Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
29 rules
Suspicious BeyondTrust Bomgar Process Spawning Remote Access Client (via process_creation)
This rule detects a BeyondTrust Bomgar process spawning a renamed SimpleHelp remote access binary. Operators abused the CVE-2026-1731 command-execution flaw to deploy SimpleHelp under the SYSTEM account as a secondary remote access foothold.
HuntRule TeamWindowsprocess_creationHigh90Premium2026-09-07Suspicious RustDesk Remote Access Service Installation via sc (via process_creation)
This rule detects creation of a Windows service that launches RustDesk with an imported configuration. Akira ransomware operators installed RustDesk as an auto-start service using sc create to maintain unattended remote access to compromised hosts.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-07Malicious Scheduled Task ForceNetbirdRestart for Remote Access Persistence (via process_creation)
This rule detects creation of a scheduled task named ForceNetbirdRestart that restarts the NetBird agent after boot, a persistence behavior used by MuddyWater to keep its remote-access tunnel available. Adversaries leverage the task to guarantee the covert NetBird channel reconnects on every reboot.
HuntRule TeamWindowsprocess_creationHigh110Premium2026-08-30Suspicious Silent AnyDesk Installation for Remote Access by DeadLock Ransomware
This rule detects silent unattended installation of AnyDesk configured to start with Windows. The DeadLock ransomware operators deploy AnyDesk as a covert remote access tool for persistence and hands-on control. Silent installation with automatic startup indicates the tool is being planted rather than installed by a user.
HuntRule TeamWindowsprocess_creationHigh71Premium2026-07-26Antivirus Remote Access Tool Signature Matches Known RAT Names
Alerts on antivirus detections referencing multiple known RAT family signature names in the event signature field.
Arnim Rupp (Nextron Systems), Huntrule Team—antivirusCritical162Free2026-06-15Suspicious TeamViewer Remote Access DNS Resolution (via dns_query)
This rule detects DNS queries to TeamViewer infrastructure subdomains such as master, ping, router, and server nodes under teamviewer.com. Abuse of TeamViewer remote access enabled the Oldsmar water treatment facility intrusion where an operator workstation was manipulated remotely. TeamViewer is dual-use, so this detection is most valuable in ICS and OT segments where remote-access tooling should be absent or tightly controlled.
HuntRule TeamWindowsdns_queryLow193Premium2026-06-05Suspicious Octo Tempest Remote Access and Tunneling Tooling (via process_creation)
This rule detects execution of remote monitoring and tunneling tools favored by Octo Tempest such as ScreenConnect Ngrok and Tailscale. The actor deployed these tools to maintain covert remote access and tunnel traffic out of victim networks.
HuntRule TeamWindowsprocess_creationMedium442Premium2026-05-23Suspicious Chrome Remote Desktop Host Silent Binding for Remote Access (via process_creation)
This rule detects headless registration of a Chrome Remote Desktop host using the start host binary with authorization code redirect and pin arguments, the remote access tool abuse observed in a Kimsuky campaign to obtain interactive control of victim machines. Adversaries leverage legitimate remote desktop software to blend with sanctioned IT tooling while retaining hands on keyboard access, making early detection critical for exposing unauthorized remote sessions.
HuntRule TeamWindowsprocess_creationMedium3210Premium2026-05-22Suspicious NTFS Symbolic Link Evaluation Enabled via fsutil for Remote Access (via process_creation)
This rule detects fsutil enabling remote-to-local or remote-to-remote symbolic link evaluation, an uncommon configuration change made in the RansomHub intrusion to let symlinks resolve across hosts during propagation and encryption. Adversaries flip these SymlinkEvaluation settings to reach files through crafted links that are normally blocked, so this fsutil behavior change is a distinctive attacker-preparation indicator.
HuntRule TeamWindowsprocess_creationMedium308Premium2026-05-16Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)
This rule detects the SimpleHelp Remote Access client spawning a command shell that runs account and domain enumeration utilities. Following exploitation of SimpleHelp RMM for initial access, operators used the persisted client to run net and nltest reconnaissance.
HuntRule TeamWindowsprocess_creationMedium141Premium2026-05-04OpenCanary RDP New Connection Attempt on Application Logtype 14001
Alerts on OpenCanary logging a new RDP connection attempt (logtype 14001), indicating remote access probing.
Marco Pedrinazzi (@pedrinazziM), Huntrule TeamOpencanaryapplicationHigh447Free2026-01-06Windows MeshAgent Remote Access Tool Command Line Execution Indicators
Flags Windows processes invoking MeshAgent with --meshServiceName, indicating potential remote access tool execution.
Norbert Jaśniewicz (AlphaSOC), Huntrule TeamWindowsprocess_creationMedium120Free2025-05-19macOS Process Creation: MeshAgent renamed execution via --meshServiceName
Identifies macOS executions of MeshAgent instances that include --meshServiceName, indicating potential renamed remote access tooling.
Norbert Jaśniewicz (AlphaSOC), Huntrule TeamMacosprocess_creationHigh214Free2025-05-19macOS Process Creation: MeshAgent Remote Access via --meshServiceName
Alerts on macOS process executions containing --meshServiceName, indicating potential MeshAgent remote access usage.
Norbert Jaśniewicz (AlphaSOC), Huntrule TeamMacosprocess_creationMedium150Free2025-05-19OpenCanary Telnet Login Attempt Recorded in Application Logs
Alerts on OpenCanary Telnet login attempt events to highlight potential remote access probing.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh192Free2024-03-08