Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,217 rules
Malicious Phantom Taurus OutlookEN Web Shell File Creation (via file_event)
This rule detects creation of the OutlookEN.aspx web shell dropped by Phantom Taurus on compromised Exchange and IIS servers. The web shell loads the NET-STAR IIServerCore backdoor into the worker process to provide persistent server access. Detecting the file drop catches the initial foothold before the backdoor is loaded into memory.
HuntRule TeamWindowsfile_eventHigh123Premium2026-07-20Suspicious Scheduled Task Masquerading as Wininet CacheTask (via process_creation)
This rule detects schtasks creating a scheduled task under a Wininet CacheTask name that impersonates a legitimate Windows maintenance task. The malvertising backdoor operators registered a task with this masqueraded name for persistence and periodic payload execution. A user-created task mimicking a built-in system task path is a strong persistence and masquerading indicator.
HuntRule TeamWindowsprocess_creationHigh218Premium2026-07-20Scheduled Task Creating Per-Minute Hidden PowerShell Execution
This rule detects schtasks creating a task that runs at a one-minute interval and launches a hidden PowerShell script. The GPU miner campaign registered a scheduled task firing every minute to run hidden powershell against cor.ps1 or core.ps1 for persistence and re-infection. A minute-cadence hidden PowerShell task is a strong indicator of automated malware persistence.
HuntRule TeamWindowsprocess_creationHigh299Premium2026-07-20Suspicious osascript to zsh Executing Hidden Payload via Axios Compromise
This rule detects osascript launching zsh with an inline command that runs a hidden binary under Library Caches as documented in Elastic detections for the Axios supply chain compromise. The AppleScript to shell handoff to a caches resident payload marks macOS implant execution on infected developer systems.
HuntRule TeamMacosprocess_creationHigh215Premium2026-07-20Malicious LSASS Credential Dumping via Comsvcs MiniDump (via process_creation)
This rule detects the use of the built-in comsvcs.dll MiniDump export (typically invoked through rundll32) to write a memory dump of a target process such as LSASS to disk. Credential access via LSASS memory is a top technique in the Red Canary Threat Detection Report, giving adversaries plaintext credentials and hashes for lateral movement. Because this pattern relies on a signed system DLL, detecting the comsvcs MiniDump invocation surfaces stealthy credential theft.
HuntRule TeamWindowsprocess_creationHigh1810Premium2026-07-20Malicious Microsoft Defender Massive Host Infection (via windefend)
This rule detects scenarios where multiple suspicious threats are detected on a single host.
HuntRule TeamWindowswindefendHigh102Premium2026-07-20Possible Ivanti EPMM CVE-2025-4428 Exploitation via format Parameter (via webserver)
This rule detects requests to the Ivanti EPMM api v2 endpoint carrying a format parameter that invokes runtime code execution, the exploitation pattern for CVE-2025-4428. Attackers embedded Java Runtime.exec calls in this parameter to achieve remote command execution. Such requests against the mifs api are a strong exploitation indicator.
HuntRule TeamWebwebserverHigh73Premium2026-07-20OceanLotus (APT-C-00) Payload Staging in Fake NVIDIA Setup Temp Directory (via file_event)
This rule detects files being written into a fake NVIDIA setup directory under the user Temp folder, a staging behavior observed by the 360 Threat Intelligence Center in the OceanLotus double-loader campaign where the loader created a NVidiaSetup working directory to host encrypted host data and the reflectively loaded Cobalt Strike beacon. Adversaries masquerade attacker directories as trusted vendor installers to blend payload staging into ordinary Temp activity.
HuntRule TeamWindowsfile_eventHigh101Premium2026-07-20Malicious InvisibleFerret Python Loader Execution from Hidden .pyp Directory
This rule detects a python.exe located in a hidden .pyp user directory executing the .npl payload, matching the InvisibleFerret stage of the North Korean job-hunter campaigns described by Unit 42. The actor stages a private Python runtime and payload under a dotted folder in the user profile which is an unusual pattern that reveals the second-stage backdoor.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-07-20AdminSDHolder Permissions Changed for Persistence (via security)
This rule detects changes permissions on the AdminSDHolder container to establish persistence.
HuntRule TeamWindowssecurityHigh287Premium2026-07-20Suspicious Msiexec Remote Package Installation from URL via Process Creation
This rule detects msiexec.exe installing an MSI package directly from a remote HTTP or HTTPS URL, a technique used in the Operation Rusty Flag campaign to deploy a Rust implant from a Dropbox-hosted MSI reached through a double-extension LNK. Adversaries abuse the trusted Windows Installer to proxy execution and pull payloads while evading application controls.
HuntRule TeamWindowsprocess_creationMedium132Premium2026-07-20Suspicious Peach Sandstorm Password Spray via go-http-client User Agent (via proxy)
This rule detects inbound authentication traffic carrying the default Go HTTP library user agent go-http-client. Peach Sandstorm used this user agent while conducting password spray attacks against enterprise sign-in endpoints for initial access.
HuntRule TeamWebproxyMedium81Premium2026-07-20Suspicious Snowflake Anomalous Client Application Associated With UNC5537 (via cloud)
This rule detects Snowflake sessions authenticating with client application strings tied to the UNC5537 data theft campaign such as the rapeflake FROSTBITE reconnaissance utility and the DBeaver_DBeaverUltimate client. UNC5537 abused stolen customer credentials to access Snowflake instances at scale for bulk data theft and extortion. Anomalous client applications on a control-plane login indicate credential abuse and unauthorized data access.
HuntRule TeamSnowflakelogin_historyMedium122Premium2026-07-20Malicious ClickFix PowerShell DownloadFile Loader with Hidden Window
This rule detects a hidden-window PowerShell process using DownloadFile to fetch a script from a remote host, the NetSupport RAT ClickFix loader pattern. Victims pasted a command that ran PowerShell with hidden window and no-profile flags to download and then execute a follow-on .ps1 payload. Hidden PowerShell combined with a remote file download is a classic first-stage loader behavior.
HuntRule TeamWindowsprocess_creationHigh61Premium2026-07-19Suspicious MSHTA Execution of Polyglot PDF File Spawned by cmd (via process_creation)
This rule detects mshta.exe launched by cmd.exe with a PDF file argument, matching the UNK_CraftyCamel chain where an LNK ran cmd then mshta to execute a PDF and HTA polyglot. Legitimate mshta rarely processes files with a .pdf extension.
HuntRule TeamWindowsprocess_creationHigh123Premium2026-07-19