<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://huntrule.com/</loc>
    <changefreq>daily</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules</loc>
    <changefreq>hourly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert</loc>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog</loc>
    <changefreq>daily</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/pricing</loc>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>
  <url>
    <loc>https://huntrule.com/how-it-works</loc>
    <changefreq>monthly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://huntrule.com/about</loc>
    <changefreq>monthly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://huntrule.com/contact</loc>
    <changefreq>monthly</changefreq>
    <priority>0.2</priority>
  </url>
  <url>
    <loc>https://huntrule.com/terms</loc>
    <changefreq>monthly</changefreq>
    <priority>0.1</priority>
  </url>
  <url>
    <loc>https://huntrule.com/privacy</loc>
    <changefreq>monthly</changefreq>
    <priority>0.1</priority>
  </url>
  <url>
    <loc>https://huntrule.com/attribution</loc>
    <changefreq>monthly</changefreq>
    <priority>0.1</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-splunk</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-splunk-raw</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-microsoft-sentinel</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-microsoft-defender</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-elastic</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-elastic-lucene</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-elastic-esql</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-crowdstrike</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-sentinelone</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-cortex-xdr</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-carbon-black-cloud</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-google-secops</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/convert/sigma-to-qradar</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-event-log-clearing-via-wevtutil-via-process-creation-e0acd6e3</loc>
    <lastmod>2026-09-09T06:00:20.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shadow-copy-and-backup-catalog-deletion-via-process-creation-acefcbb3</loc>
    <lastmod>2026-09-09T05:00:18.014Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-boot-recovery-disabled-via-bcdedit-via-process-creation-d42ef299</loc>
    <lastmod>2026-09-09T05:00:18.014Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-applaunch-exe-spawned-as-injection-target-via-process-creation-eeee7384</loc>
    <lastmod>2026-09-09T04:00:18.812Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-regsvr32-shellexec-rundll-proxy-execution-via-process-creation-3a34c378</loc>
    <lastmod>2026-09-09T04:00:18.812Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-running-powershell-every-minute-via-process-creation-c9e87b6b</loc>
    <lastmod>2026-09-09T03:00:19.027Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-script-host-spawning-powershell-with-invoke-expression-via-process-cre-d2af0916</loc>
    <lastmod>2026-09-09T03:00:19.027Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-roboform-signed-binary-executed-from-non-standard-path-via-process-cr-7059690b</loc>
    <lastmod>2026-09-09T03:00:19.027Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-plink-ssh-tunnel-execution-via-process-creation-431f27e5</loc>
    <lastmod>2026-09-09T02:00:18.409Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-credential-dump-via-procdump-via-process-creation-45dd5719</loc>
    <lastmod>2026-09-09T02:00:18.409Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remcos-c2-connection-from-eilowutil-process-dede6611</loc>
    <lastmod>2026-09-09T01:00:19.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dal-keepalives-dll-sideloaded-by-signed-binary-via-image-load-1cc3522a</loc>
    <lastmod>2026-09-09T01:00:19.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-coinloader-dll-sideload-from-z-1-36-81-directory-via-image-load-a8c713d6</loc>
    <lastmod>2026-09-09T01:00:19.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cortex-xdr-binary-sideloading-winutils-dll-via-image-load-765e6c07</loc>
    <lastmod>2026-09-09T01:00:19.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-storm-2603-ransom-note-file-creation-ab1a3c5c</loc>
    <lastmod>2026-09-09T00:00:20.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-akira-ransomware-note-or-encrypted-extension-creation-3c4e01d5</loc>
    <lastmod>2026-09-09T00:00:20.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wezrat-keylog-file-in-temp-directory-2e9041a4</loc>
    <lastmod>2026-09-09T00:00:20.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bugsleep-marker-file-in-public-directory-bffd3f5f</loc>
    <lastmod>2026-09-09T00:00:20.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ransomware-note-or-encrypted-file-extension-creation-780c4745</loc>
    <lastmod>2026-09-08T22:00:17.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-written-to-user-documents-subfolder-via-file-event-ffb4b8b5</loc>
    <lastmod>2026-09-08T22:00:17.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-react2shell-cve-2025-55182-prototype-pollution-exploitation-2c3d4e5f</loc>
    <lastmod>2026-09-08T22:00:17.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/xeno-stealer-persistence-via-display-calibration-run-key-4d5e6f7a</loc>
    <lastmod>2026-09-08T21:00:17.492Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/hidden-powershell-archive-extraction-via-extracttodirectory-e2f3a4b5</loc>
    <lastmod>2026-09-08T20:00:18.297Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-purplefox-mshta-to-msiexec-remote-msi-chain-9c1d2e3f</loc>
    <lastmod>2026-09-08T20:00:18.297Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-vbscript-wscript-shell-execution-2b8c4d1a</loc>
    <lastmod>2026-09-08T20:00:18.297Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-hta-payload-execution-via-mshta-7f3a1c2e</loc>
    <lastmod>2026-09-08T20:00:18.297Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-node-js-script-execution-from-appdata-roaming-d1e2f3a4</loc>
    <lastmod>2026-09-08T19:00:18.151Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shell-payload-piped-from-curl-to-zsh-e5f6a7b8</loc>
    <lastmod>2026-09-08T19:00:18.151Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/castleloader-clickfix-powershell-hex-decode-and-re-execution-8a7b6c5d</loc>
    <lastmod>2026-09-08T18:00:17.245Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cabinet-extraction-of-masqueraded-vstm-archive-via-extrac32-3d4e5f6a</loc>
    <lastmod>2026-09-08T17:00:18.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-software-discovery-via-tasklist-and-findstr-5e6f7a8b</loc>
    <lastmod>2026-09-08T16:00:18.442Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/agent-tesla-persistence-via-realtek-named-scheduled-task-batch-1a2b3c4d</loc>
    <lastmod>2026-09-08T16:00:18.442Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-execution-via-regsvr32-dllinstall-of-dat-file-6f5e4d3c</loc>
    <lastmod>2026-09-08T16:00:18.442Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/chisel-reverse-tunnel-tool-execution-from-temporary-directory-c1d2e3f4</loc>
    <lastmod>2026-09-08T14:00:19.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-tampering-via-set-mppreference-and-exclusions-b8c9d0e1</loc>
    <lastmod>2026-09-08T14:00:19.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ftp-data-exfiltration-via-curl-with-embedded-credentials-3c4d5e6f</loc>
    <lastmod>2026-09-08T14:00:19.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-check-and-remote-loader-retrieval-in-lnk-command-chain-6b7c8d9e</loc>
    <lastmod>2026-09-08T12:00:19.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/msbuild-executing-non-project-file-or-remote-payload-1f2e3d4c</loc>
    <lastmod>2026-09-08T12:00:19.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-real-time-protection-disabled-via-policy-registry-by-2b8c4d90</loc>
    <lastmod>2026-09-08T12:00:19.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-desktop-enabled-via-fdenytsconnections-registry-by-sandworm-0b3c6d24</loc>
    <lastmod>2026-09-08T12:00:19.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-autoadminlogon-enabled-via-winlogon-registry-by-ransomhub-ransomware-8c1d4e26</loc>
    <lastmod>2026-09-08T11:00:19.173Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-hidden-web-download-via-invoke-webrequest-by-catb-ransomwa-9d2e5f18</loc>
    <lastmod>2026-09-08T11:00:19.173Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-memory-dump-via-comsvcs-dll-by-salt-typhoon-1a4b7c96</loc>
    <lastmod>2026-09-08T10:00:18.957Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-named-test3-by-salt-typhoon-6c9d2e04</loc>
    <lastmod>2026-09-08T10:00:18.957Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-symbolic-link-evaluation-enabled-via-fsutil-by-ransomhub-ransomware-3a6b9c28</loc>
    <lastmod>2026-09-08T10:00:18.957Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-volume-shadow-copy-deletion-via-powershell-wmi-by-akira-ransomware-9a2b5c30</loc>
    <lastmod>2026-09-08T09:00:18.904Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-next-js-middleware-auth-bypass-via-x-middleware-subrequest-header-cve-2-c2216e15</loc>
    <lastmod>2026-09-08T09:00:18.904Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ivanti-pulse-connect-secure-command-injection-via-license-keys-status-e-90bd732a</loc>
    <lastmod>2026-09-08T08:00:18.405Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ivanti-pulse-connect-secure-auth-bypass-via-totp-backup-code-path-trave-0df96075</loc>
    <lastmod>2026-09-08T07:00:18.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-citrix-sharefile-unauthenticated-upload-path-traversal-webshell-cve-202-3b39a272</loc>
    <lastmod>2026-09-08T06:00:18.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-citrix-storefront-saml-test-endpoint-access-for-xss-cve-2023-5914-via-38820b25</loc>
    <lastmod>2026-09-08T06:00:18.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-citrix-bleed-session-token-leak-via-openid-configuration-endpoint-cve-2-1e6f2146</loc>
    <lastmod>2026-09-08T06:00:18.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-citrix-netscaler-gateway-buffer-overflow-via-formssso-endpoint-cve-2023-6d139ed2</loc>
    <lastmod>2026-09-08T05:00:18.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-magento-xxe-via-guest-carts-estimate-shipping-methods-cve-2024-34102-72c4d40f</loc>
    <lastmod>2026-09-08T04:00:18.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-progress-ws-ftp-ad-hoc-deserialization-via-aht-default-upload-parameter-44a15e32</loc>
    <lastmod>2026-09-08T04:00:18.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-moveit-transfer-ssrf-via-moveitisapi-action-m2-6ad4bd8e</loc>
    <lastmod>2026-09-08T04:00:18.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-moveit-transfer-token-request-with-grant-type-session-897f30ae</loc>
    <lastmod>2026-09-08T04:00:18.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sitecore-speak-bundle-arbitrary-file-read-via-path-traversal-e1cf0d6b</loc>
    <lastmod>2026-09-08T03:00:18.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-craft-cms-rce-via-query-string-cli-option-injection-15a605d4</loc>
    <lastmod>2026-09-08T03:00:18.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-bitbucket-pre-auth-rce-via-git-archive-exec-null-byte-injection-cve-202-2f2efcd0</loc>
    <lastmod>2026-09-08T02:00:17.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-unauthenticated-admin-creation-in-dynamicweb-cve-2022-25369-558112ab</loc>
    <lastmod>2026-09-08T01:00:18.042Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dotcms-path-traversal-webshell-upload-via-content-api-cve-2022-26352-4d93e1a2</loc>
    <lastmod>2026-09-08T00:00:18.340Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-avaya-aura-acs-path-traversal-to-admin-login-via-semicolon-bypass-via-597bae49</loc>
    <lastmod>2026-09-08T00:00:18.340Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-avaya-aura-device-services-webdav-php-webshell-upload-via-phonebackup-v-82ab931b</loc>
    <lastmod>2026-09-07T23:00:18.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aspera-faspex-pre-auth-rce-via-yaml-deserialization-in-package-relay-vi-01ee53c4</loc>
    <lastmod>2026-09-07T23:00:18.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dynamicweb-unauthenticated-administrator-creation-via-setup-default-as-d56cceb6</loc>
    <lastmod>2026-09-07T23:00:18.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dotcms-arbitrary-file-upload-and-jsp-webshell-drop-via-api-content-via--b10ecac1</loc>
    <lastmod>2026-09-07T23:00:18.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-php-webshell-access-after-malicious-zip-upload-via-webserver-3b5999a0</loc>
    <lastmod>2026-09-07T22:00:17.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fastly-client-ip-header-spoofed-to-localhost-via-webserver-f18b5b64</loc>
    <lastmod>2026-09-07T22:00:17.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-progress-whatsup-gold-path-traversal-and-unc-coercion-via-core-api-via--a0cd64cb</loc>
    <lastmod>2026-09-07T21:00:17.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-solarwinds-web-help-desk-arbitrary-hql-evaluation-via-rawhql-via-webser-fabd5007</loc>
    <lastmod>2026-09-07T19:00:19.007Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sitecore-pre-auth-rce-via-report-ashx-insecure-deserialization-via-webs-06429906</loc>
    <lastmod>2026-09-07T19:00:19.007Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-jamf-pro-ssrf-exploitation-via-edufeaturesettingstest-imageurl-via-webs-821100ac</loc>
    <lastmod>2026-09-07T19:00:19.007Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-websphere-portal-ssrf-via-proxy-servlet-targeting-cloud-metadata-cve-20-c1a478d0</loc>
    <lastmod>2026-09-07T18:00:19.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ssrf-via-websphere-portal-docpicker-internal-proxy-cve-2021-27748-a2824d9f</loc>
    <lastmod>2026-09-07T16:00:03.150Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ssrf-to-aws-metadata-via-workspace-one-uem-blobhandler-cve-2021-22054-e091ec60</loc>
    <lastmod>2026-09-07T15:00:03.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ssrf-via-vmware-workspace-one-access-instancehealth-cve-2021-22056-39b5fe0e</loc>
    <lastmod>2026-09-07T15:00:03.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-watchguard-pre-auth-rce-via-agent-login-xml-rpc-cve-2022-26318-3719a873</loc>
    <lastmod>2026-09-07T15:00:03.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-yellowfin-bi-authentication-bypass-via-storybody-endpoint-0015f491</loc>
    <lastmod>2026-09-07T13:00:03.741Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-oracle-opera-cgi-webshell-command-execution-via-operabin-d949d19b</loc>
    <lastmod>2026-09-07T12:00:03.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-pre-auth-webshell-upload-via-oracle-opera-filereceiver-servlet-c1bb234c</loc>
    <lastmod>2026-09-07T10:00:03.984Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-reflected-xss-via-cpanel-cpanelwebcall-endpoint-cve-2023-29489-4df370b0</loc>
    <lastmod>2026-09-07T10:00:03.984Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ssrf-via-gatsby-gatsby-file-proxy-endpoint-bd3ee61b</loc>
    <lastmod>2026-09-07T09:00:03.216Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ssrf-to-cloud-metadata-via-nuxt-ipx-image-proxy-57fde49c</loc>
    <lastmod>2026-09-07T08:00:03.193Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-iis-worker-spawning-nslookup-via-ws-ftp-deserialization-7aa2b0d4</loc>
    <lastmod>2026-09-07T07:00:03.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-connection-to-local-zoom-opener-webserver-launch-endpoint-via-network-2afd4748</loc>
    <lastmod>2026-09-07T06:00:02.962Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-jsp-webshell-dropped-in-tomcat-webroot-by-dotcms-exploit-cve-2022-26352-6c8a1ec7</loc>
    <lastmod>2026-09-07T06:00:02.962Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-plugx-persistence-via-canonprinter-run-key-via-registry-set-6c9e2a51</loc>
    <lastmod>2026-09-07T05:00:02.795Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mass-windows-event-log-clearing-via-powershell-via-ps-script-9e3c7a15</loc>
    <lastmod>2026-09-07T04:00:02.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-fake-fortinet-patch-infostealer-execution-via-process-creation-2c8a1e95</loc>
    <lastmod>2026-09-07T04:00:02.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-beyondtrust-bomgar-process-spawning-remote-access-client-via-process--8d1e5c92</loc>
    <lastmod>2026-09-07T03:00:02.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntds-extraction-via-ntdsutil-ifm-via-process-creation-4c8e1a37</loc>
    <lastmod>2026-09-07T03:00:02.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-meshagent-persistence-via-scheduled-task-meshusertask-via-process-cre-2b9d4c17</loc>
    <lastmod>2026-09-07T03:00:02.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-anubis-ransomware-cloudflare-tunnel-via-cloudflared-via-process-creati-7c1f2a9e</loc>
    <lastmod>2026-09-07T02:00:02.761Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tar-extraction-of-staged-archive-to-temp-via-process-creation-3d7a1c92</loc>
    <lastmod>2026-09-07T01:00:08.046Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-defender-path-exclusion-of-user-directories-via-process-cre-5e1c9a83</loc>
    <lastmod>2026-09-07T00:00:03.071Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rustdesk-remote-access-service-installation-via-sc-via-process-creati-1d7e4a92</loc>
    <lastmod>2026-09-07T00:00:03.071Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-tampering-via-set-mppreference-via-process-creation-8f3d5b21</loc>
    <lastmod>2026-09-06T23:00:02.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-non-interactive-encoded-powershell-stager-via-process-creation-6f2c8a51</loc>
    <lastmod>2026-09-06T23:00:02.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-creation-pointing-to-public-data-file-via-sc-via-process-creat-5a1d8c93</loc>
    <lastmod>2026-09-06T22:00:03.226Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-msi-execution-with-image-extension-via-msiexec-via-process-crea-2e8c1a95</loc>
    <lastmod>2026-09-06T21:00:03.331Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-activemq-exploitation-java-spawning-powershell-downloader-via-process--9c5a3e18</loc>
    <lastmod>2026-09-06T20:00:03.594Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-boryptgrab-infostealer-staging-directory-via-file-event-4e8a2c91</loc>
    <lastmod>2026-09-06T20:00:03.594Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntds-database-staging-to-audit-directory-via-file-event-5e8a1c3f</loc>
    <lastmod>2026-09-06T19:00:04.698Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cleo-autorun-health-check-file-drop-via-file-event-1a9d5c73</loc>
    <lastmod>2026-09-06T19:00:04.698Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-koske-persistence-via-systemd-service-and-shell-profile-hijack-via-pro-e974f36a</loc>
    <lastmod>2026-09-06T19:00:04.698Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-automated-ssh-lateral-movement-with-batch-mode-via-process-creation-b7504982</loc>
    <lastmod>2026-09-06T17:00:03.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-multi-layer-base64-decoded-payload-execution-via-bash-via-process-crea-21e366f2</loc>
    <lastmod>2026-09-06T17:00:03.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sobolan-payload-download-from-jupyter-compromise-via-process-creation-498f4a67</loc>
    <lastmod>2026-09-06T17:00:03.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-teamtnt-docker-gatling-gun-initialization-script-via-process-creation-8ff2cf91</loc>
    <lastmod>2026-09-06T16:00:03.720Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hadooken-cryptominer-execution-via-masqueraded-binaries-via-process-cr-1fadc794</loc>
    <lastmod>2026-09-06T16:00:03.720Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-spawned-by-postgresql-server-process-via-process-creation-f0bec4dc</loc>
    <lastmod>2026-09-06T14:00:03.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-payload-download-from-filebin-via-wget-via-process-creation-197522d6</loc>
    <lastmod>2026-09-06T12:00:04.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cloud-instance-metadata-access-from-command-line-via-process-creation-283510bf</loc>
    <lastmod>2026-09-06T12:00:04.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-looney-tunables-privilege-escalation-exploit-by-kinsing-via-process-cr-e3b513cd</loc>
    <lastmod>2026-09-06T12:00:04.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-container-runtime-tampering-via-chmod-on-runc-via-process-creation-cfb0fbdf</loc>
    <lastmod>2026-09-06T12:00:04.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-koske-userland-rootkit-installation-via-ld-so-preload-via-file-event-f214e992</loc>
    <lastmod>2026-09-06T11:00:07.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sobolan-staging-directory-creation-in-var-tmp-via-file-event-78e284b3</loc>
    <lastmod>2026-09-06T10:00:03.651Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-teamtnt-prochider-rootkit-deployment-as-shared-object-via-file-event-1d1a8314</loc>
    <lastmod>2026-09-06T10:00:03.651Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-perfctl-rootkit-library-drop-via-ld-so-preload-via-file-event-a34cdc3f</loc>
    <lastmod>2026-09-06T09:00:03.080Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tomcat-campaign-command-and-control-domain-resolution-via-dns-query-b5da8421</loc>
    <lastmod>2026-09-06T08:00:02.993Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-teamtnt-command-and-control-domain-resolution-via-dns-query-fb90e384</loc>
    <lastmod>2026-09-06T07:00:03.360Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-proxyjacking-service-resolution-observed-in-perfctl-campaign-via-dns--d9431de9</loc>
    <lastmod>2026-09-06T07:00:03.360Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lucifer-botnet-mining-pool-domain-resolution-via-dns-query-25ab57ac</loc>
    <lastmod>2026-09-06T07:00:03.360Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-gh0stbins-rat-registry-marker-hhclient-1f5a8e4c</loc>
    <lastmod>2026-09-06T06:00:03.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-castleloader-c2-communication-via-hardcoded-user-agent-9c2d5b3e</loc>
    <lastmod>2026-09-06T06:00:03.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-spawned-by-vbscript-for-rmm-delivery-2a47f5d9</loc>
    <lastmod>2026-09-06T06:00:03.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-banana-rat-uac-skip-environment-variable-in-powershell-6b92a084</loc>
    <lastmod>2026-09-06T06:00:03.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-loading-fake-edge-update-script-4a819f73</loc>
    <lastmod>2026-09-06T04:00:02.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-jscript-net-compiler-spawned-by-autoit-for-process-hollowing-2b8f4a1c</loc>
    <lastmod>2026-09-06T04:00:02.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-autoit3-compiled-script-execution-via-a3x-file-7a1c3e9d</loc>
    <lastmod>2026-09-06T04:00:02.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-masquerading-python-interpreter-csshost-executing-script-6e4f7d3b</loc>
    <lastmod>2026-09-06T03:00:02.851Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-interlock-fake-updater-executable-execution-8b3c6a2e</loc>
    <lastmod>2026-09-06T03:00:02.851Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-powershell-executing-substring-of-dropped-file-2e0f3d9b</loc>
    <lastmod>2026-09-06T02:00:02.946Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-pureminer-persistence-executable-in-appdata-hresult-folder-5e25d3b7</loc>
    <lastmod>2026-09-06T01:00:03.202Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-connection-from-caspol-binary-5d5e8c40</loc>
    <lastmod>2026-09-06T00:00:03.275Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shfolder-dll-sideloading-via-vmware-net-service-binary-3b7c0a6e</loc>
    <lastmod>2026-09-05T22:00:04.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-interlock-credential-stealer-output-file-6a2b5f1d</loc>
    <lastmod>2026-09-05T22:00:04.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wdigest-uselogoncredential-enablement-for-plaintext-credential-theft--d3f1a2b4</loc>
    <lastmod>2026-09-05T22:00:04.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pebbledash-c2-configuration-stored-under-wmi-security-key-via-registr-d3f1a2b4</loc>
    <lastmod>2026-09-05T22:00:04.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-invoke-wmiexec-lateral-movement-download-and-execute-via-ps-script-d3f1a2b4</loc>
    <lastmod>2026-09-05T20:00:49.822Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certutil-urlcache-download-of-remote-cab-payload-via-process-creation-d3f1a2b4</loc>
    <lastmod>2026-09-05T20:00:49.822Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-xctdoor-xcloader-execution-via-regsvr32-appx-path-abuse-via-process-cr-d3f1a2b4</loc>
    <lastmod>2026-09-05T20:00:49.822Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-backdoor-account-creation-ending-with-dollar-sign-via-process--d3f1a2b4</loc>
    <lastmod>2026-09-05T19:00:50.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-potato-family-privilege-escalation-tool-execution-via-process-creation-d3f1a2b4</loc>
    <lastmod>2026-09-05T19:00:50.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-certutil-decode-of-encoded-web-shell-to-aspx-via-process-creation-d3f1a2b4</loc>
    <lastmod>2026-09-05T19:00:50.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-coinminer-watchdog-staging-in-shared-memory-via-process-creatio-d3f1a2b4</loc>
    <lastmod>2026-09-05T19:00:50.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-payload-download-from-xrpl-city-miner-host-via-process-creation-d3f1a2b4</loc>
    <lastmod>2026-09-05T18:00:54.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msbuild-execution-from-office-or-archive-extraction-context-via-proce-d3f1a2b4</loc>
    <lastmod>2026-09-05T18:00:54.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kimsuky-scheduled-task-impersonating-google-update-cgi-via-process-cr-d3f1a2b4</loc>
    <lastmod>2026-09-05T18:00:54.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ladon-powershell-attack-framework-import-via-process-creation-d3f1a2b4</loc>
    <lastmod>2026-09-05T18:00:54.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fscan-internal-network-scanner-execution-via-process-creation-d3f1a2b4</loc>
    <lastmod>2026-09-05T17:00:52.329Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-history-wipe-via-rundll32-clearmytracksbyprocess-via-process--d3f1a2b4</loc>
    <lastmod>2026-09-05T16:00:53.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-crat-injection-named-pipe-chromeupdatepipe-via-pipe-created-d3f1a2b4</loc>
    <lastmod>2026-09-05T16:00:53.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xctdoor-script-dropper-staging-in-public-videos-folder-via-file-event-d3f1a2b4</loc>
    <lastmod>2026-09-05T16:00:53.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-larva-24009-keylogger-log-staging-in-onedrive-path-via-file-event-d3f1a2b4</loc>
    <lastmod>2026-09-05T15:00:55.540Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-atlasrat-loader-artifacts-in-public-documents-via-file-event-d3f1a2b4</loc>
    <lastmod>2026-09-05T15:00:55.540Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kimsuky-python-backdoor-staging-in-winii-directory-via-file-event-d3f1a2b4</loc>
    <lastmod>2026-09-05T15:00:55.540Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-t-rex-coinminer-binaries-in-windows-nt-program-files-folder-via-file--d3f1a2b4</loc>
    <lastmod>2026-09-05T14:01:01.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-malicious-iis-module-dll-written-to-inetsrv-directory-via-file-event-d3f1a2b4</loc>
    <lastmod>2026-09-05T14:01:01.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-privileged-container-creation-in-kubernetes-via-audit-25ed6d69</loc>
    <lastmod>2026-09-05T13:01:05.114Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-assignment-of-a-privileged-azure-ad-role-via-auditlogs-63184ccc</loc>
    <lastmod>2026-09-05T13:01:05.114Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/launchagent-or-launchdaemon-persistence-file-creation-on-macos-via-file-event-7ffd9769</loc>
    <lastmod>2026-09-05T13:01:05.114Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/eap-service-activation-by-liontail-framework-for-dll-sideloading-via-command-via-1f721262</loc>
    <lastmod>2026-09-05T13:01:05.114Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-commonly-hijacked-dll-loaded-from-a-user-writable-path-via-image-load-7e3ddcbc</loc>
    <lastmod>2026-09-05T12:01:00.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-user-password-change-using-current-hash-password-changentlm-mimikatz-v-99ae1fef</loc>
    <lastmod>2026-09-05T12:01:00.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-account-password-set-to-never-expire-via-security-fca31e8f</loc>
    <lastmod>2026-09-05T12:01:00.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cluster-admin-role-binding-creation-via-audit-34fa6e50</loc>
    <lastmod>2026-09-05T12:01:00.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-email-hiding-inbox-rule-creation-via-exchange-4c79bac8</loc>
    <lastmod>2026-09-05T11:00:59.961Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-modification-of-a-computer-account-spn-via-security-5cdac636</loc>
    <lastmod>2026-09-05T11:00:59.961Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-massive-group-membership-changes-via-security-d90ad03a</loc>
    <lastmod>2026-09-05T11:00:59.961Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mailbox-audit-bypass-association-in-exchange-online-via-exchange-7cf80134</loc>
    <lastmod>2026-09-05T11:00:59.961Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-high-risk-active-directory-group-membership-change-via-security-19d1ffd0</loc>
    <lastmod>2026-09-05T09:00:51.555Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-making-a-file-executable-in-a-temp-directory-via-process-creation-99c71003</loc>
    <lastmod>2026-09-05T09:00:51.555Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-account-marked-as-sensitive-and-cannot-be-delegated-had-its-protection-97b876f5</loc>
    <lastmod>2026-09-05T09:00:51.555Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iam-access-key-creation-for-persistence-via-cloudtrail-f8491eee</loc>
    <lastmod>2026-09-05T08:00:58.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-active-directory-enumeration-via-sharphound-or-bloodhound-via-process--7c010ff3</loc>
    <lastmod>2026-09-05T07:00:55.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-host-constrained-delegation-settings-changed-for-potential-abuse-rubeu-7c343e70</loc>
    <lastmod>2026-09-05T07:00:55.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-host-set-with-unconstrained-delegation-via-security-88ee72f6</loc>
    <lastmod>2026-09-05T06:00:53.035Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-host-set-with-constrained-delegation-via-security-5eaa178a</loc>
    <lastmod>2026-09-05T05:00:52.242Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-computer-account-manipulation-for-delegation-rbcd-via-security-9e5978be</loc>
    <lastmod>2026-09-05T03:00:53.471Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bits-job-persistence-via-bitsadmin-notify-command-via-process-creation-2e4510ca</loc>
    <lastmod>2026-09-05T02:00:51.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-whoami-execution-with-output-redirected-to-a-file-via-process-creatio-b3f00d8a</loc>
    <lastmod>2026-09-05T02:00:51.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-office-application-loading-a-user-path-dll-via-regsvr32-or-rundll32-vi-8606b12d</loc>
    <lastmod>2026-09-05T02:00:51.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-amsi-or-etw-bypass-in-powershell-via-process-creation-89a61c9e</loc>
    <lastmod>2026-09-04T21:00:52.444Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-command-execution-inside-a-kubernetes-pod-via-audit-ea924160</loc>
    <lastmod>2026-09-04T21:00:52.444Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-permissions-hijacked-for-privileges-abuse-service-via-process--9e5d6eee</loc>
    <lastmod>2026-09-04T21:00:52.444Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-program-execution-from-a-mounted-iso-or-disk-image-via-process-creati-ccc21e17</loc>
    <lastmod>2026-09-04T17:00:55.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-abuse-with-backdoored-command-failure-service-via-process-crea-0f6a76a7</loc>
    <lastmod>2026-09-04T17:00:55.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cmstp-execution-of-an-inf-profile-via-process-creation-62fbbfa8</loc>
    <lastmod>2026-09-04T16:00:49.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-account-set-with-reversible-encryption-weakness-introduction-via-secur-5ac7a87d</loc>
    <lastmod>2026-09-04T16:00:49.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabled-guest-or-builtin-account-activated-via-security-9fe0191d</loc>
    <lastmod>2026-09-04T15:00:58.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/psexec-remote-service-execution-on-target-host-via-process-creation-bea30282</loc>
    <lastmod>2026-09-04T15:00:58.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-permissions-hijacked-for-privileges-abuse-reg-via-command-via--539bac03</loc>
    <lastmod>2026-09-04T14:00:58.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/xsl-script-processing-via-wmic-or-msxsl-via-process-creation-6be8b10d</loc>
    <lastmod>2026-09-04T14:00:58.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-file-decoding-via-certutil-via-process-creation-86d87c9a</loc>
    <lastmod>2026-09-04T14:00:58.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-network-share-manipulation-via-commandline-via-process-creation-dea2fee2</loc>
    <lastmod>2026-09-04T13:01:00.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-file-download-via-uncommon-lolbin-via-process-creation-007f267e</loc>
    <lastmod>2026-09-04T13:01:00.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-defender-critical-security-components-disabled-command-via-p-67aa113c</loc>
    <lastmod>2026-09-04T13:01:00.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-user-password-change-without-previous-password-known-setntlm-mimikatz--c3acc4fc</loc>
    <lastmod>2026-09-04T12:00:55.651Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-process-creation-via-wmic-process-call-create-via-process-crea-ade2364f</loc>
    <lastmod>2026-09-04T12:00:55.651Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-code-compilation-via-aspnet-compiler-lolbin-via-process-creation-b640d470</loc>
    <lastmod>2026-09-04T11:00:59.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mimikatz-driver-registration-reg-via-sysmon-via-registry-event-f5178234</loc>
    <lastmod>2026-09-04T10:00:50.864Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-systemd-service-persistence-creation-via-process-creation-dc480a40</loc>
    <lastmod>2026-09-04T09:00:55.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-defender-service-deactivation-attempt-command-via-process-cr-7705131d</loc>
    <lastmod>2026-09-04T09:00:55.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-number-of-oustanding-smb-requests-increased-via-process-creation-71966e0f</loc>
    <lastmod>2026-09-04T08:00:59.146Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-network-service-scanning-via-nmap-or-masscan-via-process-creation-ab382c10</loc>
    <lastmod>2026-09-04T08:00:59.146Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-dump-via-process-access-via-process-access-debab1cb</loc>
    <lastmod>2026-09-04T08:00:59.146Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-or-flushing-of-the-linux-host-firewall-via-process-creation-2fd43528</loc>
    <lastmod>2026-09-04T05:00:50.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-script-piped-directly-to-a-shell-via-process-creation-d579f450</loc>
    <lastmod>2026-09-04T05:00:50.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-smb-insecure-guest-authentication-activated-native-via-security-510bad46</loc>
    <lastmod>2026-09-04T05:00:50.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cryptocurrency-miner-execution-via-process-creation-1abeb0d7</loc>
    <lastmod>2026-09-04T05:00:50.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rundll32-loading-an-export-from-a-user-path-via-process-creation-580f59fc</loc>
    <lastmod>2026-09-04T03:00:55.949Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-clipboard-data-capture-via-powershell-via-process-creation-5d738975</loc>
    <lastmod>2026-09-04T02:00:54.421Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/renamed-user-account-creation-disguised-in-a-computer-account-via-security-9600e350</loc>
    <lastmod>2026-09-04T02:00:54.421Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-raspberry-robin-msiexec-spawning-a-proxy-binary-via-process-creation-1df7e419</loc>
    <lastmod>2026-09-04T01:00:52.687Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-modification-of-a-user-account-spn-to-enable-kerberoast-attack-via-sec-bef2168d</loc>
    <lastmod>2026-09-04T01:00:52.687Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-secure-deletion-of-free-space-via-cipher-via-process-creation-00a16331</loc>
    <lastmod>2026-09-04T00:00:50.722Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-account-set-with-kerberos-des-encryption-activated-weakness-introducti-441705d5</loc>
    <lastmod>2026-09-04T00:00:50.722Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-extension-sideload-from-a-user-path-via-process-creation-70bf92c1</loc>
    <lastmod>2026-09-04T00:00:50.722Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-credential-dump-with-lsassy-process-via-process-creation-ad359dfd</loc>
    <lastmod>2026-09-04T00:00:50.722Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-account-set-with-kerberos-pre-authentication-not-required-as-rep-roast-e3cfd7e1</loc>
    <lastmod>2026-09-03T23:00:50.724Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-logged-on-session-discovery-via-quser-or-qwinsta-via-process-creation-d301dece</loc>
    <lastmod>2026-09-03T22:00:51.585Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-service-installation-via-security-be04f3ca</loc>
    <lastmod>2026-09-03T22:00:51.585Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-proxy-execution-via-syncappvpublishingserver-via-process-creation-a49341d2</loc>
    <lastmod>2026-09-03T22:00:51.585Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-execution-via-odbcconf-lolbin-via-process-creation-059664fd</loc>
    <lastmod>2026-09-03T21:00:57.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/socgholish-fake-browser-update-script-execution-via-process-creation-3f0417e8</loc>
    <lastmod>2026-09-03T21:00:57.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sticky-key-file-created-from-cmd-copy-via-file-event-f8a586cb</loc>
    <lastmod>2026-09-03T21:00:57.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-execution-over-smb-share-via-security-d0a12b2b</loc>
    <lastmod>2026-09-03T20:00:59.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-paste-and-run-execution-from-the-windows-run-dialog-via-process-creat-8d8ab223</loc>
    <lastmod>2026-09-03T20:00:59.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-credential-dump-with-lsassy-admin-share-via-security-bbe9e2a0</loc>
    <lastmod>2026-09-03T20:00:59.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-impact-of-smokedham-backdoor-with-msdtc-service-privilege-escalation--2509cfd6</loc>
    <lastmod>2026-09-03T20:00:59.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shell-spawned-by-mshta-delivery-via-process-creation-9854dd3e</loc>
    <lastmod>2026-09-03T19:00:48.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-silent-installation-of-remote-management-software-via-process-creatio-d73b6523</loc>
    <lastmod>2026-09-03T18:00:56.106Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sql-server-brutforce-enumeration-with-non-existing-users-login-via-app-0790aba7</loc>
    <lastmod>2026-09-03T17:00:52.544Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-the-macos-quarantine-attribute-via-xattr-via-process-creat-76a81f4c</loc>
    <lastmod>2026-09-03T17:00:52.544Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dsrm-password-changed-native-via-security-e9eca79c</loc>
    <lastmod>2026-09-03T17:00:52.544Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-script-piped-to-a-shell-on-macos-via-process-creation-10ec8fbf</loc>
    <lastmod>2026-09-03T17:00:52.544Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-macos-keychain-credential-access-via-security-utility-via-process-creat-29596746</loc>
    <lastmod>2026-09-03T16:01:06.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-storing-an-encoded-payload-in-the-registry-via-process-creation-63407243</loc>
    <lastmod>2026-09-03T16:01:06.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dcsync-domain-replication-credential-theft-via-process-creation-ad32d68d</loc>
    <lastmod>2026-09-03T15:00:53.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shared-library-preload-persistence-via-ld-so-preload-via-process-creat-68f63369</loc>
    <lastmod>2026-09-03T15:00:53.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-software-discovery-via-wmi-or-defender-query-via-process-cre-da6e5327</loc>
    <lastmod>2026-09-03T15:00:53.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-serverlevelplugindll-command-installation-via-process-creation-00275b63</loc>
    <lastmod>2026-09-03T15:00:53.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scheduled-persistent-task-with-system-privileges-creation-via-process--ea2edfce</loc>
    <lastmod>2026-09-03T12:00:55.747Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vss-backup-deletion-or-resize-via-process-creation-737b5a8c</loc>
    <lastmod>2026-09-03T12:00:55.747Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wdigest-authentication-enabled-reg-via-command-via-process-creation-77950c71</loc>
    <lastmod>2026-09-03T11:00:57.151Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-boot-recovery-tampering-via-bcdedit-via-process-creation-b9a11a91</loc>
    <lastmod>2026-09-03T10:00:51.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-task-manager-used-for-lsass-dump-kernel-via-security-6ebfb642</loc>
    <lastmod>2026-09-03T10:00:51.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-load-via-launchctl-via-process-creation-b551c12a</loc>
    <lastmod>2026-09-03T10:00:51.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-compiled-html-help-process-spawning-a-script-interpreter-via-process-c-5f444bc9</loc>
    <lastmod>2026-09-03T09:00:55.897Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-staging-via-password-protected-archive-utility-via-process-creat-133ba501</loc>
    <lastmod>2026-09-03T08:01:00.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-winlogon-process-contact-to-c2-blacklotus-sysmon-via-process-creation-2b099e39</loc>
    <lastmod>2026-09-03T08:01:00.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kernel-extension-load-on-macos-via-process-creation-c4a64d42</loc>
    <lastmod>2026-09-03T07:01:03.464Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-event-log-clear-attempt-wmi-via-process-creation-01608e88</loc>
    <lastmod>2026-09-03T07:01:03.464Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-permission-grant-to-everyone-via-icacls-via-process-creation-6cf0f29b</loc>
    <lastmod>2026-09-03T07:01:03.464Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-interactive-privileged-shell-triggered-by-schedule-task-deprecated-via-f33eea5b</loc>
    <lastmod>2026-09-03T07:01:03.464Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/applescript-do-shell-script-abuse-via-osascript-via-process-creation-bf771675</loc>
    <lastmod>2026-09-03T06:01:01.521Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-brutforce-enumeration-with-non-existing-users-login-via-security-4c126db4</loc>
    <lastmod>2026-09-03T05:00:55.562Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-host-constrained-delegation-settings-changed-for-potential-abuse-rubeu-1e903187</loc>
    <lastmod>2026-09-03T05:00:55.562Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webserver-iis-configuration-edited-sysmon-via-file-event-387112fd</loc>
    <lastmod>2026-09-03T04:01:06.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sql-server-lateral-movement-with-clr-activation-via-application-c9522a88</loc>
    <lastmod>2026-09-03T04:01:06.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/untrusted-disabling-of-macos-gatekeeper-via-spctl-via-process-creation-2be13c64</loc>
    <lastmod>2026-09-03T04:01:06.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-profile-persistence-modification-via-process-creation-d4c951af</loc>
    <lastmod>2026-09-03T03:00:58.992Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-history-clearing-or-disabling-via-process-creation-5355176f</loc>
    <lastmod>2026-09-03T03:00:58.992Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ssh-authorized-keys-persistence-modification-via-process-creation-9fba45cc</loc>
    <lastmod>2026-09-03T01:00:57.337Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/usn-change-journal-deletion-via-fsutil-via-process-creation-ee99de22</loc>
    <lastmod>2026-09-03T00:00:09.792Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sql-server-auditing-deactivated-via-application-4a22553e</loc>
    <lastmod>2026-09-03T00:00:09.792Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-massive-service-failures-tchopper-via-system-754f3f76</loc>
    <lastmod>2026-09-02T23:00:13.563Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-execution-via-wuauclt-update-handler-via-process-creation-0e46efc6</loc>
    <lastmod>2026-09-02T22:00:09.400Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-timestamp-manipulation-via-powershell-via-process-creation-009a28dd</loc>
    <lastmod>2026-09-02T22:00:09.400Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-serverlevelplugindll-registration-reg-via-sysmon-via-registry-set-ad11160b</loc>
    <lastmod>2026-09-02T22:00:09.400Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/registry-query-for-wdigest-cf23c788</loc>
    <lastmod>2026-09-02T21:00:11.633Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-registry-hive-dump-of-sam-or-system-via-reg-save-via-process-creation-5f894f9c</loc>
    <lastmod>2026-09-02T21:00:11.633Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-code-execution-via-installutil-lolbin-via-process-creation-4d3c4100</loc>
    <lastmod>2026-09-02T20:00:11.675Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-read-access-to-the-linux-shadow-password-file-via-process-creation-cb40d8fc</loc>
    <lastmod>2026-09-02T19:00:22.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-uac-bypass-via-sdclt-handler-hijack-via-registry-set-bd9096d2</loc>
    <lastmod>2026-09-02T19:00:22.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-winlogon-shell-or-userinit-persistence-modification-via-registry-set-77213af5</loc>
    <lastmod>2026-09-02T19:00:22.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-bulk-data-exfiltration-via-rclone-via-process-creation-97d0a3a1</loc>
    <lastmod>2026-09-02T19:00:22.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-diskshadow-command-abuse-to-expose-vss-backup-via-process-creation-6e884eef</loc>
    <lastmod>2026-09-02T18:00:15.456Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-houken-php-webshell-written-into-ivanti-csa-webroot-via-shell-redirect-7a1c9f42</loc>
    <lastmod>2026-09-02T18:00:15.456Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-shadow-session-started-native-via-rdp-0b69548e</loc>
    <lastmod>2026-09-02T17:00:07.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-tampering-with-windows-defender-protection-via-process-creation-b543306b</loc>
    <lastmod>2026-09-02T17:00:07.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-credential-dump-with-lsassy-powershell-via-powershell-bf7ccdca</loc>
    <lastmod>2026-09-02T17:00:07.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-medium-risk-local-domain-local-group-membership-change-via-security-c60c38f5</loc>
    <lastmod>2026-09-02T16:00:09.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-brutforce-with-denied-access-due-to-account-restrictions-policies-via-5e484fce</loc>
    <lastmod>2026-09-02T16:00:09.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-with-command-line-via-process-creation-38748fb9</loc>
    <lastmod>2026-09-02T16:00:09.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-massive-processes-termination-burst-via-process-creation-25822da3</loc>
    <lastmod>2026-09-02T15:00:29.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-permissions-modification-on-a-network-share-via-security-aa5caf8f</loc>
    <lastmod>2026-09-02T15:00:29.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gatedoor-dll-search-order-hijacking-via-webview2loader-from-microsoftedging-via--29e3c669</loc>
    <lastmod>2026-09-02T15:00:29.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-firewall-deactivation-powershell-via-powershell-178b5e3a</loc>
    <lastmod>2026-09-02T14:00:05.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-administrator-login-impersonation-with-forged-golden-ticket-via-sec-9a6eb486</loc>
    <lastmod>2026-09-02T14:00:05.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-kerberos-proxiable-s4u2self-ticket-cve-2021-42278-42287-via-security-a64be740</loc>
    <lastmod>2026-09-02T14:00:05.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-creation-powershell-via-powershell-4db04d2b</loc>
    <lastmod>2026-09-02T14:00:05.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-uac-bypass-via-ms-settings-handler-hijack-via-registry-set-1d493c82</loc>
    <lastmod>2026-09-02T13:00:11.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-event-log-clear-attempt-command-via-process-creation-48bff6ae</loc>
    <lastmod>2026-09-02T13:00:11.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-massive-remote-service-creation-via-named-pipes-tchopper-cme-via-secur-be597843</loc>
    <lastmod>2026-09-02T13:00:11.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-subsystem-for-linux-wsl-installation-command-via-process-crea-08de1cd4</loc>
    <lastmod>2026-09-02T13:00:11.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-kerberos-ticket-file-creation-indicating-credential-theft-via-file-eve-e3b7e84c</loc>
    <lastmod>2026-09-02T12:00:14.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-system-reconnaissance-via-wmi-command-line-queries-via-process-creati-e7509c3d</loc>
    <lastmod>2026-09-02T10:00:12.348Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/renamed-regsvr32-or-rundll32-loading-a-dll-with-a-non-standard-extension-via-pro-353b5138</loc>
    <lastmod>2026-09-02T10:00:12.348Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-event-log-deactivation-or-size-reduction-command-via-process-creation-c34854c6</loc>
