Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,217 rules
SSH over port 443 with known Server and Client Strings
Will detect the presence of known SSH client and SSH server strings that have been used for SSH tunneling.
HuntRule TeamZeeksshHigh91Premium2026-07-19Suspicious InvisibleFerret C2 Endpoints over Port 1224 (via proxy)
This rule detects HTTP requests to the InvisibleFerret command and control server that exposes payload, browser, clipboard and key exfiltration endpoints over TCP port 1224. The Lazarus backdoor cycles through fixed URI paths such as payload, brow, mclip and keys on this port. The pairing of the non-standard port with these named resources reveals the backdoor traffic.
HuntRule TeamWebproxyHigh63Premium2026-07-19Suspicious Linux Network Route Reconnaissance via Proc Filesystem by UAT-7290
This rule detects reading of the kernel routing table from proc and filtering for the default gateway using awk. UAT-7290 runs this one-liner to fingerprint the network configuration of compromised edge devices. Parsing the default route helps an actor understand the victim network before deploying tunneling implants.
HuntRule TeamWindowsprocess_creationMedium92Premium2026-07-19ShadowPad DLL Sideloading via logger.exe Loading logexts.dll (via image_load)
This rule detects logger.exe loading a logexts.dll from outside the Windows system directories, the DLL side-loading behavior used to launch the ShadowPad backdoor in the NailaoLocker intrusions across Europe. Adversaries abuse benign binary and library names to run the ShadowPad loader under a trusted-looking process while evading detection.
HuntRule TeamWindowsimage_loadMedium121Premium2026-07-19Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
This rule detects non-interactive Microsoft 365 sign-ins using the BAV2ROPC legacy authentication client. In the Railway PaaS token replay campaign, operators used BAV2ROPC to silently refresh stolen tokens and access mailboxes without triggering interactive MFA, so this client string on sign-ins indicates likely token abuse and legacy protocol exploitation.
HuntRule TeamM365signinlogsHigh82Premium2026-07-19Suspicious Masqueraded Zemana Driver Written to Disk via updatedrv (via file_event)
This rule detects the vulnerable Zemana driver being written to disk under the masqueraded name updatedrv.sys, a staging step used by the Terminator tool before creating a service and loading the driver to disable endpoint protection. The file is typically dropped into the system drivers directory or a ProgramData usoshared path.
HuntRule TeamWindowsfile_eventHigh205Premium2026-07-19Suspicious Microsoft Defender Exclusion Added via Add-MpPreference (via process_creation)
This rule detects the use of Add-MpPreference to register a Microsoft Defender exclusion, a defense-evasion action performed by the malvertising-delivered info stealers to whitelist their payload paths before execution. Adversaries add exclusions so downloaded stealer and NetSupport components run without inspection, so unexpected exclusion changes outside managed policy warrant investigation.
HuntRule TeamWindowsprocess_creationMedium141Premium2026-07-19Malicious Lazarus Rundll32 Execution of Sup ETL Privilege Escalation Loader (via process_creation)
This rule detects rundll32.exe executing a sup.etl file from the USOShared directory using the SerializeMarketTable export as observed in the Lazarus attack on Windows web servers. Loading an etl file as a DLL through an unusual export is a strong indicator of this loader.
—Windowsprocess_creationHigh122Premium2026-07-19IFM Detected - ESENT - Installation from Media (via application)
This rule detects create an IFM image (usually used for deploying domain controllers to reduce replication traffic) for dumping credentials.
HuntRule TeamWindowsapplicationHigh417Premium2026-07-19Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)
This rule detects Entra ID operations that add cross-tenant partners, invite external users, or create access packages, overlooked entry points into Microsoft Azure that adversaries abuse for persistence per Red Canary. These identity changes can silently grant outside principals durable access to a tenant, so unexpected occurrences should be validated against approved administrative activity.
HuntRule TeamAzureauditlogsMedium132Premium2026-07-19WordPress wp2shell PoC User-Agent HTTP Requests
Alerts on web requests with User-Agent exactly equal to "wp2shell", matching wp2shell PoC behavior.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverHigh12310Free2026-07-19WordPress wp2shell Plugin Webshell Access via wp-content/plugins URL Path
Alert on HTTP requests targeting the wp2shell WordPress plugin path used for webshell execution/persistence.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverCritical323Free2026-07-19WordPress REST Batch Endpoint (wp2shell) POST Exploitation Activity
Alert on POST requests containing rest_route=/batch/v1 that return HTTP 207, consistent with wp2shell-style REST batch probing/exploitation.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverMedium272Free2026-07-19Suspicious Privileged Group Membership Change via net.exe (via process_creation)
This rule detects net.exe adding an account to a privileged local group such as Administrators or Remote Desktop Users. Medusa operators manipulate group membership to escalate privileges and retain access, so an account addition to a sensitive group during an intrusion is a persistence and privilege-escalation signal.
HuntRule TeamWindowsprocess_creationMedium102Premium2026-07-18Malicious GitHub Repository Creation With s1ngularity Exfiltration Name
This rule detects a GitHub audit repo create event where the repository name contains s1ngularity, the naming convention of the exfiltration repositories used to publish stolen secrets. It matters because these attacker created repositories are the exfiltration destination in the nx supply chain attack.
HuntRule TeamGithubauditHigh176Premium2026-07-18