Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,228 rules
Malicious GachiLoader C2 Beacon via X-Secret gachifamily Header
This rule detects HTTP traffic carrying the custom header value gachifamily or the GachiLoader C2 URI patterns /log and /richfamily, structural markers of the malware's command-and-control channel. These fixed protocol artifacts identify GachiLoader beaconing and tasking regardless of the C2 host in use.
HuntRule TeamWebproxyHigh2610Premium2026-07-16Masquerading Scheduled Task Masquerading as WindowsUpdate with One-Minute Interval (via process_creation)
This rule detects creation of a scheduled task named WindowsUpdate configured to run every minute, a persistence behavior used by the Anivia loader for rapid respawn of OctoRAT. Adversaries leverage a benign-sounding task name and an aggressive minute interval to keep the implant resident on the host.
HuntRule TeamWindowsprocess_creationMedium106Premium2026-07-16Suspicious Parallax RAT Startup Folder Executable Persistence via File System (via file_event)
This rule detects creation of an executable named milk.exe in the Windows Startup folder, the persistence artifact used by the Parallax RAT. It is associated with a campaign targeting cryptocurrency entities with Parallax RAT as reported by Uptycs. Dropping an executable directly into Startup guarantees relaunch at logon, so this artifact indicates established persistence by the RAT.
HuntRule TeamWindowsfile_eventMedium121Premium2026-07-16Suspicious Scheduled Task Launching VBScript From ProgramData (via process_creation)
This rule detects schtasks creating a minute-interval task that runs a VBScript from ProgramData. The AgentTesla loader registers such a task to repeatedly re-launch its VBS staging script.
HuntRule TeamWindowsprocess_creationHigh372Premium2026-07-16Suspicious Archive Staged in Web Root via tar on Ivanti EPMM
This rule detects creation of a compressed tar archive written into the Ivanti EPMM public web directory /var/www/ext/html. It corresponds to collection and staging behaviour where stolen data is archived in a web-accessible path for later download. Detecting it exposes exfiltration staging on the appliance.
HuntRule TeamLinuxprocess_creationHigh111Premium2026-07-16Malicious PsExec Service Installation via PSEXESVC
This rule detects installation of the PSEXESVC service on a target host which is created when Sysinternals PsExec is used for remote command execution as described in the WithSecure lateral movement lab. Attackers routinely abuse PsExec for hands on keyboard lateral movement so a PSEXESVC service install on a system that does not routinely receive one is a strong lateral movement indicator.
HuntRule TeamWindowssystemMedium63Premium2026-07-16Suspicious VBScript Dropped to Startup Folder (via file_event)
This rule detects Hive0051 GammaInstall and GammaSteel persistence where a randomly named VBScript launcher is written to the user Startup folder so it executes at every logon. Writing a vbscript file directly under the Start Menu Programs Startup path is uncommon for legitimate software. The behavior provides logon persistence for the loader chain.
HuntRule TeamWindowsfile_eventMedium358Premium2026-07-16Suspicious Registry Modification Disabling RestrictedAdmin Mode (via process_creation)
This rule detects a reg add command disabling RestrictedAdmin mode under the LSA key. The SLOW#TEMPEST campaign disabled this protection to enable pass-the-hash remote desktop logons during lateral movement.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-07-16Suspicious AWS Long-Term Access Key Creation for Persistence via CloudTrail (via aws)
This rule detects the creation of a long-term IAM access key, which adversaries generate as a backup AKIA credential to maintain persistent access to a compromised AWS account per Red Canary. Key creation for a user other than the caller, or immediately following STS token abuse, is a strong indicator that an attacker is establishing durable persistence.
HuntRule TeamAwscloudtrailLow133Premium2026-07-16Suspicious Osascript Muting System Volume via BANSHEE Infostealer
This rule detects osascript executing an AppleScript command that mutes the system output volume which is an anti-analysis behavior performed by the BANSHEE macOS infostealer to hide audible feedback during execution. Adversaries silence the host so credential and data theft proceed without alerting the user.
HuntRule TeamMacosprocess_creationMedium81Premium2026-07-16Suspicious Credential Store Access for WinSCP and PuTTY via PowerShell (via ps_script)
This rule detects PowerShell script content referencing WinSCP and PuTTY session registry stores or the Windows Credential Manager enumeration API, the credential theft behavior of the SEO poisoning infostealer. These paths and calls harvest saved SSH, SFTP and enterprise credentials. Scripts touching these secrets stores are a strong credential access indicator.
HuntRule TeamWindowsps_scriptMedium92Premium2026-07-16AnyDesk Network
Detects use of AnyDesk
HuntRule TeamWindowsdns_queryHigh113Premium2026-07-16Suspicious Child Process Spawned From Java Following Web Exploitation
This rule detects a Java process spawning a command shell or discovery utility, the post-exploitation behavior seen after ShinyHunters exploited the Oracle PeopleSoft PeopleTools zero-day to gain code execution. A Java application server launching cmd, PowerShell or reconnaissance commands is a strong web-exploitation indicator. This pattern precedes remote-management deployment and lateral movement.
HuntRule TeamWindowsprocess_creationHigh196Premium2026-07-16Malicious Katz Stealer Command-and-Control via katz-ontop User-Agent (via proxy)
This rule detects outbound HTTP requests carrying the distinctive katz-ontop token appended to the User-Agent string by the Katz Stealer implant during command-and-control communication. Adversaries leverage this hardcoded agent identifier to beacon to their infrastructure, making detection valuable for exposing active stealer command-and-control on the network.
HuntRule TeamWebproxyHigh102Premium2026-07-15Suspicious Child Process Spawned by 3CXDesktopApp via Supply Chain Compromise
This rule detects the 3CXDesktopApp.exe process spawning a command interpreter such as cmd.exe or powershell.exe. During the 3CX supply chain compromise the trojanized client executed follow-on commands to profile the host and retrieve second-stage payloads after sideloading a malicious ffmpeg.dll. The VoIP client has no legitimate reason to launch shells.
HuntRule TeamWindowsprocess_creationHigh83Premium2026-07-15