Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,279 rules
Suspicious Command and Control via Discord or Telegram Bot API
This rule detects processes connecting to Discord webhook or Telegram bot API endpoints, a command and control and exfiltration channel used by the Tomiris APT. The actors tunneled tasking and stolen data through Discord webhooks and Telegram bot APIs to hide inside allowed messaging traffic. Non-browser processes contacting these bot endpoints strongly suggest abuse of trusted web services for C2.
HuntRule TeamWebproxyMedium123Premium2026-07-14Malicious Shell Execution via Foomatic-rip Print Filter through CUPS Exploit
This rule detects the foomatic-rip CUPS print filter spawning a shell interpreter such as bash or sh. The CUPS foomatic-rip vulnerability chain lets an attacker-supplied printer inject commands through the FoomaticRIPCommandLine field, yielding a reverse shell and follow-on CoinMiner deployment. Execution of a shell as a child of foomatic-rip indicates remote command injection.
HuntRule TeamLinuxprocess_creationHigh102Premium2026-07-14Malicious Nova Ransomware Note and Encrypted File Extension via File Event
This rule detects creation of the Nova ransomware note README_NOVA.me alongside files bearing the .xgWLckNV extension appended during encryption. These artifacts are dropped as Nova encrypts a host and demands ransom.
HuntRule TeamWindowsfile_eventHigh144Premium2026-07-14Malicious Defender Behavior Monitoring Disable via Set-MpPreference
This rule detects commands that disable Microsoft Defender behavior monitoring through Set-MpPreference or the MpPreference registry path. A fake KMSPico installer delivering Vidar Stealer used a javaw hosted stage to switch off behavior monitoring before running AutoIt. Turning off behavior monitoring lets the loader execute without real-time detection.
HuntRule TeamWindowsps_scriptHigh63Premium2026-07-14Malicious Mini Shai-Hulud TanStack Destructive rm Killswitch (via process_creation)
This rule detects the destructive rm -rf against the user home directory that the Mini Shai-Hulud TanStack payload invokes as a killswitch on certain regional systems. While recursive home deletion can occur in scripts its use here follows credential theft and signals the payloads self-destruct or sabotage stage.
HuntRule TeamLinuxprocess_creationMedium177Premium2026-07-14Suspicious Recursive Credential and Wallet Search Written to Temp Inventory File
This rule detects a recursive filesystem search for wallet and credential material whose results are written to a temporary inventory file which matches the collection behavior observed when adversaries abuse AI command line tools to harvest secrets. Automating discovery of keys and wallets into a single staging file precedes exfiltration. Detecting this pattern surfaces credential and data collection on the host.
HuntRule TeamWindowsprocess_creationMedium71Premium2026-07-14Malicious Scheduled Task Masquerading as Google Updater via Schtasks
This rule detects creation of a scheduled task named after the Google updater with the highest run level triggered on user logon. The CL-STA-1062 actor deploying the TinyRCT backdoor against Southeast Asian governments registers a task called GoogleUpdaterTaskSystem to blend with legitimate Chrome update tasks. Detecting this masqueraded persistence surfaces an elevated logon-triggered foothold hiding behind a trusted name.
HuntRule TeamWindowsprocess_creationHigh298Premium2026-07-14Suspicious Executable Running From Fake Chrome User Profile Directory
This rule detects a process executing from a user profile directory named Chrome such as C\Users\Chrome. QwixxRAT copies itself as a hidden rat.exe into this fabricated profile path to blend with the Chrome browser and evade casual inspection. A process running from a user folder named after a browser is an uncommon masquerading pattern that warrants review.
HuntRule TeamWindowsprocess_creationMedium307Premium2026-07-14Malicious Recovery Disablement via bcdedit
This rule detects bcdedit disabling Windows recovery, used by the hacktivist ransomware operators to block system restoration before encryption. Turning off automatic recovery removes a victim safety net. Combined with shadow deletion this is a strong pre-encryption impact signal.
HuntRule TeamWindowsprocess_creationHigh61Premium2026-07-14Rogue Privileged Account Names on Cisco IOS XE
This rule detects references to the rogue privilege-15 account names created during active exploitation of the Cisco IOS XE Web UI vulnerability. Attackers created local accounts named cisco_tac_admin, cisco_support and cisco_sys_manager to maintain administrative access. These specific usernames are attacker-chosen masquerade artifacts and should never exist in a normal configuration.
HuntRule TeamCiscoaaaHigh52Premium2026-07-14Malicious Node.js Execution of test.js from .vscode Folder in Lazarus Lure (via process_creation)
This rule detects the Node.js runtime running a script named test.js located inside a .vscode project folder, the exact loader pattern used by the Lazarus BeaverTail campaign after a victim runs npm install. The hidden .vscode directory disguises the malicious bootstrap among normal editor files. This execution kicks off the download of the follow-on Python infostealer.
HuntRule TeamWindowsprocess_creationHigh223Premium2026-07-14Suspicious Regsvr32 Loading DLL from Remote WebDAV Location via Strela Stealer (via process_creation)
This rule detects regsvr32 executing a DLL from a remote WebDAV or HTTP location without writing it to disk, the fileless second stage delivery technique used by Strela Stealer.
HuntRule TeamWindowsprocess_creationHigh302Premium2026-07-14Malicious OMI Server Spawning Shell as Root via OMIGOD SCX Provider (via process_creation)
This rule detects the OMI server or engine process spawning a shell or command interpreter, which the OMIGOD CVE-2021-38647 and CVE-2021-38648 flaws abuse to execute attacker commands as root through the SCX provider on Azure Linux virtual machines. Such child processes indicate unauthenticated remote code execution or local privilege escalation and should be investigated as an active intrusion.
HuntRule TeamLinuxprocess_creationHigh253Premium2026-07-14Suspicious Lateral Movement via Invoke-WMIExec or Invoke-SMBExec (via ps_script)
This rule detects PowerShell use of the Invoke-WMIExec or Invoke-SMBExec pass-the-hash tooling observed alongside the ThrottleStop AV-killer intrusion. These functions authenticate to remote hosts with an NTLM hash and run commands such as local account creation without a plaintext password. Their presence indicates hands-on lateral movement using stolen credential material.
HuntRule TeamWindowsps_scriptHigh3810Premium2026-07-14Malicious Update Orchestrator Service Reconfiguration for Privilege Escalation
This rule detects reconfiguration of the Update Orchestrator Service binary path via sc.exe, the abuse chain behind CVE-2019-1322 that runs an attacker command as SYSTEM. Repointing UsoSvc to an arbitrary command lets a low-privileged user escalate to SYSTEM when the service restarts.
HuntRule TeamWindowsprocess_creationHigh101Premium2026-07-14