Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,379 rules
Suspicious Ahnenblatt Application Execution From User-Writable Directory
This rule detects the legitimate Ahnenblatt genealogy application Ahnenblatt4.exe running from a Temp or AppData directory. In the RenEngine campaign this signed application was abused as a DLL side-loading host by dropping it next to malicious borlndmm.dll and cc32290mt.dll to launch HijackLoader as reported by Kaspersky. Execution of this uncommon application from a user-writable path signals a DLL search-order hijack rather than normal use.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-06-04WWLIB DLL Sideloading via WinWord Outside Office Directory in KamiKakaBot Chain (via image_load)
This rule detects WinWord.exe loading WWLIB.dll from a path outside the legitimate Microsoft Office installation directory, the DLL sideloading pair used by KamiKakaBot when a masqueraded Office binary is executed from an ISO or temporary folder. Adversaries leverage this sideload to run malicious code under a trusted Office process, making detection valuable for catching the initial execution stage.
HuntRule TeamWindowsimage_loadHigh71Premium2026-06-04Malicious Sed Tampering of Juniper Syslog Configuration by UNC3886 (via process_creation)
This rule detects sed modifying the Junos syslog configuration file at /mfs/var/etc/syslog.conf, the logging suppression technique UNC3886 used to disable syslog before operating on compromised routers. Editing the appliance syslog configuration indicates deliberate impairment of defenses.
HuntRule TeamLinuxprocess_creationHigh73Premium2026-06-04Windows Process Creation: curl.exe Using NTLM with Empty Username (-u :)
Alerts when curl is run on Windows with --ntlm and empty -u : credentials, a pattern that may leak the current user's NTLMv2 response.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3610Free2026-06-04Malicious Event Log Tampering via wevtutil Channel Disable by FunkSec Ransomware (via process_creation)
This rule detects use of wevtutil to disable the Security and Application event log channels, a defense-evasion action performed by FunkSec ransomware to blind logging before encryption. Adversaries turn off event channels so their tampering, service termination and encryption activity is not recorded for responders.
HuntRule TeamWindowsprocess_creationHigh143Premium2026-06-03Suspicious Certutil URLCache Download
This rule detects certutil.exe used with the urlcache option to download a remote file. The DragonRank SEO-poisoning operators abused certutil urlcache to pull additional tooling onto compromised IIS servers. Certutil functioning as a downloader is a living-off-the-land ingress technique that evades controls expecting a browser or dedicated transfer tool.
HuntRule TeamWindowsprocess_creationHigh83Premium2026-06-03Malicious Impacket-Style Remote Command Execution Pattern (via process_creation)
This rule detects the command shell pattern used by Impacket remote-execution tools such as wmiexec, smbexec and atexec, where cmd.exe runs a command and redirects its output to a local admin share or loopback path (for example 1> \\127.0.0.1\ADMIN$). Remote execution over SMB/WMI is a lateral-movement behavior featured in the Red Canary Threat Detection Report and is heavily used by hands-on-keyboard operators. Detecting this redirect-to-share signature surfaces Impacket-driven lateral movement.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-06-03Malicious S3 Object Encryption with Customer Provided Key via CopyObject
This rule detects S3 CopyObject or PutObject API calls that supply a customer provided SSE-C encryption key which is the technique used in the CopyObjection intrusion to encrypt a victim S3 bucket for ransom. Because the attacker holds the key AWS cannot recover the data making this a destructive extortion action. Detecting SSE-C on bulk object operations surfaces ransomware activity in cloud storage.
HuntRule TeamAwscloudtrailHigh62Premium2026-06-03Malicious SQL Server Xp_cmdshell Activation - Native Event (via application)
This rule detects enable the xp_cmdshell in order to execute non SQL content and escalate privileges.
HuntRule TeamMssqlapplicationHigh101Premium2026-06-03Suspicious Download to tmp Followed by chmod Execution on Linux
This rule detects a single command line that downloads a file into a temporary directory and makes it executable. SSH compromise scripts fetch architecture specific botnet binaries into tmp with wget or curl and immediately grant execute permissions before launching them.
HuntRule TeamLinuxprocess_creationHigh2210Premium2026-06-02Suspicious Script Host Executing VBS from ConnectWiseControl Temp Directory
This rule detects wscript or cscript executing a VBScript dropped under Documents ConnectWiseControl Temp, the staging path used by PhantomControl to run Ande Loader after ScreenConnect delivery. Abusing a remote support tool folder lets attackers stage and run malicious scripts while appearing to be legitimate support automation.
HuntRule TeamWindowsprocess_creationHigh101Premium2026-06-02Possible Pre-Auth SSRF via VMware Workspace One UEM BlobHandler CVE-2021-22054
This rule detects HTTP requests to the VMware Workspace One UEM BlobHandler.ashx endpoint carrying a Url parameter. CVE-2021-22054 is a pre-authentication server-side request forgery reached through this handler with an encrypted Url payload as detailed by Assetnote, letting attackers pivot to internal services and cloud metadata.
HuntRule TeamWebwebserverHigh1810Premium2026-06-02Malicious Mimikatz Malicious Security Package (SSP) Exfiltrates Cleartext Passwords in File (via file_event)
This rule detects loaded the Mimikatz SSP "mimilib.dll" into the LSA process in order to exfiltrate clear text passwords into a file.
HuntRule TeamWindowsfile_eventHigh132Premium2026-06-02Malicious BlackBeard SCR Payload Execution (via process_creation)
This rule detects execution of WebDeepPlayer.scr, a screensaver-disguised executable used to deliver the BlackBeard payload in Boggy Serpens operations. The .scr extension conceals an executable that runs on user interaction, so its launch indicates delivery of the malware to the endpoint.
HuntRule TeamWindowsprocess_creationHigh102Premium2026-06-02Malicious MuddyWater ManageOnDriveUpdater Scheduled Task Persistence
This rule detects creation of a scheduled task named ManageOnDriveUpdater, the persistence mechanism used by the MuddyWater MuddyViper implant. The task name imitates a OneDrive update service to blend in, and its registration signals attacker-established persistence following a spearphishing intrusion.
HuntRule TeamWindowsprocess_creationHigh491Premium2026-06-02