Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,392 rules
Suspicious ASPX Webshell Written to IIS inetsrv Directory via file_event
This rule detects an fd.aspx file being written under the IIS inetsrv directory, matching the webshell dropped by the hacktivist actors for server access. Web-facing script files appearing in the IIS binaries path are a hallmark of server-side webshell deployment. This supports persistence and remote command execution on internet-facing hosts.
HuntRule TeamWindowsfile_eventHigh91Premium2026-07-03Malicious more_eggs Scriptlet DLL Registration via regsvr32 Action Install from AppData (via process_creation)
This rule detects regsvr32 registering a DLL from a user AppData path with the /i Action install switch, the second-stage more_eggs loader behavior in which wmiprvse.exe spawned regsvr32 to activate a payload dropped under AppData Roaming Microsoft. Adversaries use the regsvr32 /n /i scriptlet-install path to run code through a trusted binary while avoiding on-disk executables, so this pattern from a user directory is a strong loader indicator.
HuntRule TeamWindowsprocess_creationHigh93Premium2026-07-02Malicious SAM and SYSTEM Hive Dump via reg save (via process_creation)
This rule detects use of reg.exe to save the SAM or SYSTEM registry hives to disk for offline credential extraction. This technique was observed in the APT41 intrusion targeting government IT services in Africa. Dumping these hives lets attackers recover local account password hashes and boot keys away from the host and is a strong precursor to lateral movement.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-07-02Malicious Disabling of Linux Security Modules AppArmor and SELinux
This rule detects commands that disable the SELinux and AppArmor kernel security modules on Linux hosts. The RondoDox payload deployed after CVE-2025-55182 exploitation disables these protections to run unhindered as reported by Kaspersky. Tampering with mandatory access controls is a strong defense evasion indicator that precedes further malicious activity.
HuntRule TeamLinuxprocess_creationHigh437Premium2026-07-02Malicious Project CAV3RN DNS Configuration Recovery via cloudlanecdn.com (via dns_query)
This rule detects DNS queries to encoded subdomains of cloudlanecdn.com, a channel used by the Project CAV3RN espionage framework to recover configuration data from DNS AAAA records. The encoded label structure and attacker-controlled domain indicate covert command-and-control and data-encoding activity that should not appear in normal traffic.
HuntRule TeamNetworkdns_queryHigh454Premium2026-07-02Suspicious Ivanti Connect Secure License Keys-Status Command Injection Request (via webserver)
This rule detects HTTP requests to the Ivanti Connect Secure /api/v1/license/keys-status/ endpoint that embed a shell command separator followed by an interpreter reference. Actors chained a semicolon and python invocation onto this path to achieve command injection and drop reverse shells. Requests to this endpoint carrying inline command syntax indicate active exploitation.
HuntRule TeamWebwebserverHigh256Premium2026-07-02Malicious UNC1549 MINIBIKE DLL Side-Load of secur32.dll via FileCoAuth (via image_load)
This rule detects the OneDrive-associated FileCoAuth.exe binary loading a secur32.dll from a non-system directory, the side-load path for UNC1549 MINIBIKE and MINIBUS backdoors. The suspected Iranian actor abused a trusted-looking executable to load a malicious DLL of the same name as a system library. Loading secur32.dll from outside System32 through FileCoAuth is a high-fidelity side-loading indicator.
HuntRule TeamWindowsimage_loadHigh162Premium2026-07-02Possible DLL Side-Loading via DicomPortable Spawned by ITarian RmmService
This rule detects DicomPortable launched by the ITarian RmmService process which the phishing RMM campaigns abuse to side-load HijackLoader and DeerStealer through a trojanized DLL. Chaining a legitimate RMM service into a vulnerable portable binary lets adversaries execute malware under a trusted parent. Detecting this parent-child pair surfaces DLL search order hijacking used for stealer delivery.
HuntRule TeamWindowsprocess_creationHigh93Premium2026-07-02Malicious DLL Side-Loading of SBAMBRES.DLL by VIPRE Binary via DeedRAT (via image_load)
This rule detects the legitimate VIPRE MambaSafeModeUI.exe binary loading SBAMBRES.DLL from the ProgramData Micro directory, the side-loading step that launches the DeedRAT backdoor. Genuine VIPRE components load this DLL from their install directory, not ProgramData.
HuntRule TeamWindowsimage_loadHigh163Premium2026-07-01Suspicious notepad Spawned by mshta for Process Injection
This rule detects mshta spawning notepad which in the WithSecure Windows lab was created suspended as an injection host for a Covenant Grunt implant. The script host mshta launching notepad has no legitimate purpose and strongly suggests it is being used as a hollow target for process injection.
HuntRule TeamWindowsprocess_creationHigh335Premium2026-07-01Conhost Suspicious Command Execution
Detects use of conhost in "headless" mode. By running conhost.exe in "headless" mode, it means that no visible window will pop up on the victim's machine.
HuntRule TeamWindowsprocess_creationHigh72Premium2026-07-01Malicious Apache Camel Exec Header Injection
This rule detects HTTP requests containing Apache Camel exec-command headers used to bypass the header filter in CVE-2025-27636 and CVE-2025-29891. Attackers inject CamelExecCommandExecutable and CamelExecCommandArgs headers to run arbitrary commands on vulnerable Camel routes. Presence of these headers in inbound traffic indicates exploitation attempts.
HuntRule TeamWebwebserverHigh132Premium2026-07-01Malicious Service Abuse with Backdoored "command Failure" - Reg via Command (via process_creation)
This rule detects modify the configuration of a service to trigger an action when the service is crashed.
HuntRule TeamWindowsprocess_creationHigh347Premium2026-07-01Malicious Iptables Drop of Syslog Forwarding Ports on Ivanti Connect Secure (via process_creation)
This rule detects iptables commands adding DROP rules for the syslog forwarding ports 514 and 6514 on Ivanti Connect Secure, an anti-forensics step observed during zero-day exploitation to sever remote log delivery. Blocking log egress on an appliance indicates active defense evasion by an intruder.
HuntRule TeamLinuxprocess_creationHigh179Premium2026-07-01Windows Process: SystemSettingsAdminFlows.exe Used to Disable Windows Defender
Alerts when SystemSettingsAdminFlows.exe is launched with command-line arguments consistent with disabling Windows Defender.
Chirag Damani (KPMG India), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh341Free2026-07-01