Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,390 rules
MintsLoader Stage-Two C2 Beacon via htr.php Key and Campaign Parameters (via proxy)
This rule detects MintsLoader stage-two command-and-control beacons that request the htr.php endpoint with key, host id, and campaign parameters against DGA-generated domains. Adversaries leverage this structured request to fetch the next-stage payload keyed to the infected host, making the endpoint-and-parameter combination a strong C2 indicator.
HuntRule TeamWebproxyHigh52Premium2026-06-27Suspicious AWS CloudTrail Logging Disabled
This rule detects API calls that stop or delete AWS logging such as StopLogging, DeleteTrail and DeleteFlowLogs. Adversaries disable CloudTrail and VPC flow logs to blind defenders before carrying out further actions, a defense evasion step that should be rare and deliberate.
HuntRule TeamAwscloudtrailHigh121Premium2026-06-27Malicious Windows Defender Exclusion of Drive Roots via Add-MpPreference (via process_creation)
This rule detects a PowerShell Add-MpPreference command adding whole drive roots as Windows Defender scan exclusions, an impairment step the 8220 Gang cryptomining campaign runs before dropping miner payloads. Excluding entire drives blinds antivirus across the system. Detecting broad exclusion-path additions surfaces defense evasion that precedes cryptominer deployment.
HuntRule TeamWindowsprocess_creationHigh133Premium2026-06-27Possible Bitbucket Pre-Auth RCE via git archive Spawning Shell (CVE-2022-36804) (via process_creation)
This rule detects the git process spawning a shell interpreter as a child on a Bitbucket server host. This maps to CVE-2022-36804 exploitation where git archive with an injected --exec argument executes /bin/bash. Such a parent-child relationship indicates unauthenticated command execution rather than normal repository operations.
HuntRule TeamLinuxprocess_creationHigh82Premium2026-06-27Suspicious ShadowGuard Rootkit Hidden Artifacts via swsecret Files (via file_event)
This rule detects creation of the swsecret_config.txt and swsecret_data artifacts used by the ShadowGuard rootkit to store hidden configuration and data in the Shadow espionage campaigns. These named files back the rootkit hiding logic, so their appearance on disk indicates rootkit deployment.
HuntRule TeamLinuxfile_eventHigh4110Premium2026-06-27Malicious setcap Assigning cap_sys_admin for GameOverlay Privilege Escalation (via process_creation)
This rule detects setcap granting effective inheritable and permitted file capabilities such as cap_sys_admin to an executable, the step the GameOverlay Ubuntu OverlayFS exploit CVE-2023-2640 and CVE-2023-32629 uses to smuggle privileged capabilities across a copy-up. Assigning powerful capabilities to non-root executables is a strong local privilege escalation indicator.
HuntRule TeamLinuxprocess_creationHigh112Premium2026-06-27Malicious Active Directory Database Backup via wbadmin to Loopback Admin Share (via process_creation)
This rule detects wbadmin backing up the NTDS database and registry hives while including ntds.dit in the target set, the domain credential-theft technique used in the Akira intrusion to copy the directory database via a loopback admin share. Adversaries abuse wbadmin to snapshot ntds.dit and the SYSTEM and SECURITY hives for offline hash extraction, so a wbadmin job referencing ntds.dit is a high-confidence dumping indicator.
HuntRule TeamWindowsprocess_creationHigh81Premium2026-06-27Malicious Impacket WMIExec ADMIN Share Output Redirection
This rule detects the Impacket wmiexec pattern where a command is executed through WMI and its output is redirected to the local ADMIN$ share on 127.0.0.1. The BlackJack group used WMIExec for remote command execution during lateral movement, and this loopback ADMIN$ redirection is characteristic of the tool.
HuntRule TeamWindowsprocess_creationHigh136Premium2026-06-27Suspicious SafeBoot RunOnce Persistence for Safe Mode Encryption by RA World
This rule detects registry additions creating a RunOnce entry under the SafeBoot key, a technique the RA World ransomware group uses to force execution after rebooting the host into safe mode where security tooling is inactive. Encrypting in safe mode evades endpoint defenses that do not load there. Detecting this configuration exposes preparation for defense-evasive ransomware execution.
HuntRule TeamWindowsprocess_creationHigh202Premium2026-06-27Malicious Salat Stealer Microsoft Defender Disable via Multiple Set-MpPreference Flags (via process_creation)
This rule detects PowerShell invoking Set-MpPreference with the behavior, real-time, or script-scanning disable flags used by the Salat Stealer Rust loader to turn off Microsoft Defender protections before deploying its payload. Adversaries leverage this to blind endpoint protection ahead of credential theft and exfiltration, making early detection critical for stopping the intrusion.
HuntRule TeamWindowsprocess_creationHigh91Premium2026-06-27Suspicious Gh0stGambit Run Key Persistence for Phone Executable
This rule detects a Run key value named Phone pointing at a Phone executable being written for persistence. The Gh0stGambit dropper set this autorun entry to relaunch its payload across reboots. Autorun persistence under this specific value and image name maps to the Gh0st RAT deployment chain.
HuntRule TeamWindowsregistry_setHigh61Premium2026-06-26Malicious Event Log Cleared - Native (via security, system)
This rule detects cleared the event logs.
HuntRule TeamWindowssecurity, systemHigh349Premium2026-06-26Malicious GhostSocks Loader Execution with johnpidar Argument via process_creation
This rule detects process command lines containing the distinctive johnpidar argument. This hardcoded flag is passed to the GhostSocks loader delivered by fake OpenClaw installers, and its presence on a command line is a strong indicator of active infostealer and SOCKS proxy execution on the host.
HuntRule TeamWindowsprocess_creationHigh3910Premium2026-06-26Malicious rundll32 Loading DLL from WebDAV SSL Share
This rule detects rundll32 loading a DLL from a WebDAV SSL share indicated by the @SSL path token, an intrusion step observed in ACR Stealer delivery chains. Executing a remotely hosted DLL over WebDAV lets the attacker run code without writing the payload to local disk and evades application controls.
HuntRule TeamWindowsprocess_creationHigh243Premium2026-06-26Suspicious Scheduled Task Creation Spawned by Microsoft Office
This rule detects a Microsoft Office application spawning schtasks to register a scheduled task which mirrors the Cobalt Kitty initial access chain described by WithSecure where a malicious Word document created a persistence task. An Office document launching schtasks is highly abnormal and typically indicates macro driven persistence or execution following a phishing lure.
HuntRule TeamWindowsprocess_creationHigh1510Premium2026-06-26