    <lastmod>2026-09-02T08:00:12.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-kimsuky-vbe-payload-download-via-curl-to-appdata-and-execution-via-pro-6b1e7d2a</loc>
    <lastmod>2026-09-02T07:00:20.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-mustang-panda-pcl2bmp-sideloading-host-executed-from-public-documents-v-fe48788e</loc>
    <lastmod>2026-09-02T07:00:20.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/enabling-restricted-admin-mode-8e9de57d</loc>
    <lastmod>2026-09-02T07:00:20.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-inhibition-of-system-recovery-via-shadow-copy-or-backup-deletion-via-p-6c5487ba</loc>
    <lastmod>2026-09-02T07:00:20.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-enumerated-via-process-creation-72401816</loc>
    <lastmod>2026-09-02T06:00:14.785Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-iis-application-pool-credential-dumping-via-process-creation-1f46ecad</loc>
    <lastmod>2026-09-02T06:00:14.785Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/clickfix-powershell-in-memory-execution-via-invoke-restmethod-piped-to-invoke-ex-9bd40223</loc>
    <lastmod>2026-09-02T06:00:14.785Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rdp-blueekeep-connection-closed-cve-2019-0708-via-rdp-3d8be71f</loc>
    <lastmod>2026-09-02T05:00:16.940Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/openssh-native-server-feature-installation-via-powershell-13f8dfc1</loc>
    <lastmod>2026-09-02T04:00:13.780Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-impacket-dcomexec-process-abuse-via-mmc-via-process-creation-86e06208</loc>
    <lastmod>2026-09-02T04:00:13.780Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-anonymous-login-domain-specified-via-security-0f4fe8aa</loc>
    <lastmod>2026-09-02T03:00:23.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bits-payload-downloaded-via-commandline-via-process-creation-7a348334</loc>
    <lastmod>2026-09-02T02:00:12.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-group-discovery-command-via-process-creation-9231ef72</loc>
    <lastmod>2026-09-02T01:00:11.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sql-server-dedicated-admin-connection-dac-suspicious-activity-via-appl-234c805f</loc>
    <lastmod>2026-09-02T00:01:06.155Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-deactivation-command-via-process-creation-012b54b5</loc>
    <lastmod>2026-09-02T00:01:06.155Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitlocker-feature-activation-on-multiple-hosts-native-via-bitlocker-45236f08</loc>
    <lastmod>2026-09-02T00:01:06.155Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-brutforce-enumeration-on-windows-openssh-server-with-non-existing-user-7fae4851</loc>
    <lastmod>2026-09-02T00:01:06.155Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-massive-remote-service-creation-via-named-pipes-tchopper-via-security-dd2eefcb</loc>
    <lastmod>2026-09-01T23:01:05.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-audit-policy-disabled-by-command-line-via-process-creation-88e629ad</loc>
    <lastmod>2026-09-01T23:01:05.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shared-folder-access-with-forged-golden-ticket-via-security-447dc5d3</loc>
    <lastmod>2026-09-01T23:01:05.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-user-files-dump-via-network-share-donpapi-lazagne-via-security-a509b12f</loc>
    <lastmod>2026-09-01T23:01:05.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-credential-dump-with-lsassy-kernel-access-via-security-81f79463</loc>
    <lastmod>2026-09-01T22:00:04.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/systemnightmare-by-gentilkiwi-external-printer-mapped-cve-2021-1675-cve-2021-345-e7ad1bd2</loc>
    <lastmod>2026-09-01T22:00:04.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-rdp-tunneling-configuration-enabled-for-port-forwarding-via-process-c-65c6ed27</loc>
    <lastmod>2026-09-01T22:00:04.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-metasploit-reverse-shell-injection-in-sql-server-via-process-creation-c8521141</loc>
    <lastmod>2026-09-01T21:00:04.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-impacket-wmiexec-process-execution-via-process-creation-b2d5fd90</loc>
    <lastmod>2026-09-01T21:00:04.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-fortinet-apt-group-abuse-on-windows-user-via-security-8d5c309f</loc>
    <lastmod>2026-09-01T20:00:04.250Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-abuse-with-backdoored-command-failure-reg-via-powershell-via-p-51a65cca</loc>
    <lastmod>2026-09-01T19:00:05.464Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rubeus-kerberos-unconstrained-delegation-abuse-via-security-60bfe9c1</loc>
    <lastmod>2026-09-01T18:00:05.257Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-stickey-key-called-cmd-via-command-execution-hash-detection-via-proces-2d351f80</loc>
    <lastmod>2026-09-01T18:00:05.257Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/muddywater-netbird-deployment-via-hardcoded-setup-key-via-process-creation-7d24448e</loc>
    <lastmod>2026-09-01T17:00:06.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-firewall-deactivation-firewall-via-firewall-as-ffefd6e9</loc>
    <lastmod>2026-09-01T17:00:06.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-defender-threat-exclusion-added-native-via-windefend-115fadc0</loc>
    <lastmod>2026-09-01T17:00:06.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/asyncrat-injector-libpk-dll-written-to-public-folder-via-file-event-a5383ced</loc>
    <lastmod>2026-09-01T16:00:04.494Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/funksec-ransomware-encryption-artifacts-via-funksec-extension-and-markdown-ranso-19537761</loc>
    <lastmod>2026-09-01T15:00:05.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-xe-group-webshell-upload-via-veracore-uploadimage-cve-2024-57968-via-w-a2c6f394</loc>
    <lastmod>2026-09-01T14:00:04.996Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/hamsaupdate-wiper-trigger-via-f5updater-confirmdeletefiles-argument-via-process--1e6b9d47</loc>
    <lastmod>2026-09-01T14:00:04.996Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fake-crypto-wallet-installer-batch-script-staging-via-file-event-05366764</loc>
    <lastmod>2026-09-01T14:00:04.996Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-msiexec-installation-of-a-remote-msi-package-via-process-creation-711a53f6</loc>
    <lastmod>2026-09-01T12:00:07.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-memory-access-from-a-non-system-process-via-process-access-9918b67e</loc>
    <lastmod>2026-09-01T12:00:07.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gatedoor-persistence-via-schtasks-microsoftedging-task-via-process-creation-db7b74de</loc>
    <lastmod>2026-09-01T12:00:07.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kimsuky-alphaseed-artifacts-in-edge-hidden-directory-via-file-event-bc5544f4</loc>
    <lastmod>2026-09-01T12:00:07.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-impacket-atexec-remote-scheduled-task-execution-via-process-creation-9b04b9b3</loc>
    <lastmod>2026-09-01T11:00:05.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-spawned-by-wmi-provider-host-via-process-creation-259a0c26</loc>
    <lastmod>2026-09-01T11:00:05.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rundll32-dllregisterserver-execution-from-a-user-writable-path-via-pro-87014522</loc>
    <lastmod>2026-09-01T11:00:05.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-encoded-or-download-cradle-command-line-via-process-creation-df8f1acd</loc>
    <lastmod>2026-09-01T11:00:05.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-trojanized-screenconnect-client-installer-with-guest-relay-parameters-43d40f6a</loc>
    <lastmod>2026-09-01T09:00:05.754Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/patchcord-sheetcord-startup-folder-vbscript-persistence-via-file-event-8f2eb230</loc>
    <lastmod>2026-09-01T09:00:05.754Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/nullsoft-scriptable-installer-script-nsis-execution-221f15de</loc>
    <lastmod>2026-09-01T09:00:05.754Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-php-code-injection-in-url-via-craftcms-cve-2025-32432-exploitation-via-8a163c14</loc>
    <lastmod>2026-09-01T09:00:05.754Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-houken-sysinitd-rootkit-kernel-module-load-via-insmod-via-process-crea-9f8e7d6c</loc>
    <lastmod>2026-09-01T06:00:05.098Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-kimsuky-remote-hta-execution-via-url-shortener-via-process-creation-3c9d1e46</loc>
    <lastmod>2026-09-01T05:00:06.701Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-queries-to-public-ethereum-rpc-endpoints-for-etherhiding-payload-re-5f3b8a24</loc>
    <lastmod>2026-09-01T05:00:06.701Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-kimsuky-scheduled-task-persistence-executing-vbe-via-wscript-via-pr-9d2a3f18</loc>
    <lastmod>2026-09-01T05:00:06.701Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-sload-ramnit-loader-execution-via-powershell-running-a-masqueraded--7c4e9a12</loc>
    <lastmod>2026-09-01T05:00:06.701Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-browser-master-key-decryption-artifacts-written-by-katz-stealer-via-fi-a6f7bd42</loc>
    <lastmod>2026-09-01T04:00:06.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/renamed-dll-sideloading-of-totpguard-via-renamed-setup-binary-in-nimbus-manticor-9438a891</loc>
    <lastmod>2026-09-01T04:00:06.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-matanbuchus-loader-dll-sideloading-via-notepad-genericupdater-loading--87f8f321</loc>
    <lastmod>2026-09-01T04:00:06.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-certificate-services-outbound-ldap-or-smb-connection-via-certighost-2d7c3778</loc>
    <lastmod>2026-09-01T03:00:05.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-spawned-by-sharepoint-worker-process-after-toolshell-exploitation-via-29f3e651</loc>
    <lastmod>2026-09-01T03:00:05.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/nailaoloader-dll-sideloading-via-usysdiag-exe-loading-sensapi-dll-via-image-load-a9bf12b8</loc>
    <lastmod>2026-09-01T02:00:04.765Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/clickfix-netsupport-rat-staging-via-password-protected-7-zip-extraction-via-proc-54f468f5</loc>
    <lastmod>2026-09-01T01:00:04.555Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-iis-worker-spawning-encoded-powershell-after-sharepoint-toolshell-via-ea84cf8e</loc>
    <lastmod>2026-09-01T01:00:04.555Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/terrastealerv2-data-staging-in-bay0nsqizx-package-directory-via-file-event-f347de67</loc>
    <lastmod>2026-09-01T00:00:05.395Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-xworm-persistence-via-minute-interval-scheduled-task-named-xclient-via-75aed5ce</loc>
    <lastmod>2026-08-31T23:00:04.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/apt28-scheduled-task-named-onedrivehealth-via-process-creation-69125a35</loc>
    <lastmod>2026-08-31T23:00:04.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wdigest-authentication-enabled-registry-via-registry-set-248faf11</loc>
    <lastmod>2026-08-31T22:00:04.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/reddelta-plugx-dll-sideloading-via-legitimate-utilities-loading-planted-dlls-via-fec8922a</loc>
    <lastmod>2026-08-31T22:00:04.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/clickfix-paste-jacking-execution-of-mshta-retrieving-remote-payload-via-process--c2815319</loc>
    <lastmod>2026-08-31T22:00:04.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rdp-shadow-session-configuration-enabled-registry-via-registry-event-633699e5</loc>
    <lastmod>2026-08-31T21:00:04.665Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ifm-creation-detected-from-commandline-installation-from-media-via-process-creat-2d1e7d8c</loc>
    <lastmod>2026-08-31T21:00:04.665Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lateral-movement-by-mounting-a-network-share-net-use-command-via-secu-d2c581de</loc>
    <lastmod>2026-08-31T20:00:04.638Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-impacket-dcomexec-privilege-abuse-via-mmc-via-security-94f4dba1</loc>
    <lastmod>2026-08-31T19:00:04.984Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-encoded-powershell-payload-deployed-via-process-execution-via-process-a3cd986e</loc>
    <lastmod>2026-08-31T18:00:05.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-native-pktmon-sniffer-abuse-via-process-creation-8293d229</loc>
    <lastmod>2026-08-31T18:00:05.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/openssh-server-listening-on-socket-via-openssh-2cea7cec</loc>
    <lastmod>2026-08-31T18:00:05.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bits-payload-downloaded-via-powershell-via-powershell-b59e89aa</loc>
    <lastmod>2026-08-31T17:00:05.941Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wmi-spwaning-powershell-process-wmimplant-via-process-creation-12f7ac06</loc>
    <lastmod>2026-08-31T16:00:04.814Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-encoded-powershell-payload-deployed-powershell-via-powershell-56f9caad</loc>
    <lastmod>2026-08-31T16:00:04.814Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scheduled-task-created-and-deleted-fastly-atexec-py-via-security-b69bc6b9</loc>
    <lastmod>2026-08-31T16:00:04.814Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharphound-host-enumeration-over-kerberos-via-security-32889c69</loc>
    <lastmod>2026-08-31T14:00:06.019Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-event-log-cleared-using-diagnostics-via-powershell-via-powershell-b764b19f</loc>
    <lastmod>2026-08-31T13:00:05.892Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dot-dns-over-tls-activation-command-via-process-creation-9d1db8a7</loc>
    <lastmod>2026-08-31T10:00:04.925Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-system-time-changed-via-security-304fc197</loc>
    <lastmod>2026-08-31T10:00:04.925Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-success-login-attempt-on-a-windows-openssh-server-via-security-dd881b09</loc>
    <lastmod>2026-08-31T09:00:07.070Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/spn-enumeration-previous-to-kerberoasting-attack-native-commands-via-process-cre-fca5b9d4</loc>
    <lastmod>2026-08-31T08:00:06.066Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modification-of-a-sensitive-group-policy-gpo-via-security-fdeb9d7a</loc>
    <lastmod>2026-08-31T07:00:04.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-edge-abuse-for-payload-download-via-console-via-process-creation-0cbe7905</loc>
    <lastmod>2026-08-31T07:00:04.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-certutil-payload-obfuscation-command-via-process-creation-607fb4de</loc>
    <lastmod>2026-08-31T07:00:04.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-user-account-created-by-a-computer-account-via-security-3ca8130d</loc>
    <lastmod>2026-08-31T07:00:04.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-netsh-helper-dll-abuse-process-via-process-creation-074c3769</loc>
    <lastmod>2026-08-31T06:00:05.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wmi-registration-powershell-via-powershell-f71ed791</loc>
    <lastmod>2026-08-31T06:00:05.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sql-server-sqlcmd-utility-abuse-for-privilege-escalation-via-process-c-34dd97fe</loc>
    <lastmod>2026-08-31T06:00:05.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-user-application-credentials-dump-via-network-share-donpapi-lazagne-vi-1fde6368</loc>
    <lastmod>2026-08-31T05:00:05.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ntfs-hard-link-creation-via-process-creation-9a686fb6</loc>
    <lastmod>2026-08-31T05:00:05.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-security-package-ssp-added-reg-via-command-via-process-creation-cc070636</loc>
    <lastmod>2026-08-31T05:00:05.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-defender-critical-security-components-disabled-powershell-vi-c42e95e7</loc>
    <lastmod>2026-08-31T04:00:05.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rubeus-kerberos-constrained-delegation-abuse-s4u2proxy-via-security-45160f93</loc>
    <lastmod>2026-08-31T04:00:05.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/renamed-procdump-tool-used-for-dumping-lsass-process-via-process-creation-cf3b91c2</loc>
    <lastmod>2026-08-31T03:00:05.146Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-impacket-smbexec-service-creation-registry-via-registry-event-222c9b85</loc>
    <lastmod>2026-08-31T03:00:05.146Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-user-creation-via-commandline-via-process-creation-2161cf83</loc>
    <lastmod>2026-08-31T01:00:04.783Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-network-share-discovery-and-or-connection-via-commandline-via-process--243595e3</loc>
    <lastmod>2026-08-31T01:00:04.783Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rdp-tunneling-via-rdp-94017a2a</loc>
    <lastmod>2026-08-31T01:00:04.783Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-permissions-hijacked-for-privileges-abuse-reg-via-powershell-v-b7d1c0ca</loc>
    <lastmod>2026-08-31T00:00:04.750Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-native-backup-deletion-via-process-creation-dbe88752</loc>
    <lastmod>2026-08-31T00:00:04.750Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-credentials-protected-by-dpapi-dump-via-network-share-via-security-41d15a40</loc>
    <lastmod>2026-08-30T23:00:04.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-stickey-key-ifeo-registry-changed-reg-via-sysmon-via-registry-event-85c99db2</loc>
    <lastmod>2026-08-30T23:00:04.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mimispool-printer-driver-installation-printnightmare-vulnerability-cve-707a05ff</loc>
    <lastmod>2026-08-30T22:00:04.552Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-kerberos-tgs-ticket-request-related-to-a-potential-golden-ticket-via-s-41017a00</loc>
    <lastmod>2026-08-30T22:00:04.552Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/synkloader-python-stager-execution-from-appdata-via-pythonw-via-process-creation-4390bc77</loc>
    <lastmod>2026-08-30T21:00:04.456Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-command-injection-via-syncappvpublishingserver-vbs-lolbin-via-process--172edd87</loc>
    <lastmod>2026-08-30T21:00:04.456Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/forticlient-binary-executed-from-localappdata-compliance-directory-via-process-c-21bf1267</loc>
    <lastmod>2026-08-30T21:00:04.456Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/operator-bloopers-cobalt-strike-modules-507249b7</loc>
    <lastmod>2026-08-30T20:00:04.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cobalt-strike-loader-c2-traffic-via-forged-msie-yie9-user-agent-via-p-bdd27455</loc>
    <lastmod>2026-08-30T20:00:04.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scheduled-task-forcenetbirdrestart-for-remote-access-persistence-via-p-09315edf</loc>
    <lastmod>2026-08-30T19:00:04.207Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/tinyloader-usb-propagation-via-double-extension-executables-via-file-event-2ce7c0a8</loc>
    <lastmod>2026-08-30T18:00:04.963Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/eset-security-service-disabling-via-sc-exe-via-process-creation-93494221</loc>
    <lastmod>2026-08-30T18:00:04.963Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/toneshell-backdoor-persistence-via-dokanctl-scheduled-task-via-process-creation-2f8c1d64</loc>
    <lastmod>2026-08-30T17:00:05.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-utilities-rurat-host-deployment-via-fake-crypto-wallet-install-44bd1f26</loc>
    <lastmod>2026-08-30T17:00:05.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-edge-update-masquerade-executed-from-appdata-via-process-creation-a7ade1fe</loc>
    <lastmod>2026-08-30T17:00:05.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hardware-inventory-discovery-via-wmic-device-class-queries-via-proces-44935fc6</loc>
    <lastmod>2026-08-30T17:00:05.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-ssload-phantomloader-dll-execution-via-regsvr32-silent-load-from-ap-c5a71f28</loc>
    <lastmod>2026-08-30T16:00:06.758Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/hamsaupdate-linux-payload-download-via-wget-piped-to-bash-via-process-creation-8c3f0d72</loc>
    <lastmod>2026-08-30T16:00:06.758Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-pngplug-dll-sideloading-of-libcef-into-down-exe-host-binary-via-ima-6f2b9d47</loc>
    <lastmod>2026-08-30T15:00:06.334Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/imeex-framework-dll-execution-via-rundll32-loading-imaadp-via-process-creation-c3a70d68</loc>
    <lastmod>2026-08-30T15:00:06.334Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/system-time-lookup-9bd28cfc</loc>
    <lastmod>2026-08-30T14:00:04.271Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-kimsuky-alphaseed-payload-execution-via-regsvr32-loading-edge-dat-via--e47bbff4</loc>
    <lastmod>2026-08-30T12:00:04.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dragonforce-ransomware-volume-shadow-copy-deletion-via-wmic-shadowcopy-where-del-45854f6d</loc>
    <lastmod>2026-08-30T11:00:04.372Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/renamed-mimikatz-credential-theft-command-indicators-via-process-creation-7f861457</loc>
    <lastmod>2026-08-30T10:00:04.426Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gatedoor-command-and-control-via-gateway-rest-endpoints-via-proxy-d2e8405d</loc>
    <lastmod>2026-08-30T10:00:04.426Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-executable-written-to-startup-folder-by-winrar-via-cve-2025-8088-path-t-5d7a2f19</loc>
    <lastmod>2026-08-30T09:00:05.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-local-account-creation-and-privileged-group-addition-via-net-exe-via--1bd6334b</loc>
    <lastmod>2026-08-30T09:00:05.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-accessibility-feature-backdoor-via-image-file-execution-options-debugg-9dded3d9</loc>
    <lastmod>2026-08-30T09:00:05.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-alexantr-file-manager-webshell-access-after-craftcms-compromise-via-we-5b8f1cd5</loc>
    <lastmod>2026-08-30T07:00:05.577Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-version-dll-proxy-sideloading-from-user-appdata-directory-via-image-l-5270976d</loc>
    <lastmod>2026-08-30T07:00:05.577Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/silentmare-updater-execution-from-user-appdata-directory-via-process-creation-7c4e9a2f</loc>
    <lastmod>2026-08-30T07:00:05.577Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rclone-smb-share-exfiltration-889bc648</loc>
    <lastmod>2026-08-30T06:00:05.407Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/splashtop-network-53d94914</loc>
    <lastmod>2026-08-30T06:00:05.407Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/javascript-execution-using-msdos-8-3-file-notation-81cfbbae</loc>
    <lastmod>2026-08-30T05:00:05.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/flawedgrace-spawning-threat-injection-target-295e71e5</loc>
    <lastmod>2026-08-30T05:00:05.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/hiding-local-user-accounts-59e3a079</loc>
    <lastmod>2026-08-30T05:00:05.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/custom-cobalt-strike-command-execution-782de568</loc>
    <lastmod>2026-08-30T05:00:05.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-khmer-shadow-scheduled-task-vmwarenamespace-creation-via-process-crea-42520591</loc>
    <lastmod>2026-08-30T04:00:05.125Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sparkrat-scheduled-task-taskhandler-running-as-system-from-c-drivers-via-process-3f3a5623</loc>
    <lastmod>2026-08-30T03:00:04.226Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/filefix-browser-spawning-script-interpreter-child-process-via-process-creation-11e75acd</loc>
    <lastmod>2026-08-30T02:00:04.825Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/untrusted-makop-ransomware-vulnerable-driver-hlpdrv-drop-for-edr-kill-via-file-e-8896bae1</loc>
    <lastmod>2026-08-30T01:00:04.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/inc-ransomware-ransom-note-inc-readme-written-to-disk-via-file-event-c10e27fb</loc>
    <lastmod>2026-08-30T01:00:04.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/purehvnc-process-hollowing-into-regasm-spawned-by-powershell-via-process-creatio-d8a4e888</loc>
    <lastmod>2026-08-29T23:00:04.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-browser-launched-with-remote-debugging-port-for-cookie-theft-via-proces-bcc7042d</loc>
    <lastmod>2026-08-29T23:00:04.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shadow-vector-persistence-via-schtasks-onlogon-highest-from-appdata-v-5d269534</loc>
    <lastmod>2026-08-29T23:00:04.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/patchcord-beacon-c2-tasking-via-api-jsp-clientid-poll-via-proxy-bc491417</loc>
    <lastmod>2026-08-29T23:00:04.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-ramnit-process-injection-target-spawned-by-wmiprvse-in-driban-fraud-op-b2d9f4a6</loc>
    <lastmod>2026-08-29T22:00:04.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-sideloading-via-nthandlecallback-loading-log-dll-for-winos-rat-vi-8b2d0e19</loc>
    <lastmod>2026-08-29T22:00:04.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dbatloader-dll-sideloading-via-easinvoker-exe-loading-netutils-dll-via-5c0a2e78</loc>
    <lastmod>2026-08-29T22:00:04.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-timestomping-of-php-webshell-in-ivanti-csa-webroot-via-touch-via-proc-2b4d6f8a</loc>
    <lastmod>2026-08-29T21:00:04.353Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-jsp-webshell-deployment-in-ivanti-epmm-tomcat-via-file-event-c4bb2c02</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-etherrat-ssh-authorized-keys-backdoor-injection-via-shell-via-process--29272441</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-devman-ransomware-encrypted-file-and-note-artifacts-4f1a4e0c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-teampcp-systemd-user-unit-dropper-via-sysmon-py-persistence-via-file-e-72950215</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dot-dns-over-tls-activation-powershell-via-powershell-842e329e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-teampcp-durabletask-payload-python3-managed-pyz-from-tmp-via-process-c-0f93ca60</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-load-from-public-directory-by-svchost-via-image-load-207cda83</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-amsi-bypass-via-amsiinitfailed-field-manipulation-in-powershell-via-ps-7821acf5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-firewall-block-rule-added-via-netsh-advfirewall-d4d55631</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ctfmon-masqueraded-binary-execution-via-process-creation-7e6d5c4b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-asa-webvpn-login-scanning-with-spoofed-chrome-user-agent-cae665ff</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-volume-shadow-copy-deletion-via-vssadmin-the-dfir-report-85b25c07</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-flax-typhoon-system-utility-masquerade-outside-system32-via-renamed-v-1d64f2ed</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dllhost-exe-spawned-with-clsid-and-anomalous-parent-via-process-creat-0160f5f9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ms-settings-delegateexecute-uac-bypass-registry-change-2f9c6a3e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-kb-document-masqueraded-executable-spawned-by-script-interpreter-via-r-90763342</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-aspnet-compiler-exe-injection-host-spawned-by-powershell-via-process-c-5d59bcb1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-subsystem-for-linux-wsl-package-turned-on-native-via-setup-b7d0f454</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-akira-ransomware-encrypted-file-extension-via-file-event-6d9e2f14</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-contagious-interview-disk-enumeration-via-node-spawning-wmic-a3bb46c1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-regsvr32-executing-dll-from-windows-temp-eb29bd72</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-memory-read-from-proc-mem-for-secret-extraction-db721391</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-exchange-server-impersonation-via-privexchange-relay-attack-via-sec-c2eaee6d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-to-cloud-and-database-credential-files-via-process-3e72e2f1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-inline-node-exe-command-executing-network-and-process-spawning-code-5b46c079</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/silentmare-loader-c2-beacon-via-custom-gatewayclient-user-agent-via-proxy-3f2b1c04</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-shell-execution-via-smb-admin-share-via-security-4c394f9c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-duser-dll-sideloading-by-credwiz-via-image-load-0a02bd7c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-denied-rdp-login-with-valid-credentials-via-security-b7dddbe6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-bitlocker-abuse-for-ransomware-via-powershell-via-ps-script-6f1f9175</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wingup-updater-sideloading-libcurl-via-gup-exe-via-image-load-1c5a9e83</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-masqueraded-windows-update-python-script-execution-2a70c4bc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gogrpc-screen-capture-log-file-creation-via-file-event-34a9e7c1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-defender-exclusion-added-via-add-mppreference-during-medusa-intrusion--7ac37d9e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-c2-beacon-with-fixed-authorization-uri-parameter-via-proxy-a3e6f238</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-storm-2561-fake-pulse-vpn-persistence-via-runonce-key-via-registry-se-767998fe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-defender-tamper-via-registry-modification-8340a696</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-weaxor-ransomware-encryption-artifacts-on-disk-via-file-event-bad8e9cb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dotnet-utility-spawned-by-script-host-for-hollowing-via-process-creat-fca1359f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-exclusion-for-windows-dell-folder-8ce3635a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rdp-session-hijacking-via-tscon-command-line-6167218a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-curl-download-from-c2-captcha-path-via-process-creation-b4e2d3c5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-group-discovery-powershell-via-powershell-249168f4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-history-logging-disabled-via-psreadline-via-process-creati-802902f8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-impacket-smbexec-service-registration-native-via-security-012c916d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-oauth-application-granted-full-mailbox-and-ews-permissions-via-m365-33b54081</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-powershell-profile-script-for-persistence-c58b1a70</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-react-server-components-exploitation-via-next-action-header-1ce9f769</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ppl-abuse-via-clipup-protected-process-launch-6b75f755</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-host-exe-in-windows-directory-running-as-service-014ad928</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-command-execution-spawned-by-apache-tomcat-68170cb5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-super-ssrf-via-jira-server-nativemobile-batch-cve-2022-26135-aaf0b939</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-in-memory-payload-execution-via-powershell-downloadstring-via-process--5c7e9f1a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-php-stream-wrapper-in-query-string-cli-argument-0fdd33a2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-zone-export-via-dnscmd-for-reconnaissance-3851a96f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-sideloading-via-renamed-fixmapi-swom-exe-loading-mapistub-dll-via-d3b1c7e2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-scanning-tool-execution-75143eff</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/untrusted-disabling-of-macos-system-integrity-protection-via-process-creation-1edd83fd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-user-account-control-bypass-via-auto-elevating-binary-hijack-via-proce-36028c5b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-service-account-token-generation-via-kubectl-7bda5e8b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-agent-exe-from-winsyncdefender-appdata-directory-via-pro-53e484a0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-powershell-downloading-payload-via-clickfix-via-process-creati-9eab80fe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-double-extension-docx-executable-execution-via-process-creation-30eb4cbd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-side-loading-of-vcomp100-via-converter-exe-b2c022c3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-remcos-rat-keylog-store-created-under-programdata-rema-via-file-event-3389f55c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dll-side-loading-of-nvsmartmax-via-nvsmart-host-process-f2ce103d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-defender-default-action-changed-to-allow-any-threat-command--c853595b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dns-hosts-file-accessed-via-network-share-via-security-6c7bd2ad</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-akira-ransomware-execution-via-encryption-command-line-parameters-83daf91d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-disabling-via-dc-exe-defender-control-by-elpaco-ranso-ea286b07</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-startup-pth-file-creation-for-interpreter-persistence-69476435</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-configuration-enumerated-powershell-via-powershell-f8cbc1f2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mock-trusted-directory-with-trailing-space-via-process-creation-9d3a7f21</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-script-execution-via-wget-or-curl-piped-to-shell-via-process-c-81ca6313</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-compute-disk-iam-policy-modification-granting-owner-role-via-gcp-audi-ca39748e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-powershell-encoded-iex-execution-b1bf2498</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-deadlock-ransomware-encrypted-file-extension-creation-via-file-event-6f1eaa3a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-disabling-of-macos-automatic-software-updates-via-defaults-7e05ec50</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ssh-reverse-tunnel-via-renamed-plink-utility-on-triofox-host-e2362b45</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-astaroth-spambot-browser-profile-staging-directory-via-file-event-4c8e1b73</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-spawned-by-oracle-weblogic-identity-manager-process-via-process-e8d2a6b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-coffeeloader-armoury-dll-dropped-to-user-writable-path-via-file-event-e2861f43</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-exfiltration-to-webhook-site-via-dns-query-e2121ddd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-crontab-removal-via-command-line-via-process-creation-74164415</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-deadbolt-ransomware-note-and-encrypted-file-artifacts-97a39c61</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cryptomining-beacon-to-c3pool-mining-domain-bc8a7359</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-script-execution-with-unrestricted-execution-policy-c973b372</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-vice-society-directory-crawling-script-for-data-exfiltration-via-ps-sc-fd769d85</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dragonforce-ransomware-file-association-registration-for-encrypted-extension-via-e13af18a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-reflective-shellcode-loader-via-dynamic-api-delegates-via-ps-script-edc424f8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-bash-dev-tcp-reverse-shell-via-shell-via-process-creation-4f517e08</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-script-download-and-execution-via-iwr-piped-to-iex-24d64f39</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/httpspy-payload-registration-via-regsvr32-of-non-dll-file-via-process-creation-1b6e9d34</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dragonforce-ransomware-encrypted-file-extension-via-file-event-b9d27506</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-side-loading-of-wbemcomn-from-non-system-path-6eacd613</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-esxi-virtual-machine-termination-and-snapshot-removal-fa0bcdc4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-veeam-credential-theft-via-powershell-via-ps-script-1e5c8a93</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-base64-decoded-payload-piped-to-a-shell-via-process-creation-5eb73025</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fog-ransomware-file-artifacts-via-file-event-4a2d9c17</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/swimsnake-driver-execution-persistence-via-session-manager-platformexecute-via-r-2a8c6d31</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/firewood-backdoor-persistence-files-in-hidden-kde-root-directory-via-file-event-3b7e0d51</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-for-efimer-controller-via-process-creation-93fc6a15</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-immutability-manipulation-via-chattr-3b289921</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-firewall-disable-via-netsh-d76bcf98</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-certutil-payload-download-command-via-process-creation-147cafc1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-icedid-c2-communication-via-http-parameters-via-proxy-6722da25</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-hardware-identifier-reconnaissance-via-ioreg-via-process-creati-71d41a8f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-openssh-reverse-tunnel-establishment-via-ssh-exe-3f7cf9f4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-transferloader-temporary-file-creation-in-windows-temp-via-file-event-1e4f8a26</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-softether-vpn-hamcore-config-written-to-programdata-via-file-event-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-transferloader-configuration-storage-in-phone-config-registry-key-via-3f9a1c72</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-oilrig-solar-and-mango-c2-uri-pattern-via-proxy-via-proxy-4bf1af7f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-discovery-command-spawned-by-java-process-290584c8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-stuffing-blocked-by-conditional-access-in-microsoft-365-9d396e9b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-via-pcalua-launching-rundll32-control-rundll-9d0e1f2a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-log4shell-jndi-exploitation-attempt-in-web-request-uptycs-4f54ac83</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invoke-webrequest-piped-to-invoke-expression-via-fakebat-l-f84cd1b3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-ssh-loopback-connection-for-tcc-bypass-95cf990e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lazarus-signbt-dll-side-loading-via-pchealthcheck-host-via-image-load-22d9cdc0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-side-loading-from-non-standard-winsystem-directory-4acc1dde</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/clickfix-pastejacking-via-script-interpreter-command-in-run-dialog-mru-via-regis-70cc42ee</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browsercore-execution-from-anomalous-parent-for-prt-cookie-via-proces-01ae1a4d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-sideloading-via-wsprint-and-bugsplatrc64-by-uat-9244-7e3a2e6c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/openssh-server-firewall-configuration-on-windows-firewall-via-firewall-as-6424f8c2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-stickey-key-called-cmd-via-command-execution-via-process-creation-1f3d5f27</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sip-or-trust-provider-registration-via-registry-set-e7e7150a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-brickstorm-backdoor-execution-via-masqueraded-binary-path-c1e0d8a5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-caret-obfuscated-command-execution-via-process-creation-1fb49a20</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-keenadu-android-backdoor-c2-registration-and-task-polling-uris-9c66c567</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-tool-execution-from-inetpub-web-root-directory-32ca1499</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-office-365-email-rule-breach-on-behalf-via-office365-86d57009</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-regsvcs-lolbin-loading-ransomware-dll-from-unc-path-59216bb4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-subnet-enumeration-via-adfind-subnets-query-via-proc-c96a9e9f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-executing-dll-start-export-with-control-flags-e3643114</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-reverse-shell-spawned-by-web-server-user-via-process-creation-ef844bc3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dero-cryptojacking-dropper-script-execution-4bdeb3f9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-netsupport-rat-execution-from-public-folder-via-process-creation-94d614e8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-rule-added-using-powershell-or-cmd-via-firewall-as-c10303f9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-rule-masquerading-as-cloudexperiencehost-via-netsh-1e6b3a80</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-konni-registry-run-key-launching-wscript-javascript-from-programdat-4b7e1c92</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gam-oauth-token-enumeration-via-process-creation-84ffe16b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-local-account-creation-via-dscl-via-process-creation-b08fd6c4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-xe-group-reflective-loader-via-powershell-spawned-by-iis-worker-proce-f3d80a17</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-xmrig-cryptominer-execution-with-nicehash-pool-arguments-ecaa4f30</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sticky-key-sethc-command-for-replacement-by-cmd-via-process-creation-5a74846c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lynx-ransomware-encrypted-file-extension-creation-via-file-event-d4a5e234</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winrm-vbs-lolbas-script-execution-for-code-proxying-a2de5a75</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-sideloading-via-fake-apowerrec-exe-loading-lastbld2base-dll-via-w-d9b7c3e8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sitecore-experience-platform-pre-auth-rce-via-typeconfusedelegate-gadge-c8de4e7b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-to-disk-then-execute-via-process-creation-9c7935e3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mstsc-launch-of-rdp-file-from-user-download-or-temp-path-via-process--67d9e326</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/krbrelayup-service-installation-native-via-system-a8c93044</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-applescript-payload-execution-via-osascript-macos-d93a8640</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iam-administratoraccess-policy-attachment-via-cloudtrail-via-cloudtra-c0a8b4d9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-darkvnc-vncdll64-dll-hidden-vnc-module-load-a6574264</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-installation-masquerading-as-winupd-87c9a6ae</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-nspx30-dll-side-loading-of-comx3-via-rsstub-via-image-load-380db434</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sneaky-2fa-phishing-kit-license-check-via-api-key-endpoint-via-proxy-4854a579</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-payload-execution-from-systemd-private-temporary-directory-on-linux-cf7b1f3f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-software-discovery-via-powershell-securitycenter2-antivirusp-86ff6423</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-credential-hive-copy-from-volume-shadow-copy-66bf2635</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-curl-to-shell-dropper-from-paste-site-via-command-line-91236129</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pan-os-exploit-user-agent-for-cve-2024-0012-1d295e20</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/nitrogenloader-sideloading-via-renamed-setup-binary-loading-python312-dll-via-im-50c8fe8b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-smb-dll-lateral-movement-8fe1524e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-or-uv-execution-spawned-by-ai-cli-assistant-72ff2e0c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regsvcs-reflective-net-load-from-fake-update-chain-fdda4e53</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hellonet-ssh-reverse-tunnel-via-frontpage-exe-via-process-creation-a56266e9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-credential-harvesting-via-lazagne-via-process-creation-78f9de5a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-applescript-execution-spawning-a-shell-via-osascript-fc703831</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-administrator-policy-attachment-via-cloudtrail-via-aws-1d93c9b2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shadow-copy-and-backup-deletion-for-ransomware-recovery-inhibition-3655df82</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-execution-of-remote-hta-payload-2e7c0a91</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-startup-folder-redirection-via-user-shell-folders-by-muddywater-via-r-4655b2b0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-octo-tempest-credential-theft-tooling-via-process-creation-86f2e8b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-cuckoo-stealer-launchagent-masquerading-as-homebrew-updater-via-fil-c3e2fe95</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-litterdrifter-vbscript-execution-via-wscript-trash-dll-5daa261f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-remote-package-installation-over-http-ef72f35b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-notepad-outbound-network-connection-after-early-bird-injection-f3e71c4f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-rule-masquerading-as-windows-update-via-process-creation-b6006180</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/leakystealer-persistence-via-edgeupdatecore-run-key-masquerade-via-registry-set-2960f7bb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-encoded-powershell-with-hidden-window-via-process-creation-c7f30488</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-spawning-hidden-command-script-via-process-creation-9ee5b272</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-download-from-bullethost-cloud-staging-server-0e4bb257</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-encoded-powershell-host-reconnaissance-via-get-computerinfo-via-ps-sc-3c7f1a9b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-itg05-headlace-staging-via-mocky-and-mockbin-services-via-proxy-6a1e9d38</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-renamed-curl-binary-execution-via-original-filename-mismatch-1a4a5720</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-traffic-capture-abuse-via-process-creation-83199771</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certutil-urlcache-remote-payload-download-via-process-creation-af0dcc22</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-onlogon-scheduled-task-pointing-to-programdata-executable-beedece9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sparkrat-service-creation-with-binpath-in-c-drivers-directory-via-process-creati-16a74827</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-executed-from-non-system-path-via-process-creation-9bf614c1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lamehug-staging-directory-and-info-file-creation-on-windows-d0e2f1a3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-xworm-injection-target-regasm-spawned-from-user-appdata-via-process-cr-ac7c130d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-group-policy-file-system-path-redirection-via-directory-service-chang-d068af9d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-hidden-bypass-execution-from-programdata-via-command-line-ac3f7e26</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-defender-security-components-disabled-powershell-via-powers-49b47d00</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-delphi-runtime-dll-side-loading-by-ahnenblatt-host-process-2aee576e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-userland-rootkit-persistence-via-ld-so-preload-on-linux-60951cce</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-server-connection-attempt-using-a-disabled-account-via-applicatio-cbd7e0db</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-meshcentral-remote-command-execution-via-meshctrl-via-process-creatio-b3efc699</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wsus-service-spawning-command-shell-via-remote-code-execution-b2a0d780</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msimg32-dll-hijack-in-appdata-templates-1cd21fe4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-c2-download-embedding-host-reconnaissance-in-url-a2bc2bc4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-aes-decryption-and-reflective-method-invocation-in-solarma-104ebc83</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chafer-backdoor-registry-configuration-under-microsoft-drm-key-1096385d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-zharkbot-execution-via-explert-masquerade-in-temp-via-process-creation-77e1044f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-inhibit-system-recovery-via-shadow-copy-deletion-and-boot-configuratio-3e87bb3f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-directory-junction-creation-via-mklink-for-masquerading-94356926</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-scheduled-task-creation-running-as-system-f3b48b15</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