Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,228 rules
Malicious Payload Download and Execution via certutil urlcache (via process_creation)
This rule detects certutil being used with the urlcache option to download a remote executable to disk, a living off the land technique used by a ransomware actor after exploiting an unsupported ColdFusion server to fetch and launch beacon payloads into the Windows temp directory. Legitimate use of certutil to download arbitrary executables over HTTP is rare.
HuntRule TeamWindowsprocess_creationHigh214Premium2026-07-17Suspicious Kerberos Password Account Reset to Issue Potential Golden Ticket (via security)
This rule detects scenarios where a suspicious password reset of the Krbtgt account is performed by attacker to issue a potential Golden ticket.
HuntRule TeamWindowssecurityMedium102Premium2026-07-17Malicious Keyhunter Worker Systemd Unit File Creation
This rule detects creation of the keyhunter-worker systemd unit file dropped by the NATS-as-C2 credential harvesting campaign. The unit establishes persistence for a worker that connects to an attacker NATS broker and exfiltrates cloud and AI API keys. A unit file with this name is a strong indicator of compromise.
HuntRule TeamLinuxfile_eventHigh259Premium2026-07-17Suspicious Scheduled Task Masquerading as Realtek Audio Service (via process_creation)
This rule detects the AsyncRAT campaign registering scheduled tasks that impersonate Realtek audio maintenance to launch its batch and AutoHotkey loaders. The tasks use names such as CheckRealtekAudioVersion and execute dropped RealtekAudioService64 components. Creation of these named tasks indicates persistence by the loader.
HuntRule TeamWindowsprocess_creationHigh391Premium2026-07-17Suspicious Remote Desktop Enablement via Registry fDenyTSConnections and Firewall Rule (via process_creation)
This rule detects Remote Desktop being switched on by setting fDenyTSConnections to zero or by opening the RDP firewall group through netsh advfirewall, the lateral-access preparation in the ELPACO-team intrusion before RDP movement to backup and file servers. Adversaries enable inbound RDP to pivot with stolen credentials, so these host-hardening reversals outside change control warrant investigation and can be filtered on approved administration hosts.
HuntRule TeamWindowsprocess_creationMedium408Premium2026-07-17Suspicious TALONITE Certutil LOLBIN Decode and Download Abuse (via process_creation)
This rule detects certutil.exe invoked with decode, URL cache, or verifyctl arguments used to deobfuscate or download payloads. TALONITE abuses certutil as a living-off-the-land binary to decode staged content and retrieve additional tooling during intrusions. Certutil used for file decoding or remote fetch outside certificate management is a common defense-evasion and delivery technique.
HuntRule TeamWindowsprocess_creationMedium4310Premium2026-07-17Suspicious Disabling of Windows Firewall via Netsh (via process_creation)
This rule detects netsh being used to turn the Windows firewall off across profiles, a defense-impairment step attackers take to unblock command-and-control or lateral-movement traffic. Disabling the host firewall is a defense-evasion technique tracked in the Red Canary Threat Detection Report. Detecting these commands surfaces an attacker lowering host defenses ahead of further activity.
HuntRule TeamWindowsprocess_creationMedium131Premium2026-07-17Malicious TALONITE FlowCloud Renamed HTML Help Workshop Binary (via process_creation)
This rule detects a process whose original file name is the legitimate HTML Help Workshop binary hhw.exe but which runs under a different image name. TALONITE FlowCloud executes a renamed copy of hhw.exe to store harvested host data in database files while evading name-based detection. A mismatch between the embedded original name and the on-disk name is a strong masquerading signal.
HuntRule TeamWindowsprocess_creationHigh404Premium2026-07-16Malicious PowerShell IEX DownloadString One-Liner
This rule detects PowerShell using Invoke-Expression together with a WebClient DownloadString call to fetch and run remote code in memory. This one-liner is delivered through the Win+R fake CAPTCHA lure used to distribute Lumma Stealer. Catching the fetch-and-execute pattern flags fileless staging before the stealer touches disk.
HuntRule TeamWindowsps_scriptMedium101Premium2026-07-16Malicious Mimikatz LSASS Credential Dumping via Command Line
This rule detects Mimikatz command modules such as sekurlsa logonpasswords or lsadump on the process command line, the credential harvesting method TrickBot uses through its Mimikatz-based module to dump LSASS memory. These module strings are distinctive to Mimikatz regardless of the binary name. Their presence indicates active credential theft supporting lateral movement.
HuntRule TeamWindowsprocess_creationHigh72Premium2026-07-16Masquerading Noodlophile Payload Execution via Video File Double Extension (via process_creation)
This rule detects execution of an image named with a video double extension such as .mp4.exe, the masquerading technique used by the Noodlophile stealer campaign delivered through fake AI video-generation platforms. Adversaries leverage a video-looking filename so users who expect a rendered clip instead launch the wrapper binary, making early detection critical for catching the intrusion at first execution before the CapCut loader and XWorm injection proceed.
HuntRule TeamWindowsprocess_creationHigh436Premium2026-07-16Suspicious Windows Event Log Clearing via wevtutil
This rule detects clearing of Windows event logs using wevtutil cl. Ransomware operators covered in this report chain wevtutil cl commands against the Security, System and Application logs to erase forensic evidence around encryption. Bulk event-log clearing is a strong indicator of anti-forensic activity.
HuntRule TeamWindowsprocess_creationHigh134Premium2026-07-16Malicious Sparkling Pisces Backdoor C2 URI Pattern (via proxy)
This rule detects web requests to the fixed command-and-control URIs used by the Sparkling Pisces KLogEXE keylogger and FPSpy backdoor, which encode operator index parameters in PHP endpoints. These structured request patterns are specific to the toolset and indicate an infected host communicating with its controller.
HuntRule TeamWebproxyHigh153Premium2026-07-16ValleyRat Beacon Sideloading via NtHandleCallback Loading log.dll (via image_load)
This rule detects the NtHandleCallback.exe process loading log.dll from its working directory, the DLL sideloading pair used to launch the ValleyRat beacon in the Silver Fox campaign. Adversaries leverage a masqueraded executable and a co-located malicious DLL to run the beacon under a benign-looking process, making detection valuable for surfacing command-and-control staging.
HuntRule TeamWindowsimage_loadHigh202Premium2026-07-16Malicious Microsoft Defender Service Components Status Disabled - Registry via Sysmon (via process_creation)
This rule detects disable Defender security features by modifying service configuration in registry.
HuntRule TeamWindowsprocess_creationHigh259Premium2026-07-16