Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,388 rules
Malicious TELEPUZ ClickFix Stager via Hidden PowerShell Grab Endpoint
This rule detects a hidden execution-policy-bypass PowerShell command that pulls a payload from an index.php grab endpoint which is the ClickFix stager of the TELEPUZ malware-as-a-service delivered through Vidar chains. Victims are lured into pasting the command from a fake verification prompt. The specific grab API path combined with bypass flags marks the malicious download.
HuntRule TeamWindowsprocess_creationHigh203Premium2026-06-26Malicious Cobalt Strike C2 Beaconing via REST URI Paths and Legacy MSIE User-Agent (via proxy)
This rule detects HTTP command-and-control beaconing that combines the /rest/funcStatus and /rest/policy/3/ URI paths with a legacy MSIE 7.0 .NET CLR User-Agent, a Malleable C2 profile used by a multi-stage Cobalt Strike loader analyzed by Joe Sandbox. Adversaries craft these profiles to blend beacon traffic into ordinary web requests, making the combined URI and User-Agent pattern a reliable signal of an active beacon before hands-on-keyboard activity.
HuntRule TeamWebproxyHigh375Premium2026-06-26Malicious APT29 DLL Side-Loading via msoev.exe from Windows Tasks Directory (via process_creation)
This rule detects the signed msoev binary executing from the Windows Tasks directory, the side-loading launcher APT29 used to load the Duke malware in the German Embassy lure campaign. Running this legitimate binary from C:\Windows\Tasks side-loads a malicious Mso DLL from the same folder. Execution of msoev from this path is highly anomalous.
HuntRule TeamWindowsprocess_creationHigh181Premium2026-06-25Malicious SQL SA Admin User Enabled (via application)
This rule detects enables the disabled (recommended) SA admin account on the SQL Server instance.
HuntRule TeamMssqlapplicationHigh132Premium2026-06-25Malicious IIS Native Module Installation via Appcmd IsapiCachesModule (via process_creation)
This rule detects appcmd.exe installing a native IIS module named IsapiCachesModule backed by a caches.dll image as used by the Larva-25003 IIS malware. Registering a malicious native module allows the actor to intercept and manipulate all HTTP traffic on the server.
—Windowsprocess_creationHigh132Premium2026-06-25Malicious File Upload to SAP NetWeaver Metadata Uploader Endpoint
This rule detects HTTP POST requests to the SAP NetWeaver Visual Composer metadatauploader endpoint exploited in CVE-2025-31324. Threat actors abuse this unauthenticated upload flaw to drop JSP web shells and achieve remote code execution on internet-facing SAP servers. Detecting these uploads catches initial access before web shell deployment.
HuntRule TeamWebwebserverHigh142Premium2026-06-25Malicious System Crash Behavior Manipulation - WMImplant - Registry (via registry_event)
This rule detects abuses the Windows "system failure and recovery" capacities (CrashControl) to store information or to establish persistence.
HuntRule TeamWindowsregistry_eventHigh429Premium2026-06-25Malicious Head Mare Credential Dumping via XenAllPasswordPro
This rule detects execution of XenAllPasswordPro with the -a switch writing to report.html, the credential-recovery tool used by Head Mare to harvest stored passwords into an HTML report. Presence of this dual-use recovery utility in an interactive attack context signals active credential theft.
HuntRule TeamWindowsprocess_creationHigh125Premium2026-06-25Malicious IIS Worker Process Spawning Command Shell via process_creation
This rule detects the IIS worker process w3wp.exe spawning a command interpreter, PowerShell or certutil which is a strong indicator of web shell command execution on a compromised web server. Kaspersky observed a Behinder web shell driving w3wp.exe to launch cmd.exe and download follow-on payloads. Web shell to shell transitions are an early sign of hands-on-keyboard server intrusion.
HuntRule TeamWindowsprocess_creationHigh133Premium2026-06-25Uncommon Kimsuky OneNote Document Spawning Script Interpreter (via process_creation)
This rule detects Microsoft OneNote launching a scripting or shell interpreter such as wscript, cscript, mshta, cmd or powershell, the execution behavior seen when Kimsuky embeds rows of VBS files inside a .ONE document disguised with a Hangul document icon. OneNote spawning an interpreter is abnormal for legitimate note-taking and is a reliable indicator of embedded-object abuse for initial execution.
HuntRule TeamWindowsprocess_creationHigh355Premium2026-06-25Suspicious SugarGh0st Persistence via CTFMON Masqueraded Run Key (via registry_set)
This rule detects a Run key persistence entry referencing CTFM0N.exe, a binary named to impersonate the legitimate ctfmon.exe with a zero substituted for the letter O. The SugarGh0st RAT used this masqueraded autorun value to survive reboot.
HuntRule TeamWindowsregistry_setHigh112Premium2026-06-25Malicious Volume Shadow Copy Deletion via vssadmin by RA World
This rule detects deletion of all volume shadow copies through vssadmin, an inhibit-recovery action the RA World ransomware group performs to prevent victims from restoring encrypted files. Destroying shadow copies is a hallmark of ransomware staging. Detecting this exposes imminent or in-progress encryption impact on the host.
HuntRule TeamWindowsprocess_creationHigh252Premium2026-06-24Suspicious Restic Cloud Backup Exfiltration via Renamed winupdate Binary via process_creation
This rule detects the restic backup tool being run, including copies renamed to winupdate.exe, with arguments targeting a Wasabi or S3 object store. The threat actor renamed restic to a Windows-update-like name and used it to back up and exfiltrate victim data to attacker-controlled cloud storage, so this pattern indicates staged bulk exfiltration disguised as backup activity.
HuntRule TeamWindowsprocess_creationHigh182Premium2026-06-24Malicious UAC Bypass via ms-settings Shell Open Command Registry Hijack (via registry_set)
This rule detects modification of the ms-settings protocol handler shell open command under the current user classes hive, the registry hijack that a Kimsuky campaign chained to trigger a batch file with elevated rights through fodhelper style auto-elevation. Adversaries leverage this key because trusted binaries query it while running high integrity, making early detection critical for catching privilege escalation before elevated payload execution.
HuntRule TeamWindowsregistry_setHigh121Premium2026-06-24Suspicious Renamed git Binary gcmd.exe Execution (via process_creation)
This rule detects execution of gcmd.exe, a renamed copy of the legitimate git binary used by APT-C-60 to proxy execution of its loader from a masqueraded LICENSES.LOG directory. Renaming a signed tool defeats name-based allowlists while preserving the trusted binary behavior the actor relies on.
HuntRule TeamWindowsprocess_creationHigh143Premium2026-06-24