Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,388 rules
Malicious Winlogon Shell Persistence Modification (via registry_set)
This rule detects modification of the Winlogon Shell registry value to something other than the default explorer.exe, a persistence technique used by MuddyWater per Group-IB. Adversaries alter the Winlogon Shell entry so their payload launches at every interactive logon, making changes to this value a strong persistence signal.
HuntRule TeamWindowsregistry_setHigh133Premium2026-06-24Suspicious Process Execution from CHM Help File (via process_creation)
This rule detects the compiled HTML help viewer hh.exe spawning a command shell or PowerShell. The PHANTOM#SPIKE campaign delivered a malicious CHM file whose embedded script launched a hidden backdoor executable.
HuntRule TeamWindowsprocess_creationHigh242Premium2026-06-24Malicious Chisel Reverse SOCKS Proxy Execution (via process_creation)
This rule detects command-line arguments consistent with a Chisel reverse SOCKS proxy client, tooling deployed by Turla during TinyTurla-NG operations. The reverse tunnel exposes internal hosts to attacker infrastructure and enables pivoting through the compromised network.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-06-24Malicious Langflow Exploitation Marker File Creation
This rule detects creation of the lang_pwn marker file that the Langflow CVE-2026-55255 exploitation chain drops to confirm successful code execution. The file acts as a proof-of-exploitation beacon left in the temp directory. Its presence is a high-confidence indicator that the host was compromised through the Langflow vulnerability.
HuntRule TeamLinuxfile_eventHigh219Premium2026-06-24Suspicious Network Connection From CUPS Foomatic-Rip Child Process
This rule detects an outbound network connection initiated by a child of the foomatic-rip print filter which indicates post-exploitation activity following abuse of the CUPS printing vulnerability. Adversaries who gain execution through the print filter reach out to command and control or download additional tooling from the compromised host.
HuntRule TeamLinuxnetwork_connectionHigh228Premium2026-06-24VSS Backup Deletion via WMI - Powershell (via powershell)
This rule detects delete existing VSS backup via WMI.
HuntRule TeamWindowspowershellHigh134Premium2026-06-24Malicious TeamPCP LiteLLM .pth Startup Hook and Payload Dropper (via file_event)
This rule detects the litellm_init.pth site-packages file and the p.py payload dropped by the trojanized LiteLLM PyPI releases 1.82.7 and 1.82.8 published by TeamPCP. The .pth mechanism forces arbitrary code execution during any Python interpreter startup so writing these files establishes a supply-chain backdoor that steals API keys SSH keys and cloud credentials.
HuntRule TeamLinuxfile_eventHigh161Premium2026-06-23Malicious Triada binder.so Planted in Android System Framework
This rule detects creation of a binder.so library inside the Android system framework arm directory which the Triada trojan replaces to hook Zygote and inject into every app process. This system-level modification gives the malware persistent control over the device including clipboard wallet clipping and premium SMS abuse. A write to the framework native library path is highly abnormal on a clean device.
HuntRule TeamAndroidfile_eventHigh255Premium2026-06-23Suspicious File Download via certutil urlcache
This rule detects certutil used with the urlcache and split flags to download a remote file, an ingress tool transfer technique observed in the REF7707 espionage campaign. Adversaries abuse the signed certutil utility to retrieve payloads while blending in with trusted Windows binaries. This flag combination has no routine administrative use and reliably indicates tooling download.
HuntRule TeamWindowsprocess_creationHigh337Premium2026-06-23In-Memory Enabling of WDigest Cleartext Credential Caching (via registry_set)
This rule detects the UseLogonCredential value being set under the WDigest security provider, which forces Windows to cache cleartext passwords in memory so they can be harvested from LSASS. Re-enabling WDigest credential caching is a credential-access preparation technique tracked in the Red Canary Threat Detection Report. Detecting this registry change surfaces an attacker priming the host for plaintext credential theft.
HuntRule TeamWindowsregistry_setHigh325Premium2026-06-23Suspicious Scheduled Task with NetworkProfile Event Trigger (via process_creation)
This rule detects schtasks creating a task triggered on Microsoft-Windows-NetworkProfile operational events. The PHANTOM#SPIKE campaign used this uncommon event based trigger to persistently launch a custom CSharp backdoor.
HuntRule TeamWindowsprocess_creationHigh163Premium2026-06-23CastleLoader Stager HTTP Beacon via Misspelled GoogeBot User-Agent (via proxy)
This rule detects outbound HTTP requests carrying the misspelled GoogeBot user-agent used by the CastleLoader stager to retrieve follow-on TAG-150 payloads while masquerading as a search-engine crawler. Adversaries leverage crawler-like user-agents to blend malicious downloads into ordinary web traffic, making this distinctive typo a reliable delivery-stage indicator.
HuntRule TeamWebproxyHigh221Premium2026-06-23Suspicious SSRF Probe for Cloud Instance Metadata Service
This rule detects HTTP requests attempting to reach the cloud instance metadata service link local address through a url parameter. Attackers abuse server side request forgery to pull IAM security credentials from the metadata endpoint of a misconfigured public facing application.
HuntRule TeamWebwebserverHigh142Premium2026-06-23Malicious Credential Dumping via XenAllPasswordPro
This rule detects execution of the XenAllPasswordPro password recovery utility. The Crypt Ghouls group ran this tool to harvest stored credentials into an HTML report during their intrusions, and its presence on endpoints is rarely legitimate.
HuntRule TeamWindowsprocess_creationHigh269Premium2026-06-23Suspicious Reactivation of Guest Account via net user (UAT-8099)
This rule detects reactivation of the built-in Guest account using net user guest with the active flag. UAT-8099 re-enables and elevates the Guest account to maintain covert administrative access to compromised IIS servers. Enabling the normally disabled Guest account is an account-manipulation persistence technique.
HuntRule TeamWindowsprocess_creationHigh347Premium2026-06-23