Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,379 rules
Suspicious Renamed credwiz Binary Execution via Process Creation
This rule detects execution of the Windows Credential Wizard binary under typosquatted names used by the Russian actor Secret Blizzard to side-load its DUser.dll payload. Renaming the trusted credwiz.exe to cridviz.exe or crezly.exe is a masquerading technique that helps the DLL side-loading chain evade name-based detection.
HuntRule TeamWindowsprocess_creationHigh257Premium2026-05-31Suspicious PowerShell Spawning .NET LOLBIN (via process_creation)
This rule detects PowerShell spawning uncommon .NET framework utilities used as living-off-the-land execution proxies. The Veil#Drop loader cascaded through these binaries as fallback execution paths for its payload.
HuntRule TeamWindowsprocess_creationHigh172Premium2026-05-31Malicious SYSTEM Registry Hive Dump via reg.exe by Sandworm
This rule detects reg.exe saving the HKLM SYSTEM hive to a file, a credential access step Sandworm uses to obtain secrets for offline extraction. Exporting registry hives is a common precursor to dumping cached secrets and boot keys.
HuntRule TeamWindowsprocess_creationHigh225Premium2026-05-31Suspicious RedHook Android RAT WebSocket Device Channel (via proxy)
This rule detects WebSocket connections to the RedHook Android RAT device channel identified by the ws/device path with the misspelled menberId parameter. The RAT maintains a real-time control socket to the operator using this distinctive URI. Detecting it flags a live command-and-control session from an infected device.
HuntRule TeamWebproxyHigh123Premium2026-05-31Suspicious Script Interpreter Spawned by OneNote via Embedded File (via process_creation)
This rule detects onenote.exe spawning a command shell or scripting engine, matching campaigns that embed HTA, BAT, VBS, JSE, CMD and WSF files inside OneNote documents to launch loaders such as QakBot, IcedID and RedLine. OneNote does not normally start these interpreters.
HuntRule TeamWindowsprocess_creationHigh4810Premium2026-05-31Suspicious WScript Execution of VBScript from WhatsApp Transfers Folder via process_creation
This rule detects wscript.exe executing a .vbs file from the WhatsApp Desktop LocalState Transfers directory. The WhatsApp-delivered VBScript campaign runs its loader from this download staging path. Script execution out of a messenger transfer folder is a strong initial-access and execution indicator.
HuntRule TeamWindowsprocess_creationHigh365Premium2026-05-30ScreenConnect SetupWizard Authentication Bypass Path Traversal (CVE-2024-1709)
This rule detects web requests to the ScreenConnect SetupWizard.aspx endpoint followed by an extra trailing path segment, the request shape that triggers the CVE-2024-1709 authentication bypass. Huntress observed this pattern used to reach the setup wizard on already configured servers and create attacker administrator accounts. A trailing path after SetupWizard.aspx is not produced by normal setup flows and indicates exploitation.
HuntRule TeamWebwebserverHigh337Premium2026-05-30Suspicious Reconnaissance Spawned by Injected SearchProtocolHost via process_creation
This rule detects PikaBot post injection reconnaissance where a hollowed SearchProtocolHost.exe process spawns native discovery utilities such as whoami, ipconfig and netstat. PikaBot injects into SearchProtocolHost.exe using indirect syscalls before enumerating the host and network. The Windows indexing host does not legitimately launch these recon tools, so this parent child pairing is a high confidence indicator of injected loader activity.
HuntRule TeamWindowsprocess_creationHigh93Premium2026-05-30Suspicious sslconf Execution From AppData EdgeUpdate Directory
This rule detects a process named sslconf.exe running from a user AppData EdgeUpdate\Install path, matching the SectopRAT payload staged by the FakeAgent Claude Desktop malvertising campaign. The binary masquerades under an EdgeUpdate directory name in a user-writable location that legitimate Edge updater components never use. Execution from this wrong context indicates malware persistence and RAT activity.
HuntRule TeamWindowsprocess_creationHigh61Premium2026-05-30Mshta Spawning PowerShell or Command Shell
This rule detects mshta.exe spawning powershell.exe or cmd.exe as a child process. YoroTrooper used an HTA to JScript to PowerShell execution chain to run reverse shells and stage further tooling. Mshta launching a scripting interpreter is a classic proxy-execution and living-off-the-land pattern used to evade application controls.
HuntRule TeamWindowsprocess_creationHigh193Premium2026-05-30Suspicious C2 Beacon via cpp-httplib User Agent
This rule detects outbound HTTP requests carrying the cpp-httplib user agent, matching the Potemkin loader command-and-control channel observed with the test_agent identifier. The loader is built on the cpp-httplib library and this user agent rarely appears in legitimate enterprise browsing. Its presence in proxy or web telemetry indicates loader check-in and tasking.
HuntRule TeamWebproxyHigh316Premium2026-05-30Suspicious Scheduled Task Executing DeElevate64
This rule detects a scheduled task configured via schtasks to run DeElevate64.exe. This behavior matches Ivanti CVE-2025-0282 intrusions where attackers established persistence and privilege manipulation through a scheduled task launching this binary. Scheduled tasks referencing uncommon named binaries are a persistence indicator warranting review of the task action and origin.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-05-30Suspicious Dism Execution from ProgramData Directory (via process_creation)
This rule detects execution of Dism.exe from the ProgramData directory rather than its legitimate System32 location. The FLUX#CONSOLE campaign copied Dism there to sideload a malicious DismCore.dll via search order hijacking.
HuntRule TeamWindowsprocess_creationHigh246Premium2026-05-30Malicious Zloader C2 Communication Over HTTP
This rule detects HTTP requests to the Zloader command-and-control gate path milagrecf.php observed in the attempted attack against Intel 471. The fixed PHP gate receives beacons from the loader after the malicious Excel 4.0 macro executes. The hardcoded C2 path identifies compromised hosts contacting the operator regardless of the C2 host.
HuntRule TeamWebproxyHigh153Premium2026-05-30Suspicious Persistence via Windows NT CurrentVersion Windows Load Value (via registry_set)
This rule detects Confucius writing to the legacy Windows load value under the HKCU Windows NT CurrentVersion Windows key which auto starts the copied Swom.exe loader at logon. The load value is an uncommon and abused autostart location. Any modification pointing to an executable is suspicious.
HuntRule TeamWindowsregistry_setHigh62Premium2026-05-30