-npm-install-hook-executing-setup-script-via-node-1c14bf08</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-sso-account-role-enumeration-via-listaccountroles-via-cloudtrail-b6b2bda3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scheduled-task-masquerading-as-windows-update-by-screening-serpens-via-e1028970</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-shell-folders-startup-path-modification-via-registry-set-b32091dc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/chcp-codepage-locale-lookup-dfbdd206</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-side-loading-via-printui-exe-outside-system32-3e4542a2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-self-deletion-via-ping-loopback-and-del-via-process-creation-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-backdoored-liblzma-xz-utils-library-file-via-file-event-fbc73353</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-payload-execution-from-private-temp-directory-via-process-creation-48510619</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pikabot-command-and-control-connection-on-non-standard-ports-via-netw-8d8d3b91</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-creation-to-execute-tscon-for-rdp-session-hijacking-fe2071a2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wordpress-webshell-session-manager-php-in-mu-plugins-4258bc7d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/renamed-autohotkey-binary-141c8cd8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-connection-to-invisibleferret-c2-ports-1224-and-1245-8eadbd47</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-clearing-of-windows-event-logs-via-process-creation-126287da</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-nimbus-manticore-agent-polling-endpoints-over-http-via-proxy-48c7645e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-colorcpl-exe-spawned-for-process-injection-via-lua-loader-via-process-a8e6f2b7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-ec2-runinstances-of-large-compute-optimized-instance-for-cryptomi-786d89c5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-execution-of-timestamp-named-dll-2cf0445c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-file-copy-via-esentutl-volume-shadow-access-via-process-creation-af1ad2bf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msc-file-with-double-extension-via-file-event-92605143</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shai-hulud-worm-stager-execution-from-temp-via-process-creation-b23b33f3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-host-recon-via-convertfrom-csv-and-convertto-json-c806d665</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-risepro-stealer-password-dump-file-in-temp-via-file-event-b8e3d0a1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tsvipsrv-dll-loaded-from-non-system-path-via-dreamloaders-via-image-l-4d5b6e7f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rmm-daisy-chain-action1-spawning-screenconnect-via-process-creation-2a6d0c81</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-logging-disabled-via-appcmd-48fa7284</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-salesforce-query-history-deletion-anti-forensics-b3c6f0ed</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ses-account-sending-enablement-and-identity-verification-via-cloudtra-994cf05f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-loading-dll-from-localappdata-with-short-export-via-process--7e0b3a91</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deletion-of-system-logs-under-var-log-on-linux-appliance-05ec469c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-type-command-piping-encoded-log-to-renamed-git-binary-via-process-cre-792104e2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-masquerading-as-googleupdate-from-wrong-path-via-registry-set-0391af52</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-http-post-to-local-ai-malware-exfil-endpoint-via-proxy-a8a8d1fa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-remote-download-from-bunny-cdn-host-1a0cfe1b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-interpreter-spawned-by-launchd-from-application-bundle-51da2444</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lateral-movement-detection-based-on-special-groups-feature-via-securi-46fe25d9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-prt-scan-campaign-credential-harvesting-via-proc-environ-scan-via-pro-44b19c01</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ifeo-debugger-hijack-of-vds-exe-by-fishmonger-e8b57620</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-stately-taurus-visual-studio-code-tunnel-abuse-via-vscode-cli-via-pro-69e944c6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-kagent-rat-delivery-via-huggingface-space-download-via-process-creatio-e6350c3e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ngrok-rdp-tunnel-exposure-via-tcp-3389-602a78be</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-tcp-session-hijacking-via-rshijack-1bef8b11</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-vulnerable-driver-hwrwdrv-loaded-for-byovd-1a70bc27</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hdutil-loader-execution-with-nouac-arguments-via-process-creation-c9ea73f7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-perfwatson2-execution-from-local-appdata-3b9ee6f3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-event-log-clearing-via-wevtutil-during-ransomware-activity-06ca0b75</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scheduled-task-masquerading-as-auto-update-via-schtasks-via-process-cr-e100e3a1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-brutforce-on-windows-openssh-server-with-valid-users-via-security-8443951a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-koske-dns-configuration-locking-via-chattr-via-process-creation-5ae3c5fb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-word-spawning-rundll32-loading-dll-from-roaming-word-folder-803a0d08</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wp2shell-batch-endpoint-exploitation-via-webserver-b053f83c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-dll-persistence-under-masquerading-service-names-17385439</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invoke-webrequest-download-of-executable-payload-7bb9df3c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kernel-service-creation-for-byovd-driver-loading-qilin-18ddee74</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-plugx-run-key-persistence-via-avastsvcpcp-path-59e84d09</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cactus-ransomware-ransom-note-creation-via-file-event-6662a77b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-disabling-of-huntress-updater-via-systemctl-stop-bbf5a875</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-masquerading-as-microsoftedgeupdate-with-minute-interv-4d16285d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-stolen-aws-credential-validation-via-sts-getcalleridentity-25c4df72</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-launching-svczhost-masquerading-binary-via-schtasks-12a82666</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ateraagent-malicious-installations-fb0f2d48</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-svchost-masquerading-binary-scvhost-executed-from-common-files-8ed0c5d1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-local-account-creation-on-linux-via-process-creation-3c80b0ba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-creation-for-apt41-loader-via-sc-create-via-process-creation-eaa653b1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-exchange-or-sharepoint-worker-process-spawning-command-shell-from-web--ead24bee</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-creation-with-auto-start-via-process-creation-8ffc1a86</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-minimized-command-shell-launching-decoy-pdf-via-process-creation-df50b7cf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-bloodalchemy-dll-side-loading-via-brdifxapi-executable-03197393</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitlocker-feature-configuration-reg-via-command-via-process-creation-c5e46dd7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-osascript-execution-of-encoded-applescript-on-macos-via-process-creat-1d029ff0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-upload-via-curl-multipart-form-819e2bdd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-bring-your-own-vulnerable-driver-load-for-edr-killing-7907d484</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regasm-or-regsvcs-spawned-by-script-host-via-process-creation-0ede56f7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-exposed-ollama-api-service-connection-63c6bdd9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-masquerading-as-edge-update-running-as-system-via-scht-83a12272</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-query-for-trycloudflare-tunnel-abused-for-malware-delivery-via-dn-b0a19283</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-copyfail-root-exploitation-via-python-spawning-suid-shell-via-process-c-00c2018d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-security-spoofing-via-pin-executable-writing-output-txt-via-p-4e8c1b60</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-typosquatted-apple-user-agent-beaconing-from-ivanti-implant-via-proxy-6b2aadfe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-autorun-persistence-masquerading-as-vmware-nat-service-8a6b9f5d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bootkitty-rootkit-component-drop-under-opt-via-file-system-415d9f02</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-exfiltration-to-webhook-site-following-wsus-exploitation-b7b98f23</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scheduled-task-deploying-dynowiper-payload-via-process-creation-f863186b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/valleyrat-dll-sideloading-via-douyin-loading-non-standard-dll-via-image-load-804f72f1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-for-hijackloader-persistence-via-process-crea-819fa2b3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-prompt-phishing-via-osascript-via-process-creation-d0eca288</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-antsword-webshell-access-on-ivanti-epmm-403-jsp-c803f85a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-stopping-of-security-or-backup-services-before-impact-via-process-crea-f34227fc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scmbanker-clickfix-payload-fetch-via-curl-piped-to-cmd-8bd620c5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-badiis-service-persistence-masquerading-as-system-services-00b9d11f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-panamorfi-ddos-jar-execution-via-java-via-process-creation-943ff99e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-regsvr32-scriptlet-execution-via-scrobj-dll-6b4c2082</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-esx-admins-domain-group-creation-via-process-creation-cf36cc2a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-host-spawning-powershell-via-blindeagle-chain-f32fed64</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-base64-download-cradle-via-frombase64string-and-invoke-expression-via-750f21b7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-loading-dll-from-user-writable-path-via-process-creation-1e8d42cc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chrome-remote-debugging-port-for-browser-session-theft-33e29e8d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winlogon-autoadminlogon-credential-registration-923b589e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-andariel-keylogger-output-archive-staged-in-temp-via-file-event-74c36545</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-enumeration-via-ad-explorer-snapshot-process-creatio-9741c23c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-secretdump-password-dumping-via-smb-admin-share-via-security-5127d628</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-systemd-service-masquerade-via-systemctl-reenable-of-rsyslogd-via-p-3a7d9c14</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-base64-decoding-via-certutil-69028fd4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wezrat-command-and-control-http-uri-pattern-674a715f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-process-dump-by-a-non-system-account-via-security-b23eb84a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsb-steganography-image-decoding-via-powershell-via-ps-script-6d2c8a15</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-inline-policy-granting-full-s3-access-79ecc84f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-arkanix-stealer-c2-communication-via-custom-user-agent-b8969b87</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-script-execution-via-curl-piped-to-bash-with-nohup-on-macos-vi-c439b9c0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-payload-assembly-via-mz-header-prepend-and-copy-concatenation-via-proc-6c8e0a2c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mini-shai-hulud-tanstack-c2-git-tanstack-and-getsession-via-dns-query-c9fdc973</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vbscript-execution-from-programdata-microsoft-subfolder-8c03b195</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-exchange-group-membership-change-to-perform-dcsync-attack-via-security-86cdb70e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-execution-of-webdav-hosted-dll-via-entry-export-via-process--a1f4c8e2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-secret-enumeration-via-kubectl-2da54439</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-tamper-protection-disabled-via-registry-by-nova-rans-5a7b9c02</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobalt-strike-malleable-c2-uri-beacon-via-proxy-8e77e33e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-attrib-hiding-of-stealer-artifacts-via-process-creation-be41358f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitdefender-binary-sideloading-log-dll-loader-d3f5a7c9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-cli-enumeration-of-roles-and-logic-apps-7f60baea</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-account-set-with-password-not-required-weakness-introduction-via-secu-b0a3c008</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-double-base64-decoded-payload-piped-to-shell-in-ci-reviewdog-supply-c-d4a6fbe5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unattended-anydesk-silent-install-with-auto-start-7ce4a723</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-java-process-spawning-reconnaissance-commands-via-cleo-mft-via-proces-3c7a9e18</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-tpwinprn-dll-loaded-via-renamed-rundll32-by-diplomatic-specter-f507301b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-host-spawning-powershell-or-cmd-via-gootloader-c93ee432</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-to-moveit-transfer-internal-machine2-endpoint-00551302</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-persistence-masquerading-as-microsoftupdate-via-axios-npm-com-a293e725</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-extended-rights-backdoor-obfuscation-via-localizationdisplayid-attrib-8b780c0c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sednit-guardrailed-loader-dll-loaded-outside-system32-15b348cf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sql-server-spawning-command-interpreter-via-mallox-ransomware-ac02d751</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-exclusion-path-addition-via-process-creation-c6184723</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-object-access-to-dpapi-machine-keys-and-system-protect-directories-vi-fc6569dc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-console-window-hiding-via-showwindow-c4ed08f6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/apt28-notdoor-outlook-macro-security-bypass-via-registry-set-672565cd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-access-code-validation-beacon-to-malware-delivery-c2-via-proxy-df165d9b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-event-log-clearing-via-get-winevent-clearlog-qilin-8ced902a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-reflective-assembly-load-in-powershell-via-ps-script-3c0afbed</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invoking-remote-hta-via-environment-variable-masquerading--c9fce03a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regsvr32-squiblydoo-remote-scriptlet-execution-via-command-line-via-p-47533e7f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-n8n-campaign-datto-rmm-relay-contact-via-centrastage-net-4013a0f2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ssh-daemon-spawning-shell-via-xz-backdoor-via-process-creation-d37fc042</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-jsp-webshell-written-to-sap-netweaver-servlet-directory-11cd36ff</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-web-shell-child-process-spawned-by-sap-java-process-via-process-creati-4695c4de</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-alternate-data-stream-creation-by-muddywater-via-file-event-5b261b9a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-winlogon-automatic-logon-persistence-via-registry-autoadminlogon-via-p-fe6d5b9c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pythonlauncher-scheduled-task-creation-via-powershell-script-edb1acfe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cloudflared-tunnel-established-with-token-cd090c7c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-download-to-appdata-temp-directory-via-process-creation-2d4f6a8c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-node-js-spawning-powershell-archive-download-to-temp-67af7800</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-payload-download-via-invoke-webrequest-to-status-php-ce49ec55</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-javaw-exe-network-connection-to-pastebin-by-d3f-ck-loader-via-network-46847dd6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-silver-fox-run-key-persistence-via-appclient-via-registry-set-18db27da</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-apt29-certutil-decode-of-disguised-text-file-to-archive-via-process-cr-e4a3b10d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pxa-stealer-payload-decoding-via-certutil-via-process-creation-aa5ffe0c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-masqueraded-rundll32-with-mismatched-original-filename-via-process-cr-224745fd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-parallax-rat-keylogger-output-file-creation-via-file-system-via-file--ac37f05b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-home-directory-modification-via-dscl-process-creation-9133605d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-recovery-environment-tampering-via-bcdedit-74fce13b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sql-server-database-auditing-deactivated-via-application-6ce11171</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-autoit3-script-execution-from-user-directory-via-process-creation-c205f242</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kerberoasting-via-setspn-service-principal-query-9b1d3f5a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/janaware-ransomware-ransom-note-onemli-not-written-to-disk-via-file-event-26b711d8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mini-shai-hulud-gh-token-monitor-persistence-service-via-file-event-f46c23d6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-temporary-dfae-command-script-by-careto-603bcfdc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lnk-launch-of-webdav-batch-via-trycloudflare-tunnel-89521094</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rundll32-loading-dat-payload-via-afunix-export-1c8f5d2b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmic-execution-from-anomalous-parent-process-via-process-creation-078cf2a6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-process-injection-into-attrib-via-mispadu-autoit-loader-via-process-cre-9a5c2f7d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-teamtnt-silentbob-cryptominer-setup-script-execution-via-process-creat-2fa82eb8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-perfctl-hidden-ipc-directory-creation-in-tmp-via-file-event-a161fce3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-reconnaissance-commands-spawned-by-samsung-magicinfo-server-9b13f33c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deadglyph-rundll32-dll-execution-by-ordinal-via-process-creation-729e6a65</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lmadmin-license-manager-dll-sideload-from-public-path-via-image-load-d37f83a5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-launchagent-masquerading-as-coreaudiod-via-file-event-1ecd9c22</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-memory-dump-via-dllhost-with-comsvcs-minidump-arguments-via-proc-873f931a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-computerdefaults-auto-elevated-binary-via-process-crea-df3a3b74</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certutil-encode-or-decode-for-payload-obfuscation-via-process-creatio-908c8f81</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-unc4841-ssh-backdoor-persistence-via-non-standard-port-and-allowusers--0991ffe8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-novaservice-binary-executing-from-public-user-directory-via-process-c-47271110</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-darkgate-hvnc-credential-stash-via-cmdkey-52529a08</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntds-extraction-via-netexec-via-process-creation-2516630c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-fortios-authentication-bypass-via-local-access-token-on-websocket-cli-e-3a9e7c14</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kernel-module-load-via-insmod-on-linux-via-process-creation-23169bf0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-go-http-client-user-agent-via-proxy-19c504ce</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-voidlink-rootkit-dropper-artifacts-via-filesystem-via-file-event-3be95b52</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msxsl-execution-with-text-script-dropper-2cb0e557</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mirage-kitten-c2-communication-via-keyboard-walk-uris-via-proxy-10260a29</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-c2looper-shell-output-artifact-file-creation-via-file-event-1c8a5d37</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vbscript-launcher-execution-via-wscript-for-mining-operation-via-proc-ecd3a4f2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-plink-ssh-tunnel-used-for-data-exfiltration-fb8ddacf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmic-remote-process-creation-installing-msi-via-command-line-996932eb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-member-added-to-an-exchange-administration-group-high-risk-via-se-830ab7f4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-medium-risk-active-directory-group-membership-change-via-security-e3fe378c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-to-webhook-site-via-command-line-via-process-creati-104c09fe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/falsefont-backdoor-persistence-via-registry-run-key-pointing-to-user-directory-b-a4267764</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-extexport-dll-side-loading-execution-fa0f3937</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-persistence-via-installutil-with-masqueraded-service-name-495794c5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-stickey-key-ifeo-reg-via-command-via-process-creation-70829477</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-federated-console-login-from-programmatic-credentials-06b6590a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ngrok-tunnel-using-svchost-masqueraded-config-b62ff313</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-uac-bypass-via-dllhost-icmluautil-elevated-com-interface-in-valleyrat--8e142087</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gcp-service-account-key-creation-for-persistence-via-gcp-audit-red-ca-baeb550d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-denogate-run-key-persistence-launching-headless-deno-backdoor-77df15c4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-web-browser-spawning-command-or-script-interpreter-52b49fe9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gatekeeper-quarantine-database-query-via-sqlite3-c8ba4bc8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-exchange-inbox-rule-hiding-workday-payroll-notifications-via-payroll-p-8dac389c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-device-registration-following-oauth-token-theft-132e4ea4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ebs-snapshot-shared-with-external-account-via-cloudtrail-b7e16203</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-vmware-workspace-one-access-authentication-bypass-via-embedded-auth-bro-93c25183</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-stealth-soldier-c2-user-agent-via-proxy-0d305678</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rogue-wordpress-rest-route-morning-v1-via-webserver-08667f8d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-user-browser-credentials-dump-via-network-share-donpapi-lazagne-via-se-1cca1141</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-local-credential-validation-via-dscl-authonly-9c214358</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-autohotkey-script-execution-from-programdata-via-process-creation-1e39b673</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unattended-rmm-installer-execution-via-msiexec-4b58a6ea</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-com-based-script-execution-and-http-retrieval-via-ps-scrip-92605143</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-via-tftp-client-7900b584</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-archive-staged-in-web-accessible-directory-via-tar-dbca5855</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-content-wiping-via-fsutil-setzerodata-via-process-creation-dac5d126</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-via-rclone-to-cloud-storage-via-process-creation-mi-3a918f1a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-started-from-windows-help-directory-via-process-creation-d234aab2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-executing-javascript-from-public-directory-via-process-3a9c1e75</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cron-job-downloading-and-executing-payload-via-globalprotect-exploita-297c0187</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-java-runtime-execution-from-localappdata-staging-folder-8f7e6d5c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-active-directory-database-dump-via-ntdsutil-ifm-via-process-creation-6068450b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cloud-instance-metadata-credential-access-via-command-line-tool-on-lin-62ad4a55</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitlocker-feature-installation-via-servermanagercmd-or-powershell-via-process-cr-77e3a803</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-pam-module-pam-unix-modification-via-file-event-a7dac8e6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-reverse-shell-via-socat-5c9fc9e0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-running-dll-from-programdata-e07daa0f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-postgresql-copy-from-program-command-execution-via-managed-cloud-datab-9e2087e3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-venomrat-offline-keylog-file-creation-via-file-event-a7dac8e6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-forfiles-proxy-execution-launching-powershell-and-mshta-in-peaklight-c-436abd25</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-shim-database-registration-via-registry-set-ac88602f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-process-execution-from-an-smb-admin-share-via-process-creation-68d5763c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lummac2-stealer-c2-endpoint-beacon-via-proxy-0990a5e3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-volt-typhoon-port-proxy-configuration-via-netsh-via-process-creation-280238dc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/hamsaupdate-handala-loader-payload-assembly-via-copy-binary-concatenation-to-pif-5a1d7c39</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shadowpad-dll-sideloading-via-imecmnt-exe-via-image-load-26abb682</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powerfun-reverse-shell-script-via-script-block-via-ps-script-3cb61615</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-credential-dumping-via-mimikatz-sekurlsa-and-lsadump-commands-vi-0fa1caee</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-file-inclusion-path-traversal-targeting-centrestack-web-config-0e98b981</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vietcredcare-stealer-persistence-via-startup-folder-drop-2432be3e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-edge-headless-download-execution-via-process-creation-7e0a4c93</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ms-sql-ole-automation-abuse-via-wscript-shell-919cf416</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-scheduled-task-masquerading-as-windows-defender-via-typosquatted-na-32cdca2d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rdp-discovery-performed-on-multiple-hosts-via-rdp-ed944fbc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-spawned-by-iis-worker-process-via-owassrf-exchange-exploita-b99b366b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/onenote-spawning-script-interpreter-for-asyncrat-delivery-via-process-creation-b5d1522d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-obfuscated-powershell-spawned-by-explorer-via-run-dialog-06e60cba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-defender-real-time-protection-disabled-6dfbdb4a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ransomware-extension-class-registration-for-elpaco-team-by-elpaco-rans-014f240d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-atlassian-confluence-cve-2023-22518-setup-restore-exploitation-via-webs-8db1228c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-phishing-url-with-unrendered-template-placeholder-via-proxy-b589f220</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-solarwinds-web-help-desk-java-process-spawning-command-shell-via-proc-935016f5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tomcat-manager-war-deployment-via-http-put-by-unc6201-71233868</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-clickfix-execution-chain-spawning-mshta-via-pcalua-on-etherrat-infecti-37100b2c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-with-reversed-http-string-via-process-creation-eb7468c2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shadowpad-dll-sideloading-via-tosbtkbd-by-knife-framework-84a3a06c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bruteforce-via-password-reset-via-security-fa28e245</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-oversized-numeric-x-forwarded-for-header-targeting-ivanti-connect-sec-e5a1c983</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-download-to-public-user-directory-054c731f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-exploitation-of-confluence-setup-restore-endpoint-b1b64825</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-edge-unpacked-extension-load-via-unc6692-edgecution-4dfac28b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-spawned-by-iis-worker-w3wp-0b31e9ec</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-shim-database-installation-via-sdbinst-38ecb720</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fsutil-symlink-evaluation-enablement-via-process-creation-66870562</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regasm-msbuild-or-autoit-accessing-browser-credential-stores-3908dcaf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shadow-copy-deletion-via-vssadmin-via-process-creation-be6df15b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortios-websocket-cli-authentication-bypass-via-node-js-exploit-tooling-via-webs-ebc8927e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fl-studio-executable-side-loading-flengine-dll-from-non-standard-path-c605d836</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobalt-strike-post-exploitation-named-pipe-48e6a84f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-script-download-piped-to-shell-via-8220-gang-hadooken-f8af8d91</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-logging-disable-via-netsh-via-process-creation-c5938476</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-konni-powershell-loader-reading-script-from-programdata-via-invoke-exp-7c2f4a90</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mailbox-forwarding-rule-creation-via-exchange-071e3c68</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-gtfobins-shell-breakout-via-apt-command-c958e7c3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xz-utils-backdoor-kill-switch-environment-string-via-process-creation-e60d3339</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-event-log-clearing-via-wevtutil-on-ec2-host-f0465abb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-axios-npm-compromise-windows-payload-artifacts-wt-exe-and-6202033-via--86833d01</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-api-exposure-via-kubectl-proxy-600efb7b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-exclusion-of-system32-via-registry-via-registry-set-38aef4c3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-print-spooler-privilege-escalation-via-printer-added-cve-2020-1048-via-df024f80</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-warmcookie-dll-execution-from-rtlupd-path-via-rundll32-a3192744</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-workday-payment-election-change-via-compromised-account-via-workday-b0cbef17</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-sideloading-of-brmod104-dll-by-stately-taurus-via-image-load-1cc2c770</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sesameop-netapi64-artifact-files-written-to-windows-temp-via-file-even-c1669655</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fontdrvhost-execution-with-config-argument-00a9a402</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-persistence-masquerading-as-teamviewer-qilin-239917d0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-script-execution-via-curl-piped-to-shell-78113eea</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-fake-homebrew-installer-execution-via-curl-to-typosquatted-domain-via--852223cb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/reported-bindcloak-encrypted-payload-file-event-9179a5b3</loc>
    <lastmod>2026-07-30T07:13:59.270Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-systemd-service-masquerading-as-sysmon-via-file-event-6bff5441</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-download-history-query-via-sqlite3-db7b4a65</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-encoded-powershell-execution-following-sharepoint-exploitation-via-ps-9f85e1ac</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sesameop-netapi64-loader-dll-load-via-masqueraded-netapi-module-via-im-d3d66a41</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-apt-c-60-spyglace-masqueraded-artifact-files-via-process-creation-a97b4759</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dcom-lateral-movement-via-mmc20-via-powershell-20fe3c78</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mshta-exe-spawning-bitsadmin-via-clickfix-phantom-meet-57afbea6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-execution-of-remote-payload-from-explorer-via-clickfix-lure-via-103e4f2c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-application-execution-via-process-creation-f8f63418</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lockbit-rundll32-execution-with-gdll-export-and-pass-argument-517f98f8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-anonymous-access-performed-to-multiple-targets-via-security-9b4b17fb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-run-key-persistence-with-xcschemer-value-b3284f8e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/asyncrat-c2-check-in-via-structured-verify-query-parameters-via-proxy-2827d23e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-edr-termination-via-rundll32-loading-polers-dll-targeting-fortinet-pro-d7b5c1e6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-network-file-share-created-via-security-60c30261</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/craftcms-yii-object-injection-via-generate-transform-endpoint-via-webserver-f789e389</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-renaming-of-system-wget-and-curl-binaries-via-process-creation-fa050dcb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-azure-wireserver-access-impersonating-walinuxagent-via-process-creatio-1b66b99b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lazarus-queue-bat-persistence-dropped-in-startup-folder-56bcea63</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-via-certutil-urlcache-huntress-cac030b6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-svchost-masquerading-executed-outside-system-directory-faecb5f3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-self-deletion-via-fsutil-setzerodata-a6325f66</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-entra-id-device-code-flow-authentication-d6e8f7a9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sharepoint-toolshell-exploitation-via-toolpane-edit-post-with-spoofed-r-d6025741</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-from-var-tmp-masquerading-as-apt-via-gridtide-6642260b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-coldriver-runmru-history-clearing-via-reg-delete-via-process-creation-2b6e9a14</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-credential-added-to-an-azure-ad-application-via-auditlogs-31beb976</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ssti-remote-command-execution-from-web-application-process-61f5c9c4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-script-execution-from-winrar-extraction-directory-via-cve-2023-38831-9f51afdc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-botnet-payload-drop-to-hidden-xdiag-temp-path-77a66507</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-calc-exe-execution-from-non-system-directory-via-dll-side-loading-376a19f9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-atlassian-confluence-cve-2023-22515-setup-recovery-exploitation-via-web-66363437</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-desktop-enablement-via-registry-40ec199e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-proxy-execution-of-rundll32-control-rundll-via-pcalua-exe-via-process-51ea90e6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-massive-services-deletion-burst-via-process-creation-ad6aaf31</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-command-output-written-to-smb-named-pipe-18bd17bc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mamona-ransomware-note-and-encrypted-file-extension-7d9e2c8a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wordpress-rest-batch-union-sql-injection-attempt-e0c9b482</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-computer-account-password-reset-via-net-user-by-unc1549-9cf670f4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-qilin-edr-killer-byovd-service-installation-via-sc-ed3429e5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-argv0-masquerade-as-kernel-worker-via-gsocket-75c92518</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/apt28-httd-implant-persistence-via-systemd-linux-service-from-boot-directory-via-5a340213</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/autoit-payload-reassembly-via-copy-b-file-concatenation-e7ed4c78</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-web-shell-written-to-a-web-server-root-by-a-server-worker-process-via--1fcc683c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-registry-hive-dump-of-sam-and-system-via-reg-save-via-process-creation-8c6365ad</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regsvr32-execution-from-non-standard-datop-directory-a1f3c7e2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/etherrat-persistence-via-windowshost-run-key-via-registry-set-79de7a2d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-clickfix-stager-piping-curl-output-to-osascript-3abbe8d3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/stealc-persistence-via-lnk-dropped-to-startup-folder-by-non-shell-process-via-fi-4037503d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-history-wipe-via-rundll32-clearmytracksbyprocess-1c7c47d1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-kernel-module-loaded-from-a-user-writable-path-on-linux-via-process-cr-c6fc5c5e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-larva-24009-c2-command-and-exfiltration-uri-patterns-via-proxy-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-antispyware-disable-via-registry-via-registry-set-d8c5450c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-apphostragistreationverifier-creation-by-fishmonger-a8dc550b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-execution-of-javascript-from-appdata-local-temp-via-process-c-9d9b1a7b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-latrodectus-loader-dll-execution-via-rundll32-via-process-creation-8aa7022c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-rundll32-execution-without-a-command-line-via-process-creation-051cd20d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-external-ip-discovery-via-curl-to-ifconfig-me-via-process-creation-6b2d84f1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netsh-port-proxy-configuration-for-covert-tunneling-62dede09</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pan-os-shell-execution-setting-panusername-via-command-injection-via--4c9a7e18</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-launch-with-remote-debugging-port-via-process-creation-bae4dfcb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-silent-anydesk-installation-for-remote-access-by-deadlock-ransomware-7098e341</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-internet-settings-zonemap-modification-enabling-unc-as-intranet-via-r-bb2f0144</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-desktop-window-manager-spawning-shutdown-utility-via-process-creation-04aa065e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-process-injection-target-regasm-launched-without-arguments-via-process--a0c153cd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntds-extraction-via-ntdsutil-ifm-media-creation-558a869f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-local-account-creation-via-net-command-ff1819a0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-hta-execution-disguised-as-media-file-via-mshta-via-process-cre-36b5b210</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-com-handler-hijack-of-msctfmonitor-clsid-via-charmingcypress-97041301</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-volume-shadow-copy-deletion-via-wmi-powershell-via-process-creation-af11d4c5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wscript-executing-temp-file-as-javascript-via-process-creation-1a8c3d67</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-launched-by-explorer-from-archive-path-via-process-creatio-c303bb8e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webserver-iis-module-installed-command-via-process-creation-c0f9bf04</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enabling-of-remote-desktop-via-fdenytsconnections-via-registry-set-5669b0ac</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-account-added-to-domain-admins-group-via-net-command-5eccb4eb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-execution-delay-via-w32tm-stripchart-via-process-creation-d8c046d3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-loading-deepdata-data-dll-with-mod-dat-key-via-brazenbamboo-ea10080b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-silver-fox-scheduled-task-persistence-via-appclient-via-process-creati-7e3c92e2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-assembly-execution-via-regasm-or-regsvcs-from-a-user-path-via-process-7960f0c7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uat-8302-dll-side-loading-via-signed-application-launcher-18cf5d08</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-volume-shadow-copy-deletion-via-vssadmin-by-medusa-ransomware-400e2cac</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-fileless-powershell-registry-payload-execution-via-process-creation-e8900766</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-command-line-obfuscation-constructs-via-process-creation-e0e5f471</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/batch-script-execution-from-recyclers-bin-masquerade-directory-e5b7abc6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/tinyloader-persistence-via-txtfile-shell-open-command-hijack-via-registry-set-96fadc69</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/operator-bring-your-own-tools-dee0aaa1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-kerberos-ticket-abuse-via-rubeus-via-process-creation-59179f1f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-large-gpu-instance-launch-via-cloudtrail-via-aws-893aea0b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-pypi-package-installation-from-gleaming-pisces-supply-chain-via-proces-64c49ef4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-powershell-download-and-archive-expansion-feab9ffa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-credentials-dump-via-task-manager-file-via-file-creation-13c46580</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-file-harvesting-of-npm-claude-and-ssh-secrets-603ba9cc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-scheduled-task-creation-via-schtasks-for-lateral-movement-via--c4d02d03</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-regsvr32-registration-of-dynamicwrapperx-via-process-creation-cf7e026c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-masquerading-as-system-process-169f491b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fincounter-dns-tunneling-query-via-dns-query-639684a2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-security-service-tampering-via-wmic-pathname-query-via-process-creatio-7c9e1a3b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-named-mail-for-loader-persistence-84ef7d3b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-selinux-policy-module-loading-to-whitelist-linux-implant-via-process--227f6bf8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-new-member-added-to-a-ocs-lync-skype-for-business-administration-group-5c07f48d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dns-query-to-clickfix-infostealer-c2-domain-d1212e5a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-duke-malware-dlls-written-to-windows-tasks-directory-via-file-event-4f6a8c0e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-referencing-mounted-dmg-volume-via-terminal-macos-660eb4e7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/splashtop-process-20b92a34</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ec2-serial-console-ssh-public-key-push-via-cloudtrail-9981635d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-download-and-silent-msi-install-of-remote-management-software-vi-5a11cc7b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webshell-written-to-citrix-netscaler-vpn-theme-directory-via-file-even-2b8d5f13</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-simps-botnet-infection-marker-file-creation-via-file-event-0bc960c1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-moveit-w3wp-child-process-execution-via-process-creation-41746280</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/default-account-usage-dca5d253</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntds-dit-extraction-via-ntdsutil-ifm-snapshot-via-process-creation-0e058b61</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-viper-c2-installation-via-f8x-one-liner-setup-script-via-process-creat-ee4cbffa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dcrat-payload-masquerading-as-mixed-reality-exe-via-process-creation-f9894468</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sunburst-command-and-control-dns-query-to-avsvmcloud-domain-via-dns-qu-d32dcae8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-action-inf-dropped-alongside-vipnet-update-loader-c9d1a6b3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-sideloading-via-signed-utility-binaries-used-by-storm-2603-892a6574</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-execution-spawned-by-microsoft-word-via-process-creation-4f5e6d7c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mimikatz-credential-dumping-command-line-d8b1d596</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitsadmin-file-transfer-download-via-process-creation-f84078f7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-spawning-wscript-with-silent-flag-via-process-creation-09d7c8ba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-firewall-deactivation-deprecated-command-via-process-creation-3ed42d7d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/qbot-process-creation-from-scheduled-task-regsvr32-regsvr32-exe-s-flag-and-syste-33d9c3f4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/lotuslite-renamed-loader-datatechnology-executed-with-data-argument-via-process--edf26bfd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-policy-export-via-secedit-via-process-creation-16864600</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enabling-of-network-discovery-firewall-rules-via-powershell-1a762978</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-antivirus-product-enumeration-via-wmi-query-via-process-creation-7fff9e21</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pythonw-exe-executing-winresume-pyc-via-confucius-anondoor-backdoor-v-f5d3e9a4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-written-to-windows-fonts-directory-via-file-event-a53eb940</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-security-info-registration-following-aitm-session-theft-via-azure-d869c3d0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sd-wan-compromise-nim-implant-c2-beacon-063e9126</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/httpsnoop-masquerading-as-cyveraconsole-outside-palo-alto-path-687c4598</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-loading-dll-from-appdata-via-dllregisterserver-39174d14</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-host-execution-from-appdata-windowshelper-staging-folder-via-p-3959df05</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-regasm-process-hollowing-spawned-by-powershell-via-process-creation-36bc73fb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-keychain-credential-extraction-via-security-utility-5b02fb75</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-c2-configuration-stored-in-titanplus-registry-key-via-registry-set-9f5e20d6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-php-webshell-file-creation-linked-to-beyondtrust-exploitation-via-fil-a65c20ca</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-of-system-logs-on-linux-via-process-creation-390afda9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-plugx-scheduled-task-named-internetupdatetask-via-process-creation-c04153b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-api-request-from-anonymous-user-2fb66443</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-execution-from-webdav-share-via-powershell-via-process-creatio-5d4c3b2a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-reverse-ssh-tunnel-via-renamed-putty-svchosts-exe-via-process-creation-3e9a7c40</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/self-deletion-via-ping-loopback-delay-and-del-command-6f514360</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wi-fi-credential-harvesting-via-netsh-wlan-show-profile-via-process-c-5c3f1b95</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-stealth-soldier-c2-request-uri-via-proxy-95a4fe19</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-linux-cryptominer-masquerading-as-systemd-logind-via-var-tmp-execution-8c126b61</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-spawned-by-postgresql-server-via-copy-from-program-on-linux-f6a8b7c9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rundll32-execution-of-html-payload-with-dllregisterserver-08bcd090</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-launchagent-or-launchdaemon-load-via-launchctl-e0e0f391</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-screen-capture-via-powershell-graphics-api-via-process-creation-456cddcc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netsh-outbound-network-connection-from-idat-loader-injection-e184eb31</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-voidlink-fileless-execution-via-memfd-via-memory-via-process-creation-3c4b4e61</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-msi-installation-from-remote-webdav-share-via-process-creation-f421e96d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-event-log-clearing-via-dire-wolf-ransomware-via-process-creat-87051697</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dsrm-password-changed-reg-via-powershell-via-powershell-47214110</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-edge-chrome-headless-feature-abuse-for-payload-download-via-process-c-0639e0d9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-data-exfiltration-via-megacmd-1d862980</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-indirect-execution-via-get-command-09b6bb28</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-user-added-to-a-group-via-commandline-via-process-creation-8f8e161f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-payload-retrieval-from-cloudflare-tunnel-via-lolbin-via-process-creat-4e7b1d9c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-snipbot-dll-execution-via-rundll32-from-keystore-directory-via-process-b23b7350</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-phantom-taurus-outlooken-web-shell-file-creation-via-file-event-ac60fccd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-masquerading-as-wininet-cachetask-via-process-creation-6c101e84</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/scheduled-task-creating-per-minute-hidden-powershell-execution-9f67ba5c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-osascript-to-zsh-executing-hidden-payload-via-axios-compromise-b9eadec5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-credential-dumping-via-comsvcs-minidump-via-process-creation-ca849691</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-defender-massive-host-infection-via-windefend-d04e8f9a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ivanti-epmm-cve-2025-4428-exploitation-via-format-parameter-via-webserv-9b1d3f5a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/oceanlotus-apt-c-00-payload-staging-in-fake-nvidia-setup-temp-directory-via-file-9b2c6e40</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-invisibleferret-python-loader-execution-from-hidden-pyp-directory-d824c138</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/adminsdholder-permissions-changed-for-persistence-via-security-cd22e0b0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-remote-package-installation-from-url-via-process-creation-1b02fca6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-peach-sandstorm-password-spray-via-go-http-client-user-agent-via-prox-091f54db</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-snowflake-anomalous-client-application-associated-with-unc5537-via-cl-ba0f2bea</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-clickfix-powershell-downloadfile-loader-with-hidden-window-cbf9e017</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-execution-of-polyglot-pdf-file-spawned-by-cmd-via-process-creat-6c5d4e3f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ssh-over-port-443-with-known-server-and-client-strings-3c5791a2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invisibleferret-c2-endpoints-over-port-1224-via-proxy-34162fe5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-network-route-reconnaissance-via-proc-filesystem-by-uat-7290-0455cb0b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/shadowpad-dll-sideloading-via-logger-exe-loading-logexts-dll-via-image-load-a65e6e63</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-m365-legacy-authentication-via-bav2ropc-client-via-m365-2b8e0c47</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-masqueraded-zemana-driver-written-to-disk-via-updatedrv-via-file-even-9d1f3b5a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-defender-exclusion-added-via-add-mppreference-via-process-c-189930bc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lazarus-rundll32-execution-of-sup-etl-privilege-escalation-loader-via--d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ifm-detected-esent-installation-from-media-via-application-3c49ba2b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-entra-cross-tenant-access-or-external-user-invitation-via-azure-audit-f250b3cb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-user-agent-wp2shell-indicates-wp2shell-poc-activity-a7c4e2f9</loc>
