 extension. These artifacts are dropped by the SesameOp backdoor while it decrypts payloads and stores state for its OpenAI Assistants API C2 relay. Surfacing these distinctive on-disk markers reveals an active backdoor foothold that hides its traffic inside a legitimate cloud API.
HuntRule TeamWindowsfile_eventHigh132Premium2026-07-30Suspicious fontdrvhost Execution with Config Argument
This rule detects a process named fontdrvhost.exe executed with a config file argument, a masquerading pattern from the REF7707 campaign where a renamed tool was staged via a scheduled task named EPolicyManager. The genuine Windows font driver host takes no such command line arguments so this indicates an impostor binary. Combined with scheduled task execution this reveals attacker persistence and execution.
HuntRule TeamWindowsprocess_creationHigh433Premium2026-07-30Suspicious Scheduled Task Persistence Masquerading as TeamViewer (Qilin)
This rule detects creation of a scheduled task named TVInstallRestore configured to run at user logon. The Qilin ransomware group creates this task, masquerading as a TeamViewer component, to persist and restore access. Logon-triggered scheduled tasks with deceptive names are a common persistence technique.
HuntRule TeamWindowsprocess_creationHigh52Premium2026-07-30Malicious Remote Script Execution via curl Piped to Shell
This rule detects curl downloading a remote script with insecure TLS and piping it directly into a shell, observed in a Huntress Linux intrusion where the actor fetched a worker script from an attacker host before deploying a cryptominer. The -k flag ignores certificate validation while the pipe executes the payload in memory without touching disk for review. Fetch-and-execute one-liners are a common initial staging technique for Linux malware.
HuntRule TeamLinuxprocess_creationMedium101Premium2026-07-30Malicious Fake Homebrew Installer Execution via curl to Typosquatted Domain (via process_creation)
This rule detects a shell one-liner that curls an install script from the typosquatted homabrews domain and pipes it to bash, the ClickFix delivery behavior for Cuckoo Stealer on macOS. Adversaries leverage a fake Homebrew install command copied from a lure page to fetch and run the first-stage payload.
HuntRule TeamMacosprocess_creationHigh115Premium2026-07-30Reported BINDCLOAK Encrypted Payload File Event
Detects file telemetry for the exact encrypted payload filename shown in the attack-flow image. It covers the file IOC, not the decryption or reflective loading behavior.
HuntRule TeamWindowsfile_eventHigh682Premium2026-07-30