Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,214 rules
Suspicious EC2 Serial Console SSH Public Key Push (via cloudtrail)
This rule detects the SendSerialConsoleSSHPublicKey call used to push an SSH key to an instance serial console, an uncommon access path adversaries leverage to reach hosts that block normal network SSH. Legitimate serial console use is rare, so this event strongly suggests an attacker seeking out of band interactive access to a cloud instance.
HuntRule TeamAwscloudtrailHigh133Premium2026-07-23Suspicious Curl Download and Silent MSI Install of Remote Management Software (via process_creation)
This rule detects a command chain that uses curl to fetch an MSI package and then runs msiexec with a silent install flag, the delivery technique used in the vishing campaign against US law firms to deploy SuperOps and other remote management tooling. Adversaries pair remote download with unattended installs to stand up remote access without user interaction, so this chained behavior is worth flagging.
HuntRule TeamWindowsprocess_creationMedium102Premium2026-07-23Malicious Webshell Written to Citrix NetScaler VPN Theme Directory (via file_event)
This rule detects the post-exploitation stage of Citrix NetScaler CVE-2026-8452 where a php webshell is dropped into the vpn theme directory after a pre-auth heap overflow. A php file in this template directory indicates appliance compromise.
HuntRule TeamLinuxfile_eventHigh81Premium2026-07-23Malicious Simps Botnet Infection Marker File Creation (via file_event)
This rule detects creation of the keksec.infected.you.log marker file dropped by the Simps botnet to flag a compromised host. The presence of this Keksec group artifact indicates the device has been enrolled into Mirai and Gafgyt based DDoS operations.
HuntRule TeamLinuxfile_eventHigh238Premium2026-07-23Suspicious MOVEit w3wp Child Process Execution via process_creation
This rule detects the MOVEit Transfer IIS worker process w3wp.exe spawning command interpreters, which is the expected behavior when a dropped ASPX web shell is executed. During CVE-2023-34362 exploitation the attacker used the web shell under w3wp to run follow-on commands, so interpreter children of this worker are a strong web exploitation signal.
HuntRule TeamWindowsprocess_creationMedium367Premium2026-07-23Default Account Usage
Threat actor (APT35) created user, enabled it, set password, add to admins and remote desktop users.
HuntRule TeamWindowsprocess_creationMedium392Premium2026-07-23Malicious NTDS.dit Extraction via ntdsutil IFM Snapshot (via process_creation)
This rule detects use of ntdsutil to create an install-from-media snapshot, the technique Storm-1175 uses to extract the NTDS.dit Active Directory database and steal domain credential hashes during Medusa ransomware operations. Adversaries dump NTDS.dit to obtain every domain account hash for offline cracking and mass lateral movement, so this command on a domain controller is a critical credential-access alert.
HuntRule TeamWindowsprocess_creationHigh111Premium2026-07-23Malicious Viper C2 Installation via f8x One-Liner Setup Script (via process_creation)
This rule detects execution of the f8x offensive setup script used by the You Dun group to deploy Viper command-and-control tooling on Linux staging hosts, invoked through bash with flags such as -viper or -all. The f8x helper is an attacker-specific installer for red-team infrastructure, so its execution on a server is a high-confidence indicator of adversary tooling being stood up rather than legitimate administration.
HuntRule TeamLinuxprocess_creationMedium415Premium2026-07-23Malicious DcRAT Payload Masquerading as Mixed Reality.exe via process_creation
This rule detects execution of a binary named Mixed Reality.exe from the Windows Media Player directory, a masquerading trick used by Operation DragonReturn to stage its multi-stage DcRAT loader. The China-nexus actor placed the payload under a trusted vendor folder to blend with legitimate software while conducting espionage against Indian tax infrastructure, so early detection exposes the loader before injection and C2.
HuntRule TeamWindowsprocess_creationHigh72Premium2026-07-23Malicious SUNBURST Command and Control DNS Query to avsvmcloud Domain (via dns_query)
This rule detects DNS lookups containing the avsvmcloud domain used as the SUNBURST first-stage command and control and victim beaconing channel. The backdoor encodes environment data into subdomains of avsvmcloud during its DGA-style callbacks. Detecting any avsvmcloud query is a high fidelity indicator of a SUNBURST compromised host.
HuntRule TeamWindowsdns_queryCritical336Premium2026-07-23Suspicious action.inf Dropped Alongside ViPNet Update Loader
This rule detects the creation of an action.inf file inside a ViPNet update directory which carries the extra_command configuration consumed by the malicious update loader. This drop is part of a backdoor masquerading as ViPNet updates that stores its attacker-controlled parameters next to the substituted binary. Catching the config write reveals the staging step before execution.
HuntRule TeamWindowsfile_eventMedium314Premium2026-07-23Suspicious DLL Sideloading via Signed Utility Binaries Used by Storm-2603
This rule detects execution of signed helper binaries such as 7z.exe, clink_x86.exe, MpCmdRun.exe and VMToolsEng.exe from outside their legitimate installation directories, a DLL search-order hijacking technique abused by Storm-2603 to load malicious payload DLLs under a trusted process. Running these tools from user-writable or temporary paths is anomalous and indicates staged loader activity during the intrusion.
HuntRule TeamWindowsprocess_creationMedium141Premium2026-07-23Suspicious WScript Execution Spawned by Microsoft Word (via process_creation)
This rule detects wscript.exe spawned as a child of Microsoft Word, indicating macro-driven script execution. The returning Bumblebee campaign used a macro-enabled document that dropped a temp script and ran it via wscript to fetch the loader.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-07-23Malicious Mimikatz Credential Dumping Command Line
This rule detects Mimikatz style command modules on the process command line such as privilege debug and sekurlsa logonPasswords. In the WithSecure Catching Lazarus Part Two research the actor runs these modules to dump credentials from lsass memory. Attackers use Mimikatz to harvest passwords and hashes for lateral movement.
HuntRule TeamWindowsprocess_creationCritical112Premium2026-07-23Suspicious BITSAdmin File Transfer Download (via process_creation)
This rule detects use of bitsadmin with the transfer switch to download a remote payload which the LilacSquid actor uses to retrieve the MeshAgent remote management tool. Living-off-the-land download via the Background Intelligent Transfer Service evades network monitoring and blends with legitimate update traffic.
HuntRule TeamWindowsprocess_creationMedium2810Premium2026-07-23