Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,198 rules
Suspicious Systemd Service Masquerading as Sysmon (via file_event)
This rule detects creation of a systemd unit named sysmon.service, a masquerade used in the TeamPCP supply chain attack to disguise a persistence service as a monitoring agent. A systemd service impersonating Sysmon establishes boot persistence while blending in with expected security tooling.
HuntRule TeamLinuxfile_eventMedium123Premium2026-07-30Suspicious macOS Download History Query via sqlite3
This rule detects sqlite3 querying the macOS LSQuarantine download history database. Silver Sparrow reads the quarantine events database to identify the URL it was downloaded from as part of its execution and environment checks. Command-line sqlite3 access to the LSQuarantine store is unusual and can indicate malware inspecting its own delivery.
HuntRule TeamMacosprocess_creationMedium91Premium2026-07-30Suspicious Encoded PowerShell Execution Following SharePoint Exploitation (via ps_script)
This rule detects PowerShell invoked with a base64 encoded command, used in ToolShell post-exploitation to stage payloads while obscuring intent. Encoded command execution on SharePoint servers exploiting CVE-2025-53770 indicates hands-on-keyboard activity following initial access.
HuntRule TeamWindowsps_scriptMedium416Premium2026-07-30Malicious SesameOp Netapi64 Loader DLL Load via Masqueraded Netapi Module (via image_load)
This rule detects loading of Netapi64.dll, a loader module used by the SesameOp backdoor that masquerades as a legitimate Windows networking library while relaying commands through the OpenAI Assistants API for command and control. Adversaries use this .NET loader to decrypt and execute payloads under a trusted-looking name, so catching the module load exposes the implant before its covert C2 channel activates.
HuntRule TeamWindowsimage_loadHigh122Premium2026-07-30Malicious APT-C-60 SpyGlace Masqueraded Artifact Files (via process_creation)
This rule detects command lines referencing the iconcache.dat, Cached2014.tmp, sdll.tmp, or sDll_jj.dll artifacts dropped by APT-C-60 in its 2026 SpyGlace intrusions. These deliberately mundane cache and temp filenames masquerade loader and backdoor components to blend with legitimate system files.
HuntRule TeamWindowsprocess_creationHigh328Premium2026-07-30DCOM Lateral Movement - Via MMC20 (via powershell)
This rule detects execute the Impacket DCOMexec tool in order to abuse DCOM services.
HuntRule TeamWindowspowershellHigh247Premium2026-07-29Malicious mshta.exe Spawning bitsadmin via ClickFix Phantom Meet
This rule detects mshta.exe spawning bitsadmin.exe, the process chain produced by the ClickFix Phantom Meet campaign where a pasted clipboard command runs a remote HTA that then uses bitsadmin to download follow on executables. Neither mshta launching bitsadmin nor this fake meeting lure is normal user behavior. The parent child relationship is a high confidence detection of the ClickFix delivery chain.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-07-29Suspicious Mshta Execution of Remote Payload from Explorer via ClickFix Lure (via process_creation)
This rule detects mshta launched by explorer with a remote http argument, the ClickFix fake CAPTCHA pattern where a user pastes an attacker command into the Run dialog to fetch a remote HTA.
HuntRule TeamWindowsprocess_creationHigh133Premium2026-07-29Suspicious PSexec Application Execution (via process_creation)
This rule detects installs and executes PSexec.
HuntRule TeamWindowsprocess_creationMedium1810Premium2026-07-29Malicious LockBit Rundll32 Execution With gdll Export and -pass Argument
This rule detects rundll32.exe invoking a DLL export named gdll together with a -pass argument, the loader pattern used by LockBit 3.0 payloads staged from a batch file on the user Desktop. Huntress observed operators abusing a TeamViewer session to drop and run this payload for ransomware deployment. Catching the export and password-flag combination flags encryptor execution before file encryption completes.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-07-29Malicious Anonymous Access Performed to Multiple Targets (via security)
This rule detects would attempt to enumerate hosts and collect relevant information using anonymous access. Vulnerability scanners, enumeration software or tool like CrackMapexec may generate such behavior.
HuntRule TeamWindowssecurityHigh92Premium2026-07-29Malicious Run Key Persistence with xcschemer Value
This rule detects creation of a Run key value named xcschemer. SideWinder used this autorun value to persist its loader across reboots, and the specific value name is a strong indicator of this campaign on Windows hosts.
HuntRule TeamWindowsregistry_setHigh81Premium2026-07-29AsyncRAT C2 Check-in via Structured Verify Query Parameters (via proxy)
This rule detects AsyncRAT command-and-control check-ins carrying the structured verify query parameters observed in the ScreenConnect campaign, including the verify host, Support and Guest markers. Adversaries leverage these fixed request parameters to register infected hosts with the controller over web traffic.
HuntRule TeamWebproxyHigh133Premium2026-07-29Malicious EDR Termination via rundll32 Loading polers.dll Targeting Fortinet Processes (via process_creation)
This rule detects the Interlock EDR killer which uses rundll32.exe to invoke the exported start routine of polers.dll and terminate security processes matching the Forti pattern through a vulnerable anti cheat driver. The watchdog repeatedly relaunches to keep defenses down. This command line is unique to the tooling.
HuntRule TeamWindowsprocess_creationHigh141Premium2026-07-29Suspicious New Network File Share Created (via security)
This rule detects scenarios when a new file share is created.
HuntRule TeamWindowssecurityMedium52Premium2026-07-29