Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,276 rules
Malicious Sparkling Pisces Backdoor C2 URI Pattern (via proxy)
This rule detects web requests to the fixed command-and-control URIs used by the Sparkling Pisces KLogEXE keylogger and FPSpy backdoor, which encode operator index parameters in PHP endpoints. These structured request patterns are specific to the toolset and indicate an infected host communicating with its controller.
HuntRule TeamWebproxyHigh153Premium2026-07-16ValleyRat Beacon Sideloading via NtHandleCallback Loading log.dll (via image_load)
This rule detects the NtHandleCallback.exe process loading log.dll from its working directory, the DLL sideloading pair used to launch the ValleyRat beacon in the Silver Fox campaign. Adversaries leverage a masqueraded executable and a co-located malicious DLL to run the beacon under a benign-looking process, making detection valuable for surfacing command-and-control staging.
HuntRule TeamWindowsimage_loadHigh202Premium2026-07-16Malicious Microsoft Defender Service Components Status Disabled - Registry via Sysmon (via process_creation)
This rule detects disable Defender security features by modifying service configuration in registry.
HuntRule TeamWindowsprocess_creationHigh259Premium2026-07-16Malicious GachiLoader C2 Beacon via X-Secret gachifamily Header
This rule detects HTTP traffic carrying the custom header value gachifamily or the GachiLoader C2 URI patterns /log and /richfamily, structural markers of the malware's command-and-control channel. These fixed protocol artifacts identify GachiLoader beaconing and tasking regardless of the C2 host in use.
HuntRule TeamWebproxyHigh2610Premium2026-07-16Masquerading Scheduled Task Masquerading as WindowsUpdate with One-Minute Interval (via process_creation)
This rule detects creation of a scheduled task named WindowsUpdate configured to run every minute, a persistence behavior used by the Anivia loader for rapid respawn of OctoRAT. Adversaries leverage a benign-sounding task name and an aggressive minute interval to keep the implant resident on the host.
HuntRule TeamWindowsprocess_creationMedium106Premium2026-07-16Suspicious Parallax RAT Startup Folder Executable Persistence via File System (via file_event)
This rule detects creation of an executable named milk.exe in the Windows Startup folder, the persistence artifact used by the Parallax RAT. It is associated with a campaign targeting cryptocurrency entities with Parallax RAT as reported by Uptycs. Dropping an executable directly into Startup guarantees relaunch at logon, so this artifact indicates established persistence by the RAT.
HuntRule TeamWindowsfile_eventMedium121Premium2026-07-16Suspicious Scheduled Task Launching VBScript From ProgramData (via process_creation)
This rule detects schtasks creating a minute-interval task that runs a VBScript from ProgramData. The AgentTesla loader registers such a task to repeatedly re-launch its VBS staging script.
HuntRule TeamWindowsprocess_creationHigh382Premium2026-07-16Suspicious Archive Staged in Web Root via tar on Ivanti EPMM
This rule detects creation of a compressed tar archive written into the Ivanti EPMM public web directory /var/www/ext/html. It corresponds to collection and staging behaviour where stolen data is archived in a web-accessible path for later download. Detecting it exposes exfiltration staging on the appliance.
HuntRule TeamLinuxprocess_creationHigh111Premium2026-07-16Malicious PsExec Service Installation via PSEXESVC
This rule detects installation of the PSEXESVC service on a target host which is created when Sysinternals PsExec is used for remote command execution as described in the WithSecure lateral movement lab. Attackers routinely abuse PsExec for hands on keyboard lateral movement so a PSEXESVC service install on a system that does not routinely receive one is a strong lateral movement indicator.
HuntRule TeamWindowssystemMedium63Premium2026-07-16Suspicious VBScript Dropped to Startup Folder (via file_event)
This rule detects Hive0051 GammaInstall and GammaSteel persistence where a randomly named VBScript launcher is written to the user Startup folder so it executes at every logon. Writing a vbscript file directly under the Start Menu Programs Startup path is uncommon for legitimate software. The behavior provides logon persistence for the loader chain.
HuntRule TeamWindowsfile_eventMedium358Premium2026-07-16Suspicious Registry Modification Disabling RestrictedAdmin Mode (via process_creation)
This rule detects a reg add command disabling RestrictedAdmin mode under the LSA key. The SLOW#TEMPEST campaign disabled this protection to enable pass-the-hash remote desktop logons during lateral movement.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-07-16Suspicious AWS Long-Term Access Key Creation for Persistence via CloudTrail (via aws)
This rule detects the creation of a long-term IAM access key, which adversaries generate as a backup AKIA credential to maintain persistent access to a compromised AWS account per Red Canary. Key creation for a user other than the caller, or immediately following STS token abuse, is a strong indicator that an attacker is establishing durable persistence.
HuntRule TeamAwscloudtrailLow133Premium2026-07-16Suspicious Osascript Muting System Volume via BANSHEE Infostealer
This rule detects osascript executing an AppleScript command that mutes the system output volume which is an anti-analysis behavior performed by the BANSHEE macOS infostealer to hide audible feedback during execution. Adversaries silence the host so credential and data theft proceed without alerting the user.
HuntRule TeamMacosprocess_creationMedium81Premium2026-07-16Suspicious Credential Store Access for WinSCP and PuTTY via PowerShell (via ps_script)
This rule detects PowerShell script content referencing WinSCP and PuTTY session registry stores or the Windows Credential Manager enumeration API, the credential theft behavior of the SEO poisoning infostealer. These paths and calls harvest saved SSH, SFTP and enterprise credentials. Scripts touching these secrets stores are a strong credential access indicator.
HuntRule TeamWindowsps_scriptMedium102Premium2026-07-16AnyDesk Network
Detects use of AnyDesk
HuntRule TeamWindowsdns_queryHigh113Premium2026-07-16