Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,201 rules
AsyncRAT C2 Check-in via Structured Verify Query Parameters (via proxy)
This rule detects AsyncRAT command-and-control check-ins carrying the structured verify query parameters observed in the ScreenConnect campaign, including the verify host, Support and Guest markers. Adversaries leverage these fixed request parameters to register infected hosts with the controller over web traffic.
HuntRule TeamWebproxyHigh133Premium2026-07-29Malicious EDR Termination via rundll32 Loading polers.dll Targeting Fortinet Processes (via process_creation)
This rule detects the Interlock EDR killer which uses rundll32.exe to invoke the exported start routine of polers.dll and terminate security processes matching the Forti pattern through a vulnerable anti cheat driver. The watchdog repeatedly relaunches to keep defenses down. This command line is unique to the tooling.
HuntRule TeamWindowsprocess_creationHigh141Premium2026-07-29Suspicious New Network File Share Created (via security)
This rule detects scenarios when a new file share is created.
HuntRule TeamWindowssecurityMedium52Premium2026-07-29CraftCMS Yii Object Injection via generate-transform Endpoint (via webserver)
This rule detects requests to the CraftCMS asset generate-transform endpoint carrying Yii gadget class markers, the object-injection primitive exploited in CVE-2025-32432 to reach PhpManager and execute attacker code from a session file. Adversaries send crafted class references such as FnStream and PhpManager to trigger unauthenticated remote code execution.
HuntRule TeamWebwebserverHigh81Premium2026-07-29Suspicious Renaming of System wget and curl Binaries (via process_creation)
This rule detects the system wget and curl binaries being renamed to wget_w and curl_c on QNAP and embedded devices. The PolarEdge QNAP backdoor relocates these download utilities to evade detection rules that watch the standard tool names while retaining download capability. Renaming trusted system binaries to these suffixed names is a defense evasion tactic specific to the implant.
HuntRule TeamLinuxprocess_creationMedium102Premium2026-07-29Malicious Azure WireServer Access Impersonating WALinuxAgent (via process_creation)
This rule detects a process contacting the Azure WireServer host address while presenting the WALinuxAgent identity, a technique used in the ChaosDB walkthrough to steal certificates and goal-state data. A non-agent process impersonating the Linux guest agent to reach WireServer is a strong sign of credential theft. Legitimate agent traffic originates from the agent binary itself, not ad-hoc curl commands.
HuntRule TeamLinuxprocess_creationHigh399Premium2026-07-29Suspicious Lazarus queue.bat Persistence Dropped in Startup Folder
This rule detects the creation of a file named queue.bat inside a Windows Startup folder which is the persistence mechanism used by the Lazarus DeceptiveDevelopment and Contagious Interview campaigns. The batch file relaunches the malicious Node.js and Python loader chain at every logon. Attackers use it to maintain foothold on developer machines targeted through fake job interviews.
HuntRule TeamWindowsfile_eventHigh95Premium2026-07-29Suspicious File Download via Certutil URLCache
This rule detects certutil abused as a downloader through its urlcache and file flags to retrieve a remote payload over HTTP. This LOLBin technique was documented delivering executables into the temp directory before execution. Living-off-the-land downloads via certutil let attackers stage tooling while evading application controls.
HuntRule TeamWindowsprocess_creationMedium348Premium2026-07-29Suspicious svchost Masquerading Executed Outside System Directory
This rule detects a process named svchost.exe running from any location other than the System32 or SysWOW64 directories, matching the GopherWhisper JabGopher component that spawns a fake svchost.exe host for LaxGopher injection. The legitimate service host only executes from System, so a copy elsewhere reveals masquerading and process injection.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-07-29Malicious Self-Deletion Via Fsutil SetZeroData
This rule detects fsutil.exe being used with the setZeroData operation to overwrite file contents with zeros. BlackByte used fsutil setZeroData to zero out and self-delete its own binary after execution to hinder forensic recovery. Zeroing file data through fsutil is an anti-forensic indicator removal action rarely performed by legitimate administration.
HuntRule TeamWindowsprocess_creationHigh319Premium2026-07-29Suspicious Entra ID Device Code Flow Authentication
This rule detects Entra ID sign-ins performed through the OAuth device code flow which threat actors abuse in device code phishing campaigns to trick users into authorizing attacker-controlled sessions and obtain tokens for apps such as Azure AD PowerShell and the Microsoft Authentication Broker. Device code authentications with inconsistent user agent and location across a shared session are a hallmark of this phishing technique.
HuntRule TeamAzuresigninlogsMedium321Premium2026-07-29Possible SharePoint ToolShell Exploitation via ToolPane Edit POST With Spoofed Referer (CVE-2025-53770)
This rule detects a POST to the SharePoint ToolPane page in edit display mode with a Referer spoofing SignOut.aspx, the exploitation request of the ToolShell CVE-2025-53770 and CVE-2025-53771 chain. It matters because this unauthenticated request is the entry point for deserialization based remote code execution.
HuntRule TeamWebwebserverHigh224Premium2026-07-29Suspicious Execution From var tmp Masquerading as apt via GRIDTIDE
This rule detects a binary named xapt executing from the var tmp directory as used by the GRIDTIDE espionage campaign to masquerade as the legitimate apt package manager. Attackers run this payload with root privileges to spawn shells and establish backdoor access.
HuntRule TeamLinuxprocess_creationHigh93Premium2026-07-29Suspicious COLDRIVER RunMRU History Clearing via Reg Delete (via process_creation)
This rule detects deletion of the Explorer RunMRU registry key through reg delete which the COLDRIVER ClickFix chain performs to erase evidence of the Run dialog command the victim was tricked into executing. Programmatic clearing of RunMRU is a strong anti forensics signal.
HuntRule TeamWindowsprocess_creationMedium51Premium2026-07-29Malicious Credential Added to an Azure AD Application (via auditlogs)
This rule detects a password or key credential being added to an Azure AD application or service principal, an account-manipulation technique that grants an attacker persistent, app-based access to a tenant. Adding application credentials is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting this operation surfaces a stealthy tenant backdoor being created.
HuntRule TeamAzureauditlogsHigh102Premium2026-07-29