    <lastmod>2026-07-31T12:17:59.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wordpress-wp2shell-webshell-plugin-path-access-webserver-c9e6f412</loc>
    <lastmod>2026-07-31T12:17:57.856Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wordpress-rest-batch-endpoint-wp2shell-exploitation-via-post-with-rest-route-bat-b8d5f301</loc>
    <lastmod>2026-07-31T12:17:56.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-privileged-group-membership-change-via-net-exe-via-process-creation-514a9b51</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-github-repository-creation-with-s1ngularity-exfiltration-name-f480dfc9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/enable-wdigest-using-powershell-bda01c73</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ssh-reverse-tunnel-over-port-443-via-ssh-exe-by-unc1549-eb3d7723</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-download-cradle-via-invoke-webrequest-and-iex-5bad945f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-masquerading-as-edge-update-telemetry-via-process-crea-815f4032</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-crontab-reboot-persistence-to-hidden-sys-cache-binary-via-proce-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-from-winrar-temporary-extraction-path-via-command-line-via--2c69e90c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-plugx-sideload-via-acrobat-dll-e7b3c3b0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-silent-msi-installation-from-appdata-spawned-by-powershell-via-proces-426e4892</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-node-exe-inline-script-execution-via-e-dbe552f1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-applaunch-exe-execution-as-process-hollowing-target-1b712d46</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/driverquery-lookup-94751fb0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-coffeeloader-execution-via-armoury-crate-dll-side-loading-via-process-5d7b1c92</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-metasploit-psexec-named-pipe-command-execution-3a7eb3ff</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wannacry-run-key-persistence-to-tasksche-via-registry-set-72443156</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-created-in-startup-folder-by-winrar-via-cve-2025-8088-3b772bd7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sysaid-on-premise-command-injection-via-api-jsp-javalocation-parameter--a3e6c1b7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-host-spawning-command-interpreter-in-session-0-via-wfp-kernel-49b5dcc8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-esxi-secure-boot-bypass-via-execinstalledonly-disable-032d2fd3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-docker-socket-access-via-curl-unix-socket-d0537281</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-payload-download-and-execution-via-certutil-urlcache-via-process-creat-7f9a1c3e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kerberos-password-account-reset-to-issue-potential-golden-ticket-via--7df5c06e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-keyhunter-worker-systemd-unit-file-creation-cccce80b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-masquerading-as-realtek-audio-service-via-process-crea-d1b9c5e0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-desktop-enablement-via-registry-fdenytsconnections-and-firewal-13b002ee</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-talonite-certutil-lolbin-decode-and-download-abuse-via-process-creati-2a9e8506</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-firewall-via-netsh-via-process-creation-738b96c8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-talonite-flowcloud-renamed-html-help-workshop-binary-via-process-creat-c3ba0653</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-iex-downloadstring-one-liner-e1c5a9d7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mimikatz-lsass-credential-dumping-via-command-line-43ba2f30</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-noodlophile-payload-execution-via-video-file-double-extension-via-p-5ee79e38</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-event-log-clearing-via-wevtutil-cisco-talos-70311d13</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sparkling-pisces-backdoor-c2-uri-pattern-via-proxy-82c17cba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/valleyrat-beacon-sideloading-via-nthandlecallback-loading-log-dll-via-image-load-5826a66f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-defender-service-components-status-disabled-registry-via-sys-6146bc15</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-gachiloader-c2-beacon-via-x-secret-gachifamily-header-d2edd145</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-scheduled-task-masquerading-as-windowsupdate-with-one-minute-interv-e531e891</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-parallax-rat-startup-folder-executable-persistence-via-file-system-vi-6785c401</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-launching-vbscript-from-programdata-via-process-creati-e5b8acd6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-archive-staged-in-web-root-via-tar-on-ivanti-epmm-0253e38d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-psexec-service-installation-via-psexesvc-d2e1ee9d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vbscript-dropped-to-startup-folder-via-file-event-2e6b1c88</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-modification-disabling-restrictedadmin-mode-via-process-crea-4d1b0cfe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-long-term-access-key-creation-for-persistence-via-cloudtrail-via--bbd957ff</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-osascript-muting-system-volume-via-banshee-infostealer-a0ba3a19</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-store-access-for-winscp-and-putty-via-powershell-via-ps-sc-1d3f5a7c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/anydesk-network-b26feb0b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-spawned-from-java-following-web-exploitation-26d161bc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-katz-stealer-command-and-control-via-katz-ontop-user-agent-via-proxy-1e1dd584</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-spawned-by-3cxdesktopapp-via-supply-chain-compromise-4894f1c3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-efimer-persistence-via-run-controller-value-via-registry-set-1ee3bd50</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sts-assumerole-with-exfil-session-name-via-cloudtrail-via-cloudtrail-d1b9c5e0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-execution-from-recycle-bin-directory-f9edf6f7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-veeam-credential-extraction-via-sqlcmd-query-via-process-creation-9c1e3f5a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/purehvnc-rat-execution-via-autoit-interpreter-from-wordgenius-technologies-direc-20b8afa0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-regsvr32-dll-execution-with-custom-install-argument-3d4d30c4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-obfuscated-shell-execution-via-sh-c-bash-redirection-via-process-crea-3a5c7e9b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-event-log-clearing-via-wevtutil-via-process-creation-efe56aa5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cloudflared-tunnel-execution-with-token-0307faf4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-command-and-control-via-discord-or-telegram-bot-api-aa02c9a8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shell-execution-via-foomatic-rip-print-filter-through-cups-exploit-d8bbec30</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-nova-ransomware-note-and-encrypted-file-extension-via-file-event-3f9a2c14</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-defender-behavior-monitoring-disable-via-set-mppreference-93805fe7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mini-shai-hulud-tanstack-destructive-rm-killswitch-via-process-creatio-14cd962d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-recursive-credential-and-wallet-search-written-to-temp-inventory-file-e6de68c4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scheduled-task-masquerading-as-google-updater-via-schtasks-750bc80d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-running-from-fake-chrome-user-profile-directory-9aa3296e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-recovery-disablement-via-bcdedit-9e55a186</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rogue-privileged-account-names-on-cisco-ios-xe-ab67f00f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-node-js-execution-of-test-js-from-vscode-folder-in-lazarus-lure-via-pr-c504fe13</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regsvr32-loading-dll-from-remote-webdav-location-via-strela-stealer-v-dcfa0bed</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-omi-server-spawning-shell-as-root-via-omigod-scx-provider-via-process--2f35056b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lateral-movement-via-invoke-wmiexec-or-invoke-smbexec-via-ps-script-1fb9b5b7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-update-orchestrator-service-reconfiguration-for-privilege-escalation-6d1a68aa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-command-prompt-spawned-by-winlogon-9c3d5e7f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-zone-enumeration-via-dnscmd-5c7e9a1b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-uac-bypass-via-ms-settings-shell-open-command-hijack-via-registry-set-7af7baa6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-base64-decode-piped-to-python-interpreter-5e2f7acb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/openssh-server-firewall-configuration-on-windows-powershell-via-powershell-28e5e389</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-unsigned-libconfigurer64-dylib-side-loading-via-image-load-1f4bc89a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-blackbyte-ransomware-host-marker-via-control-panel-registry-8f1a4b26</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-fortiweb-authentication-bypass-via-path-traversal-to-fwbcgi-via-webserv-d7f2b940</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-exploitation-callback-to-dnslog-service-via-dns-query-87d5bfdb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-event-log-service-disabled-via-sc-exe-soco404-cryptomining-a9358a74</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-macos-launchdaemon-persistence-masquerading-as-finder-helper-6bb15fcf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sharpdpapi-machine-masterkey-extraction-via-process-creation-ceb88fc1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sload-payload-download-via-bitsadmin-lolbin-transfer-via-process-crea-e9b3d7c2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-amsi-bypass-via-powershell-reflection-via-ps-script-e9d827ea</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-teampcp-durabletask-infection-markers-and-rope-state-via-file-event-786d2de1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bunnyloader-keylog-capture-file-in-appdata-temp-via-file-event-dbc86f19</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bad-apples-file-transfer-server-via-tftpd-bf5ffd1e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-chrome-extension-sideload-via-load-extension-from-user-writable-path-v-8c7243f3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/resolverrat-loader-dll-sideloading-via-hpreader-via-image-load-c10d8af3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharepoint-toolshell-exploitation-via-toolpane-aspx-displaymode-edit-via-webserv-2ede3bd3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-network-login-performed-to-multiple-targets-via-security-7ecfb02b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-launchdaemon-load-via-launchctl-d9d59c78</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/data-exfiltration-to-webdav-share-via-curl-upload-5a6b7c8d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-hive0051-gammaload-c2-beacon-via-crafted-user-agent-via-proxy-a4f0d9b1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-download-spawned-by-node-js-during-package-install-89c1774d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ermac-or-hook-android-malware-c2-via-php-endpoint-uri-pattern-461f3684</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-uac-restriction-disabled-via-localaccounttokenfilterpolicy-via-4a1c9e72</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-com-hijack-of-psfactorybuffer-inprocserver32-86f43cb4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntlm-downgrade-attack-reg-via-sysmon-via-registry-set-0d15b4b5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-replacement-of-termsrv-dll-to-enable-concurrent-rdp-via-file-event-345faab8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cicada3301-ransomware-locker-execution-via-command-line-key-via-proces-12af6270</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-warmcookie-scheduled-task-for-rundll32-persistence-via-process-creati-6737ed21</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-audit-policy-disabled-by-command-line-via-security-faed3580</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/netsupport-manager-rat-execution-from-a-user-writable-path-via-process-creation-8c0dd6bf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-active-directory-replication-request-indicating-dcsync-8f46dc4a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-softperfect-network-scanner-execution-for-discovery-944dc931</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-iscsicpl-auto-elevation-in-operation-truechaos-3d550db6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-keychain-credential-theft-via-security-find-generic-password-by-clickl-a787553b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-gpo-permission-abuse-via-sharpgpoabuse-a84fe4d6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-connection-to-adws-port-9389-via-security-5a0c7e93</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobalt-strike-default-named-pipe-creation-via-pipe-created-89c0bfaa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-reversesocks5-tunneling-tool-execution-on-linux-via-process-creation-7a39700e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sharepoint-spinstall0-webshell-dropped-in-layouts-3078b7c1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-run-key-persistence-masquerading-as-microsoft-updater-via-pr-ad30247e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-moustachedbouncer-command-execution-from-smb-edgein-directory-via-cmd-338abbcb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-gcleaner-loader-c2-check-in-via-cpa-ping-php-endpoint-via-proxy-c9c50bad</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/deleting-windows-defender-scheduled-tasks-2a6239f4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-backup-and-shadow-copy-destruction-via-native-utilities-7bf8a156</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-execution-from-winrar-temporary-extraction-directory-b599cdab</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ssh-authorized-keys-modification-following-web-server-compromise-via-p-cb0f7465</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-finger-client-execution-for-command-and-control-2beb6476</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cgroup-release-agent-abuse-for-container-escape-5314482a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sam-registry-hive-dump-to-windows-temp-by-bianlian-c867a36a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-defender-real-time-protection-disabled-via-registry-c356b85c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-veeam-backup-credential-harvesting-via-powershell-via-ps-script-a152ec09</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cryptomining-via-addinprocess-launching-nexa-miner-via-process-creatio-39e72fe3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scheduled-task-creation-named-comboxresettask-44d42de9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-atera-agent-installation-via-msiexec-from-perflogs-directory-fa1fe3fd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-registry-run-key-persistence-to-programdata-batch-file-via-registry-se-25766e76</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-host-executing-vbscript-from-system32-via-command-line-2ee5781a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-run-key-persistence-for-plugx-gdatas-payload-via-registry-se-f8061729</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-saml-identity-provider-creation-893b7b55</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-via-finger-lolbin-aad6b36b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ld-preload-library-injection-via-pumakit-userland-rootkit-7581eae2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sql-server-dedicated-admin-connection-dac-mode-activated-native-via-ap-2aec4a26</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-scheduled-task-via-taskcache-security-descriptor-manipulation-684967be</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bluenoroff-hidden-payload-drop-in-users-shared-via-file-event-ef42bb8b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-recurring-scheduled-task-named-windowshelper-via-schtasks-ce2e8d43</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ghostlocker-watchdog-process-execution-via-process-creation-0ee09c9f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mint-sandstorm-mediapl-dll-loaded-from-media-player-appdata-path-via--2cc7fdc3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/legionloader-dll-sideloading-via-vmware-mkssandbox-loading-fake-libcrypto-via-im-31611223</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-exclusion-added-for-powershell-and-conhost-85efcea2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-creation-command-via-process-creation-b65ed73b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-network-connection-from-windows-dialer-process-095e31cf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-xmrig-cryptominer-connecting-to-supportxmr-pool-jinx-0132-d0acf1eb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/njrat-fileless-keylogger-storage-via-registry-value-via-registry-set-0ce7a0de</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-reverse-shell-and-in-memory-payload-staging-during-ivanti-csa-exploita-c3d5e7f9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-bedrock-guardrail-updated-updateguardrail-api-via-cloudtrail-1c722651</loc>
    <lastmod>2026-07-31T12:27:05.437Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-bedrock-guardrail-deletion-via-cloudtrail-deleteguardrail-api-call-59b70e4d</loc>
    <lastmod>2026-07-31T12:27:03.565Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-spawned-by-headless-conhost-via-process-creation-8b62a34f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ghostpulse-dll-side-loading-of-libcurl-via-vboxsvc-ff0c5fc8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ctfmon-exe-execution-with-command-line-arguments-via-pikabot-injectio-64e3105b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-server-payload-staging-via-bcp-queryout-via-process-creation-1e3f5a7c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-entra-agent-service-principal-sign-in-with-powershell-user-agent-via--b4d887b0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-execution-from-public-user-folder-staging-directory-c20093b5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hidden-logon-scheduled-task-runtimeoptimizeservice-via-tclbanker-98ffcdf1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cloud-atlas-powershell-download-cradle-via-iex-webclient-via-process-c-6b4b628d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lateral-movement-via-impacket-wmiexec-command-pattern-24afeeb1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sonicwall-credential-testing-via-userlogin-endpoint-d6a4f5b7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-entra-id-auth-broker-sign-in-with-node-js-user-agent-via-tycoon-2fa-883a55db</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/plugx-dll-sideloading-via-mcoemcpy-exe-loading-mcutil-dll-via-image-load-eb258a22</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modification-of-rc-local-startup-script-by-knife-framework-d1d8ba8f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-32-bit-powershell-executed-from-syswow64-via-process-creation-e7c4c586</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/renamed-dll-sideloading-via-renamed-greenshot-loading-greenshotplugin-from-appda-4d474918</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-execution-of-binary-from-var-log-directory-via-process-creation-8e2c1a76</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curkeep-backdoor-c2-api-endpoints-via-proxy-398193f6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-masquerading-as-wt-exe-in-programdata-via-axios-npm-comprom-e55353ce</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-spawning-powershell-from-vbs-loader-via-wscript-exe-via-proce-86965a72</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-sideload-from-public-music-directory-235117b7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-disable-via-set-mppreference-29b13fb7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-downloader-spawned-by-batch-script-via-process-creation-e46b0746</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-inline-exec-execution-in-starkveil-chain-2f3c75bd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cryptominer-masquerading-as-kubernetes-pause-container-3236cd28</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-spawned-by-windows-script-host-from-html-smuggling-via-pro-a9b8c7d6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-executable-launched-from-mounted-image-via-shortcut-via-proces-39adcaac</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-launchagent-or-launchdaemon-plist-creation-6f2b7059</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-reflective-assembly-load-invoking-vai-method-via-process-c-da8f137d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kimsuky-js-downloader-staging-in-public-and-templates-paths-via-file--d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-worker-process-spawning-command-shell-via-web-shell-via-process-c-b8c8c5de</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-computer-account-modifying-active-directory-permissions-privexchange-v-34d80694</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-akira-ransomware-encryptor-command-line-flags-e5547251</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modification-of-ssh-authorized-keys-on-sd-wan-appliance-by-uat-8616-428022e4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cron-persistence-installing-a-downloader-via-command-line-f1ce9659</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-inbox-rule-moving-mail-to-junk-for-concealment-via-m365-240ffcbb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/stealc-loader-execution-via-blender-spawning-script-interpreter-via-process-crea-cd121219</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-brutforce-enumeration-with-unexisting-users-kerberos-via-security-d0699f21</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-session-manager-execute-value-modification-for-persistence-via-regist-b1e7d3a2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-icacls-grant-of-full-control-to-everyone-7972c9ca</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-defender-exclusion-for-fake-defenderupdates-folder-via-add-mppreferenc-04bc501c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-bumblebee-loader-msi-download-via-powershell-invoke-webrequest-and--b301e8d4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-self-copied-cmd-script-in-programdata-via-file-event-815f4032</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webserver-iis-module-installed-command-via-process-creation-variant-2-d2574dc9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-targeted-kerberoasting-via-serviceprincipalname-modification-7c2f0b93</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-service-disable-via-sc-utility-via-process-creation-aee308d0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-updtae-backdoor-reverse-shell-http-beacon-via-quad7-operators-09489f3f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wp2shell-user-agent-in-web-requests-via-webserver-918b972a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cloud-security-agent-uninstallation-via-shell-via-process-creation-225aa19d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-runonce-persistence-pointing-to-programdata-payload-5496890b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/netscan-share-enumeration-write-access-check-8a0d153f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-loader-execution-of-skype-ps1-from-public-folder-via-process-creation-9cac82b2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-and-wallet-credential-theft-via-javascript-stealer-241a1c5a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-clickfix-powershell-launching-mshta-with-remote-url-via-process-creati-61be7168</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webserver-iis-module-installed-powershell-via-powershell-e44e7eba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-replication-privileges-accessed-to-perform-dcsync-attack-via-security-29a69c9e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-persistence-in-startup-folder-via-file-event-5b9883ad</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-worker-process-spawning-encoded-powershell-via-gladinet-exploitat-4db0ffb1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cscript-execution-of-javascript-spawned-by-powershell-6f6054bb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/psexec-custom-named-service-binary-752956d6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-plugx-dll-side-loading-via-iviewers-ole-object-viewer-via-image-load-3ae7b4f2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wireless-credential-extraction-via-netsh-wlan-show-profile-in-katz-st-2ac05d6d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-softperfect-network-scanner-execution-via-process-creation-edc652d7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-defender-whole-drive-exclusion-via-powershell-da9b1340</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modification-of-dmsa-managed-account-link-attributes-7bf8c0ad</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cve-2023-23397-outlook-forced-authentication-via-outbound-smb-via-netwo-6379932e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntds-database-access-via-command-line-via-process-creation-37b6eac1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winhlp32-network-connection-indicating-remcosrat-injection-922d20fa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-macos-credential-verification-via-dscl-authonly-f52d2383</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-kimsuky-keylogger-powershell-functions-pokdoc-and-infokey-via-ps-scrip-ce985140</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/redcurl-qwcrypt-ransomware-execution-with-hyper-v-targeting-flags-3e4f5a6b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-event-log-clearing-via-wevtutil-via-process-creation-intel471-ca9c0b95</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-process-creation-via-wmic-node-61a16f72</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-decoy-copy-and-rename-of-pdf-to-executable-via-process-creation-08b20d00</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-apt-c-60-com-hijack-via-spyglace-clsid-inprocserver32-via-registry-set-7e1f6e58</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-lolbin-spawned-by-screenconnect-client-ecaa46d2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-organizations-and-account-discovery-via-aws-via-cloudtrail-b2e5d3f1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-memory-dump-via-procdump-full-dump-flag-05c6dd4b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-payload-staging-in-public-libraries-directory-via-file-event-ae62a720</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-defender-exclusion-for-executables-via-add-mppreference-via-process-cr-4cf2f734</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-event-log-clearing-via-wevtutil-palo-alto-unit-42-ba121458</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-domain-admins-group-enumeration-via-net-exe-via-process-creation-1e34cef3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dpapi-credential-decryption-via-powershell-protecteddata-unprotect-1927ef29</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-fakesg-scheduled-task-vcc-runner2-netsupport-loader-via-process-creati-76ac5a38</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cron-persistence-file-creation-in-system-cron-directories-via-file-ev-adeafd8f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-quarantine-bypass-via-xattr-and-chmod-after-curl-download-d4e854e1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-project-cav3rn-logazure-txt-configuration-drop-via-file-event-b6de6e27</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sharepoint-toolshell-exploitation-request-to-toolpane-via-webserver-e596c04d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hidden-local-account-via-winlogon-specialaccounts-userlist-1c972869</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-security-product-bypass-via-defendnot-loader-0f02e59a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hiddengh0st-guest-account-activation-and-admin-group-addition-via-proc-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-data-staging-via-ditto-to-temp-archive-in-attacker-directory-vi-4a01e528</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-tool-s3-browser-execution-via-process-creation-61705483</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/valleyrat-keylog-output-file-creation-in-programdata-via-file-event-e1d4c98c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-kimsuky-troll-stealer-collected-data-staging-files-with-gte1-extension-0f1ccd4a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-systemsoundsservice2-creation-via-process-creation-46d90500</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xscan-network-vulnerability-scanner-execution-after-citrix-bleed-expl-6599748b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-download-and-script-execution-chain-via-command-line-4d3e6c2a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-image-file-execution-options-debugger-hijack-by-miner-campaign-81c423fd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-node-reverse-shell-spawned-on-fortigate-via-inline-code-5627234f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-server-member-got-new-privileges-added-on-a-database-via-applicat-c91f3e60</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-console-login-without-mfa-datadog-security-labs-db952f40</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-clickfix-powershell-iex-downloadstring-execution-dcae40b6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-center-health-notification-hidden-via-registry-208e18b7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntds-dit-copy-for-domain-credential-theft-via-file-event-fe402ce2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-com-hijack-via-clsid-inprocserver32-registry-modification-via-registry-8811769d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scheduled-task-for-cryptominer-persistence-at-logon-via-process-creati-1f1c81e8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-danabot-updater-scheduled-task-running-rundll32-from-appdata-via-scht-aefc31f4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntospy-network-provider-dll-registration-for-credential-capture-1a392fed</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-voidlink-pinned-ebpf-map-in-bpf-filesystem-via-file-event-9a076717</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-venomrat-scheduled-task-masquerading-as-windows-gaming-preview-via-pro-f6c9b7d5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-check-point-smartconsole-token-redemption-endpoint-access-via-proxy-4ce7fde8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-post-downloading-powershell-payload-to-temp-directory-via-proces-19609ddb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aspx-webshell-written-to-iis-inetsrv-directory-via-file-event-8c67f545</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-in-memory-shellcode-execution-via-memory-allocation-apis-via-ps-scrip-2d7e5b40</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-more-eggs-scriptlet-dll-registration-via-regsvr32-action-install-from--3a02cb04</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sam-and-system-hive-dump-via-reg-save-via-process-creation-641f936a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-disabling-of-linux-security-modules-apparmor-and-selinux-d5637964</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-project-cav3rn-dns-configuration-recovery-via-cloudlanecdn-com-via-dns-4a9c2a94</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-executing-un-vbs-cleanup-script-via-command-line-via-process--f4ba9dec</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ivanti-connect-secure-license-keys-status-command-injection-request-v-bd61ba7c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-unc1549-minibike-dll-side-load-of-secur32-dll-via-filecoauth-via-image-27a46ab6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-spoofed-inbound-email-with-failed-authentication-and-anonymous-intern-4e7f573b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-side-loading-via-dicomportable-spawned-by-itarian-rmmservice-520ea7e8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-via-certutil-urlcache-the-dfir-report-aba87bdc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invoke-webrequest-and-invoke-expression-download-cradle-vi-919fee47</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-side-loading-of-sbambres-dll-by-vipre-binary-via-deedrat-via-image-09172a3b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-notepad-spawned-by-mshta-for-process-injection-123cabaa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-spawned-by-wmiprvse-516f1fd3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/conhost-suspicious-command-execution-21c034f0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-credential-manager-enumeration-via-process-creation-1c78e646</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-apache-camel-exec-header-injection-bae832c5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-abuse-with-backdoored-command-failure-reg-via-command-via-proc-db7584db</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-iptables-drop-of-syslog-forwarding-ports-on-ivanti-connect-secure-via--c198032f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-monsterv2-payload-masquerading-as-windows-health-executable-via-proce-c5b4a392</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-notpetya-payload-execution-via-rundll32-ordinal-export-from-windows-di-7f7cd1c1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deeppost-data-exfiltration-uri-pattern-via-brazenbamboo-07269fe2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-installer-invocation-spawned-via-zoom-opener-helper-via-process-451d1458</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-systemsettingsadminflows-exe-used-to-disable-windows-defender-da92713f</loc>
    <lastmod>2026-07-30T05:10:54.146Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/failed-wmi-nteventlogfile-cleareventlog-attempts-on-windows-event-5858-d4f1a2b3</loc>
    <lastmod>2026-07-31T12:59:25.240Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-anydesk-silent-install-with-unattended-password-kaspersky-securelist-2b9e6c3a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shadowguard-ebpf-rootkit-control-via-magic-kill-signal-via-process-cre-b609d371</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-tbk-dvr-command-injection-exploitation-via-rondodox-via-webserver-a4e2f8b3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-triada-mms-core-jar-backdoor-dropped-in-app-data-5a2d9b6f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-hardware-reconnaissance-via-dmidecode-baseboard-query-f4cf2088</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-quick-assist-spawning-command-interpreter-or-download-tooling-via-pro-9b7d0c97</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-curl-insecure-download-to-appdata-or-temp-015593d0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-defender-exclusion-for-public-controller-path-via-process-creation-e1923159</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ctfmon-masquerade-persistence-via-run-key-via-registry-set-9261e1e7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-execution-from-alternate-data-stream-via-wscript-e07754e1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/legionloader-process-hollowing-via-syswow64-explorer-exe-self-invocation-via-pro-44674ff8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-persistence-pointing-to-temp-or-public-folder-7a9921a1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-of-scrss-or-ekrn-masquerading-scripts-4930b406</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-firewall-deactivation-modern-command-via-process-creation-d5d54df2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-encoded-powershell-command-execution-via-process-creation-e84968f5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-linux-audit-or-system-logging-via-process-creation-75513628</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-voidlink-kernel-module-load-via-insmod-via-process-creation-2e665416</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-sideloading-of-screen-retriever-plugin-via-tclbanker-loader-d55f69ee</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-injection-via-mavinject-injectrunning-2c4e6a8c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-task-manager-access-indicator-for-potential-lsass-dump-via-process-crea-b985538a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cloudflare-tunnel-masquerading-as-conhost-exe-during-medusa-operation-da2629b1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-via-certutil-urlcache-split-d0d66e4e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-winring0-vulnerable-driver-load-6511a9d4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-remote-script-execution-from-github-via-irm-and-iex-via-pr-b3f1a7c2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cloud-sign-in-from-an-anonymizer-or-high-risk-session-via-signinlogs-79107419</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-credential-harvesting-request-via-all-in-1-php-endpoint-via-proxy-7d4c6c9c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/systemnightmare-by-gentilkiwi-new-external-device-added-cve-2021-1675-cve-2021-3-4fe37c53</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-esxi-virtual-machine-termination-and-snapshot-removal-via-esxcli-and-v-32b8b113</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winlogon-loading-keyboard-layout-dll-kbdus1-dll-b4c7e2a9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-searchindexer-outbound-network-connection-after-injection-728ac31c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-edgestepper-iptables-dns-redirection-for-adversary-in-the-middle-2639408a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-coldriver-baitswitch-execution-via-rundll32-verifyme-export-via-proce-c9502e83</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-installed-software-enumeration-via-registry-uninstall-key-query-dbe408be</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xloader-persistence-via-policies-explorer-run-registry-key-via-regist-6f2d8b41</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-masquerading-as-dockerdesktop-d9fe699e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-payload-piped-to-shell-via-wget-on-pan-os-13592059</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-local-account-creation-masquerading-as-krbtgt-via-process-creation-379c2d4c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-search-for-passwords-via-findstr-via-process-creation-f0cf04a6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-rule-added-for-masqueraded-csrss-process-via-netsh-09657064</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-fileless-execution-via-memfd-anonymous-file-on-linux-cloud-workload-vi-d812ff9d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/web-shell-written-to-screenconnect-app-extensions-directory-ec199f18</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-oysterloader-c2-beacon-using-wordpressagent-user-agent-d61df573</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-service-trigger-configuration-via-registry-modification-4f2b9d31</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-persistence-launching-headless-conhost-node-js-on-etherrat-in-c96c036b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/swimsnake-autorecoverdat-dll-execution-via-rundll32-or-regsvr32-via-process-crea-c1e4a7b8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-system-process-name-executing-from-non-system-path-528fe7b1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tycoon-2fa-credential-exfiltration-fields-0718efc2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-webclient-downloadfile-with-execution-policy-bypass-via-pr-cde78f83</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/renamed-nimbus-manticore-stager-execution-with-doit-argument-from-2faguard-direc-5e51410f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-moveit-transfer-sql-injection-via-x-silock-sessvar-header-03d084de</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-machine-like-local-admin-account-creation-ending-with-dollar-sign-v-a0612131</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-entra-sign-in-to-officehome-with-axios-user-agent-2841d820</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-to-public-libraries-folder-via-process-creation-6d8fad84</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-veeam-credential-extraction-via-sqlcmd-via-process-creation-3e6b8d41</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-recursive-icacls-grant-of-full-access-to-everyone-via-process-creatio-51afae7c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mintsloader-stage-two-c2-beacon-via-htr-php-key-and-campaign-parameters-via-prox-226494b1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-cloudtrail-logging-disabled-7c93348c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-exclusion-of-drive-roots-via-add-mppreference-via-pro-e0fa337f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-bitbucket-pre-auth-rce-via-git-archive-spawning-shell-cve-2022-36804-vi-866f234f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shadowguard-rootkit-hidden-artifacts-via-swsecret-files-via-file-even-fad3be4d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-setcap-assigning-cap-sys-admin-for-gameoverlay-privilege-escalation-vi-449b9745</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aimmy-cheat-loader-executing-renamed-luajit-launcher-via-process-crea-b9484662</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-active-directory-database-backup-via-wbadmin-to-loopback-admin-share-v-bd242bbe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-font-file-passed-as-argument-to-script-interpreter-via-lua-loader-via-f7d5e1a6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-impacket-wmiexec-admin-share-output-redirection-e7784ed3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-root-filesystem-remount-as-writable-on-appliance-via-mount-via-proces-547d1c7d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-safeboot-runonce-persistence-for-safe-mode-encryption-by-ra-world-afd48ec6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-salat-stealer-microsoft-defender-disable-via-multiple-set-mppreference-84ad02d5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/smartloader-execution-via-luajit-interpreter-running-obfuscated-text-script-via--89c13baf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-larva-24009-scheduled-task-masquerading-as-google-update-or-intel-dri-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hardcoded-legacy-chrome-user-agent-from-sparkling-pisces-tooling-via--0444bf53</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gh0stgambit-run-key-persistence-for-phone-executable-0728b8e9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-event-log-cleared-native-via-security-system-fa496493</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vidar-second-stage-download-via-structured-index-zip-dropzone-paths-v-7d