Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,381 rules
Malicious Azure Deletion of Resource Locks and Immutability Policies
This rule detects deletion of Azure resource locks and blob immutability policies, an anti-recovery step preceding storage ransomware. Removing locks and immutability protections strips the guardrails that would otherwise prevent an actor from overwriting or destroying blob data. A burst of these delete operations on storage resources indicates preparation for data destruction or ransom.
HuntRule TeamAzureactivitylogsHigh132Premium2026-06-09Malicious Khmer Shadow DLL Sideloading via VMwareNamespaceCmd Loading vmtools (via image_load)
This rule detects the signed VMwareNamespaceCmd binary loading a vmtools DLL from outside the trusted VMware install path, the side-loading behavior used to run the Khmer Shadow loader against Cambodian government entities. Adversaries drop a malicious vmtools.dll beside a relocated VMware binary to execute under a trusted process. Loads originating outside Program Files expose the sideloaded implant.
HuntRule TeamWindowsimage_loadHigh344Premium2026-06-09Suspicious PowerShell Masquerading as Windows Terminal via process_creation
This rule detects a process whose original file name is PowerShell but which executes under the wt.exe Windows Terminal file name. The axios supply chain payload renamed powershell.exe to wt.exe to evade name-based detection, so a mismatch between the internal PowerShell identity and a wt.exe image name indicates a masqueraded interpreter.
HuntRule TeamWindowsprocess_creationHigh131Premium2026-06-09Malicious Reverse SSH Tunnel via Plink for RDP Forwarding
This rule detects use of the Plink SSH client to establish a reverse tunnel that forwards local RDP back to attacker infrastructure which Conti operators use for persistent remote access. Observed in NCC Group research on Conti operations after the leaks using a renamed Plink binary over port 53. Reverse RDP tunneling through SSH is a strong indicator of hands-on-keyboard intrusion.
HuntRule TeamWindowsprocess_creationHigh277Premium2026-06-09Suspicious Webshell Written To F5 TMUI Web Directory
This rule detects creation of a PHP or JSP file within the F5 BIG-IP xui web directory tree which is where operators dropped webshells after TMUI exploitation as described in NCC Group RIFT F5 TMUI intelligence. Adversaries plant these webshells to maintain persistent remote command execution on the appliance so any script file appearing in these image and script paths is highly suspicious.
HuntRule TeamLinuxfile_eventHigh132Premium2026-06-09Suspicious Access to SonicWall SMA JSP Webshell
This rule detects HTTP requests to JSP webshells planted on a compromised SonicWall SMA appliance. In the 0-day exploitation the actor placed error.jsp and errorDialog.jsp under the workplace directory and proxied them to a local listener to execute commands. Access to these attacker-planted endpoints indicates active webshell interaction and hands-on-keyboard control of the appliance.
HuntRule TeamWebwebserverHigh91Premium2026-06-09Possible MOVEit Transfer Exploitation via MOVEitISAPI action m2 and X-siLock Headers
This rule detects requests to MOVEitISAPI.dll with action=m2 that also carry X-siLock control headers, matching the MOVEit Transfer RCE chain analyzed by Assetnote for CVE-2023-34362. The X-siLock headers drive internal session-variable manipulation used in the SQL injection to RCE path. Detecting this handler and header pairing surfaces active exploitation of the MOVEit ISAPI extension.
HuntRule TeamWebwebserverHigh152Premium2026-06-09In-Memory Process Injection via Mavinject INJECTRUNNING (via process_creation)
This rule detects mavinject.exe called with the INJECTRUNNING flag, which injects a DLL into a running process through a signed Microsoft binary, a stealthy execution and defense-evasion technique. Mavinject abuse is tracked in the Red Canary Threat Detection Report. Detecting this invocation surfaces trusted-binary process injection.
HuntRule TeamWindowsprocess_creationHigh205Premium2026-06-09Possible MuddyWater C2 Domain Resolution
This rule detects DNS resolution of the domain screenai.online, a command-and-control host observed in a MuddyWater APT campaign that combined WMI execution and remote management tool abuse against Middle East targets. It captures beaconing infrastructure lookups tied to the intrusion. Detecting this is important because resolution of this campaign-specific domain is a high-confidence indicator of an infected host reaching out to attacker infrastructure.
HuntRule TeamWindowsdns_queryHigh408Premium2026-06-08Suspicious SonicWall SMA init.d Persistence Launching deploy_new.py
This rule detects the workplace init script executing deploy_new.py which the actor used for persistence on a compromised SonicWall SMA appliance. The 0-day exploitation established a boot-time service under /etc/init.d/workplace to relaunch attacker tooling after reboots. Boot persistence on an internet-facing appliance provides durable access that survives restarts and patching attempts.
HuntRule TeamLinuxprocess_creationHigh393Premium2026-06-08CMSTP UAC Bypass via Automatic Install Flag (via process_creation)
This rule detects cmstp.exe invoked with the /au automatic-install flag, the User Account Control bypass used by the Caminho loader in the PureRAT chain to run an INF-defined command with elevated privileges. Adversaries leverage CMSTP as a trusted binary to silently elevate and execute payloads, making detection of this rarely legitimate flag critical for catching privilege escalation before process hollowing.
HuntRule TeamWindowsprocess_creationHigh375Premium2026-06-08Suspicious Scheduled Task Masquerading as EdgeUpdateHelper via process_creation
This rule detects schtasks.exe creating a scheduled task named EdgeUpdateHelper. GhostSocks operators use this Edge-updater-themed task name to blend malicious persistence with legitimate Microsoft Edge update tasks, keeping the infostealer running while evading casual review of scheduled tasks.
HuntRule TeamWindowsprocess_creationHigh103Premium2026-06-08Malicious C2 Configuration Stored in Registry via TitanPlus Key (via registry_set)
This rule detects the creation of the TitanPlus registry key used by the STAC5777 threat cluster to store a list of command and control IP addresses and ports read by a sideloaded malicious DLL. The activity followed Microsoft Teams vishing and Quick Assist abuse and provides resilient C2 configuration storage.
HuntRule TeamWindowsregistry_setHigh162Premium2026-06-08Malicious Member Added to DNSadmin Group (via security)
This rule detects scenarios where a suspicious change is done on DNSadmin group in order to abuse DNSadmin privileges for DLL load.
HuntRule TeamWindowssecurityHigh103Premium2026-06-08Suspicious Chained Host Reconnaissance One-Liner via DenoGate Backdoor
This rule detects a single cmd.exe command chaining ipconfig, route print, and tasklist to profile the network and running processes. The DenoGate backdoor runs this reconnaissance one-liner shortly after gaining access to map the victim environment. Bundling several enumeration commands into one line is uncommon for administrators and signals automated triage by an implant.
HuntRule TeamWindowsprocess_creationHigh193Premium2026-06-08