Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,281 rules
Malicious NTLM Downgrade Attack - Reg via SYSMON (via registry_set)
This rule detects modifies the registry configuration in order to enable or downgrade NTLM protocol version, to later on perform relay attacks.
HuntRule TeamWindowsregistry_setHigh101Premium2026-07-12Suspicious Replacement of termsrv DLL to Enable Concurrent RDP via file_event
This rule detects a write to the Terminal Services termsrv.dll in System32, the technique OkoBot uses to patch the RDP service and allow multiple concurrent sessions. The genuine termsrv.dll changes only through Windows servicing. An out-of-band modification indicates tampering to enable stealthy remote access.
HuntRule TeamWindowsfile_eventMedium92Premium2026-07-12Malicious Cicada3301 Ransomware Locker Execution via Command Line Key (via process_creation)
This rule detects execution of the Cicada3301 ransomware locker binary with its command-line decryption key argument, which the Repellent Scorpius affiliate launched remotely through PsExec to encrypt hosts. Passing the encryption key on the command line is characteristic of this Rust-based locker and indicates active ransomware deployment.
HuntRule TeamWindowsprocess_creationHigh83Premium2026-07-11Suspicious WARMCOOKIE Scheduled Task for rundll32 Persistence via process_creation
This rule detects creation of a scheduled task that runs rundll32 against the WARMCOOKIE loader RtlUpd at a short recurring interval to maintain persistence. The backdoor registers a task firing every ten minutes to ensure continuous execution. The combination of a minute-based recurrence with rundll32 loading this DLL is characteristic of WARMCOOKIE.
HuntRule TeamWindowsprocess_creationHigh132Premium2026-07-11Malicious Audit Policy Disabled by Command Line (via security)
This rule detects attempts disbaled the audit policy for defense evasion purposes.
HuntRule TeamWindowssecurityHigh123Premium2026-07-11NetSupport Manager RAT Execution From a User-Writable Path (via process_creation)
This rule detects the NetSupport Manager remote-control client (client32.exe) running from a user-writable directory such as AppData, ProgramData or Temp, where adversaries deploy the otherwise-legitimate RMM tool as a covert remote access trojan. Abuse of remote monitoring and management software is a leading access technique in the Red Canary Threat Detection Report. Because sanctioned installs live in Program Files, execution from user paths is a strong indicator of malicious NetSupport deployment.
HuntRule TeamWindowsprocess_creationHigh188Premium2026-07-11Malicious Active Directory Replication Request Indicating DCSync
This rule detects a directory service access event granting the replicating directory changes right which the ALPHV actor exercised through a credential tool to perform DCSync and pull domain hashes and this matters because outside of domain controllers and a small set of sync services the request for the replication extended right is a high fidelity indicator of DCSync credential theft.
HuntRule TeamWindowssecurityHigh111Premium2026-07-11Suspicious SoftPerfect Network Scanner Execution for Discovery
This rule detects execution of the SoftPerfect Network Scanner netscan.exe used for internal network discovery. The Christmas Miracle actor ran this tool to map reachable hosts and services before lateral movement. Unsanctioned network scanning is a common precursor to broader compromise.
HuntRule TeamWindowsprocess_creationMedium62Premium2026-07-11Suspicious UAC Bypass via iscsicpl Auto-Elevation in Operation TrueChaos
This rule detects iscsicpl.exe spawning a command interpreter or script host child process, an auto-elevation UAC bypass abused in Operation TrueChaos against Southeast Asian government targets. iscsicpl launching cmd, powershell or a temporary binary indicates privilege escalation ahead of Havoc C2 deployment.
HuntRule TeamWindowsprocess_creationHigh191Premium2026-07-11Malicious Keychain Credential Theft via security find-generic-password by ClickLock macOS Stealer (via process_creation)
This rule detects the macOS security utility invoked with find-generic-password to dump the Chrome keychain secret, the exact command ClickLock stealer runs to extract stored browser credentials. Reading the keychain password non-interactively reveals credential theft. Detecting it exposes ClickLock harvesting saved secrets.
HuntRule TeamMacosprocess_creationHigh257Premium2026-07-11Malicious GPO Permission Abuse via SharpGPOAbuse
This rule detects execution of SharpGPOAbuse, a tool CrazyHunter operators use to weaponize edit rights over a Group Policy Object for domain-wide code execution. Abusing GPO permissions lets an attacker push tasks or scripts to every host in scope. Presence of this tooling indicates active privilege abuse against Active Directory.
HuntRule TeamWindowsprocess_creationHigh112Premium2026-07-11Suspicious Remote Connection to ADWS Port 9389 via security
This rule detects Windows Filtering Platform event 5156 recording an allowed inbound connection to TCP port 9389, the Active Directory Web Services port. Correlating the real source address from event 5156 exposes remote ADWS enumeration that would otherwise appear as localhost in Directory Service logs, so non-loopback connections to 9389 indicate potential SOAPHound style directory collection.
HuntRule TeamWindowssecurityMedium63Premium2026-07-11Malicious Cobalt Strike Default Named Pipe Creation (via pipe_created)
This rule detects creation of named pipes matching Cobalt Strike default and post-exploitation patterns such as msagent_, postex_ and status_ pipes used for beacon inter-process communication and privilege escalation. Cobalt Strike is among the most prevalent adversary tools in the Red Canary Threat Detection Report, used across ransomware and espionage intrusions for command and control. Detecting its characteristic named pipes surfaces beacon activity that often evades network-based controls.
HuntRule TeamWindowspipe_createdHigh52Premium2026-07-11Possible ReverseSocks5 Tunneling Tool Execution on Linux (via process_creation)
This rule detects execution of the ReverseSocks5 tunneling utility staged as R5 under /tmp or /var during PAN-OS Captive Portal zero-day exploitation. Attackers use this SOCKS5 tunnel to proxy traffic and maintain covert access into the internal network.
HuntRule TeamLinuxprocess_creationMedium103Premium2026-07-11Malicious SharePoint spinstall0 Webshell Dropped in LAYOUTS
This rule detects the spinstall0.aspx file being written into the SharePoint LAYOUTS directory. Attackers exploiting the ToolShell chain drop this ASPX webshell to steal machine keys and maintain access. Creation of spinstall0.aspx in LAYOUTS is a definitive post-exploitation indicator.
HuntRule TeamWindowsfile_eventCritical122Premium2026-07-11