3d5c5a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-loading-dll-from-user-desktop-c448f1d5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outlook-security-manager-dll-load-for-mail-harvesting-via-image-load-3c9e5b70</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ghostsocks-loader-execution-with-johnpidar-argument-via-process-creati-1d6f83b5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rundll32-loading-dll-from-webdav-ssl-share-5c1e8a40</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-spawned-by-microsoft-office-274de352</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-delegated-permission-grant-to-entra-agent-access-scope-via-azure-audi-96942e60</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-forest-blizzard-gooseegg-batch-launcher-chain-via-process-creation-170b80e9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scmbanker-remote-utilities-rmm-install-via-silent-msiexec-3825925a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sudoers-nopasswd-rule-written-for-passwordless-privilege-escalation-58332242</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-applescript-execution-via-osascript-inline-command-aa4c5c6d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-telepuz-clickfix-stager-via-hidden-powershell-grab-endpoint-cc8e3cdc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-entra-sign-in-interrupt-with-high-aggregated-risk-via-aitm-dns-hijack-c727ce41</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deadlock-ransomware-c2-proxy-request-to-prrq-php-endpoint-via-proxy-86fbcb87</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobalt-strike-c2-beaconing-via-rest-uri-paths-and-legacy-msie-user-age-cf828a45</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-adversary-in-the-middle-proxy-login-via-crafted-url-parameters-c6bf807e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-apt29-dll-side-loading-via-msoev-exe-from-windows-tasks-directory-via--8c0e2a4c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gcp-log-sink-tampering-for-defense-evasion-via-gcp-bb9fae30</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sql-sa-admin-user-enabled-via-application-e652b3d4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-eastwind-named-pipe-creation-698f30d9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-iis-native-module-installation-via-appcmd-isapicachesmodule-via-proces-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ivanti-dropper-hidden-files-in-tmp-during-cve-2025-22457-exploitation-ceb837ad</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-file-upload-to-sap-netweaver-metadata-uploader-endpoint-f1e1d4da</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vulnerable-driver-load-for-byovd-abuse-by-dragonforce-ransomware-via--6b5aba32</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-system-crash-behavior-manipulation-wmimplant-registry-via-registry-eve-9c0cb6c2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-head-mare-credential-dumping-via-xenallpasswordpro-a6cf1f59</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-citrix-netscaler-cve-2023-4966-session-token-disclosure-38f767d7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-iis-worker-process-spawning-command-shell-via-process-creation-1654621d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-kimsuky-onenote-document-spawning-script-interpreter-via-process-creati-d5b608c2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cve-2023-23397-outlook-forced-authentication-via-outbound-ldap-via-netw-53108b40</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-double-extension-pdf-executable-via-process-creation-ea7ae6de</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ctf-framed-vulnerability-scanner-user-agent-via-webserver-4d10a2a5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sugargh0st-persistence-via-ctfmon-masqueraded-run-key-via-registry-se-4d3c2b1a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-execution-via-wmic-node-process-call-create-e3558ca0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gigawiper-execution-counter-under-onedrive-environment-key-8b1c4a90</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-volume-shadow-copy-deletion-via-vssadmin-by-ra-world-e557ff95</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mamba-2fa-aitm-phishing-url-pattern-e63624fd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-restic-cloud-backup-exfiltration-via-renamed-winupdate-binary-via-pro-6f2b9c07</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-uac-bypass-via-ms-settings-shell-open-command-registry-hijack-via-regi-2f7c4b90</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-octo-tempest-domain-and-network-reconnaissance-tooling-via-process-cr-3b9fb3fe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-renamed-git-binary-gcmd-exe-execution-via-process-creation-4ea919f3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hiddengh0st-rootkit-driver-qassist-written-to-system32-via-file-event-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-winlogon-shell-persistence-modification-via-registry-set-817b0b64</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-internet-explorer-helper-process-network-connection-via-network-conne-4585b108</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sumatrapdf-execution-from-user-download-directory-in-operation-dreamjob-via-proc-2d1cead7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-execution-from-chm-help-file-via-process-creation-4d1b0cfe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-single-character-named-batch-script-execution-linked-to-salt-typhoon-fcd4d475</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-chisel-reverse-socks-proxy-execution-via-process-creation-6834aee8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-langflow-exploitation-marker-file-creation-83e51ab4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-from-cups-foomatic-rip-child-process-0d412d78</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-to-telegram-bot-api-senddocument-via-proxy-3d0a4852</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vss-backup-deletion-via-wmi-powershell-via-powershell-6db6571f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-running-as-system-via-schtasks-fb8af02e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntds-database-dump-file-creation-b3558b77</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-teampcp-litellm-pth-startup-hook-and-payload-dropper-via-file-event-791e4301</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-triada-binder-so-planted-in-android-system-framework-4f1c8a5e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-via-certutil-urlcache-elastic-security-labs-15858da6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-interpreter-execution-spawned-by-script-host-via-process-creat-e5d4c3b2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-enabling-of-wdigest-cleartext-credential-caching-via-registry-set-8673792b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-minute-interval-scheduled-task-for-mscheck-backdoor-via-process-creat-a9b84d43</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-with-networkprofile-event-trigger-via-process-creation-3c0afbed</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/castleloader-stager-http-beacon-via-misspelled-googebot-user-agent-via-proxy-ea379e7b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ssrf-probe-for-cloud-instance-metadata-service-a37d0e92</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-credential-dumping-via-xenallpasswordpro-c5c9daf3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/renamed-grandoreiro-dll-sideloading-via-mingwm10-from-user-writable-path-via-ima-316d6773</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-reactivation-of-guest-account-via-net-user-uat-8099-8667a4da</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/idat-loader-delivery-via-compromised-wordpress-wpstream-youtube-min-js-via-proxy-32c091a3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scheduled-task-epolicymanager-by-squidoor-via-process-creation-ee4dbe18</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removable-media-spread-via-my-pictures-executable-via-process-creatio-dbdb32eb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntds-credential-theft-via-volume-shadow-copy-via-process-creation-2f52406e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-persistence-launching-headless-deno-runtime-via-tag-150-0a58df56</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-to-anonymous-file-sharing-services-via-dns-query-32ab2d8f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmd-script-dropped-in-startup-folder-for-persistence-35c11dc7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-blank-grabber-payload-decoding-via-certutil-decode-flag-via-process-76718d43</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-http-beacon-using-rare-myie-user-agent-via-proxy-3bed5f5f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-error-524-decoy-smishing-phishing-endpoint-access-via-proxy-a55d177b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-named-pipe-redsun-created-by-nightmare-eclipse-tooling-e3ed4afe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-real-time-monitoring-disabled-via-powershell-8056d56b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-from-catbox-moe-via-process-creation-6ef0e7bb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-powershell-retrieving-vbscript-from-mcdir-me-by-millenium-rat--77f6cbd9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/renamed-computer-account-renamed-without-a-trailing-cve-2021-42278-42287-via-sec-1defa57d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-fortiweb-authentication-bypass-via-path-traversal-to-fwbcgi-via-webserv-a2b9c4d1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lazarus-dll-side-loading-of-ualapi-dll-via-spoolsv-exe-via-image-load-dae08960</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-written-to-explorer-iconcache-path-f31223cb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msbuild-execution-from-writable-directory-via-process-creation-6c9800fe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-anomalous-openssh-0-3-banner-indicating-zipline-backdoor-via-network-8404f1a3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-modification-of-a-fake-domain-controller-spn-dcshadow-via-security-a116f129</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cherryloader-execution-via-encrypted-stage-arguments-via-process-crea-7e3a1c95</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-imjp14k-dll-side-loading-from-non-system-path-c4e8a13b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lazarus-scoringmathtea-wordpress-c2-url-path-df8d893e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-chisel-tunneling-tool-masquerading-as-microsoft-binary-via-process-cre-3b013681</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-brushworm-persistence-via-scheduled-task-via-process-creation-f95752b2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-persistence-referencing-sharepoint-executable-via-registry-se-ed9f6935</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-renamed-monitoringhost-binary-indicating-dll-side-loading-3d751098</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-noodlophile-persistence-via-run-key-launching-python-through-cmd-via-re-d32d9526</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-web-service-spawning-bash-reverse-shell-on-ivanti-via-exploitation-c77253f7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-software-discovery-via-tasklist-and-findstr-via-process-crea-1022107c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-computer-export-via-csvde-via-process-creation-bb16b77b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-process-enumeration-via-tasklist-and-findstr-028889b2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-f5-icontrol-rest-remote-code-execution-via-util-bash-endpoint-ac7403eb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-event-log-clearing-via-wevtutil-ad2ebd0c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-secret-and-permission-enumeration-via-kubectl-via-process--59c0e203</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-privileged-docker-container-launch-with-host-chroot-ae10a465</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dnscat2-dns-tunneling-c2-traffic-98aa52bb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mssql-server-process-spawning-command-shell-via-xp-cmdshell-71d12fdb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-0ktapus-phishing-kit-credential-post-path-access-a8d44bed</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-credential-dump-via-silentprocessexit-werfault-abuse-ee7f672e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-persistence-via-launchctl-submit-via-process-creation-a49e3be5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winlogon-shell-persistence-via-registry-by-key-group-38762116</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-spectre-ops-staging-in-cullinetprogram-directory-via-file-event-4c118a29</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-command-in-runmru-registry-indicating-clickfix-execution-via-registry-2d3e4f5a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-autorun-registry-key-pointing-to-user-writable-path-via-registry-set-8fbfd40f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hta-download-via-mshta-and-curl-in-process-creation-8ef7e804</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-virtual-machine-detection-via-registry-query-via-process-creation-f4fbced8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-trufflehog-secret-scanner-execution-326d6a9d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-tycoon-2fa-aitm-phishing-websocket-channel-2d5a8883</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-text-file-payload-staging-in-temp-via-file-event-1ae8d9cb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-xred-backdoor-persistence-via-synaptics-run-key-via-registry-set-f65ea916</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mirage-kitten-sspicli-dll-search-order-hijack-via-appvshnotify-exe-vi-1c60e789</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-side-loading-of-msimg32-via-silverlight-configuration-exe-afa26a29</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deletion-of-explorer-runmru-values-33a2ad56</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoftupdate-run-key-persistence-via-axios-compromise-104b739b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-member-added-to-an-exchange-administration-group-medium-risk-via--d58502cf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmstp-execution-with-inf-payload-via-process-creation-40a3cdb7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-from-dev-shm-shared-memory-5cd16c8f</loc>
    <lastmod>2026-07-31T12:40:45.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-malware-delivery-via-discord-cdn-attachment-cfb2d540</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntds-database-dump-via-ntdsutil-in-blacksuit-ransomware-0d0af9fa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-persistence-masquerading-as-onedrive-update-3c9e0a71</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-regsvr32-loading-a-dll-from-a-data-directory-via-process-creation-a062fd99</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bumblebee-c2-uri-pattern-via-proxy-a184e984</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-domain-trust-discovery-via-nltest-via-process-creation-d373dde6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-spawned-by-langflow-python-process-via-process-creation-3c6f9b21</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cryptominer-staging-files-dropped-in-tmp-directory-237c0bc6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xmrig-cryptominer-execution-on-linux-a9b1c0d2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitsadmin-download-to-appdata-temp-via-clickfix-revenge-chain-f8529b92</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-via-certutil-30e3c60a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-boot-configuration-change-to-safeboot-minimal-via-bcdedit-9ca4c1a5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-discovery-via-adfind-483c863e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-uat-8302-hidden-powershell-execution-of-whatpc-ps1-6476d6c9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-adfind-active-directory-reconnaissance-tool-execution-via-process-cre-8c2a5d91</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-notepad-updater-chain-via-gup-exe-spawning-update-exe-via-process-crea-e3b1d1c3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dtlcrashcatch-dll-side-loading-via-onedrive-sync-service-by-spectralvi-26a991f9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-direct-etcd-write-to-kubernetes-registry-via-etcdctl-api-via-process-c-07e6db12</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-kimsuky-registry-run-key-persistence-for-malware-loader-via-registr-4d8f2c53</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-to-windows-appcompat-directory-via-powershell-d5a22f8d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-desktop-enablement-via-netsh-0e119efc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cloud-metadata-credential-ssrf-via-http-via-proxy-e18a82ee</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-nirsoft-credential-recovery-tools-execution-2c8aa00d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-discord-rat-module-download-from-github-via-proxy-b83c6e29</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-query-of-mshta-application-class-in-peaklight-chain-via-ps-cd5ee895</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-cobalt-strike-getsystem-named-pipe-impersonation-pattern-via-proces-272dfcee</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-appdomainmanager-hijack-via-application-config-file-via-file-event-180f609f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pan-os-globalprotect-portal-font-staging-file-creation-a36e9e10</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-etw-bypass-via-psetwlogprovider-patching-via-ps-script-7e9b1d3f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/renamed-execution-of-a-renamed-windows-system-utility-via-process-creation-a848302f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-expensive-ldap-query-reconnaissance-6438d715</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitsadmin-transfer-of-coinminer-archive-via-process-creation-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deno-runtime-execution-of-remote-javascript-payload-via-process-creat-3a5c7e9f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-nssm-service-installation-via-process-creation-36afd088</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-worker-process-spawning-encoded-powershell-via-centrestack-exploi-0fae1849</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-payload-execution-from-programdata-via-pythonw-via-process-cre-02e98cac</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sharepoint-w3wp-spawning-encoded-powershell-toolshell-exploitation-f8247963</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-software-protection-service-masquerade-outside-system32-via-process-cr-6f1199e3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-masquerading-as-memory-diagnostic-running-script-host-d8d8ce16</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-event-log-clearing-via-wevtutil-via-process-creation-the-dfir--000e4db7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-launching-nvidia-geforce-experience-named-binary-d1ddae3b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-polaredge-implant-connect-back-argument-pattern-via-process-creation-6c6b57e1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-execution-from-public-user-media-folders-via-process-creation-7b3e9d10</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-s3-object-encryption-for-ransom-via-sse-c-7c91dd8b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-persistence-executing-node-js-script-via-muddywater-tsundere--f27f2663</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-protected-archive-extraction-of-everything64-dll-by-elpaco-r-d447c68e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-login-data-copied-to-temp-file-via-type-command-a78081bd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-com-object-hijack-pointing-to-a-user-writable-dll-via-registry-set-fb413c58</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-high-frequency-scheduled-task-creation-via-schtasks-1e7a1604</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-unc3944-microsoft-defender-real-time-protection-disable-via-set-mppref-e32d9277</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-native-backup-size-re-configuration-via-process-creation-db3ab88b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/tamperedchef-persistence-via-pdfeditorupdater-run-key-via-registry-set-b1704208</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sharepoint-webshell-file-creation-in-layouts-directory-via-toolshell--d6a4f5e7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-replication-privileges-granted-to-perform-dcsync-attack-via-security-f57d4a12</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-timbrestealer-execution-via-rundll32-iernonce-dll-via-process-creatio-e2d6950f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-anonymous-access-to-kubernetes-api-server-via-audit-log-0bb94966</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-terminal-launching-hidden-powershell-with-execution-bypass-vi-555cd0c4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-netsupport-rat-masquerading-as-systeminfo-exe-5e5ec955</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-search-via-findstr-for-password-strings-via-process-creati-f7e3fdde</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kimsuky-wscript-launch-from-hidden-windirr-directory-via-process-crea-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-accessibility-feature-debugger-hijack-via-ifeo-via-registry-set-2d6765e8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-sideloading-via-csmonitor-exe-loading-microsoft-servicehosting-to-b3f1a9c2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sparrowdoor-process-hollowing-of-colorcpl-exe-054a6b38</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-local-account-via-specialaccounts-userlist-registry-value-via--212d19de</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-php-webshell-access-under-wordpress-cache-directory-6b2f8c41</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tightvnc-server-installation-as-a-service-87ecb82c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-iis-worker-process-spawning-command-shell-via-sharepoint-toolshell-via-f9207d50</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-host-reconnaissance-via-whoami-and-uname-by-uat-7290-c62d67b2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-ldap-reconnaissance-via-adsearch-via-process-creatio-49a048ba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-autoit-script-execution-of-compiled-a3x-payload-6e0b3f82</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/firewall-rule-manipulation-via-authorizedapplications-registry-list-3c2e103d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-pikabot-rundll32-loading-dll-with-enter-export-a076d34e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kimsuky-rdp-wrapper-keylogger-output-in-programdata-via-file-event-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-remote-access-tool-detections-by-malware-family-signatures-agentb-agen-97233998</loc>
    <lastmod>2026-07-31T12:26:58.317Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-signature-hits-for-apt-malware-naming-patterns-101a1877</loc>
    <lastmod>2026-07-31T12:26:47.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-failed-dns-server-zone-transfer-for-enumeration-purposes-via-dns-serv-1756ba5c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gpinfo-data-store-in-odbc-registry-key-by-diplomatic-specter-71c08b9c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-termination-of-security-tooling-via-taskkill-or-sc-delete-b3cdce22</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-persistence-referencing-public-or-default-user-path-16de6ed2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rclone-mega-exfiltration-via-dns-query-to-mega-storage-endpoint-6f5fa545</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-exclusion-added-via-add-mppreference-cisco-talos-a80b67f7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/runningrat-service-persistence-via-svchost-netsysddl-group-via-process-creation-6383d793</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-remote-hta-execution-via-process-creation-53dcb1cb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/echogather-backdoor-components-dropped-to-user-windows-profile-directory-via-fil-1c9e4b70</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-forticlient-process-spawning-powershell-downloader-via-process-creatio-7d1c5a98</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-binpath-set-to-command-interpreter-or-account-creation-61ed89e2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-archive-retrieval-via-mshta-in-malware-distribution-ecosystem-5b1ba218</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-bun-runtime-payload-dropped-by-shai-hulud-npm-supply-chain-attack-14a0cc62</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharepoint-spinstall-webshell-deployment-after-toolshell-exploitation-via-webser-ae7f3ac2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scheduled-task-microsoftsupdate-loading-dll-web-shell-via-process-crea-4539ea29</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-localaccounttokenfilterpolicy-registry-modification-6a8c0e2f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-based-c2-relay-via-python-web-panel-via-process-creation-d4b1d168</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unc3944-rogue-federated-identity-provider-added-to-entra-tenant-via-a-cebe1539</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-kimsuky-run-key-autostart-to-desktop-ini-bak-in-public-folder-via-regi-15045425</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-sts-session-token-and-role-chaining-abuse-via-cloudtrail-via-aws-a4531bd4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-immutability-set-via-chattr-for-anti-removal-on-linux-5ce3a710</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-privilege-escalation-piping-password-to-sudo-354c0a35</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rce-confirmation-markers-from-offensive-agentic-tooling-44c11e8e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-amsi-bypass-via-amsiscanbuffer-patching-via-ps-script-fd88b06a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-chaos-ransomware-ransom-note-and-encrypted-extension-via-file-event-a8e6f2b7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ransomware-encryptor-execution-with-password-gate-via-process-creation-2a5d8c91</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dns-query-to-fvncbot-android-banking-trojan-c2-73fabeba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-applaunch-process-hollowing-target-8288853b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-oauth-application-registration-with-localhost-reply-url-via-azure-ad-fe6bf039</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mimikatz-credential-access-module-invocation-ee1164e4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-edge-update-setup-spawning-powershell-via-clearfake-8ca45836</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/toneshell-backdoor-guid-store-systemruntimelag-inc-in-programdata-via-file-event-4e1b9d38</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-account-creation-with-fast-deletion-via-security-b5414bb6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-plugx-dll-side-loading-via-lmiguardiansvc-from-samsungdriver-directory-2b4d6f81</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-unc4841-foxdoor-shell-execution-from-non-standard-path-via-process-cre-fe792b6e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-execution-of-script-from-netlogon-share-by-cyber-anarchy-s-65e705c0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-persistence-via-masqueraded-svhostss-value-by-elpaco-ransomwa-7677b732</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-java-runtime-executing-jar-from-user-download-or-temp-directory-7ff5ae5e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rogue-device-registration-in-entra-id-after-device-code-phishing-02e38699</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-renamed-python-interpreter-winaeromodule-via-process-creation-8e1bed9a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-eastwind-implant-execution-from-programdata-drm-directory-4924ecad</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-caspol-execution-spawned-by-powershell-for-injection-3c4d7b3f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-massive-remote-schedule-task-creation-via-named-pipes-crackmapexec-wi-d16e576a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/download-of-fake-messaging-app-update-apk-7211505f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-named-pipe-kesknq-for-token-impersonation-via-pipe-created-cd027ea0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-edgecution-malicious-extension-load-via-headless-edge-via-process-cre-b53e9a26</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-blackcat-boot-configuration-change-to-safe-mode-with-networking-via-bc-5e5aa9a4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sharepoint-spinstall-web-shell-access-leaking-machine-keys-228affc2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-disabling-of-rsyslog-or-auditd-logging-services-via-process-creation-ec68f022</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winrar-silent-archive-staging-ec50d03a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-staged-payload-execution-from-user-downloads-or-pictures-folder-8398216e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-notdoor-outlook-vba-persistence-via-vbaproject-otm-deployment-via-proc-0cf299cf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-docker-client-targeting-remote-exposed-2375-api-0f7c4a1e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shell-spawned-by-windows-script-host-via-process-creation-0ad73588</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-exclusion-for-powershell-via-add-mppreference-via-pr-c0a8b4d9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-renamed-pythonw-interpreter-execution-via-xworm-loader-via-process-cr-b4e2d3c5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-qemu-covert-network-tunnel-via-user-mode-netdev-socket-via-process-cre-f127ee23</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-autoit-execution-from-pif-file-masquerade-01d87749</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bedrock-agentcore-runtime-invocation-on-wildcard-resources-via-aws-b3949c16</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-china-chopper-web-shell-in-temporary-asp-net-files-2e77e20d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-svchost-executed-from-outside-system32-06c984bd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/enabling-rdp-service-via-reg-exe-command-execution-ded07dbe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-whatsappbackup-data-staging-archive-creation-a324286a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-saml-provider-enumeration-for-federation-recon-via-cloudtrail-3b603c7a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-tearpage-wtsapi32-dll-side-load-via-bdeuisrv-by-unc2970-via-image-load-fdacf453</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-notdoor-outlook-macro-auto-execution-enablement-via-registry-via-regis-b4e2d3c5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-kimsuky-troll-stealer-scheduled-task-deletion-of-chromeupdatetaskma-b9307c9f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-regsvr32-scriptlet-or-remote-com-object-execution-via-process-creation-0412298c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-socgholish-domain-user-enumeration-via-net1-da523a79</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-command-shell-spawned-by-wmi-provider-host-targeting-admin-share-via--8e650403</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-amos-stealer-applescript-execution-via-osascript-5e9a065b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cron-persistence-via-etc-cron-d-tsar-via-file-event-9bf9230b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/openssh-server-firewall-configuration-on-windows-command-via-process-creation-e7919c7d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vss-backup-deletion-wmi-via-process-creation-e3ce16a3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-azure-deletion-of-resource-locks-and-immutability-policies-5abf3a91</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sns-email-subscription-for-data-exfiltration-f9cd749f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-sandbox-configuration-execution-for-asyncrat-via-process-crea-94ac4bb6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-khmer-shadow-dll-sideloading-via-vmwarenamespacecmd-loading-vmtools-vi-73d55817</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-masquerading-as-windows-terminal-via-process-creation-5e9b2c04</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-smb-admin-share-accessed-via-security-165f1219</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-teams-message-soft-delete-by-agent-identity-via-m365-audit-bf34fac6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-reverse-ssh-tunnel-via-plink-for-rdp-forwarding-0be7824c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-plink-reverse-tunnel-establishment-4a76bafe</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-webshell-written-to-f5-tmui-web-directory-33a8452a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-to-sonicwall-sma-jsp-webshell-27a404ce</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-moveit-transfer-exploitation-via-moveitisapi-action-m2-and-x-silock-hea-f1b9f4ae</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntuser-man-mandatory-profile-file-created-for-logon-persistence-via-f-6f3b1c8a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-process-injection-via-mavinject-injectrunning-via-process-creation-2c8b97db</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-query-for-stored-credentials-via-process-creation-3efafb2f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-powershell-download-cradle-via-clickfix-via-process-creation-7c3f9a2d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-persistence-pointing-to-documents-folder-via-registry-set-3e19347e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-payload-download-to-temp-masquerading-as-system32-file-via-process-cr-7d6c5b4a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-muddywater-c2-domain-resolution-ca7a10cf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sonicwall-sma-init-d-persistence-launching-deploy-new-py-d196633d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-npm-credential-scan-via-whoami-and-npmrc-access-6bfd0200</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-adfind-active-directory-enumeration-via-owassrf-post-exploitation-via-88b8255b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-node-execution-of-sync-js-from-nodejs-masquerade-directory-3a7c0e91</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pipeshell-exfiltration-over-named-pipes-via-powershell-a0ef7987</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certutil-url-download-to-public-directory-soco404-cryptomining-b0469b85</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntds-database-extraction-from-system-volume-f0ce87f5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cmstp-uac-bypass-via-automatic-install-flag-via-process-creation-73a5b74a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-masquerading-as-edgeupdatehelper-via-process-creation-9c14a7f2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-c2-configuration-stored-in-registry-via-titanplus-key-via-registry-set-6e8a0c2d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-member-added-to-dnsadmin-group-via-security-9d7d07ef</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deletion-of-a-scheduled-task-to-cover-tracks-via-process-creation-241356a4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chained-host-reconnaissance-one-liner-via-denogate-backdoor-0e65197d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-query-to-html-smuggling-aitm-phishing-domain-b1b2265b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-yellowfin-bi-jwt-forgery-via-refresh-tokens-endpoint-a830a9bd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-persistence-masquerading-as-edge-updater-e78d33ba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-storm-0558-forged-token-sign-in-from-msa-consumer-tenant-via-azure-sig-d42646fd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-locating-and-running-msbuild-project-via-process-creation-5e2c1d0f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-com-object-hijack-pointing-to-iconcache-dll-9e5f15c0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/tag-144-dynamic-dns-c2-resolution-via-structured-duckdns-subdomain-via-dns-query-35f7fa67</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-bad-apples-data-exfiltration-via-snmptrap-oid-cb9fe068</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-executing-vbscript-from-masqueraded-file-extension-9e1f3a5c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-elf-magic-byte-restoration-via-dd-conv-notrunc-in-sindoor-dropper-cha-8b379c73</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-systemd-user-service-persistence-miasma-monitor-via-file-event-6c4fed7f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-firewall-allow-rule-masquerading-as-windows-defender-update-service-c3b4fcff</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/web-server-worker-process-spawning-command-interpreter-f6c8bcd7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-akira-ransomware-encryption-execution-via-process-creation-a3f2d477</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-amsi-bypass-via-amsiinitfailed-command-line-321bdb2c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-tunneling-tool-execution-on-linux-host-via-process-creation-a489e092</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-side-loading-via-avgapplicationframehost-b095d92f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-self-delete-of-executable-via-process-creation-5dd9225a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-host-execution-of-javascript-from-a-user-writable-directory-vi-3571d2d7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-script-downloaded-via-curl-and-piped-to-shell-via-process-crea-4b6c87ad</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-to-tmp-and-quarantine-removal-via-curl-and-xattr-4b3c2d1e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-logon-script-persistence-via-userinitmprlogonscript-48293693</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-boot-recovery-disable-via-bcdedit-via-process-creation-6fc97c17</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-fileless-javascript-execution-via-deno-data-uri-via-process-creation-7e9f1a3c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/tag-144-payload-staging-via-mycustomagent-user-agent-via-proxy-772290ab</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-sideloading-via-rundll32-loading-msadocg-via-process-creation-23bca641</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-path-traversal-local-file-inclusion-against-exposed-cloud-function-via--0a0d6959</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-citrix-netscaler-saml-endpoint-abuse-for-pre-auth-rce-cve-2023-3519-via-750549b5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wininit-look-alike-binary-execution-from-windows-directory-f2454267</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-enumeration-via-sysinternals-ad-explorer-snapshot-vi-ab5ca741</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vulnerable-driver-eneio-load-for-byovd-via-image-load-a0759712</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-environment-file-credential-search-via-findstr-via-process-creation-a4727186</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-adsexhaust-hidden-edge-search-automation-via-start-process-1bccac54</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-via-personalizationcsp-registry-key-via-registry-set-2e00bc4c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cr4t-c2-beacon-via-troubleshooter-user-agent-via-proxy-5d2bb1e5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-masqueraded-system-directory-creation-with-trailing-space-via-cmd-e4ac645e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-linux-systemd-persistence-miasma-monitor-service-9e3a1c60</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-persistence-masquerading-as-devquerybrokerservice-c91b3d4a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-hidden-download-cradle-via-process-creation-264abb4e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cloud-prt-theft-via-mimikatz-cloudap-via-process-creation-83235eed</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-teamviewer-remote-access-dns-resolution-via-dns-query-3e7ee826</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-spawned-by-windows-script-host-via-process-creation-via-pr-de81914a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-excel-macro-spawning-scripting-interpreter-downloader-via-process-crea-07edd3a8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-communication-with-dropbox-api-via-ps-script-c5938476</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wp2shell-wordpress-web-shell-via-php-drop-to-plugin-directory-d2047cd3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-execution-of-dllgetclassobject-export-via-process-creation-a8c13dc1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-cradle-via-cmd-mkdir-and-curl-in-process-creation-a0491709</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-bypass-spawned-by-wscript-script-host-28eb8340</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pg-mem-payload-drop-in-postgresql-data-directory-via-file-event-d395cb8d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-jumpcloud-password-brute-force-followed-by-success-8d0a9213</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fakebat-fake-browser-update-stats-and-download-endpoints-via-proxy-7c303794</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-voltzite-single-character-named-zip-exfil-staging-via-file-event-085760cb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-regsvr32-exe-spawned-by-calc-exe-via-dll-side-loading-2f23f929</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-credential-dump-via-comsvcs-dll-minidump-by-apt28-via-process-cr-4f3e2d1c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-xe-group-thump-aspx-webshell-interaction-via-file-directory-parameters-e7b1d420</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-msbuild-proxy-execution-of-a-project-from-a-user-writable-path-via-pro-a7daacbd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-recovery-inhibition-via-shadow-copy-and-winre-tampering-274397d5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disk-image-file-written-by-a-browser-or-mail-client-via-file-event-9db3be61</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-batch-script-unhiding-files-via-attrib-from-temp-2f708e62</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-exclusion-added-via-powershell-via-process-creation-c0d1e2f3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-macos-payload-download-and-execution-via-curl-piped-to-zsh-7ec97f03</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-defender-default-action-changed-to-allow-any-threat-powershe-31fc84d1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ahnenblatt-application-execution-from-user-writable-directory-0cbb3bf0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wwlib-dll-sideloading-via-winword-outside-office-directory-in-kamikakabot-chain--71f949ae</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sed-tampering-of-juniper-syslog-configuration-by-unc3886-via-process-c-5709b774</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-local-account-creation-via-net-user-075262f0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-with-ntlm-and-empty-user-credentials-can-leak-current-user-ntlmv2-r-916eb839</loc>
    <lastmod>2026-07-31T13:28:45.787Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-event-log-tampering-via-wevtutil-channel-disable-by-funksec-ransomware-61899220</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-fickle-stealer-injection-path-store-prepares-dat-under-public-via-fil-1447bd18</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cached-logon-disable-via-winlogon-cachedlogonscount-via-registry-set-0c59a962</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certutil-urlcache-download-b6f8e282</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-file-discovery-via-find-on-linux-e3f5a4b6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-darkgate-cleanup-batch-execution-2b41a1a5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-soaphound-tautological-ldap-filter-enumeration-af6c5f9d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-impacket-style-remote-command-execution-pattern-via-process-creation-b10cd427</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-account-disable-via-net-user-active-no-via-process-creation-4626784c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sshd-exe-outbound-connection-over-smb-port-via-network-connection-703d79c6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-provider-registration-for-credential-interception-via-nppspy-43382771</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-s3-object-encryption-with-customer-provided-key-via-copyobject-472ab371</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-base64-decoded-payload-piped-to-shell-via-macos-clickfix-terminal-lur-98f4e5e3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sql-server-xp-cmdshell-activation-native-event-via-application-3bc2073f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-to-tmp-followed-by-chmod-execution-on-linux-7a2e9c50</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-host-executing-vbs-from-connectwisecontrol-temp-directory-15e642e0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-modification-of-ivanti-web-binary-by-trailblaze-injection-via-file-eve-009fd63f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-external-ip-lookup-to-ipify-service-via-dns-query-6776b7fd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-pre-auth-ssrf-via-vmware-workspace-one-uem-blobhandler-cve-2021-22054-2b7e31ba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mimikatz-malicious-security-package-ssp-exfiltrates-cleartext-password-aa409fb9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regsvr32-loading-dll-from-temp-directory-via-process-creation-9e9ad22f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-blackbeard-scr-payload-execution-via-process-creation-1534621e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-muddywater-manageondriveupdater-scheduled-task-persistence-b7c8b1b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-of-linux-authentication-and-history-logs-d11a915f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-imds-iam-credential-retrieval-from-container-workload-97be9dac</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-share-enumeration-via-sharpshares-9099e9d8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chisel-reverse-tunnel-execution-by-uat-9686-d9d6341f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lazarus-rustyattr-payload-retrieval-via-curl-to-support-cloudstore-c2--99f2eb65</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-khmer-shadow-c2-beacon-with-malformed-chrome-user-agent-via-proxy-efd69639</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-credential-exfiltration-to-webhook-site-677b43d6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-office-application-spawning-script-interpreter-via-process-creation-23dd974b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-quarantine-attribute-removal-via-xattr-via-process-creation-c3cd5cb6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-word-spawning-anomalous-child-process-via-cve-2023-36884-via-8e5c43ab</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-command-execution-from-ntfs-alternate-data-stream-via-cmd-redirection-2f1e0d9c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-crash-with-netlogon-dll-fault-and-status-stack-buffer-overrun-f8a66a02</loc>
