Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
49 rules
Malicious Msiexec Execution of Staged Update Package via Process Creation
This rule detects msiexec.exe executing the update_ms.msi package staged in ProgramData, the installer proxy-execution step that loads the msaRAT lib.dll RUN export as reported by Cisco Talos in the Chaos ransomware campaign. Running a fetched MSI from ProgramData under msiexec launches the covert browser C2 implant. Detecting this execution catches proxy execution of the malicious installer after ingress.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-12Possible Aspera Faspex Pre-Auth RCE via YAML Deserialization in package_relay (via webserver)
This rule detects POST requests to the Aspera Faspex package_relay relay_package endpoint, the injection point for a pre-auth RCE where the external_emails field carries a serialized YAML payload deserialized by YAML.load. Attackers abuse this Ruby on Rails unsafe deserialization to execute arbitrary commands. Detecting it surfaces exploitation attempts against internet-facing Faspex servers.
HuntRule TeamWebwebserverHigh90Premium2026-09-07Malicious Msiexec Installation of a Remote MSI Package (via process_creation)
This rule detects msiexec.exe installing a package directly from a remote HTTP or UNC location, a System Binary Proxy Execution pattern used to fetch and run attacker-controlled installers under a signed Microsoft binary. This LOLBin abuse appears in the Red Canary Threat Detection Report as a way to bypass application allowlisting and deliver second-stage payloads. Detecting remote msiexec installs surfaces the proxy-download-and-execute behavior.
HuntRule TeamWindowsprocess_creationHigh120Premium2026-09-01TerraStealerV2 Data Staging in Bay0NsQIzx Package Directory (via file_event)
This rule detects TerraStealerV2 staging collected browser and wallet data inside the hardcoded Bay0NsQIzx package directory under LocalAppData before archiving it for exfiltration. Adversaries leverage a fixed staging folder to consolidate stolen artifacts, making file writes into this named directory a high-confidence collection indicator.
HuntRule TeamWindowsfile_eventHigh40Premium2026-09-01In-Memory Security Package (SSP) Added - Reg via Command (via process_creation)
This rule detects adds a reference in the registry to a malicious SSP (Security Support Provider). Note that this rule will not work with "in memory" SSP injection (Mimikatz).
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-31Suspicious Windows Subsystem for Linux (WSL) Package Turned on - Native (via setup)
This rule detects enables the WSL to cary out malicious activities in a virtual instance to avoid detection.
HuntRule TeamWindowssetupMedium73Premium2026-08-27Suspicious msiexec Remote Package Installation over HTTP
This rule detects msiexec.exe installing a package directly from an http or https URL in quiet mode, a NetSupport RAT delivery vector in the ClickFix campaign. The loaders invoked msiexec with a remote URL and the /qn switch to silently install the RAT from attacker infrastructure. Remote quiet MSI installation is a LOLBin abuse pattern used to bypass download controls.
HuntRule TeamWindowsprocess_creationMedium356Premium2026-08-18Malicious PyPI Package Installation from Gleaming Pisces Supply Chain (via process_creation)
This rule detects installation of the malicious PyPI packages real-ids, coloredtxt, beautifultext, or minisound published by Gleaming Pisces to deliver the PondRAT backdoor. Installing these poisoned packages compromises developer and build systems through the software supply chain.
HuntRule TeamWindowsprocess_creationHigh358Premium2026-07-24Suspicious Msiexec Remote Package Installation from URL via Process Creation
This rule detects msiexec.exe installing an MSI package directly from a remote HTTP or HTTPS URL, a technique used in the Operation Rusty Flag campaign to deploy a Rust implant from a Dropbox-hosted MSI reached through a double-extension LNK. Adversaries abuse the trusted Windows Installer to proxy execution and pull payloads while evading application controls.
HuntRule TeamWindowsprocess_creationMedium152Premium2026-07-20Suspicious Network Download Spawned by Node.js During Package Install
This rule detects the Node.js process spawning a download utility or command interpreter during an npm package install which the Stressed Pungsan campaign abuses through a malicious preinstall hook to fetch a second stage payload onto developer machines.
HuntRule TeamWindowsprocess_creationMedium134Premium2026-07-12Malicious Mimikatz Malicious Security Package (SSP) Exfiltrates Cleartext Passwords in File (via file_event)
This rule detects loaded the Mimikatz SSP "mimilib.dll" into the LSA process in order to exfiltrate clear text passwords into a file.
HuntRule TeamWindowsfile_eventHigh122Premium2026-06-02Suspicious TruffleHog Secret Scanner Spawned by Node Package Manager on Linux
This rule detects the TruffleHog secret scanning tool being launched as a child of a node or npm process which the Shai-Hulud npm worm abuses during package install to locate GitHub npm and cloud credentials on the victim host. Running a credential scanner from within a package install lifecycle is anomalous and indicates automated secret theft rather than a developer audit.
HuntRule TeamLinuxprocess_creationHigh163Premium2026-05-23Suspicious Python Site Hook or PTH File Written to Site-Packages via File Event
This rule detects the creation of Python site-initialization hooks sitecustomize.py and usercustomize.py or a .pth file inside site-packages, the persistence mechanism used by the malicious Python packages reported by Cisco Talos. These files execute automatically every time the interpreter starts, giving attackers durable code execution. Detecting writes of these hooks reveals stealthy persistence planted through the packaging ecosystem.
HuntRule TeamWindowsfile_eventMedium245Premium2026-05-08macOS: Detect Axios malicious npm execution chain using osascript, curl download, and cleanup
Flags macOS command-line patterns showing osascript execution plus npm package download and staged file cleanup.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamMacosprocess_creationHigh319Free2026-04-01Linux Process Creation Indicators for LiteLLM Backdoored Package Activity (v1.82.7/v1.82.8)
Identifies Linux process executions matching indicators tied to backdoored LiteLLM v1.82.7/v1.82.8 credential-stealer and persistence activity.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh2110Free2026-03-30