Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,392 rules
SystemNightmare by GentilKiwi - New External Device Added - CVE-2021-1675 / CVE-2021-34527 (via security)
This rule detects exploit the PrintNightmare vulnerability by abusing the Windows print spooler using the service exposed by Gentilkiwi.
HuntRule TeamWindowssecurityHigh122Premium2026-06-29Malicious ESXi Virtual Machine Termination and Snapshot Removal via esxcli and vim-cmd (via process_creation)
This rule detects the ESXi shell loops used by Lynx ransomware to force-kill running virtual machines with esxcli vm process kill and to remove all snapshots with vim-cmd snapshot.removeall as described by Group-IB. Adversaries stop VMs and delete snapshots to enable datastore encryption and inhibit recovery on hypervisors, making this a strong pre-encryption signal.
HuntRule TeamLinuxprocess_creationHigh2910Premium2026-06-29Suspicious Winlogon Loading Keyboard Layout DLL kbdus1.dll
This rule detects winlogon.exe loading a DLL named kbdus1.dll, a keyboard-layout persistence technique used by Backdoor.Stupig to execute code as SYSTEM at logon. The legitimate keyboard file is kbdus.dll without the trailing digit.
HuntRule TeamWindowsimage_loadHigh193Premium2026-06-29Suspicious SearchIndexer Outbound Network Connection after Injection
This rule detects the Windows SearchIndexer process making outbound network connections to non local addresses. SolarMarker StellarInjector injects the SolarPhantom backdoor into SearchIndexer to run hVNC and stealer traffic from a trusted host. SearchIndexer should not initiate internet connections so this indicates code injection and C2.
HuntRule TeamWindowsnetwork_connectionHigh272Premium2026-06-29Suspicious COLDRIVER BAITSWITCH Execution via Rundll32 Verifyme Export (via process_creation)
This rule detects rundll32 invoking a DLL export named verifyme as used by the COLDRIVER ClickFix chain to run the BAITSWITCH loader from a remote share. Rundll32 calling this export is characteristic of the campaign.
HuntRule TeamWindowsprocess_creationHigh3710Premium2026-06-29Malicious Remote Payload Piped to Shell via wget on PAN-OS
This rule detects a remote payload being downloaded with wget and piped directly into a shell interpreter, a technique used in Operation MidnightEclipse to fetch second-stage tooling after exploiting CVE-2024-3400. Piping downloaded content straight to bash leaves no file on disk and is a common in-memory execution pattern. Detecting this reveals remote code retrieval and execution on the appliance.
HuntRule TeamWindowsprocess_creationHigh153Premium2026-06-29Malicious Local Account Creation Masquerading as krbtgt (via process_creation)
This rule detects creation of a local account named krtbgt via net.exe, a homoglyph masquerade of the krbtgt account used by Lazarus in Operation Blacksmith. The rogue account provides persistent authenticated access while imitating a well-known service identity.
HuntRule TeamWindowsprocess_creationHigh405Premium2026-06-29Malicious Fileless Execution via memfd Anonymous File on Linux Cloud Workload (via process_creation)
This rule detects a process whose executable path resolves to an in-memory memfd anonymous file, the fileless technique the PyLoose cryptomining attack used to run its XMRig payload from a Jupyter Notebook without touching disk. Attackers rely on memfd_create to evade file-based detection, so a process backed by a memfd descriptor on a cloud workload is highly suspicious.
HuntRule TeamLinuxprocess_creationHigh314Premium2026-06-28Web Shell Written to ScreenConnect App_Extensions Directory
This rule detects aspx or ashx files written to the ScreenConnect App_Extensions directory, where post-exploitation of the authentication bypass drops server-side web shells for code execution. Huntress observed operators writing extension pages to this root after gaining admin access. Executable web content in this location is not part of normal product operation and signals web shell installation.
HuntRule TeamWindowsfile_eventHigh195Premium2026-06-28Malicious OysterLoader C2 Beacon Using WordPressAgent User Agent
This rule detects outbound web requests carrying the distinctive WordPressAgent FingerPrint user agent used by OysterLoader. The loader beacons to its command server with this hardcoded agent and reaches encrypted endpoints. A non browser user agent of this exact form is a high confidence network indicator of OysterLoader activity.
HuntRule TeamWebproxyHigh231Premium2026-06-28Suspicious Run Key Persistence Launching Headless Conhost Node.js on EtherRAT Infection
This rule detects a Run key persistence value that chains conhost.exe with the --headless flag to silently launch the Node.js interpreter. This tradecraft is used by the EtherRAT SYS_INFO module to run its JavaScript backdoor without a visible console window. The headless conhost wrapper hides execution while maintaining autostart command and control.
HuntRule TeamWindowsregistry_setHigh399Premium2026-06-28SwimSnake AutoRecoverDat.dll Execution via rundll32 or regsvr32 (via process_creation)
This rule detects rundll32.exe or regsvr32.exe executing AutoRecoverDat.dll, the module the SwimSnake (Silver Fox) group drops into the user AppData Embarcadero folder to load shellcode and deploy the WinOS backdoor. Adversaries proxy execution of the malicious DLL through trusted signed binaries to evade application controls, making early detection critical for catching the loader before backdoor communication.
HuntRule TeamWindowsprocess_creationHigh41Premium2026-06-28Suspicious System Process Name Executing From Non-System Path
This rule detects a process named csrss.exe or dllhost.exe running from a directory other than Windows System32. DCRAT in this campaign masqueraded as csrss.exe and dllhost.exe while executing from user-writable locations. Legitimate csrss and dllhost only run from System32 so execution from another path is a reliable masquerading indicator.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-06-28Renamed Nimbus Manticore Stager Execution with doit Argument from 2FAGuard Directory (via process_creation)
This rule detects the renamed setup.exe stager executed with the doit argument from the 2FAGuard working directory, the GUI-suppressing invocation Nimbus Manticore uses through its BackupCheck scheduled task to load the native main.dll payload directly. Adversaries leverage this argument to run the implant without the decoy interface, making detection useful for catching the persistence stage of the infection chain.
HuntRule TeamWindowsprocess_creationHigh72Premium2026-06-28Suspicious Entra Sign-In to OfficeHome with axios User Agent
This rule detects a successful Entra ID sign-in to the OfficeHome application where the user agent contains axios, an automation library used by the Tycoon 2FA adversary-in-the-middle platform. Tycoon 2FA relayed intercepted credentials and stolen session cookies through scripted axios clients to authenticate as the victim. A non-browser axios agent completing sign-in to OfficeHome indicates automated session token replay from an AiTM phishing kit.
HuntRule TeamAzuresigninlogsHigh81Premium2026-06-28