    <lastmod>2026-07-31T12:17:54.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-launched-from-public-music-folder-f048655f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-esxi-virtual-machine-termination-via-esxcli-via-process-creation-6416186b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-openai-training-file-upload-via-files-import-operation-via-azur-7a10757e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-via-shell-script-dropped-in-profile-d-directory-via-file--2a320836</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-into-kubernetes-pod-via-api-fecf39d6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rogue-root-user-creation-via-useradd-uid-zero-06f002a6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-teampcp-litellm-credential-exfiltration-c2-lookup-via-dns-query-e03c7d3d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/etherrat-node-js-backdoor-execution-via-headless-conhost-via-process-creation-2b483711</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-veeam-credential-dumping-script-execution-37bb732a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-added-to-existing-application-for-oauth-persistence-in-ent-ae6ff528</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-boombox-run-key-persistence-via-micronativecachesvc-via-registry-set-4e11623a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-sideloading-via-usysdiag-exe-loading-sensapi-dll-via-nailaolocker-a0e8f4b9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lateral-movement-via-psexec-service-via-process-creation-1f80cf6b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-uac-bypass-via-mscfile-handler-hijack-via-registry-set-fe3f36c4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-telegram-bot-api-command-and-control-communication-via-proxy-da525fc5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-daemon-tools-exfiltration-binary-execution-via-envchk-exe-via-process-31a54166</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-password-gathering-referencing-system-preferences-via-process-c-5bd1c834</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-renamed-credwiz-binary-execution-via-process-creation-5da46746</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-spawning-net-lolbin-via-process-creation-2bf9eadc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-system-registry-hive-dump-via-reg-exe-by-sandworm-4e7f0a12</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-redhook-android-rat-websocket-device-channel-via-proxy-381eb74e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-thread-created-in-notepad-process-214ee33a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/searchindexer-suspicious-process-activity-via-process-creation-4fb204d2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sharpshares-network-share-enumeration-tool-execution-fdb98f07</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-interpreter-spawned-by-onenote-via-embedded-file-via-process-c-1d7b4a9c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-execution-of-vbscript-from-whatsapp-transfers-folder-via-proc-24e384e3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/screenconnect-setupwizard-authentication-bypass-path-traversal-cve-2024-1709-95e6ff6d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-reconnaissance-spawned-by-injected-searchprotocolhost-via-process-cre-193c3657</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/exchange-webshell-creation-3086329b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sslconf-execution-from-appdata-edgeupdate-directory-07396cb0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mshta-spawning-powershell-or-command-shell-b98c7324</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-thread-injection-into-task-manager-9c6a67a7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-c2-beacon-via-cpp-httplib-user-agent-e6b5bfba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-smtp-submission-connection-from-non-mail-process-a4312549</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-executing-deelevate64-d3de1d04</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dism-execution-from-programdata-directory-via-process-creation-704e3f21</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-getfederationtoken-console-access-by-javaghost-via-cloudtrail-c42efa4b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-zloader-c2-communication-over-http-b68f9a1f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-via-windows-nt-currentversion-windows-load-value-via-regi-e4c2d8f3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cloud-instance-metadata-service-probing-31ac9be0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rundll32-execution-of-coldcopy-dll-via-coldriver-clickfix-c85b49a2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-high-risk-local-domain-local-group-membership-change-via-security-36453b4b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rdp-reconnaissance-with-valid-credentials-performed-on-multiple-hosts--544ad9db</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-download-of-nvidiadrivers-archive-to-temp-via-process-creation-5d562dd9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ec2-instance-metadata-credential-theft-via-curl-via-process-creation-a9fa6507</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-execution-of-file-with-media-extension-bafe1cd1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-interactive-shell-spawn-with-console-output-encoding-513c641f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-com-hijack-via-clsid-inprocserver32-pointing-to-writable-path-via-reg-5a451fca</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-eks-pod-identity-credential-theft-via-link-local-endpoint-ea7aa67a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shai-hulud-bun-payload-execution-via-npm-preinstall-script-via-process-3b1cc1ba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-akira-ransomware-encryptor-execution-via-process-creation-6a9d3c72</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hta-execution-via-mshta-from-shortcut-chain-via-process-creation-cad04b87</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-iex-downloadstring-in-memory-execution-via-process-creatio-5d9f08bb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-execution-with-undocumented-z-flag-proxying-dll-via-process-c-b9e8d7c6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-vshell-downloader-piping-curl-and-wget-fallback-into-shell-via-process-9d92f0c7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-phantom-msfte-dll-load-by-search-indexer-via-image-load-e99ecb02</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-uac-bypass-via-silentcleanup-scheduled-task-trigger-c4581587</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rclone-remote-control-daemon-for-data-exfiltration-21fdbbf8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-command-shell-spawned-by-sql-server-via-xp-cmdshell-59cb6f02</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-installation-from-non-standard-path-aa6b3489</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-vm-extension-write-for-credential-reset-via-activity-log-affcde61</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-as-rep-roasting-ldap-search-filter-for-dont-req-preauth-accounts-362587d8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-keychain-credential-dump-via-security-utility-via-process-creat-308daa28</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-noopdoor-registry-persistence-under-software-license-key-via-registry--d9928223</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-node-exe-or-code-exe-execution-from-public-music-directory-39b68450</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-command-shell-spawned-by-wing-ftp-server-process-b8651ba1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netsupport-client-execution-via-scheduled-task-dccd00ee</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-trojan-proxy-launchagent-googlehelperupdater-persistence-via-fi-53485548</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-launched-from-sysvol-share-4b1e5e7f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-download-from-storjshare-with-uac-elevation-via-oxloader-65898ded</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-readallbytes-and-expand-archive-payload-staging-via-proces-92894257</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/in-memory-offensive-powershell-tooling-cmdlet-usage-via-process-creation-4814931a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-referencing-alternate-data-stream-payload-fa638220</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-apt37-persistence-via-microsoftupdate-scheduled-task-from-programdata-a6c218e5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-psexec-remote-service-installation-with-randomly-named-service-via-secu-1b719156</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-exchange-transport-agent-installation-artifacts-native-via-msexchange--488adf00</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-printnightmare-privilege-escalation-via-invoke-nightmare-b4ef0f59</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-named-pipe-netcat-reverse-shell-via-shell-via-process-creation-54cab432</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-netdnsactivatorsharing-creation-via-process-creation-0cb48b59</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-exchange-online-mail-flow-rule-or-connector-creation-via-compromised--6a55eba3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-nagios-xi-unauthenticated-terminal-web-shell-access-d0ec446f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-byovd-driver-signed-by-revoked-certificate-load-via-image-load-1a3c5e7f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-ec2-windows-password-retrieval-via-getpassworddata-db335a11</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-sign-on-policy-lifecycle-modification-4a7d66b7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regasm-process-hollowing-for-darkcloud-stealer-043380e1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-prefetch-deletion-for-anti-forensics-fb4d5058</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sisfader-rat-loader-dll-written-to-local-appdata-62932580</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-reverse-tunnel-agent-execution-with-hidden-server-flags-5f0f86ab</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-peerblight-command-and-control-beacon-to-qtss-cc-domain-27c918aa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-keepass-configuration-discovery-via-powershell-script-31fc39e5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-memory-dump-via-rundll32-comsvcs-dll-minidump-8643908b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-nightspire-encryptor-execution-producing-nspire-extension-via-process-9e4b7c02</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-spawning-rundll32-to-load-remote-dll-via-process-creation-b2e5d9f3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-interpreter-command-recorded-in-explorer-runmru-history-via-re-c8b130a8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-backdoor-staging-in-systemservices-folder-via-file-event-a3716254</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-macos-launchagent-persistence-com-nvm-protocal-plist-6e0b9c41</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-payload-download-piped-to-shell-on-linux-f0c5fa3c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-command-shell-spawned-by-service-or-remote-execution-parent-7db260be</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-batch-file-persistence-in-startup-folder-e2bc65d4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ld-preload-rootkit-persistence-via-ld-so-preload-043d1a1a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copy-of-outlook-ost-email-data-file-for-exfiltration-4c73b200</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-local-administrator-account-creation-via-cherryloader-via-process-crea-4b8d2a61</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-event-log-clearing-via-powershell-6e8c9b45</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/qbot-scheduled-task-regsvr32-with-c-image-path-014da553</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cron-job-executing-binary-from-var-tmp-via-process-creation-e4b95f3b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cloudflared-tunnel-execution-via-renamed-svchost-binary-eb1c334c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-byovd-throttlestop-vulnerable-driver-load-via-image-load-c48f1720</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rclone-configuration-file-creation-in-user-config-directory-82a77de4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bash-reverse-shell-via-dev-tcp-945214fa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-auto-color-backdoor-self-copy-on-linux-via-process-creation-7b91e669</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-domain-computers-group-enumeration-via-net-command-via-process-creati-e9fda0db</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharphound-enumeration-via-smb-named-pipes-via-security-6aadd0a8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-teams-installer-masquerade-via-mc-teams-binary-via-process--5ecdd429</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rdp-session-hijack-via-service-creation-abuse-via-security-43ed9258</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ntfs-symbolic-link-configuration-change-via-process-creation-961e227b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-autoit-script-execution-of-au3-payload-via-process-creation-5f7b9d1a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-get-content-piped-to-powershell-via-process-creation-704e3f21</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-netcat-reverse-shell-with-command-execution-flag-via-process-creation-b4715097</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-localaccounttokenfilterpolicy-enabled-via-registry-by-blackbyte-ranso-2e5f8a14</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntds-database-extraction-via-ntdsutil-via-process-creation-9b052da4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-fortigate-rce-via-chunked-hostcheck-validate-request-cve-2024-21762-3b8c905b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-amsi-bypass-via-powershell-amsiinitfailed-patch-dc3a4f03</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-service-executing-batch-file-from-temp-directory-912a722d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-level-io-rmm-silent-install-via-powershell-via-ps-script-7f322fb3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-prt-token-forging-via-aadinternals-via-ps-script-0595c168</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hidden-powershell-execution-from-perflogs-via-process-creation-f25ecc40</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-bitmap-cache-temp-files-written-by-mstsc-in-rogue-rdp-campaign-vi-30a2f29c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-security-service-deletion-via-sc-c62900cc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-named-servicehub-testwindowstorehost-by-mustang-panda-3c6d9e18</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-vmware-workspace-one-ssrf-via-instancehealth-hostname-at-injection-via--b9fbb860</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-credential-hunting-via-microburst-modules-2b7e5a09</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-voltzite-ntds-dit-credential-staging-in-temp-directory-via-process-cre-b64f7dab</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ransomware-self-deletion-via-ping-loopback-and-del-5c8d1b7f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-exiftool-cve-2026-3102-command-injection-via-child-process-spawn-via-pr-9a994d8c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-lua-loader-execution-via-compiler-loading-luajit-runtime-via-image-lo-54f3ffaa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-koi-loader-c2-check-in-via-index-php-beacon-via-proxy-1565aa88</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-autorun-persistence-masquerading-as-windows-security-a71c674f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-service-creation-via-sc-exe-0ee0d7d7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-payload-downloaded-via-powershell-via-powershell-e359437f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-boot-configuration-tampering-via-bcdedit-via-process-creation-99a09eb1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-nethealth-implant-c2-beacon-uri-pattern-56c89e5a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-octo-tempest-remote-access-and-tunneling-tooling-via-process-creation-2a0e8fe7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-trufflehog-secret-scanner-spawned-by-node-package-manager-on-linux-d4e6f5a7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-spinstall0-aspx-webshell-written-to-sharepoint-layouts-fc335e45</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-side-loading-via-vssvc-or-workfolders-b9836731</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-follina-msdt-diagnostic-tool-code-execution-via-process-creation-ecbbd417</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-host-port-scan-from-single-source-address-via-network-connection-6a81f56f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysvol-group-policy-preferences-access-via-share-audit-6a74c75b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-proxyware-download-to-hidden-tmp-path-on-linux-c23fc9c9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-powershell-download-cradle-via-iex-via-process-creation-1b0a9c8d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mssql-xp-cmdshell-os-command-execution-via-sqlservr-exe-via-process-c-a059a21f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/reddelta-msi-installation-via-hidden-powershell-windowsinstaller-com-object-via--09801694</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-payload-download-and-execution-via-curl-chmod-777-via-process-creatio-a958ee86</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-autorun-persistence-via-registry-set-dca0fbed</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-boto3-kali-linux-user-agent-in-aws-cloudtrail-reconnaissance-via-clou-57def2da</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/renamed-qbot-loader-execution-via-rundll32-running-dat-file-with-xlautoopen-expo-9e1f4b56</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-updatususer-local-account-creation-by-secret-blizzard-e524a46d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-external-ip-discovery-via-api-ipify-org-106018c9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-amsi-bypass-via-amsiutils-amsiinitfailed-manipulation-c40cab58</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wdigest-uselogoncredential-enabled-for-cleartext-credential-caching-8a63c4be</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cloudflare-quick-tunnel-establishment-via-trycloudflare-com-via-proce-bf2b3103</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-firewall-disabled-via-netsh-by-blackbyte-ransomware-5b8c1d20</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-window-powershell-with-modified-execution-policy-via-process-c-0f9fc87e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chrome-remote-desktop-host-silent-binding-for-remote-access-via-proce-8a51c2d7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aitm-phishing-kit-session-validation-endpoint-via-proxy-41b89155</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-fire-ant-host-to-guest-command-execution-via-vmware-tools-via-process--a3f1c8e2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-local-administrator-added-by-atera-rmm-agent-f2e403a3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-data-file-with-double-extension-via-stockstay-vi-a7fc46c8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fatalrat-keylog-file-creation-in-windows-directory-via-file-event-8f093789</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sugarloader-configuration-masquerading-as-safari-cache-via-file-event-13e1976a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wordpress-web-shell-drop-in-plugins-directory-via-file-event-36ad68e3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ivanti-epmm-exploitation-via-appstore-fob-endpoint-via-webserver-2591e215</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rclone-masquerading-as-avast-binary-by-the-gentlemen-raas-via-process-31dc63ca</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-and-network-namespace-creation-via-unshare-on-linux-2966fd9b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-edgecution-decryption-key-storage-in-edge-appkey-value-via-registry-s-a89c3e15</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shadow-copy-deletion-via-vssadmin-delete-shadows-via-process-creation-94718d1f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uat-8302-scheduled-task-creation-for-recon-tooling-322ab417</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-indirect-command-execution-via-pcalua-for-uac-bypass-ec001d31</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-service-principal-name-enumeration-via-setspn-2c578261</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ocsp-responder-auditing-settings-changed-or-disabled-via-security-84f8ff65</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powmix-scheduled-task-launching-lnk-via-explorer-b6bcbc30</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sshpass-noninteractive-ssh-password-authentication-via-process-creati-94399a86</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-domain-trust-enumeration-via-nltest-0bb4bfcb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-akira-esxi-encryptor-execution-e57fccbf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-xsl-script-execution-via-wmic-squiblytwo-technique-f4d76004</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-copying-payload-to-windows-temp-via-process-creation-53d4aad4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-log-sanitization-via-sed-in-place-edit-6a9bc455</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-payload-dropped-under-non-standard-assembly-directory-via-file-ev-a1e83222</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-deceptivedevelopment-defender-exclusion-for-coin-miner-via-powershell-c5b03272</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-domain-controller-and-trust-enumeration-via-nltest-aac6ebf7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-coldriver-fileless-payload-storage-in-explorer-clsid-defaulticon-via--f18c5d20</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-encoded-powershell-launching-node-js-runtime-ba1084bf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-registration-loading-vulnerable-driver-e93ae41d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tapiperf-dll-load-by-wmi-provider-host-via-image-load-19119fd0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-console-aitm-phishing-kit-api-endpoints-eb41ecaa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-rule-opening-backdoor-port-49683-via-process-creation-0bf96930</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-creation-masquerading-as-fortigateupdate-via-process-creation-2328c60f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/clickfix-macos-payload-retrieval-via-curl-insecure-flags-piped-to-shell-via-proc-2906707c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cloud-storage-destruction-by-cloud-build-service-account-0c097d16</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-execution-of-short-name-javascript-from-appdata-via-process-c-a70d3c96</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sd-wan-compromise-reverse-tunnel-via-gsocket-5071d8f2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-firewall-configuration-enumerated-command-via-process-creation-c82d5e7b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/enable-wdigest-using-powershell-ps-module-c677394a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-iam-user-creation-using-support-impersonation-name-e99f7262</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-local-account-creation-via-net-user-ba91af24</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-software-enumeration-on-macos-a7b3561b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-to-chrome-login-data-on-macos-via-process-creation-0e081e12</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-marimo-terminal-websocket-rce-access-via-webserver-49325fd0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ldap-enumeration-of-certificate-templates-via-security-133287da</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-persistence-via-reg-add-a2bbd0b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-citrix-netscaler-webshell-deployment-under-vpn-theme-directory-cve-2023-cd20b43b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vmware-and-cortex-binaries-executing-from-user-writable-paths-135b52e3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-running-from-perflogs-directory-337672b9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-output-piped-to-bash-on-macos-via-clickfix-5bbee609</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iam-createloginprofile-for-root-user-via-aws-assumeroot-abuse-c3ceeb43</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-domain-trust-discovery-via-nltest-huntress-d79e0673</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-runmru-entry-containing-script-download-from-clickfix-ea367623</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-pointing-to-appdata-via-process-creation-d66fdfd8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-metabase-pre-auth-rce-via-h2-jdbc-injection-on-setup-validate-cve-2023--5b8847e2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-defender-real-time-monitoring-disable-via-registry-3361be57</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-and-file-discovery-via-system-profiler-or-mdfind-via-process-cre-51b3f0f5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-remote-html-application-execution-via-amatera-stealer-clickfix-b9f98531</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-propsys-dll-sideload-via-computerdefaults-uac-bypass-via-image-load-49f449fc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-obsidian-spawning-command-interpreter-via-shell-commands-plugin-f8a3ed9a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-execution-of-remote-hta-9f22769f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-atera-agent-silent-installation-via-command-line-via-process-creation-2067e2cb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-schtasks-persistence-spawned-from-powershell-or-script-chain-5ecd3d9b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-directory-enumeration-with-recon-tooling-user-agent-via-azure-ad-graph-03397be1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-nmap-scripting-engine-user-agent-in-http-requests-via-webserver-7d0a1726</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-to-chrome-credential-files-87318ad3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-execution-referencing-an-appdata-path-597512b8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-openclaw-ai-agent-spawning-command-shell-via-process-creation-789b15b9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-more-eggs-lolbin-scriptlet-execution-via-ie4uinit-basesettings-abuse-v-19e54f83</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lsass-memory-dump-via-comsvcs-dll-minidump-via-process-creation-7a9c1e3f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-service-disable-via-sc-exe-by-nova-ransomware-8c1d4e97</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-entra-device-code-authentication-with-office-client-and-automated-use-a8743840</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/coin-miner-masquerading-as-misspelled-svchost-process-00e2253c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shai-hulud-data-exfiltration-script-execution-via-process-creation-06a04c29</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-bitlocker-encryption-with-shadow-copy-removal-via-manage-bde-via-proce-ae358fbd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lock-screen-image-path-modification-via-registry-c1b1d217</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-pam-configuration-tampering-for-passwordless-su-via-pam-rootok-via-pro-026ee2ef</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-vulnerable-driver-load-for-byovd-defense-evasion-via-image-load-9c2a6f18</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-log4shell-jndi-injection-in-http-request-eda66013</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gcp-bucket-deletion-for-namespace-hijacking-via-gcp-578f9580</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-vulnerable-driver-deployment-for-edr-termination-via-file-event-26d879bd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-backdoored-liblzma-loaded-by-sshd-cve-2024-3094-40efdf91</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-reconfiguration-of-sessionenv-or-ikeext-for-dll-injection-by--6fc4ab09</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-iam-privilege-escalation-via-attachuserpolicy-of-administrator-po-26464501</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-enumeration-via-adws-powershell-cmdlets-via-ps-scrip-7c2a5e91</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-in-memory-download-cradle-via-iex-downloadstring-f9c4396b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lucidrook-dll-side-loading-via-renamed-msedge-exe-db5b5959</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-telegram-bot-api-command-and-control-channel-845bafef</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/office-persistence-via-wll-add-in-dropped-to-word-startup-folder-b4e0325f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/spn-added-to-an-account-by-command-line-via-process-creation-80e1a683</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-self-extracting-archive-via-tail-piped-to-funzip-d5d3c7a2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-plugx-dll-sideloading-via-canon-cnmpaui-utility-via-image-load-8f2c9a15</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-massive-services-termination-burst-via-process-creation-1f66bf2a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-keylogger-dll-execution-via-rundll32-klg-dll-8de98b6d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-side-loading-of-vcl120-bpl-from-appdata-via-hijackloader-via-image-6f7d8091</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mirai-and-rondo-payload-retrieval-via-known-loader-paths-7a8b9c0d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-payload-piped-to-shell-via-curl-or-wget-d3b8ace9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntfs-symbolic-link-evaluation-enabled-via-fsutil-for-remote-access-vi-2e70daf7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-office-vba-security-downgrade-via-registry-via-registry-set-ef3584bc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-servicedll-hijack-with-qsc-loader-dll-725a763e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-revengehotels-js-loader-spawning-powershell-via-process-creation-a78f183d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-guest-account-enablement-via-net-user-for-privilege-abuse-7ab21830</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ukraine-themed-lnk-lure-files-dropped-via-file-event-815f4032</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-port-forwarding-configuration-via-netsh-portproxy-via-process-creatio-e6c3a1d8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-filefix-typedpaths-entry-containing-powershell-or-url-e439f705</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-nsg-rule-opening-ssh-to-the-internet-d7bb6b5f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-stager-download-of-spf-script-by-seedworm-49280e57</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mustang-panda-scheduled-task-solidpdfpcl2bmp-creation-via-process-cre-08da3ad8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-to-kubernetes-service-account-token-via-curl-or-wget-via-proce-157ec964</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-secedit-security-policy-export-for-reconnaissance-via-process-creatio-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shadow-copy-deletion-and-recovery-tampering-by-bablock-ransomware-58db05ac</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-payload-decoding-via-certutil-4f2ce44e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-system-hive-dump-via-reg-save-via-process-creation-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netsupport-client32-execution-from-programdata-via-process-creation-f8c6b7a9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-jsp-webshell-written-to-sap-irj-work-directory-via-file-event-6a8c0e2f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vba-runtime-loaded-by-process-from-onenote-exported-directory-711dfb0b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-boot-recovery-disabled-via-bcdedit-before-encryption-via-process-crea-6c2bfda3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-turla-png-dropper-service-masquerading-as-windows-error-reporting-via--e5536e78</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-long-alphanumeric-dns-subdomain-indicative-of-dns-tunneling-10110e40</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-eks-access-policy-association-granting-cluster-admin-e049ccc3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-immutable-flag-on-ssh-authorized-keys-via-chattr-3c8f6a29</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-bits-job-notify-command-pointing-to-programdata-payload-via-bitsloth-6ae000a2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-php-exe-backdoor-execution-from-appdata-roaming-8beeb83c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-svcagent-dll-load-from-assetmon-programdata-directory-via-phantompulse-f83fab9b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-computerdefaults-auto-elevation-via-process-creation-8d537210</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-c2-connection-to-aws-lambda-function-url-b13abad0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-process-injection-into-notepad-via-pythonratloader-via-process-creation-9d4a2c7e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-virtual-machine-detection-via-get-mpcomputerstatus-and-win32-videocon-dbcddaa3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-retrieval-of-aws-secrets-manager-values-via-cloudtrail-65148407</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cron-job-persistence-creation-on-linux-via-process-creation-1eb92094</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dsrm-password-changed-reg-via-command-via-security-9cbc72c1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dll-side-loading-of-webui-dll-via-iscrpaint-host-binary-0f9bed0a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-office-365-email-forwarding-rule-to-external-domain-via-office365-6a20a363</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-adinsight-execution-from-programdata-via-scheduled-task-by-wikiloader-39a4d47d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zohomurk-non-browser-zoho-and-ipfetcher-user-agents-via-proxy-f59b13cd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-via-certutil-urlcache-huntress-2-9318fa91</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-command-processor-autorun-persistence-via-registry-set-5c6931f0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-pan-os-auth-bypass-via-double-encoded-path-traversal-to-ztp-gate-cve-20-5c25caf3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-domain-admin-account-escalation-via-net-group-via-process-creation-5b8a2d47</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winsvcupd-scheduled-task-persistence-via-schtasks-via-process-creatio-9a3d7c15</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-macos-gaslight-persistence-via-apple-namespace-launchagent-via-file-ev-039100bf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-wds-startupprograms-persistence-modification-via-registry-set-d3b8e0c7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outlaw-payload-download-via-wget-dota-archive-8d5a2e9c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-tpmprofiler-executing-qemu-emulator-34445f32</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-linux-xorddos-gcc-pid-device-marker-file-via-file-event-74a795b3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/lightspy-macos-implant-pid-file-creation-in-users-shared-350716ff</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kimsuky-run-key-persistence-via-masqueraded-value-via-registry-set-13fc6b92</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-privileged-docker-container-mounting-host-filesystem-5a0436f4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xdg-autostart-desktop-entry-persistence-via-disgomoji-167112a4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-cli-disk-snapshot-and-copy-for-data-theft-4bac5c06</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-launching-a-script-interpreter-via-process-cr-cf976044</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-via-rclone-to-cloud-storage-via-process-creation-in-cad1eb63</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mintsloader-amsi-bypass-via-amsiinitfailed-reflection-via-ps-script-1abf6fc3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hiloti-configuration-registry-key-creation-via-registry-set-7ed63adf</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-port-forwarding-tunnel-via-netsh-portproxy-via-process-creation-dd1ceac8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-external-ip-discovery-via-curl-to-ipinfo-59c28c19</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-perl-reverse-shell-execution-on-linux-2582b7d4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-firewall-rule-any-any-created-via-firewall-as-c85b7df4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-launchdaemon-persistence-via-plist-relocation-9c44dd79</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hijackloader-connectivity-check-to-apache-incubator-logo-via-proxy-2a8d5e71</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-amsi-bypass-in-memory-patching-d802fa39</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-subsystem-for-linux-wsl-installation-powershell-via-powershel-82ff463e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pythonw-exe-executing-license-txt-downloader-from-appdata-1d6a2c94</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esxi-virtual-machine-enumeration-via-esxcli-process-list-5289fd12</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-cmstp-inf-auto-install-6124f95a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-citrix-session-recording-soapaction-deserialization-rce-cve-2023-6184-v-8788d0d5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-sideloading-of-wke-dll-via-driverassistant-acvb-via-image-load-aa59bbab</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-disable-via-policy-registry-keys-a340ff10</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-secrets-manager-bulk-secret-retrieval-via-batchgetsecretvalue-21b846aa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shai-hulud-npm-payload-execution-via-bun-environment-script-via-proces-7e528055</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-volgmer-payload-storage-in-wmi-security-registry-key-6bd69f64</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-shell32-dll-ordinal-61-execution-8050c0f5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-microsoft-http-api-exe-from-appdata-2e6597a4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gogrpc-persistence-via-realtek-hd-audio-run-key-via-process-creation-8e1c6a29</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vmware-tools-binary-executing-from-non-standard-path-4686949b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-batch-execution-from-hidden-macosx-archive-path-via-process-creation-a3b1c4d5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-tanstack-runner-js-via-bun-exe-run-9b4f3d2e</loc>
    <lastmod>2026-07-31T12:18:34.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-execution-of-bun-runner-for-tanstack-supply-chain-comprom-3c6f5e4a</loc>
    <lastmod>2026-07-31T12:18:33.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-file-creation-of-tanstack-runner-and-router-init-persistence-arti-8a3f2c1e</loc>
    <lastmod>2026-07-31T12:18:31.020Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-creation-indicators-for-tanstack-related-supply-chain-runner-and-pers-2b5e4d3f</loc>
    <lastmod>2026-07-31T12:18:29.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-to-git-tanstack-com-and-filev2-getsession-org-for-tanstack-s-ac5a4e3f</loc>
    <lastmod>2026-07-31T12:18:27.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ssload-downloader-c2-beacon-via-custom-ssload-user-agent-via-proxy-9d3c6b81</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pam-backdoor-via-pam-exec-configuration-change-fa6e3832</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-excel-outbound-network-connection-c62be3e3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-event-log-clearing-via-wevtutil-via-process-creation-kaspersk-de221ac3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-defender-security-components-disabled-command-via-process-c-66d69db4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-fodhelper-child-process-7f36e4c8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/armouryloader-persistence-via-scheduled-task-asusupdateserviceua-via-process-cre-7d3b9f04</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windowscodecs-dll-sideload-from-non-system-path-by-fighting-ursa-31787969</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-check-point-management-application-token-authentication-as-administrato-66bf84c2</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-citrix-wfshell-spawning-command-interpreter-via-command-line-3fdbef55</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iam-policy-attachment-granting-administratoraccess-84161dd3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-office-application-spawning-a-command-shell-or-script-interpreter-via--0a30ee32</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-bring-your-own-vulnerable-driver-load-by-blackbyte-2f70e0f6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ivanti-connect-secure-path-traversal-exploitation-e77fc7a6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-defender-exclusion-added-via-powershell-91a0b9fa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cleo-file-transfer-software-spawning-command-interpreter-dc68bad7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-active-directory-federated-trust-added-via-office365-627d26ad</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-subprocess-spawned-by-litellm-proxy-process-via-process-creation-2d7f9a13</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chafer-backdoor-http-c2-communication-via-proxy-060b9035</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-appdomainmanager-injection-via-myappdomainmanager-dll-load-c1d58901</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-file-encryption-via-kraken-ransomware-encryptor-binary-0a381017</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-enumeration-via-adfind-via-process-creation-a41abee6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wsh-script-execution-from-webdav-share-via-process-creation-1c6f3a8d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-sideloading-via-lolbins-from-programdata-by-dohdoor-44d0b813</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-playit-gg-tunnel-domain-resolution-used-by-xenorat-via-dns-query-3969bf85</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-history-clearing-via-rundll32-inetcpl-clearmytracksbyprocess--5c3add53</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clickfix-command-staged-in-runmru-registry-key-804c4745</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/masquerading-certificate-issuance-with-certighost-cdc-and-rmd-request-attributes-12b32b6c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-over-https-c2-via-wildcard-dns-services-f2191348</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-sso-token-creation-and-role-credential-retrieval-via-cloudtrail-5bcdfe30</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-start-job-with-base64-scriptblock-via-ps-script-4f9b2e60</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-directory-configrc-for-bandwidth-sdk-abuse-f0fd081a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-localaccounttokenfilterpolicy-enabled-via-registry-uat-7237-c7b63b8b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-run-key-modification-for-persistence-998c7fef</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ransomware-ransom-note-readme-recover-file-creation-6c53d294</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mail-send-via-microsoft-graph-by-application-identity-via-m365-audit-cf88f013</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-origin-logger-c2-exfiltration-via-hardcoded-user-agent-and-gate-endpoin-44171808</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-added-to-application-or-service-principal-in-entra-id-via--a135a009</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-spool-process-spawned-a-cmd-shell-printnightmare-vulnerability-cve-202-f0a0923e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-outlook-process-memory-dump-via-procdump-53a90de9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webdav-payload-execution-via-rundll32-davclnt-dll-via-process-creation-ff802f92</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-crazyhunter-distribution-tool-connecting-to-file-server-on-port-9999-f7e4100f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-esxi-snapshot-removal-loop-inhibiting-recovery-via-process-creation-28e7b96f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-oauth-consent-grant-to-mail-access-permissions-via-azure-ad-2f9712c4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bunnyloader-c2-gate-endpoint-communication-via-proxy-6d436461</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-cradle-using-irm-and-iex-via-interlock-loader-via-b5f3a9c4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-palo-alto-pan-os-authentication-bypass-via-php-path-confusion-js-map-su-1f8c6a04</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wdigest-uselogoncredential-enablement-for-credential-theft-aeb00911</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-renamed-mysql-binary-executed-from-temp-via-clickfix-via-process-crea-2e8d4b1a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-domain-controller-discovery-via-nltest-dc30f55c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-octo-tempest-federation-persistence-via-aadinternals-via-ps-script-649b3471</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-matanbuchus-persistence-via-regsvr32-silent-install-with-user-context--9a3791e1</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-offensive-recon-and-credential-tools-execution-via-process-creation-5e2c1d0f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regasm-launched-by-script-host-via-process-creation-ad968ae4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-download-to-windows-temp-via-powershell-via-process-creation-47e9c945</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ci-runner-memory-scraping-via-python-process-memory-read-tj-actions-sup-c3f5eaf4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-network-share-discovery-via-net-view-via-process-creation-fbe2089c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-system-recovery-inhibition-via-bcdedit-boot-configuration-changes-via--97703221</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cookie-spider-macos-data-exfiltration-via-curl-archive-upload-via-pro-c5e2a8f0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-detect-authencesn-crypto-module-load-via-modprobe-cve-2026-31431-indicator-474b415a</loc>
    <lastmod>2026-07-31T12:17:49.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/burnbook-dll-sideloading-via-sumatrapdf-exe-loading-libmupdf-dll-from-user-direc-80d0677e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmd-using-curl-to-download-and-execute-payload-via-process-creation-be079bf5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-sts-role-chaining-from-temporary-session-credentials-via-cloudtra-7b9b3be6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rundll32-executing-w32analytics-dll-export-via-process-creation-3fe5dafc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-metabase-setup-token-disclosure-via-session-properties-endpoint-cve-2-becfb933</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntds-dit-access-via-esentutl-database-copy-via-process-creation-ea1335a3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-empyrean-stealer-run-key-persistence-via-registry-set-e7c1a4d9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-pdf-editor-update-script-execution-via-powershell-via-process-creation-b1723242</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-adnotificationmanager-execution-for-netutils-dll-side-loading-via-pro-45193667</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-forest-powershell-class-called-from-a-non-administra-4e40102d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-site-hook-or-pth-file-written-to-site-packages-via-file-event-bae8d9cb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-event-log-cleared-during-stilachirat-anti-forensics-via-secur-7e0a406f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webdav-remote-payload-retrieval-via-rundll32-davsetcookie-cb57a9c6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-scheduled-task-named-coreldefrag-under-windows-defrag-path-bec0bfb5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-detection-of-default-a-windows-host-name-in-login-attempts-via-securi-dfc202b7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-utmpdump-usage-for-wtmp-log-manipulation-5f15d348</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-disabling-of-carbon-black-edr-service-via-sc-config-34f06fd6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ngrok-tunneling-utility-execution-for-command-and-control-bd5cda03</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-janelarat-dll-side-loading-via-nevasca-exe-via-image-load-2cc377cd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-screenconnect-client-download-via-powershell-via-process-creation-09d7c8ba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sam-and-system-hive-dump-via-reg-save-3c0f7d4b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-creation-for-dcrat-persistence-via-sc-exe-via-process-creation-89e397e6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-of-hosts-deny-access-restrictions-on-linux-90b5c2e7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-eldorado-ransomware-ransom-note-creation-a7710556</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-moustachedbouncer-service-dll-hijack-of-wmdmpmsp-via-registry-via-regi-14c55a4b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-defender-real-time-monitoring-disabled-by-the-gentlemen-raas-via-proce-ac556822</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sitecore-path-traversal-via-validatexhtml-pagestate-injection-d53b1b46</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-container-escape-via-core-pattern-hijack-via-process-creation-d7824a20</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-badiis-seo-poisoning-c2-request-via-web-server-via-webserver-c90a4054</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-execution-spawned-from-batch-and-script-chain-8209b535</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-php-webshell-dropped-in-pan-os-unauthenticated-web-root-0d2668d8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-rdp-shadow-session-started-command-via-process-creation-ad97b03d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-download-cradle-from-github-raw-via-process-creation-fc4bdf39</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sharpgpoabuse-gpo-modification-tool-from-public-directory-5335d337</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-event-log-clearing-via-wevtutil-a61f2aba</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-tunneling-with-hex-subdomain-to-info-domain-via-dns-query-cdf0f012</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-azure-storage-and-compute-destruction-via-key-listing-and-snapshot-del-688ad611</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msbuild-lolbin-spawning-script-interpreter-via-process-creation-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regsvr32-execution-of-dll-from-user-writable-path-via-process-creatio-12c7173f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-smb-maxmpxct-registry-tuning-via-registry-set-e50ba436</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-download-rename-and-execute-chain-via-script-block-13c6f671</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-privileged-container-launch-with-host-root-mount-via-docker-01cf1d44</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-conhost-headless-execution-for-hidden-window-8d2a1c70</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netsupport-rat-client32-execution-fd6b3c3d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-active-directory-database-ntds-dit-extraction-via-process-creation-6547b43d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-kentico-xperience-staging-sync-authentication-bypass-via-syncserver-end-f4a7c2e9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-domain-group-membership-change-via-powershell-060d672c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-jamf-pro-ssrf-targeting-cloud-metadata-via-imageurl-via-webserver-d0c6856b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-watering-hole-exfiltration-to-fake-wp-includes-endpoint-via-silentsel-b0acb699</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-teampcp-trivy-c2-beacon-to-icp-canister-and-cloudflare-tunnel-via-dns--f8452755</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-persistence-referencing-appdata-roaming-478b519d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-freenode-linux-backdoor-helper-binary-b354ecfc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-executing-vbscript-via-process-creation-e2980708</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-or-command-shell-spawned-by-sql-server-via-xp-cmdshell-ec315557</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-qemu-ssh-tunnel-via-scheduled-task-on-nonstandard-port-via-process-cre-80b27a49</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-event-log-clearing-via-wevtutil-by-the-gentlemen-raas-via-process-crea-91451d3b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-self-deletion-batch-artifact-by-jadeprox-triback-loader-via-file-even-d2435cf9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-exchange-transport-agent-injection-via-configuration-file-via-file-eve-c51488fc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-progress-whatsup-gold-ssrf-via-core-render-baseurl-via-webserver-db0a91f4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-remote-process-creation-via-wmic-node-call-create-7df03d9c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-running-rundll32-dllregisterserver-every-minute-45d123ab</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-service-abuse-with-malicious-imagepath-reg-via-powershell-via-powershe-c266ddaa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dero-miner-binaries-nginx-and-cloud-execution-1a8d5b2f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-toshiba-binary-sideloading-toshdpapi-dll-e7f1a3c5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-search-order-hijack-of-httpapi-dll-outside-system32-via-image-load-c1a9e4b7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-simplehelp-remote-access-client-spawning-discovery-commands-via-proce-b4e17c93</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-headless-browser-automation-with-anti-detection-flags-via-astaroth-vi-d1f6a394</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-permissions-changed-on-a-group-policy-gpo-via-security-f3adcac5</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-member-added-to-privileged-directory-role-in-entra-id-1ce6dad9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chmod-777-on-dropped-payload-in-temp-directory-fc08ba00</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-launch-with-remote-debugging-for-cookie-theft-via-process-cre-da29bd17</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-motd-or-git-hook-script-creation-for-linux-persistence-129c134a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-dll-registration-via-regsvr32-silent-457270e4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-coldriver-logon-script-persistence-via-userinitmprlogonscript-via-pro-6a3d1b48</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-print-spooler-exploitation-spawning-a-child-process-via-process-creatio-c5810ece</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-hardware-fingerprinting-via-ioreg-ioplatformuuid-via-process-cr-8fbd3340</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sharepoint-toolpane-endpoint-request-via-toolshell-via-webserver-959da910</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-systemsettings-dll-sideload-from-non-system-path-via-image-load-956cb0af</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-zhong-stealer-loader-and-log-artifacts-7e6f9d51</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-to-appdata-intel-path-de32a451</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-domain-trust-discovery-via-nltest-palo-alto-unit-42-5daac41d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-telegram-bot-api-c2-beaconing-via-network-e8be1a88</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-launched-from-domain-netlogon-share-via-process-creation-be391752</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-node-payload-drop-in-local-share-directory-via-file-event-4e677c08</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-payload-drop-to-public-user-directory-by-gladinet-exploit-b58c6f9a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-equation-editor-child-process-execution-via-process-creation-c8e92161</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-awk-character-generation-piped-to-shell-on-vmware-esxi-via-process-cr-3a9c5f21</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-defender-exclusion-added-via-set-mppreference-3d14c2a6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-subtitle-file-parsing-for-staged-command-execution-c4d5e6f7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shared-printer-creation-printnightmare-vulnerability-cve-2021-36958-v-960ecc8a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windowserver-binary-masquerade-in-application-support-via-file-event-0742ca0a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-quick-format-of-drive-with-auto-confirmation-ecd6966b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-secur32-dll-sideload-from-color-profile-directory-via-image-load-d463e283</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-coinminer-killproc-termination-of-competing-miners-via-process-creati-d3f1a2b4</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dynamicwrapperx-registration-via-regsvr32-via-process-creation-dd1dcfab</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/nullsoft-scriptable-installer-script-nsis-file-creation-b95288d8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-defender-tampering-via-powershell-mppreference-12e526ff</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lazarus-signbt-loader-configuration-artifacts-wpd-files-via-file-even-98f94749</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cryptominer-payload-retrieval-into-temporary-directory-ae8a7bc8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-spawned-by-gogs-git-server-on-linux-c7d9e8f0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-sideloading-via-smadavprotect-and-solidpdfcreator-by-stately-tauru-762b453d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kernel-mode-service-creation-via-sc-72d3e974</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pif-file-as-autoit-loader-4e654ddb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-of-updserc-archive-to-appdata-via-clickfix-ae03dee6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-high-privilege-microsoft-graph-application-role-grant-via-azure-audit-e08a7312</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/clickfix-paste-jacking-command-written-to-runmru-history-via-registry-set-e4a3752b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hello-world-scraper-botnet-user-agent-in-web-requests-086a0932</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-data-exfiltration-to-restic-rest-server-over-http-via-process-creation-59f09965</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vulnerable-driver-googleapiutil64-sys-loaded-for-byovd-c9a8b7d6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-encoded-powershell-payload-deployed-via-service-via-security-ea03b9de</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-axios-npm-rat-renamed-powershell-execution-via-wt-exe-b250c9ac</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fileless-powershell-execution-via-invoke-restmethod-piped-to-iex-via--a2c4e6a8</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-defender-spynet-reporting-disabled-via-registry-a3504ef0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-rights-granted-to-an-account-for-privilege-escalation-via-securit-f0bfb9b9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mimikatz-driver-deployed-via-service-via-security-b4b7ea3e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-empire-default-user-agent-in-http-traffic-19e2572f</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-impacket-wmiexec-execution-via-smb-admin-share-via-security-2719da3c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-reverse-shell-via-socat-exec-redirection-9b0caf66</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-defender-threat-exclusion-added-powershell-via-powershell-627ad2fc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-service-imagepath-pointing-to-appdata-directory-47203954</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-daxin-backdoor-driver-srt64-sys-loaded-2f8a1c9e</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sns-publish-to-phone-number-for-smishing-56e6ec81</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-impacket-wmiexec-output-redirection-via-admin-share-6cfe9522</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-control-panel-file-execution-via-control-exe-with-cpl-argument-cd2c8197</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-side-loaded-dll-loaded-by-ssh-agent-for-lazarus-servicechanger-32f5dbaa</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-modification-of-a-fake-domain-controller-spn-dcshadow-directory-servic-56a10fab</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-svchost-spawned-by-non-services-parent-via-process-creation-81a7eff3</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-process-memory-injection-via-dd-write-to-proc-pid-mem-by-unc3886-via-p-cc74c7b7</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shai-hulud-2-0-harvested-secret-dump-file-creation-a3b5c4d6</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-autoit-script-execution-from-user-writable-path-via-darkgate-via-proc-3a9c1f6d</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-chrome-relaunch-hijack-by-fluttershell-backdoor-on-macos-via-process-c-36ac2180</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-to-elasticsearch-bulk-api-via-ps-script-5f9b2c74</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-transfer-via-curl-to-raw-ip-address-42633485</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-interactive-reverse-shell-on-linux-via-process-creation-51abb6fd</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lancefly-tdiproxy-driver-loaded-8e0f2a4c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-foxit-pdf-reader-spawning-command-interpreter-870ff7bb</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-safe-mode-boot-configuration-via-bcdedit-for-defense-evasion-via-proce-34678133</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lolbin-download-saved-as-windows-utility-ping-exe-via-certutil-or-curl-f16d0f0b</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-downloadfile-to-appdata-executable-c3f405c0</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-lolbin-spawned-by-outlook-via-monikerlink-cve-2024-21413-53c654d9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cryptbase-dll-side-loading-outside-system32-0099222c</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitlocker-fve-policy-modification-via-registry-via-registry-set-efe67f82</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-shadow-credentials-abuse-via-msds-keycredentiallink-modification-b3d9f21a</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cron-persistence-file-created-in-system-cron-directories-1006d606</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-interlock-ransomware-ransom-note-file-creation-b82e97f9</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-backup-catalog-deletion-via-wbadmin-via-process-creation-c23a00df</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-ses-production-access-request-via-putaccountdetails-cloud-email-a-c7b302fc</loc>
    <lastmod>2026-08-28T20:46:40.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detection-of-libredtail-http-user-agent-inbound-requests-6fd25dd1</loc>
    <lastmod>2026-07-31T12:18:25.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-af-alg-address-family-38-socket-syscall-creation-474b415a</loc>
    <lastmod>2026-07-31T12:17:47.489Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-print-exe-sensitive-file-dump-for-credential-access-2fcda7e2</loc>
    <lastmod>2026-07-30T04:57:12.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-ios-ios-xe-aaa-logs-manual-802-1x-dot1x-port-authentication-disabled-ef0ff092</loc>
    <lastmod>2026-07-31T12:44:15.741Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-workspace-logins-marked-suspicious-by-google-gcp-38360161</loc>
    <lastmod>2026-07-31T12:33:27.360Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-google-workspace-login-email-forwarding-out-of-domain-activity-2a0bb2dd</loc>
    <lastmod>2026-07-31T12:33:24.894Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-workspace-detect-gov-attack-warning-login-events-from-login-googleapis-co-eafe6f2b</loc>
    <lastmod>2026-07-31T12:33:23.220Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-log-signals-potential-enumeration-via-shells-and-recon-tools-597a7e84</loc>
    <lastmod>2026-07-31T12:25:01.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-id-sign-in-using-axios-user-agent-ea1a07f0</loc>
    <lastmod>2026-07-31T12:18:39.859Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-outbound-request-to-eviltokens-phaas-phishing-infrastructure-cloudflare-wo-e0e121d0</loc>
    <lastmod>2026-07-31T12:18:23.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-attempts-to-enable-suid-core-dumps-via-proc-sys-fs-suid-dumpable-33b3cfb1</loc>
    <lastmod>2026-07-31T12:17:09.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-service-changestartmode-sets-manual-or-disabled-startup-type-c0514f28</loc>
    <lastmod>2026-07-30T05:15:08.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sftp-exe-indirect-command-execution-via-proxycommand-762bb580</loc>
    <lastmod>2026-07-30T05:05:25.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pua-memprocfs-memory-dump-mounting-via-device-8a1b2c3d</loc>
    <lastmod>2026-07-30T04:58:06.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-windefend-flags-tieringengineservice-exe-eicar-test-staging-by--a7c3e5f2</loc>
    <lastmod>2026-07-31T12:18:08.014Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-created-redsun-redsun-9b4e7c2a</loc>
    <lastmod>2026-07-31T12:18:03.923Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-tieringengineservice-exe-in-rs-prefixed-temp-directory-f2e4b7d9</loc>
    <lastmod>2026-07-31T12:18:01.914Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netexec-execution-indicators-via-pyinstaller-mei-temp-file-drops-efc21479</loc>
    <lastmod>2026-07-31T13:03:31.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-chain-for-axios-npm-compromise-cscript-vbs-temp-deletion-curl-c2-f6c27ecc</loc>
    <lastmod>2026-07-31T12:18:22.060Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detects-axios-npm-compromise-process-chain-using-osascript-curl-download-a-a09ee860</loc>
    <lastmod>2026-07-31T12:18:20.096Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-axios-npm-plain-crypto-js-compromise-chain-via-curl-nohup-and-python3-0a23a62d</loc>
    <lastmod>2026-07-31T12:18:17.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detect-suspicious-dns-queries-to-axios-supply-chain-c2-domains-73e5d24f</loc>
    <lastmod>2026-07-31T12:18:15.860Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-indicators-for-axios-npm-compromise-drops-node-exe-powersh-cd6386fa</loc>
    <lastmod>2026-07-31T12:18:13.998Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-file-creation-indicators-for-axios-npm-supply-chain-compromise-2db0458c</loc>
    <lastmod>2026-07-31T12:18:12.195Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-drop-indicator-for-axios-npm-supply-chain-compromise-curl-to-tmp-ld-p-b7cb840c</loc>
    <lastmod>2026-07-31T12:18:10.298Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-indicators-of-litellm-supply-chain-backdoor-activity-lite-36603778</loc>
    <lastmod>2026-07-31T12:18:38.334Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-persistence-file-creation-via-python3-paths-for-sysmon-py-and-systemd-user-81c0b7f5</loc>
    <lastmod>2026-07-31T12:18:36.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netexec-nxc-exe-process-execution-with-network-protocol-commands-7638e5fe</loc>
    <lastmod>2026-07-31T13:33:37.338Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-file-uploads-to-file-sharing-domains-e328cc73</loc>
    <lastmod>2026-07-31T13:28:49.425Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-applocker-audit-only-events-indicate-would-be-blocked-executions-557e3bd3</loc>
    <lastmod>2026-07-31T12:48:09.087Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-restore-registry-modification-via-powershell-or-reg-exe-command-l-7c06ab9b</loc>
    <lastmod>2026-07-30T05:00:12.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-python-one-liners-decoding-base64-via-command-line-50a0aa3d</loc>
    <lastmod>2026-07-30T04:58:54.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-executions-of-python-base64-decoding-in-one-liners-55e862a8</loc>
    <lastmod>2026-07-31T12:40:05.017Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mail-forwarding-redirecting-via-exchangepowershell-cmdlets-on-windows-0c7686d5</loc>
    <lastmod>2026-07-31T12:20:52.945Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/openedr-ssh-shellhost-exe-spawning-cmd-exe-or-powershell-with-pty-on-windows-7f3a9c2d</loc>
    <lastmod>2026-07-31T13:27:49.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-creation-by-openedr-itsmservice-exe-using-executable-arc-9e4b7d3a</loc>
    <lastmod>2026-07-31T13:02:23.278Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-process-behavior-from-solarwinds-webhelpdesk-webhelpdes-8c7f4a2d</loc>
    <lastmod>2026-07-31T12:16:08.664Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/exchangepowershell-inbox-rule-creation-or-update-via-new-inboxrule-set-inboxrule-04580eed</loc>
    <lastmod>2026-07-31T12:20:55.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-node-exe-running-npx-skills-add-new-agent-skills-afa71271</loc>
    <lastmod>2026-07-30T04:53:06.858Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-process-execution-by-notepad-updater-gup-exe-bb0e87ce</loc>
    <lastmod>2026-07-31T13:31:34.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-notepad-updater-gup-exe-creates-files-in-uncommon-locations-3b8f4c92</loc>
    <lastmod>2026-07-31T13:03:12.379Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-detection-for-notepad-gup-exe-queries-to-uncommon-domains-2074e137</loc>
    <lastmod>2026-07-31T13:00:26.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-mail-delivery-of-suspicious-inbound-emails-to-inbox-or-junk-3569aefd</loc>
    <lastmod>2026-07-31T12:33:37.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vulnerable-driver-blocklist-disabled-via-registry-dword-setting-d526c60a</loc>
    <lastmod>2026-07-30T05:23:13.154Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vulnerable-driver-blocklist-registry-tampering-via-powershell-or-reg-exe-22154f0e</loc>
    <lastmod>2026-07-30T05:12:41.260Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hvci-registry-tampering-via-reg-exe-or-powershell-command-line-6225c53a</loc>
    <lastmod>2026-07-31T13:35:06.219Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-alert-on-changes-to-shell-open-command-targeting-common-malware-9e8894c0</loc>
    <lastmod>2026-07-30T05:22:34.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modification-oracleocilib-oracleocilibpath-under-msdtc-for-oci--c0e0bdec</loc>
    <lastmod>2026-07-30T05:21:46.640Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-launching-start-exe-with-hidden-window-flags-to-script-or-suspic-5a6b7c8d</loc>
    <lastmod>2026-07-31T13:26:58.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-setcap-sets-cap-setuid-on-a-binary-via-process-execution-ed447910</loc>
    <lastmod>2026-07-31T12:38:20.087Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-setcap-used-to-assign-cap-setgid-setgid-capability-to-a-binary-3a716279</loc>
    <lastmod>2026-07-31T12:38:18.282Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-query-for-system-language-using-reg-exe-c43a5405</loc>
    <lastmod>2026-07-30T05:00:10.914Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-audit-inbox-rule-creation-or-update-with-email-hiding-actions-d3577be1</loc>
    <lastmod>2026-07-31T12:18:43.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-rdp-service-new-connection-attempt-logged-598290cf</loc>
    <lastmod>2026-07-31T12:25:44.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-application-telemetry-syn-port-scan-targeting-a-host-974be8d2</loc>
    <lastmod>2026-07-31T12:25:42.307Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-network-service-logs-nmap-xmas-scan-targeting-detection-d7553d7b</loc>
    <lastmod>2026-07-31T12:25:40.575Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-nmap-os-scan-targeting-via-application-logtype-5002-e8a677fd</loc>
    <lastmod>2026-07-31T12:25:38.679Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-nmap-null-scan-targeting-logtype-5003-68b8547b</loc>
    <lastmod>2026-07-31T12:25:36.387Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-nmap-fin-scan-targeting-detection-application-logtype-5005-eae8c0c8</loc>
    <lastmod>2026-07-31T12:25:34.764Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-user-shell-folders-value-modification-via-reg-exe-or-powershell-8f3ab69a</loc>
    <lastmod>2026-07-30T05:12:08.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kernel-driver-utility-kdu-and-hamakaze-exe-execution-e76ca062</loc>
    <lastmod>2026-07-30T04:58:04.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-devcon-exe-disables-vmware-vmci-device-via-vmci-driver-identifiers-85f520e7</loc>
    <lastmod>2026-07-31T13:29:04.984Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-disable-windows-credential-guard-by-zeroing-enablevirtualiz-73921b9c</loc>
    <lastmod>2026-07-30T05:18:35.852Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-delete-of-credential-guard-enablevirtualizationbasedsecurity-or-d645ef86</loc>
    <lastmod>2026-07-30T05:16:14.374Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-tampering-of-credential-guard-registry-keys-deviceg-c17d47b7</loc>
    <lastmod>2026-07-31T13:28:18.524Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-amsi-disabled-by-registry-value-modification-amsienable-aa37cbb0</loc>
    <lastmod>2026-07-30T05:17:38.684Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-registry-modification-of-wmi-autologger-sessions-via-re-d7b81144</loc>
    <lastmod>2026-07-31T13:24:53.366Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-amsi-registry-tampering-via-reg-exe-or-powershell-comma-7dbbcac2</loc>
    <lastmod>2026-07-31T13:24:27.355Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-writing-by-executables-to-uncommon-locations-1cf465a1</loc>
    <lastmod>2026-07-31T13:06:53.167Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-browser-process-opens-html-from-downloads-folder-538c5851</loc>
    <lastmod>2026-07-31T12:23:15.102Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-child-process-spawned-by-node-js-parent-react2shell-pattern-c70834fa</loc>
    <lastmod>2026-07-31T12:16:53.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-github-self-hosted-runner-worker-listener-spawn-and-con-5bac7a56</loc>
    <lastmod>2026-07-31T13:31:10.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-npm-install-of-known-malicious-packages-sh-bae7c70b</loc>
    <lastmod>2026-07-31T12:17:41.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-npm-installs-known-shai-hulud-2-0-malicious-packages-and--514f533b</loc>
    <lastmod>2026-07-31T12:17:33.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-execution-with-renamed-schtasks-exe-binary-f91e51c9</loc>
    <lastmod>2026-07-30T05:02:48.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-werfaultsecure-to-msmpeng-exe-with-dbgcore-dll-dbghelp-dl-387df17d</loc>
    <lastmod>2026-07-31T13:24:01.955Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-to-lsass-with-dbgcore-dll-dbghelp-dll-in-calltrace-9f5c1d59</loc>
    <lastmod>2026-07-31T13:23:50.697Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-image-load-dbgcore-dll-dbghelp-dll-from-user-or-public-paths-416bc4a2</loc>
    <lastmod>2026-07-31T13:12:39.897Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-guardduty-detector-deleted-or-disabled-via-deletedetector-updated-d2656e78</loc>
    <lastmod>2026-07-31T12:27:14.032Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/werfaultsecure-loads-dbgcore-dll-or-dbghelp-dll-windows-image-load-8a2f4b1c</loc>
    <lastmod>2026-07-31T12:20:04.226Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-grixba-reconnaissance-tool-command-line-parameter-combo-af688c76</loc>
    <lastmod>2026-07-31T12:17:19.222Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-script-interpreter-launching-trufflehog-or-gitleaks-credential-scanner-0f60b28c</loc>
    <lastmod>2026-07-30T05:08:56.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/arcsoc-exe-spawns-script-and-command-interpreters-windows-process-creation-8e95e73e</loc>
    <lastmod>2026-07-31T13:24:31.470Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-arcsoc-exe-creates-potentially-malicious-script-or-executable-files-e890acee</loc>
    <lastmod>2026-07-31T13:02:18.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-script-interpreter-spawns-trufflehog-or-gitleaks-f0025a69</loc>
    <lastmod>2026-07-31T12:41:13.236Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-bun-environment-js-executed-via-bun-exe-from-node-exe-5299fadf</loc>
    <lastmod>2026-07-31T12:17:39.804Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-matching-shai-hulud-command-line-indicators-540703fb</loc>
    <lastmod>2026-07-31T12:17:37.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-bun-runtime-execution-of-bun-environment-js-from-node-parent-process-eb827bbd</loc>
    <lastmod>2026-07-31T12:17:31.700Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-shai-hulud-and-sha1hulud-command-line-indicators-11bb9b26</loc>
    <lastmod>2026-07-31T12:17:29.948Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-file-upload-clickfix-lure-via-browser-to-command-execut-b5b29e4e</loc>
    <lastmod>2026-07-30T05:07:33.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-execution-of-wsass-exe-leveraging-werfaultsecure-exe-via-wer-589ac73f</loc>
    <lastmod>2026-07-31T13:34:50.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-gpme-used-to-modify-default-domain-and-default-domain-controller-dcff7e85</loc>
    <lastmod>2026-07-30T04:50:58.950Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-unsigned-node-native-add-on-loaded-e5f5c693</loc>
    <lastmod>2026-07-31T13:09:22.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-5136-default-domain-gpo-container-modification-e5ac86dd</loc>
    <lastmod>2026-07-31T12:51:53.086Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-events-suspicious-filenames-embedding-base64-decoded-bash-commands-179b3686</loc>
    <lastmod>2026-07-31T12:37:36.604Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-creation-long-filename-pattern-100-chars-excluding-known-system-paths-11629c4d</loc>
    <lastmod>2026-07-31T12:18:48.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-creation-filegrabber-or-curl-post-exfiltration-indicators-for-amos-e710a880</loc>
    <lastmod>2026-07-31T12:17:15.362Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-file-persistence-indicators-for-atomic-macos-stealer-artifacts-e710a880</loc>
    <lastmod>2026-07-31T12:17:13.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-asa-webvpn-get-requests-via-proxy-logs-indicating-exploitation--15697955</loc>
    <lastmod>2026-07-31T12:15:38.733Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-clickfix-filefix-clipboard-phishing-leading-to-suspicious-mshta-powershe-d487ed4a</loc>
    <lastmod>2026-07-30T05:06:34.616Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connection-via-finger-exe-2fdaf50b</loc>
    <lastmod>2026-07-31T13:13:40.340Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-finger-exe-dns-queries-indicating-potential-c2-command-fetching-c082c2b0</loc>
    <lastmod>2026-07-31T13:00:24.077Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-kerberos-ticket-requests-from-powershell-using-kerberosreques-caa9a802</loc>
    <lastmod>2026-07-30T04:55:59.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-enable-disable-via-win32-terminalservicesetting-wmi-tool-commands-4b8f6d3a</loc>
    <lastmod>2026-07-30T04:59:11.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-svchost-exe-uncommon-command-line-parameter-process-creation-f17211f1</loc>
    <lastmod>2026-07-30T05:10:07.542Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-for-f-tokens-with-recursive-dir-listing-2782fbd8</loc>
    <lastmod>2026-07-30T05:06:37.987Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-suspicious-space-padded-typedpaths-details-string-8f2a5c3d</loc>
    <lastmod>2026-07-30T05:22:36.031Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-runmru-path-with-suspicious-space-characters-and-delimiter-7a1b4c5e</loc>
    <lastmod>2026-07-30T05:22:30.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-explorer-command-lines-with-unicode-whitespace-padding--3ae9974a</loc>
    <lastmod>2026-07-30T05:06:36.403Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-advanced-installer-psf-ai-stubs-executables-with-originalfilename-af5732ed</loc>
    <lastmod>2026-07-30T04:51:51.210Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-vpn-ssl-settings-edited-via-event-logs-8b5dacf2</loc>
    <lastmod>2026-07-31T12:44:59.655Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-user-group-edited-vpn-access-impact-69ffc84e</loc>
    <lastmod>2026-07-31T12:44:58.071Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-event-addition-of-vpn-ssl-web-portal-2bfb6216</loc>
    <lastmod>2026-07-31T12:44:56.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-local-user-added-user-local-via-event-logs-ddbbe845</loc>
    <lastmod>2026-07-31T12:44:54.226Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-new-firewall-policy-added-via-event-logs-f24ab7a8</loc>
    <lastmod>2026-07-31T12:44:51.122Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-firewall-address-object-added-5c8d7b41</loc>
    <lastmod>2026-07-31T12:44:49.440Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-administrator-account-added-via-system-admin-event-cd0a4943</loc>
    <lastmod>2026-07-31T12:44:47.363Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-application-logs-wsus-deserialization-exploitation-indicators-for-cve-20-e5f66e87</loc>
    <lastmod>2026-07-31T12:17:07.127Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmd-exe-and-powershell-child-processes-of-wsus-wsusservice-exe-on-win-43259cc4</loc>
    <lastmod>2026-07-31T12:17:05.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-add-wfp-filter-rules-via-bfe-parameters-path-1f1d8209</loc>
    <lastmod>2026-07-30T05:22:39.559Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-speechruntime-exe-child-process-creation-78f10490</loc>
    <lastmod>2026-07-30T05:05:35.707Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-child-process-spawned-by-winrshost-exe-79df3f68</loc>
    <lastmod>2026-07-30T05:14:30.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrs-exe-local-command-execution-via-localhost-loopback-bcfece3d</loc>
    <lastmod>2026-07-30T05:14:28.684Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-aws-cloudtrail-execution-of-trufflehog-via-trufflehog-user-agent-a840e606</loc>
    <lastmod>2026-07-31T12:27:21.005Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-write-to-apache-tomcat-webapps-root-as-jsp-from-dotnet-j-89c42960</loc>
    <lastmod>2026-07-31T13:06:39.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-commvault-qlogin-argument-injection-hints-for-localadmi-ff0225a0</loc>
    <lastmod>2026-07-31T12:17:03.238Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-commvault-qoperation-exe-webshell-drop-via-file-to-jsp--bd3b3fff</loc>
    <lastmod>2026-07-31T12:16:59.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-commvault-qlogin-exe-targeting-publicsharinguser-with-a-guid-password-917789e1</loc>
    <lastmod>2026-07-31T12:16:57.678Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-isatap-router-address-configuration-set-microsoft-windows-iphlpsvc-d22df9cd</loc>
    <lastmod>2026-07-31T12:56:36.163Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-smb-server-share-access-without-signing-or-encryption-event-4000-8d91f6e4</loc>
    <lastmod>2026-07-31T12:56:29.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-monitor-file-access-to-signal-desktop-config-json-and-db-sqlite-5d6c375a</loc>
    <lastmod>2026-07-31T12:54:40.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-vpc-flow-logs-deleted-via-ec2-deleteflowlogs-e386b9b5</loc>
    <lastmod>2026-07-31T12:27:31.729Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-enableregion-api-command-monitoring-for-account-region-enablement-a5ffb6ea</loc>
    <lastmod>2026-07-31T12:27:22.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-consolelogin-failed-authentication-events-6393e346</loc>
    <lastmod>2026-07-31T12:27:08.610Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-s3-bucket-deletion-observed-in-cloudtrail-39c9f26d</loc>
    <lastmod>2026-07-31T12:27:07.052Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-baaupdate-exe-spawns-suspicious-utilities-9f38c1db</loc>
    <lastmod>2026-07-31T13:24:57.183Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-baaupdate-exe-suspicious-dll-loads-from-publicly-writable-paths-6e8fe0a8</loc>
    <lastmod>2026-07-31T13:12:21.493Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-kaspersky-endpoint-security-stopped-via-command-line-init-d-systemctl-36388120</loc>
    <lastmod>2026-07-31T12:38:00.014Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-kms-imported-key-material-use-importkeymaterial-deleteimportedkey-1279262f</loc>
    <lastmod>2026-07-31T12:28:11.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-consolelogin-success-events-where-mfaused-is-no-77caf516</loc>
    <lastmod>2026-07-31T12:27:10.431Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-logs-repository-archived-unarchived-status-change-dca8991c</loc>
    <lastmod>2026-07-31T12:24:34.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-log-repository-pages-changed-to-public-0c46d4f4</loc>
    <lastmod>2026-07-31T12:24:27.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-restic-backup-tool-command-line-indicators-6ddff2e8</loc>
    <lastmod>2026-07-30T04:58:36.732Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-systemctl-mask-used-to-disable-power-management-targets-c172b7b5</loc>
    <lastmod>2026-07-31T12:41:27.652Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-python-http-server-execution-via-command-line-http-server-simplehttpserver-3f0f5957</loc>
    <lastmod>2026-07-31T12:40:06.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditctl-used-with-d-to-delete-all-audit-rules-bed26dea</loc>
    <lastmod>2026-07-31T12:37:58.428Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-self-launching-executable-running-as-sacrificial-proces-bafd07c6</loc>
    <lastmod>2026-07-31T12:23:16.963Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-sts-getcalleridentity-user-agent-trufflehog-enumeration-9b1b8e9b</loc>
    <lastmod>2026-07-31T12:28:38.894Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-winscp-execution-from-non-default-install-path-7674f8ef</loc>
    <lastmod>2026-07-31T12:23:28.167Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winscp-cli-ftp-sftp-open-attempt-via-command-c1477deb</loc>
    <lastmod>2026-07-31T12:23:26.461Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wsl-process-execution-of-kali-linux-on-windows-6f1a11aa</loc>
    <lastmod>2026-07-30T05:15:46.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wsl-kali-linux-installation-via-wsl-exe-install-i-eca8ae39</loc>
    <lastmod>2026-07-30T05:15:44.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-goanywhere-mft-exploitation-suspicious-powershell-and-cmd-child-process--6c76b3d0</loc>
    <lastmod>2026-07-31T12:15:36.990Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-sudo-chroot-command-execution-f2bed782</loc>
    <lastmod>2026-07-31T12:38:29.054Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-alert-on-nsswitch-conf-creation-outside-standard-paths-10ac0730</loc>
    <lastmod>2026-07-31T12:15:59.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-runmru-key-deletion-3a9b8c1e</loc>
    <lastmod>2026-07-30T05:16:25.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-reg-exe-deletion-of-runmru-registry-key-c11aecef</loc>
    <lastmod>2026-07-30T04:59:30.110Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-trufflehog-execution-on-windows-via-trufflehog-exe-process-launch-44030449</loc>
    <lastmod>2026-07-30T04:58:46.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-execution-detect-edr-freeze-exe-launch-c598cc0c</loc>
    <lastmod>2026-07-31T13:32:23.604Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-of-trufflehog-with-secret-search-platform-arguments-d7a650c4</loc>
    <lastmod>2026-07-31T12:40:02.171Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-curl-data-exfiltration-attempt-from-npm-package-to-webhook-site-efd2eb09</loc>
    <lastmod>2026-07-31T12:17:35.963Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-creation-of-malicious-github-workflows-shai-hulud-workflow-yamls-0aba5685</loc>
    <lastmod>2026-07-31T12:17:28.131Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-werfaultsecure-exe-ppl-tampering-with-dump-impair-param-1f0b4cac</loc>
    <lastmod>2026-07-30T05:13:26.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-deletion-of-iis-log-files-0649be4a</loc>
    <lastmod>2026-07-31T13:35:26.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-velociraptor-child-process-execution-indicators-4bc90587</loc>
    <lastmod>2026-07-30T05:09:51.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-uninstall-windowsfeature-remove-windowsfeature-removing-windo-c443012c</loc>
    <lastmod>2026-07-30T04:56:51.128Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vbscript-registry-write-attempt-via-wscript-shell-regwrite-on-windows-921aa10f</loc>
    <lastmod>2026-07-30T05:12:13.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-vbscript-registry-modification-attempt-via-wscript-shell-regwrite-2a0a169d</loc>
    <lastmod>2026-07-31T13:22:45.222Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-creation-of-funksec-files-used-as-funklocker-ransomware-extension-2c76a22b</loc>
    <lastmod>2026-07-31T12:17:43.818Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dns-queries-to-low-reputation-etlds-alphasoc-list-cf5ee356</loc>
    <lastmod>2026-07-31T12:18:57.418Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-traffic-with-hello-world-1-0-user-agent-using-get-1712bafe</loc>
    <lastmod>2026-07-31T12:46:04.526Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-crushftp-spawns-powershell-cmd-and-lolbins-indicative-o-0fdc7c7f</loc>
    <lastmod>2026-07-31T12:16:52.041Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reagentc-exe-winre-disabled-via-disable-command-line-switch-db1c21e4</loc>
    <lastmod>2026-07-30T04:59:14.574Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-registry-changes-via-wmi-stdregprov-write-methods-c453ab7a</loc>
    <lastmod>2026-07-30T05:15:14.212Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-stdregprov-registry-enumeration-via-wmic-exe-a0e417e2</loc>
    <lastmod>2026-07-30T05:15:12.331Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-wmic-exe-sets-user-password-to-never-expire-7864a175</loc>
    <lastmod>2026-07-30T05:14:36.676Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-write-via-command-line-tools-to-sharepoint-layouts-web-assets-1f0489be</loc>
    <lastmod>2026-07-31T13:06:41.829Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-attachment-file-created-in-outlook-temporary-directories-fabb0e80</loc>
    <lastmod>2026-07-31T13:05:04.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/iis-web-logs-sharepoint-toolpane-and-spinstall0-post-get-indicative-of-cve-2025--48d053db</loc>
    <lastmod>2026-07-31T12:16:49.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-indicators-of-sharepoint-spinstall0-aspx-encoded-comman-7477881c</loc>
    <lastmod>2026-07-30T03:42:35.904Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-in-sharepoint-web-server-extensions-indicative-of-cve-2025-ba479447</loc>
    <lastmod>2026-07-31T12:16:29.677Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrar-rar-creating-files-in-startup-folder-paths-74a2b37d</loc>
    <lastmod>2026-07-31T13:08:39.531Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-via-schtasks-exe-using-sshd-ssh-exe-for-tunnel-s-2daa93a0</loc>
    <lastmod>2026-07-30T05:04:45.987Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-delete-remove-shellex-contextmenuhandlers-epp-key-for-scan-with-72a0369a</loc>
    <lastmod>2026-07-30T05:16:12.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-set-mppreference-low-moderate-high-severethreatdefaultaction--1e8a9b4d</loc>
    <lastmod>2026-07-31T13:28:57.444Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-disables-defender-wmi-autologger-sessions-by-setting-start-to-0-a1b2c3d4</loc>
    <lastmod>2026-07-30T04:59:38.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-deletion-of-windows-defender-context-menu-registry-hand-b9e8c7d6</loc>
    <lastmod>2026-07-31T13:28:59.755Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-writes-by-adexplorer-creating-complete-ad-snapshot-dat-files-0a1255c5</loc>
    <lastmod>2026-07-31T13:07:41.981Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-filefix-style-command-evidence-in-typedpaths-url1-4fee3d51</loc>
    <lastmod>2026-07-30T05:19:45.040Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-hollowreaper-exe-execution-85d23b42</loc>
    <lastmod>2026-07-31T13:32:42.259Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-doppelganger-exe-lsass-memory-dumper-d474c8fe</loc>
    <lastmod>2026-07-31T13:32:18.981Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-regsvr32-use-by-notepad-installer-for-cve-20-933f0bb5</loc>
    <lastmod>2026-07-31T12:16:27.968Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-kerberos-coercion-tooling-via-base64-credential--0ed99dda</loc>
    <lastmod>2026-07-31T13:35:58.360Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-query-contains-base64-kerberos-coercion-credential-target-signature-e7a21b5f</loc>
    <lastmod>2026-07-31T13:00:30.084Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ad-dns-record-changes-containing-kerberos-credential-target-information--b07e58cf</loc>
    <lastmod>2026-07-31T12:53:06.549Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dns-detection-of-suspicious-kerberos-coercion-pattern-in-query-payload-5588576c</loc>
    <lastmod>2026-07-31T12:45:15.350Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-trusted-path-bypass-via-spoofed-system-directory-with-extra-s-0cbe38c0</loc>
    <lastmod>2026-07-31T13:12:41.926Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-curl-wget-download-to-temporary-dir-followed-by-sh-c-execution-a2d9e2f3</loc>
    <lastmod>2026-07-31T12:38:44.926Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-cve-2025-33053-webdav-rce-via-iediagcmd-exe-or-customshellhost-abe06362</loc>
    <lastmod>2026-07-31T12:16:06.448Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-indicating-rce-attempt-via-cve-2025-33053-and-webdav-host-9a2d8b3e</loc>
    <lastmod>2026-07-31T12:16:03.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-discovery-via-registry-queries-reg-exe-and-powershell-0022869c</loc>
    <lastmod>2026-07-31T13:29:16.296Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sharpsuccessor-exe-execution-for-privilege-escalation-38a1ac5f</loc>
    <lastmod>2026-07-31T13:34:19.406Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/regasm-exe-process-execution-missing-command-line-and-assembly-path-windows-651f87f7</loc>
    <lastmod>2026-07-30T05:00:19.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-server-audit-destructive-sql-statements-drop-truncate-00321fee</loc>
    <lastmod>2026-07-31T12:47:47.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-process-loads-bitsproxy-dll-via-image-load-e700ff14</loc>
    <lastmod>2026-07-31T12:19:51.232Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-to-malware-hosting-and-url-shortener-domains-f8c1e80b</loc>
    <lastmod>2026-07-31T13:00:15.720Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-audit-mknod-syscall-used-to-create-special-files-710bdbce</loc>
    <lastmod>2026-07-31T12:36:48.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-sysinfo-syscall-used-for-system-information-discovery-b207d563</loc>
    <lastmod>2026-07-31T12:36:43.595Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-tacticalrmm-agent-installed-with-api-auth-flags-pointing-to-remote-rmm-s-2db93a3f</loc>
    <lastmod>2026-07-30T05:01:52.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-obfuscated-com-msi-installation-via-windowsinstaller-installe-7b6a7418</loc>
    <lastmod>2026-07-30T04:54:49.406Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-clear-disable-kernel-ring-buffer-via-syslog-syscall-auditd-a0-5-6-eca5e022</loc>
    <lastmod>2026-07-31T12:36:34.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vshadow-exe-proxy-execution-via-exec-script-command-d7c75059</loc>
    <lastmod>2026-07-30T05:12:37.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-aslr-disabled-via-personality-syscall-sysctl-or-proc-randomize-va-space-e497a24e</loc>
    <lastmod>2026-07-31T12:35:59.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-creates-delegated-service-account-new-adserviceaccount-in-tar-0ea8db81</loc>
    <lastmod>2026-07-31T13:28:12.659Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-modify-dmsa-link-attribute-msds-managedaccountprecededbylink-in-ad-9b111d8e</loc>
    <lastmod>2026-07-31T13:19:36.707Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-new-adserviceaccount-creating-delegated-service-accounts-in-specific--02122374</loc>
    <lastmod>2026-07-31T13:17:53.681Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-sysrq-trigger-or-configuration-path-access-ea61bb82</loc>
    <lastmod>2026-07-31T12:36:23.903Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-registry-save-export-of-third-party-credential-paths-cc1abf27</loc>
    <lastmod>2026-07-30T05:00:39.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-deno-writing-files-to-appdata-from-remote-https-sources-6c0ce3b6</loc>
    <lastmod>2026-07-31T13:02:34.974Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-by-non-browser-processes-to-browser-credential-storage-a1dfd976</loc>
    <lastmod>2026-07-31T13:01:33.972Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-events-kerberos-tgt-requests-with-preauth-disabled-and-rc4-hmac-3e2f1b2c</loc>
    <lastmod>2026-07-31T12:53:04.665Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-http-connections-with-suspicious-user-agent-containing-katz-ontop-834c6d2f</loc>
    <lastmod>2026-07-31T12:17:26.124Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dns-queries-to-katz-stealer-associated-domains-6b0c762f</loc>
    <lastmod>2026-07-31T12:17:24.355Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-of-katz-stealer-dlls-e6c7ab7c</loc>
    <lastmod>2026-07-31T12:17:22.598Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-to-known-katz-stealer-domains-9c3d6e32</loc>
    <lastmod>2026-07-31T12:17:20.978Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rmm-tool-meshagent-execution-with-renamed-meshservicename-b471f462</loc>
    <lastmod>2026-07-30T05:01:34.727Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-meshagent-remote-access-tool-command-line-execution-indicators-2fbbe9ff</loc>
    <lastmod>2026-07-30T05:01:27.784Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-impacket-secretsdump-sessionresume-file-creation-indicators-03f4ca17</loc>
    <lastmod>2026-07-31T13:03:42.320Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-meshagent-execution-with-renamed-instance-via-meshservicename-bd3b5eaa</loc>
    <lastmod>2026-07-31T12:42:58.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detect-meshagent-remote-access-execution-via-meshservicename-22c45af6</loc>
    <lastmod>2026-07-31T12:42:56.411Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-java-webshell-upload-attempts-via-post-to-sap-netviewer-uris-639b893f</loc>
    <lastmod>2026-07-31T12:15:57.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detections-for-sap-netviewer-jsp-webshell-command-execution-via-cmd-pa-94e12f41</loc>
    <lastmod>2026-07-31T12:15:55.914Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-crash-dump-reporting-via-wer-event-id-1001-882fbe50</loc>
    <lastmod>2026-07-31T12:56:59.236Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-sap-netweaver-on-windows-using-command-and-script-in-5b304bcb</loc>
    <lastmod>2026-07-31T12:15:53.508Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-command-child-process-from-sap-netweaver-work-root-directories-69dea60b</loc>
    <lastmod>2026-07-31T12:15:51.449Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-suspicious-sap-netweaver-jsp-java-class-file-creation-86a7c91f</loc>
    <lastmod>2026-07-31T12:15:49.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-events-sap-netweaver-jsp-java-class-webshell-file-creation-5b91409c</loc>
    <lastmod>2026-07-31T12:15:47.254Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-inline-javascript-execution-by-node-js-node-exe-on-windows-8537c866</loc>
    <lastmod>2026-07-30T05:07:45.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-javascript-via-node-exe-ba3874b9</loc>
    <lastmod>2026-07-30T05:05:17.500Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-library-ms-file-creation-by-7z-winrar-explorer-5a7132c0</loc>
    <lastmod>2026-07-31T12:15:41.236Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmd-exe-spawned-by-w3wp-exe-with-centrestack-portal-config-parent-com-2d79e371</loc>
    <lastmod>2026-07-31T12:15:43.440Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/crushftp-service-spawning-suspicious-script-and-shell-child-processes-on-windows-459628e3</loc>
    <lastmod>2026-07-31T12:15:45.437Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-minint-key-added-to-disable-security-event-logging-on-reboot-8839e550</loc>
    <lastmod>2026-07-30T05:18:31.669Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-disable-security-event-logging-via-registry-minint-key-1a4bd6af</loc>
    <lastmod>2026-07-31T13:30:14.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-history-file-access-attempt-via-consolehost-history-txt-f4ff7323</loc>
    <lastmod>2026-07-30T04:54:54.555Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-runmru-tampering-with-http-https-and-script-execution-indicator-f5fe36cf</loc>
    <lastmod>2026-07-30T05:21:44.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-lnk-command-line-whitespace-padding-beyond-u-dd8756e7</loc>
    <lastmod>2026-07-30T05:07:50.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-unconstrained-delegation-discovery-via-get-adcomputer-script-block-cdfa73b6</loc>
    <lastmod>2026-07-31T13:19:57.461Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-adfind-exe-execution-for-active-directory-recon-514e7e3e</loc>
    <lastmod>2026-07-30T04:57:41.362Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-http-requests-to-low-reputation-tlds-or-suspicious-executable-file-types-68c2c604</loc>
    <lastmod>2026-07-31T12:45:26.641Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-notepad-password-file-discovery-via-process-creation-3b4e950b</loc>
    <lastmod>2026-07-30T04:53:08.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-suspicious-ksproxy-ax-loading-potential-cve-2024-35250-activit-17ce9373</loc>
    <lastmod>2026-07-31T12:14:35.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-persistence-wmic-used-to-add-run-registry-values-via-reg-exe-c80e66d8</loc>
    <lastmod>2026-07-31T13:24:55.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-execution-using-tor-socks-proxy-socks-and-onion-in-command-line-e99375eb</loc>
    <lastmod>2026-07-31T12:17:45.809Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-suspicious-wdac-policy-file-creation-in-codeintegrity-path-1d2de8a6</loc>
    <lastmod>2026-07-31T13:07:36.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-using-system-process-names-9f8573c9</loc>
    <lastmod>2026-07-30T05:05:03.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-via-schtasks-exe-with-curl-and-powershell-comman-1d174d38</loc>
    <lastmod>2026-07-30T05:04:30.980Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-nimscan-exe-execution-via-known-file-hashes-4fd6b1c7</loc>
    <lastmod>2026-07-30T04:58:16.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mmc-executes-files-with-rlo-reversed-extensions-in-process-command-line-9cfe4b27</loc>
    <lastmod>2026-07-30T04:51:02.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-conhost-exe-child-processes-dfa03a09</loc>
    <lastmod>2026-07-31T13:28:06.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mmc-loading-script-engine-dlls-vbscript-jscript-a9c73e8b</loc>
    <lastmod>2026-07-31T13:12:38.110Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-public-folder-file-creation-with-suspicious-script-or-binary-extensions-b447f7de</loc>
    <lastmod>2026-07-31T13:07:03.925Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-clfs-sys-image-loaded-from-potentially-suspicious-user-or-temp-paths-fb4e2211</loc>
    <lastmod>2026-07-31T13:08:56.668Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-shell-spawned-by-rsync-without-expected-e-flag-297241f3</loc>
    <lastmod>2026-07-31T12:40:22.120Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-eventlog-channelaccess-sddl-tampering-detection-ba226dcf</loc>
    <lastmod>2026-07-30T05:19:07.791Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/m365-audit-successful-intune-company-portal-login-tied-to-cmsi-request-13f2d3f5</loc>
    <lastmod>2026-07-31T12:33:29.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-application-error-possible-cve-2024-49113-ldap-nightmare-attempt-lsass-e-3f2c93c7</loc>
    <lastmod>2026-07-31T12:14:41.103Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-microsoft-quickassist-exe-execution-e20b5b14</loc>
    <lastmod>2026-07-30T04:59:02.741Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-from-quickassist-exe-to-remoteassistance-support-services-mi-882e858a</loc>
    <lastmod>2026-07-31T13:00:37.519Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-lambda-function-url-configuration-created-ec541962</loc>
    <lastmod>2026-07-31T12:28:12.676Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-ec2-importkeypair-cloudtrail-activity-92f84194</loc>
    <lastmod>2026-07-31T12:27:43.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-successful-deletion-of-saml-provider-ccd6a6c8</loc>
    <lastmod>2026-07-31T12:27:38.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-more-com-spawning-vbc-exe-lummac-stealer-behavior-19b3806e</loc>
    <lastmod>2026-07-31T12:14:57.186Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-targeting-rat-client-config-files-in-roaming-appdata-2f3039c8</loc>
    <lastmod>2026-07-31T12:14:49.308Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-cmd-exe-and-powershell-encodedcommand-from-c-f007b877</loc>
    <lastmod>2026-07-31T12:14:43.795Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-rds-cluster-modifydbcluster-or-deletedbcluster-activity-457cc9ac</loc>
    <lastmod>2026-07-31T12:28:19.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-setup16-exe-execution-triggered-by-custom-lst-file-99c8be4f</loc>
    <lastmod>2026-07-30T05:05:24.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-shellexec-rundll-via-shell32-dll-ordinal-in-parent-command-li-8823e85d</loc>
    <lastmod>2026-07-30T05:03:41.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-event-detect-unicode-right-to-left-override-extension-spoofing-979baf41</loc>
    <lastmod>2026-07-31T13:07:07.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-azurefd-net-excluding-common-browsers-and-known-f-8cb4d14e</loc>
    <lastmod>2026-07-30T03:45:52.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-runmru-powershell-or-wmic-execution-command-indicators-a7df0e9e</loc>
    <lastmod>2026-07-30T05:22:05.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-run-dialog-command-history-in-runmru-registry-f9d091f6</loc>
    <lastmod>2026-07-31T12:23:44.299Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-access-to-browser-credential-files-by-uncommon-processes-4b60e527</loc>
    <lastmod>2026-07-31T12:19:07.844Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-module-removal-via-iis-configuration-event-id-29-9e1a1fdf</loc>
    <lastmod>2026-07-31T12:50:00.104Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-new-http-module-added-via-iis-configuration-eventid-29-dd857d3e</loc>
    <lastmod>2026-07-31T12:49:58.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/iis-http-logging-disabled-via-system-webserver-httplogging-configuration-change-e8ebd53a</loc>
    <lastmod>2026-07-31T12:49:56.512Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-configuration-change-disables-etw-logging-processing-option-a5b40a90</loc>
    <lastmod>2026-07-31T12:49:54.841Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-meshagent-remote-command-execution-via-cmd-exe-or-powershell-child-proce-74a2b202</loc>
    <lastmod>2026-07-30T05:01:29.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-btunnel-domains-9e02c8ec</loc>
    <lastmod>2026-07-31T13:13:03.127Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gpo-startup-logon-script-added-to-user-or-computer-extensions-123e4e6d</loc>
    <lastmod>2026-07-31T12:54:55.479Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-group-policy-object-attribute-change-adding-privileges-or-local-admins-1c480e10</loc>
    <lastmod>2026-07-31T12:54:53.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-web-access-enabled-via-dism-7e8f2d3b</loc>
    <lastmod>2026-07-31T13:29:23.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-installs-and-configures-powershell-web-access-pswa-5f9c7f1a</loc>
    <lastmod>2026-07-31T13:19:59.410Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-deletes-its-own-executable-image-f01d1f70</loc>
    <lastmod>2026-07-31T13:01:48.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-anydesk-incoming-remote-connection-non-initiated-network-sessions-d58ba5c6</loc>
    <lastmod>2026-07-31T13:14:00.574Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-rsync-used-with-e-to-spawn-a-shell-e2326866</loc>
    <lastmod>2026-07-31T12:40:20.147Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-inline-python-c-calls-os-system-to-spawn-shell-2d2f44ff</loc>
    <lastmod>2026-07-31T12:40:12.341Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-shell-execution-using-nice-utility-093d68c7</loc>
    <lastmod>2026-07-31T12:39:46.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-git-invoked-with-shell-execution-via-redirected-stdin-to-bash-dash-sh-47b3bbd4</loc>
    <lastmod>2026-07-31T12:39:22.934Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-gcc-invocation-used-to-execute-shell-scripts-via-wrapper-9b5de532</loc>
    <lastmod>2026-07-31T12:39:21.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-flock-used-to-launch-an-interactive-shell-4b09c71e</loc>
    <lastmod>2026-07-31T12:39:19.310Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-find-command-using-exec-to-spawn-a-shell-6adfbf8f</loc>
    <lastmod>2026-07-31T12:39:17.192Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-detect-env-based-shell-invocation-using-common-interactive-shells-bed978f8</loc>
    <lastmod>2026-07-31T12:38:54.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-capsh-invoked-with-shell-commandline-pattern-db1ac3be</loc>
    <lastmod>2026-07-31T12:38:23.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-shell-invocation-via-awk-gawk-mawk-nawk-system-in-commandline-8c1a5675</loc>
    <lastmod>2026-07-31T12:38:02.938Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-task-scheduler-dll-taskschd-dll-loaded-from-uncommon-paths-by-a-process-3b92a1d0</loc>
    <lastmod>2026-07-31T12:19:57.020Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-ssh-used-to-invoke-a-shell-via-proxycommand-and-embedded-local-command-opt-8737b7f6</loc>
    <lastmod>2026-07-31T12:40:34.559Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-python-function-execution-warnings-in-excel-17e53739</loc>
    <lastmod>2026-07-30T05:20:33.706Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-client-queries-for-put-io-api-put-io-or-upload-put-io-8b69fd42</loc>
    <lastmod>2026-07-31T12:49:24.434Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-set-p-file-append-override-pattern-65e4c134</loc>
    <lastmod>2026-07-31T12:21:29.118Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-execution-of-chflags-to-set-hidden-file-flags-3b2c1059</loc>
    <lastmod>2026-07-31T12:41:57.098Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-audit-logs-strongauthenticationrequirement-set-to-disabled-or-state--b18454c8</loc>
    <lastmod>2026-07-31T12:31:08.102Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-bcp-exe-data-export-from-mssql-c615d676</loc>
    <lastmod>2026-07-31T13:25:06.884Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-management-ux-audit-user-risk-and-mfa-registration-policy-updated-d4c7758e</loc>
    <lastmod>2026-07-31T12:31:05.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detect-hdiutil-disk-image-mounting-via-attach-or-mount-commands-bf241472</loc>
    <lastmod>2026-07-31T12:42:26.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-hdiutil-disk-image-creation-execution-1cf98dc2</loc>
    <lastmod>2026-07-31T12:42:24.509Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-masquerading-as-svchost-exe-via-binary-name-and-location-be58d2e2</loc>
    <lastmod>2026-07-30T05:10:04.239Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ammy-admin-agent-execution-via-rundll32-7da7809e</loc>
    <lastmod>2026-07-31T12:22:44.466Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/anyviewer-rmm-remote-session-executes-cmd-exe-via-avcore-exe-bc533330</loc>
    <lastmod>2026-07-31T12:22:46.038Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-zonemap-proxy-policy-tampering-via-setvaluekeyint-16a4c7b3</loc>
    <lastmod>2026-07-31T12:15:03.015Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-oleview-and-aclui-dll-side-loading-on-windows-0f3a9db2</loc>
    <lastmod>2026-07-31T12:14:59.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-clipboard-data-collection-via-pbpaste-command-execution-d8af0da1</loc>
    <lastmod>2026-07-31T12:18:55.411Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-suspicious-updates-to-domain-group-esx-admins-47a1658b</loc>
    <lastmod>2026-07-31T12:14:38.951Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-to-crypto-wallet-files-by-uncommon-applications-f41b0311</loc>
    <lastmod>2026-07-31T13:01:28.222Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-enterprise-audit-ssh-certificate-authority-config-change-2f575940</loc>
    <lastmod>2026-07-31T12:24:39.568Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-repository-or-organization-transfer-events-04ad83ef</loc>
    <lastmod>2026-07-31T12:24:32.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-private-repository-forking-policy-enabled-or-cleared-69b3bd1e</loc>
    <lastmod>2026-07-31T12:24:21.029Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-processes-access-chromium-browser-cookie-and-history-files-c5f37810</loc>
    <lastmod>2026-07-31T12:19:16.829Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-thread-creation-via-cmd-exe-or-powershell-exe-windows-a9d4d3fa</loc>
    <lastmod>2026-07-31T12:19:15.108Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-chain-rdpinit-exe-spawning-notepad-that-executes-cmd-exe-6676896b</loc>
    <lastmod>2026-07-31T12:15:24.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-net-exe-or-powershell-creates-esx-admins-domain-group-c408acfe</loc>
    <lastmod>2026-07-31T12:14:37.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-ending-in-exe-with-no-image-name-f208d6d8</loc>
    <lastmod>2026-07-30T05:08:04.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-execution-of-renamed-boinc-exe-binary-30d07da2</loc>
    <lastmod>2026-07-30T05:02:08.611Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-via-headless-conhost-conhost-exe-056c7317</loc>
    <lastmod>2026-07-31T13:27:57.514Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-headless-child-process-spawned-via-conhost-exe-00ca75ab</loc>
    <lastmod>2026-07-31T12:21:31.090Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-uc-berkeley-boinc-related-software-execution-string-mat-0090b851</loc>
    <lastmod>2026-07-31T12:21:26.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-processes-accessing-microsoft-teams-cookies-or-local-storage-le-65744385</loc>
    <lastmod>2026-07-31T13:01:36.019Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-to-unattend-xml-in-panther-directory-76a26006</loc>
    <lastmod>2026-07-31T12:19:26.466Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-com-clsid-hijacking-via-registry-default-inprocserver32-localserver32-mo-790317c0</loc>
    <lastmod>2026-07-30T05:21:01.972Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-microsoft-teams-executable-launch-88f46b67</loc>
    <lastmod>2026-07-30T05:02:30.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-tampering-dsrmadminlogonbehavior-value-changes-dsrm-b61e87c0</loc>
    <lastmod>2026-07-30T05:19:28.520Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-bitlockertogo-exe-execution-7f2376f9</loc>
    <lastmod>2026-07-31T13:25:12.975Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-dll-sideloading-via-loading-msocrsvc-dll-cdb15e19</loc>
    <lastmod>2026-07-31T13:11:07.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-dll-sideloading-via-mpsvc-dll-loads-5ba243e5</loc>
    <lastmod>2026-07-31T13:11:05.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-suspicion-via-image-load-of-dbgmodel-dll-fef394cd</loc>
    <lastmod>2026-07-31T13:10:31.743Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-ssm-sendcommand-with-successful-execution-38e7f511</loc>
    <lastmod>2026-07-31T12:27:30.105Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-rds-security-group-rule-changes-via-cloudtrail-14f3f1c8</loc>
    <lastmod>2026-07-31T12:27:28.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-elb-alb-security-group-changes-via-applysecuritygroupstoloadbalan-7a4409fc</loc>
    <lastmod>2026-07-31T12:27:26.415Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-security-group-ingress-egress-rule-changes-6fb77778</loc>
    <lastmod>2026-07-31T12:27:24.292Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-createroute-new-network-route-added-to-route-table-c803b2ce</loc>
    <lastmod>2026-07-31T12:27:19.411Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-detect-createnetworkaclentry-new-network-acl-rule-added-e1f7febb</loc>
    <lastmod>2026-07-31T12:27:17.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-detect-assumed-role-imds-activity-outside-ssm-managed-instance-re-352a918a</loc>
    <lastmod>2026-07-31T12:27:15.925Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-secrets-modified-or-deleted-via-api-verbs-58d31a75</loc>
    <lastmod>2026-07-31T12:25:10.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-rolebinding-clusterrolebinding-created-or-modified-via-rbac-api-10b97915</loc>
    <lastmod>2026-07-31T12:25:06.650Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-cronjob-job-create-or-modification-events-batch-api-0c9b3bda</loc>
    <lastmod>2026-07-31T12:24:52.103Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-admission-webhook-configuration-changes-via-api-actions-eed82177</loc>
    <lastmod>2026-07-31T12:24:50.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-microsoft-word-loads-wll-add-in-files-1337afba</loc>
    <lastmod>2026-07-31T12:20:00.054Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regedit-exe-creating-a-pdf-file-145095eb</loc>
    <lastmod>2026-07-31T13:05:57.316Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disablehypervisorenforcedpagingtranslation-set-to-1-7f2954d2</loc>
    <lastmod>2026-07-30T05:18:48.526Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kapeka-backdoor-scheduled-task-creation-on-windows-security-event-4698-6c130acd</loc>
    <lastmod>2026-07-31T12:15:20.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-seed-value-under-cryptography-providers-path-persistence-cbaa3ef3</loc>
    <lastmod>2026-07-31T12:15:14.758Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kapeka-backdoor-autorun-registry-persistence-on-windows-run-keys-c0c67b21</loc>
    <lastmod>2026-07-31T12:15:13.105Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kapeka-backdoor-execution-via-rundll32-exe-with-ordinal-export-1-and-d-argument--e98f741c</loc>
    <lastmod>2026-07-31T12:15:11.364Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kapeka-backdoor-persistence-via-schtasks-or-run-registry-key-64a871dd</loc>
    <lastmod>2026-07-31T12:15:08.618Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kapeka-backdoor-loaded-via-rundll32-exe-a7e6b1f9</loc>
    <lastmod>2026-07-31T12:15:06.465Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-drop-indicator-for-kapeka-decrypted-backdoor-wll-in-appdata-common--20228d05</loc>
    <lastmod>2026-07-31T12:15:04.824Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-enableperiodicbackup-value-set-for-periodic-system-hive-backups-973ef012</loc>
    <lastmod>2026-07-30T05:19:30.293Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-remotekrbrelay-kerberos-relaying-tool-usage-a7664b14</loc>
    <lastmod>2026-07-31T13:33:25.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-remotekrbrelay-smb-relay-module-temp-secrets-dumps-3ab79e90</loc>
    <lastmod>2026-07-31T13:03:26.357Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-execution-of-dsinternals-cmdlets-on-windows-43d91656</loc>
    <lastmod>2026-07-30T04:55:21.811Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpdpapi-tool-execution-on-windows-via-process-command-line-and-pe-metadata-c7d33b50</loc>
    <lastmod>2026-07-31T13:34:05.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-alerts-for-dsinternals-module-cmdlet-usage-846c7a87</loc>
    <lastmod>2026-07-31T13:18:10.277Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-dpapi-backup-key-and-certificate-export-files-7892ec59</loc>
    <lastmod>2026-07-31T13:06:33.912Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-unauthenticated-command-injection-attempts-via-tp-link-archer-ax21-cgi-6c7defa9</loc>
    <lastmod>2026-07-31T12:08:59.565Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-lazagne-password-recovery-tool-execution-c2b86e67</loc>
    <lastmod>2026-07-31T13:33:29.548Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-non-browser-process-connecting-to-azurewebsites-net-5c80b618</loc>
    <lastmod>2026-07-31T13:13:01.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-system-dll-names-in-uncommon-directories-13c02350</loc>
    <lastmod>2026-07-31T13:02:40.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-query-to-azurewebsites-net-by-non-browser-process-e043f529</loc>
    <lastmod>2026-07-31T13:00:21.647Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-csharp-streamer-rat-net-image-loaded-from-temp-tmp-path-windows-6f6afac3</loc>
    <lastmod>2026-07-31T12:14:45.833Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-localtonet-tunneling-subdomains-initiated-3ab65069</loc>
    <lastmod>2026-07-31T13:13:23.346Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-network-connections-to-localtonet-tunneling-subdomains-c4568f5d</loc>
    <lastmod>2026-07-31T12:37:49.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-nscurl-file-download-via-command-line-options-6d8a7cf1</loc>
    <lastmod>2026-07-31T12:42:46.354Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-qemu-execution-with-low-memory-and-network-tunneling-flags-5fc297ae</loc>
    <lastmod>2026-07-30T04:58:59.679Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-recall-enabled-by-registry-disableaidataanalysis-set-to-0-windows-75180c5f</loc>
    <lastmod>2026-07-30T05:19:31.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-recall-enabled-by-deleting-disableaidataanalysis-registry-value-5dfc1465</loc>
    <lastmod>2026-07-30T05:16:16.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-recall-enabled-via-reg-exe-registry-changes-windows-817f252c</loc>
    <lastmod>2026-07-30T04:59:49.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-initiates-network-connection-to-portmap-io-domain-07837ab9</loc>
    <lastmod>2026-07-31T13:13:33.506Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connection-from-process-in-c-users-public-folder-bcb03938</loc>
    <lastmod>2026-07-31T12:20:42.085Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-darkgate-loader-drop-and-execute-via-c-temp-autoit-artifacts-df49c691</loc>
    <lastmod>2026-07-31T12:14:47.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detect-tmutil-adding-time-machine-exclusions-addexclusion-9acf45ed</loc>
    <lastmod>2026-07-31T12:43:57.447Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-disabling-time-machine-via-tmutil-process-execution-2c95fa8a</loc>
    <lastmod>2026-07-31T12:43:55.539Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-tmutil-time-machine-backup-deletion-command-attempt-452df256</loc>
    <lastmod>2026-07-31T12:43:53.952Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-web-browser-launch-from-pdf-office-reader-on-windows-over-http-s-1193d960</loc>
    <lastmod>2026-07-30T05:06:27.442Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-process-all-access-granted-to-uncommon-target-image-a24e5861</loc>
    <lastmod>2026-07-31T13:23:48.477Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-network-connections-to-cloudflared-tunnel-domains-7cd1dcdc</loc>
    <lastmod>2026-07-31T13:13:04.961Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-unusual-file-creation-by-mysqld-exe-with-script-executable-extensions-c61daa90</loc>
    <lastmod>2026-07-31T13:04:30.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-sysctl-execution-for-system-hardware-kernel-discovery-6ff08e55</loc>
    <lastmod>2026-07-31T12:43:41.110Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-processes-spawned-by-keyscrambler-exe-on-windows-ca5583e9</loc>
    <lastmod>2026-07-31T13:36:00.029Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-launchctl-submits-loads-starts-launch-agents-and-daemons-via-process-execu-ae9d710f</loc>
    <lastmod>2026-07-31T12:42:37.407Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-start-neteventsession-packet-event-capture-activity-windo-da34e323</loc>
    <lastmod>2026-07-31T13:19:54.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uac-promptonsecuredesktop-disabled-0d7ceeef</loc>
    <lastmod>2026-07-30T05:23:09.773Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uac-notification-disabled-via-uacdisablenotify-set-to-dword-0x0-c5f6a85d</loc>
    <lastmod>2026-07-30T05:23:08.244Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wbadmin-exe-used-to-recover-dump-sensitive-registry-hives-and-ntds-dit-84972c80</loc>
    <lastmod>2026-07-30T05:12:54.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-file-recovery-from-backup-via-wbadmin-exe-6fe4aa1e</loc>
    <lastmod>2026-07-30T05:12:52.482Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wbadmin-exe-triggered-for-backup-of-sensitive-registry--8b93a509</loc>
    <lastmod>2026-07-30T05:12:50.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-allow-rule-added-via-wmiprvse-exe-eca81e8d</loc>
    <lastmod>2026-07-31T12:49:43.784Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-external-webdav-downloads-leading-to-execution-via-proxy-logs-1ae64f96</loc>
    <lastmod>2026-07-31T12:46:55.403Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-malware-callback-style-network-connections-to-known-suspicious-ports-dbfc7c98</loc>
    <lastmod>2026-07-31T12:37:53.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-adds-windows-firewall-allow-rule-via-new-netfirewallrule-8d31dd2e</loc>
    <lastmod>2026-07-31T12:20:58.698Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-to-outlook-unistore-data-by-uncommon-processes-fc3e237f</loc>
    <lastmod>2026-07-31T12:19:20.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-new-netfirewallrule-adds-windows-allow-firewall-rule-51483085</loc>
    <lastmod>2026-07-31T12:22:21.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-outbound-connections-initiated-by-dialer-exe-microsoft-phone-dialer-37e4024a</loc>
    <lastmod>2026-07-31T13:12:59.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-softperfect-netscan-exe-network-scanner-execution-ca387a8e</loc>
    <lastmod>2026-07-30T04:58:11.261Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regasm-exe-initiating-network-connections-to-public-ips-0531e43a</loc>
    <lastmod>2026-07-31T13:13:57.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-creation-of-python-pth-path-configuration-files-in-site-packages-e3652ba3</loc>
    <lastmod>2026-07-31T12:19:35.296Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-python-pth-file-creation-in-site-packages-path-4f394635</loc>
    <lastmod>2026-07-31T12:18:53.560Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-python-pth-file-creation-in-site-packages-fb96c26c</loc>
    <lastmod>2026-07-31T12:18:46.676Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/palo-alto-globalprotect-file-creation-indicators-of-cve-2024-3400-os-command-inj-bcd95697</loc>
    <lastmod>2026-07-31T12:14:25.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-protocol-handler-clsid-server-dll-set-in-registry-d807056b</loc>
    <lastmod>2026-07-31T12:15:33.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detects-specific-forest-blizzard-tool-execution-via-has-07db928c</loc>
    <lastmod>2026-07-31T12:15:29.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-javascript-file-creation-in-driverstore-filerepository-ec7c4e9b</loc>
    <lastmod>2026-07-31T12:15:27.858Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-programdata-suspicious-driver-script-file-creation-pattern-b92d1d19</loc>
    <lastmod>2026-07-31T12:15:26.373Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/palo-alto-globalprotect-os-command-injection-indicators-via-cve-2024-3400-f130a5f1</loc>
    <lastmod>2026-07-31T12:14:31.373Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-duo-mfa-successful-login-using-bypass-code-reason-bypass-user-6f7e1c10</loc>
    <lastmod>2026-07-31T12:34:14.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-command-lines-showing-pnscan-binary-data-transfer-usage-97de11cd</loc>
    <lastmod>2026-07-31T12:39:58.642Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-dll-side-loading-keyscramblerie-dll-loaded-by-keyscrambler-ex-d2451be2</loc>
    <lastmod>2026-07-31T13:10:58.046Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-api-audit-unauthorized-401-or-forbidden-403-access-attempts-0d933542</loc>
    <lastmod>2026-07-31T12:25:15.287Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-root-shell-spawned-by-sshd-suggesting-cve-2024-3094-exploitatio-9aa27839</loc>
    <lastmod>2026-07-31T12:14:23.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-trustedcasforpasswordlessauth-root-ca-added-via-set-company-infor-4bb80281</loc>
    <lastmod>2026-07-31T12:29:57.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-certificate-based-authentication-enabled-via-authentication-methods-pol-c2496b41</loc>
    <lastmod>2026-07-31T12:29:53.359Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-sidecar-injection-via-kubectl-patch-on-deployments-ad9012a6</loc>
    <lastmod>2026-07-31T12:25:13.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-serviceaccount-created-via-audit-logging-e31bae15</loc>
    <lastmod>2026-07-31T12:25:11.731Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-logs-listing-secrets-for-enumeration-eeb3e9e1</loc>
    <lastmod>2026-07-31T12:25:08.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-selfsubjectrulesreviews-rbac-permission-enumeration-attempt-84b777bd</loc>
    <lastmod>2026-07-31T12:25:05.061Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-privileged-pod-created-via-api-server-audit-logs-c5cd1b20</loc>
    <lastmod>2026-07-31T12:25:03.274Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-pod-creation-in-kube-system-namespace-via-api-audit-logs-a80d927d</loc>
    <lastmod>2026-07-31T12:24:59.714Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-pod-created-with-hostpath-volume-mount-402b955c</loc>
    <lastmod>2026-07-31T12:24:58.261Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-pod-container-exec-via-kubernetes-api-remote-command-execution-a1b0ca4e</loc>
    <lastmod>2026-07-31T12:24:56.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-events-deleted-3132570d</loc>
    <lastmod>2026-07-31T12:24:55.129Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-deployment-deleted-via-audit-logs-40967487</loc>
    <lastmod>2026-07-31T12:24:53.547Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-winlogon-shell-modification-using-powershell-like-values-c9b86500</loc>
    <lastmod>2026-07-31T12:14:55.001Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-weekly-task-creation-with-forced-user-shutdown-command-fe9e8ba9</loc>
    <lastmod>2026-07-31T12:14:53.095Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winword-start-menu-shortcut-via-cmd-exe-launching-a-doc-lnk-24474469</loc>
    <lastmod>2026-07-31T12:14:51.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/progress-kemp-loadmaster-unauthenticated-command-injection-exploitation-via-acce-eafb8bd5</loc>
    <lastmod>2026-07-31T12:14:09.926Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-maxmpxct-value-changed-lanmanserver-parameters-0e6a9e62</loc>
    <lastmod>2026-07-30T05:20:49.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-renamed-nircmd-exe-nircmd-exe-nircmdc-exe-via-pe-originalfi-264982dc</loc>
    <lastmod>2026-07-30T05:02:34.685Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-teamviewer-remote-session-process-command-line-start-ab70c354</loc>
    <lastmod>2026-07-30T05:01:54.398Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-event-indicators-for-crackmapexec-hacktool-artifacts-736ffa74</loc>
    <lastmod>2026-07-31T13:03:14.183Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-execution-teamviewer-session-command-line-via-teamviewer-service-f459ccb4</loc>
    <lastmod>2026-07-31T12:43:00.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-teamviewer-remote-session-start-via-teamviewer-desktop-command-line-1f6b8cd4</loc>
    <lastmod>2026-07-31T12:40:14.140Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-vnc-connection-attempt-on-instrumented-node-9db5446c</loc>
    <lastmod>2026-07-31T12:25:59.178Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-tftp-service-request-observed-b4e6b016</loc>
    <lastmod>2026-07-31T12:25:57.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-telnet-login-attempt-on-port-23-512cff7a</loc>
    <lastmod>2026-07-31T12:25:56.156Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-detects-new-ssh-connection-attempts-on-monitored-nodes-cd55f721</loc>
    <lastmod>2026-07-31T12:25:54.553Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-ssh-login-attempt-on-application-log-events-ff7139bc</loc>
    <lastmod>2026-07-31T12:25:52.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-snmp-oid-request-observed-e9856028</loc>
    <lastmod>2026-07-31T12:25:51.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-smb-file-open-request-observed-22777c9e</loc>
    <lastmod>2026-07-31T12:25:49.681Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-sip-request-activity-application-logs-e30de276</loc>
    <lastmod>2026-07-31T12:25:48.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-redis-action-command-attempt-547dfc53</loc>
    <lastmod>2026-07-31T12:25:46.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-ntp-service-monlist-request-logged-7cded4b3</loc>
    <lastmod>2026-07-31T12:25:32.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-mysql-service-login-attempt-e7d79a1b</loc>
    <lastmod>2026-07-31T12:25:31.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-mssql-windows-authentication-login-attempt-6e78f90f</loc>
    <lastmod>2026-07-31T12:25:29.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-mssql-sqlauth-login-attempt-detected-3ec9a16d</loc>
    <lastmod>2026-07-31T12:25:27.810Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-httpproxy-login-attempt-proxy-request-5498fc09</loc>
    <lastmod>2026-07-31T12:25:26.254Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-http-form-post-login-attempt-application-logtype-3001-af1ac430</loc>
    <lastmod>2026-07-31T12:25:24.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-http-get-request-received-on-service-port-af6c3078</loc>
    <lastmod>2026-07-31T12:25:22.128Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-detects-git-clone-requests-on-git-service-4fe17521</loc>
    <lastmod>2026-07-31T12:25:20.509Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-ftp-login-attempt-activity-6991bc2b</loc>
    <lastmod>2026-07-31T12:25:18.876Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kerberos-key-distribution-center-errors-no-suitable-key-or-unsupported-e-b1e0b3f5</loc>
    <lastmod>2026-07-31T12:56:52.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-active-directory-certificate-services-denied-enrollment-requests-event-i-994bfd6d</loc>
    <lastmod>2026-07-31T12:56:37.773Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-secret-scanning-disabled-audit-actions-for-enterprise-or-repository-3883d9a0</loc>
    <lastmod>2026-07-31T12:24:36.133Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-secret-scanning-push-protection-disabled-ccd55945</loc>
    <lastmod>2026-07-31T12:24:31.356Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-secret-scanning-push-protection-bypass-activity-detected-02cf536a</loc>
    <lastmod>2026-07-31T12:24:29.403Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-shell32-control-rundll-execution-of-user-temp-cpl-92020b88</loc>
    <lastmod>2026-07-31T12:15:01.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-sentinelone-scan-context-menu-command-tampering-by-non-sentinel-6c304b02</loc>
    <lastmod>2026-07-30T05:22:09.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-shell-context-menu-command-tampering-via-shell-command-key-chan-868df2d1</loc>
    <lastmod>2026-07-31T12:23:47.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-utility-loads-untrusted-dll-via-image-load-telemetry-b5de0c9a</loc>
    <lastmod>2026-07-31T13:12:30.354Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-service-web-shell-execution-via-cmd-exe-or-csc-exe-b19146a3</loc>
    <lastmod>2026-07-30T05:01:48.250Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-onelaunch-update-domain-dns-queries-via-onelaunch-exe-df68f791</loc>
    <lastmod>2026-07-31T13:00:35.655Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-getsignintoken-with-suspicious-console-user-agent-f8103686</loc>
    <lastmod>2026-07-31T12:27:35.043Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-logs-user-permissions-export-attempt-87cc6698</loc>
    <lastmod>2026-07-31T12:24:12.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-ssh-user-login-failures-audit-authentication-events-d3f90469</loc>
    <lastmod>2026-07-31T12:24:10.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-user-login-failed-authentication-events-70ed1d26</loc>
    <lastmod>2026-07-31T12:24:08.822Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-logs-user-permissions-export-attempt-5259cbf2</loc>
    <lastmod>2026-07-31T12:24:07.353Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-unauthorized-full-data-export-triggered-34d81081</loc>
    <lastmod>2026-07-31T12:24:05.084Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-unauthorized-access-to-a-resource-7215374a</loc>
    <lastmod>2026-07-31T12:24:02.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-secret-scanning-rule-deleted-for-project-or-repository-ff91e3f0</loc>
    <lastmod>2026-07-31T12:24:00.665Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-secret-scanning-exempt-repository-added-b91e8d5e</loc>
    <lastmod>2026-07-31T12:23:59.065Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-project-secret-scanning-allowlist-rule-added-42ccce6d</loc>
    <lastmod>2026-07-31T12:23:57.567Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-log-configuration-updated-6aa12161</loc>
    <lastmod>2026-07-31T12:23:56.041Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-global-ssh-settings-changed-16ab6143</loc>
    <lastmod>2026-07-31T12:23:54.354Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-global-secret-scanning-rule-deleted-e16cf0f0</loc>
    <lastmod>2026-07-31T12:23:52.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-global-permission-added-or-removed-aac6c4f4</loc>
    <lastmod>2026-07-31T12:23:51.146Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-logs-full-data-export-triggered-195e1b9d</loc>
    <lastmod>2026-07-31T12:23:49.253Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-wget-exe-downloads-from-ip-to-common-staging-paths-40aa399c</loc>
    <lastmod>2026-07-30T05:13:36.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-user-added-to-highly-privileged-local-directory-groups-via-net-exe-or-ad-10fb649c</loc>
    <lastmod>2026-07-30T05:06:10.765Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-simpleservice-execution-via-remote-access-tool-wrapper-paths-95e60a2b</loc>
    <lastmod>2026-07-30T05:01:49.806Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-downloads-via-powershell-exe-from-file-sharing-domains-on-window-b6e04788</loc>
    <lastmod>2026-07-30T04:55:20.071Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-remote-command-execution-via-clientservice-exe-process-cre-d1a401ab</loc>
    <lastmod>2026-07-31T12:22:47.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-screenconnect-slashandgrab-exploitation-dropper-artifacts-05164d17</loc>
    <lastmod>2026-07-31T12:15:35.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-modification-of-screenconnect-temporary-xml-user-database-1a821580</loc>
    <lastmod>2026-07-31T12:14:18.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-query-indicators-for-dprk-c2-domains-4d16c9a6</loc>
    <lastmod>2026-07-31T12:15:22.632Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-service-modifies-temporary-xml-user-database-files-4109cb6a</loc>
    <lastmod>2026-07-31T12:14:21.730Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detection-of-screenconnect-setupwizard-authentication-bypass-exploitat-d27eabad</loc>
    <lastmod>2026-07-31T12:14:19.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-traffic-matches-cobalt-strike-malleable-profile-indicators-uri-user-agent--f3f21ce1</loc>
    <lastmod>2026-07-31T12:46:14.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-module-usage-enumeration-via-tasklist-exe-m-rdpcorets-dll-34275eb8</loc>
    <lastmod>2026-07-30T05:11:05.786Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sc-exe-service-query-for-termservice-enumeration-e83e8899</loc>
    <lastmod>2026-07-30T05:04:09.089Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-anydesk-execution-using-revoked-certificate-versions-41f407b5</loc>
    <lastmod>2026-07-30T05:01:19.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortios-sslvpnd-cve-2022-42475-exploitation-indicators-via-sensitive-file-paths-293ccb8c</loc>
    <lastmod>2026-07-31T12:08:25.023Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-iexpress-exe-self-extraction-directive-sed-package-creation-fro-b2b048b0</loc>
    <lastmod>2026-07-31T13:35:15.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-new-sed-file-creation-consistent-with-self-extraction-directive-ab90dab8</loc>
    <lastmod>2026-07-31T13:08:53.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-sed-directive-file-creation-in-suspicious-directories-760e75d8</loc>
    <lastmod>2026-07-31T13:06:08.975Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-iexpress-creating-self-extracting-packages-via-makecab-c2b478fc</loc>
    <lastmod>2026-07-31T12:21:56.420Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-disk-and-volume-discovery-via-wmic-exe-c79da740</loc>
    <lastmod>2026-07-30T05:15:03.035Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpmove-exe-execution-on-windows-dcom-wmi-vbs-and-scheduled-task-actions-055fb54c</loc>
    <lastmod>2026-07-31T13:34:17.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-edrsilencer-execution-via-filtering-platform-filter-added-98054878</loc>
    <lastmod>2026-07-31T12:52:28.165Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-soaphound-execution-via-ad-data-collection-arguments-e92a4287</loc>
    <lastmod>2026-07-31T13:34:30.357Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-network-connections-to-ad-web-services-adws-from-non-standard-p-b3ad3c0f</loc>
    <lastmod>2026-07-31T13:12:53.473Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-launched-with-non-dll-extension-via-lolbin-parents-1bf0ba65</loc>
    <lastmod>2026-07-31T12:11:26.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-page-change-via-mode-com-d48c5ffa</loc>
    <lastmod>2026-07-31T12:21:59.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-page-change-via-mode-com-selecting-russian-code-pages-12fbff88</loc>
    <lastmod>2026-07-30T04:51:05.606Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-log-detection-of-get-requests-to-api-core-command-init-restart-paths-b8225208</loc>
    <lastmod>2026-07-31T12:13:52.217Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-with-specific-suspicious-command-line-string-2e7bbd54</loc>
    <lastmod>2026-07-31T12:13:50.556Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-admin-sdk-google-workspace-application-access-level-changed-via-contextaware-22f2fb54</loc>
    <lastmod>2026-07-31T12:33:08.729Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-log-break-glass-flag-kubernetes-pod-created-in-gke-cluster-76737c19</loc>
    <lastmod>2026-07-31T12:32:41.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-access-policy-deletion-via-accesscontextmanager-audit-logs-32438676</loc>
    <lastmod>2026-07-31T12:32:39.501Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-renamed-pingcastle-binary-execution-via-pe-metadata-and-scanner-c-2433a154</loc>
    <lastmod>2026-07-30T05:02:39.825Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pingcastle-execution-from-suspicious-parent-processes-b37998de</loc>
    <lastmod>2026-07-30T04:58:28.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-pingcastle-execution-with-full-healthcheck-scanners-b1cb4ab6</loc>
    <lastmod>2026-07-30T04:58:26.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cpl-image-loads-from-non-system-paths-2b140a5c</loc>
    <lastmod>2026-07-31T13:10:25.857Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wfp-blocked-connection-involving-edr-agent-binaries-bacf58c6</loc>
    <lastmod>2026-07-31T12:50:56.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-forfiles-exe-child-process-masquerading-via-cmd-exe-execution-f53714ec</loc>
    <lastmod>2026-07-31T13:30:51.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-nofilter-execution-via-ronpolicy-filtering-platform-indi-7b14c76a</loc>
    <lastmod>2026-07-31T12:52:29.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-edrsilencer-hacktool-execution-via-edrsilencer-exe-process-creation-eb2d07d4</loc>
    <lastmod>2026-07-31T13:32:25.315Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-using-dotnet-trace-exe-proxy-arguments-9257c05b</loc>
    <lastmod>2026-07-31T13:29:43.868Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-discovery-via-system-profiler-with-targeted-data-types-4809c683</loc>
    <lastmod>2026-07-31T12:43:47.819Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-csrutil-sip-status-enumeration-via-process-command-line-53821412</loc>
    <lastmod>2026-07-31T12:42:10.183Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-csrutil-used-to-disable-system-integrity-protection-sip-3603f18a</loc>
    <lastmod>2026-07-31T12:42:08.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-suspicious-command-chains-indicative-of-pikabot-style-execution-e5144106</loc>
    <lastmod>2026-07-31T12:11:19.789Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-appcompatflags-layers-registerapprestart-b86852fb</loc>
    <lastmod>2026-07-30T05:20:52.800Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-to-desktop-wallpaper-policy-or-settings-85b88e05</loc>
    <lastmod>2026-07-30T05:18:42.543Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-changes-desktop-background-policy-values-8cbc9475</loc>
    <lastmod>2026-07-30T04:59:34.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-renamed-cloudflared-exe-with-tunnel-run-command-arg-e0c69ebd</loc>
    <lastmod>2026-07-30T05:02:12.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cloudflared-quick-tunnel-execution-via-cloudflared-exe-url-parameters-222129f7</loc>
    <lastmod>2026-07-31T13:26:36.361Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-cloudflared-exe-from-non-standard-paths-fadb84f0</loc>
    <lastmod>2026-07-31T13:26:34.084Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-matching-cloudflared-tunnel-domains-a1d9eec5</loc>
    <lastmod>2026-07-31T13:00:14.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-bash-pipeline-tail-extracting-data-from-image-and-base64-decoding-output-09a910bf</loc>
    <lastmod>2026-07-31T12:43:52.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-system-information-discovery-via-sw-vers-with-product-build-version-flags-5de06a6f</loc>
    <lastmod>2026-07-31T12:43:36.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-monitoring-for-i-o-kit-registry-discovery-via-ioreg-2d5e7a8b</loc>
    <lastmod>2026-07-31T12:42:30.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-tar-exe-archive-extraction-using-x-flag-bf361876</loc>
    <lastmod>2026-07-30T05:11:02.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-tar-exe-used-to-create-compressed-archives-418a3163</loc>
    <lastmod>2026-07-30T05:11:00.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-system-information-discovery-via-wmi-command-line-d85ecdd7</loc>
    <lastmod>2026-07-31T12:23:30.041Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-task-scheduler-svr-graphicalproton-known-malicious-scheduled-task-names-2bfc1373</loc>
    <lastmod>2026-07-31T12:12:56.511Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-using-svr-specific-task-names-8fa65166</loc>
    <lastmod>2026-07-31T12:12:53.593Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-of-svr-graphicalproton-backdoor-dll-names-e64c8ef3</loc>
    <lastmod>2026-07-31T12:12:50.616Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-lsa-nolmhash-to-0-to-enable-lm-hash-storage-c420410f</loc>
    <lastmod>2026-07-30T05:22:43.210Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-enable-lm-hash-storage-via-lsa-nolmhash-0-in-command-li-98dedfdd</loc>
    <lastmod>2026-07-30T04:59:59.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-hvci-disallowed-image-list-modified-hvcidisallowedimages-555155a2</loc>
    <lastmod>2026-07-30T05:19:56.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-whoami-exe-executed-with-all-for-full-identity-enumerat-c248c896</loc>
    <lastmod>2026-07-30T05:13:39.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-winpwn-keyword-execution-in-command-line-d557dc06</loc>
    <lastmod>2026-07-31T13:34:46.327Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-keyword-matches-for-winpwn-tool-execution-851fd622</loc>
    <lastmod>2026-07-31T13:18:43.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-dd-process-memory-overwrite-for-code-injection-via-proc-pid-mem-4cad6c64</loc>
    <lastmod>2026-07-31T12:38:48.590Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modification-via-powershell-crypto-classes-in-shell-open-comman-1c2a3268</loc>
    <lastmod>2026-07-31T12:23:42.445Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-process-command-line-uses-system-security-cryptography-classes-ad856965</loc>
    <lastmod>2026-07-31T12:22:18.063Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-netsh-helper-dll-value-added-under-software-microsoft-netsh-c90362e0</loc>
    <lastmod>2026-07-30T05:20:16.530Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-helper-dll-registration-via-suspicious-registry-paths-e7b18879</loc>
    <lastmod>2026-07-30T05:20:15.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-load-of-rstrtmgr-dll-by-uncommon-process-3669afd2</loc>
    <lastmod>2026-07-31T13:09:15.415Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-image-load-of-rstrtmgr-dll-by-windows-process-b48492dc</loc>
    <lastmod>2026-07-31T13:09:13.413Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-logs-possible-cve-2023-4966-probing-on-citrix-adc-via-long-host-header-a4e068b5</loc>
    <lastmod>2026-07-31T12:10:41.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-logs-detect-cve-2023-4966-probing-on-citrix-adc-netscaler-oidc-endpoin-87c83d8e</loc>
    <lastmod>2026-07-31T12:10:39.295Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/citrix-adc-proxy-logs-cve-2023-4966-sensitive-info-disclosure-probe-via-oidc-con-ff349b81</loc>
    <lastmod>2026-07-31T12:10:37.340Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/citrix-adc-proxy-get-to-oauth-openid-configuration-with-excessive-host-header-le-aee7681f</loc>
    <lastmod>2026-07-31T12:10:35.175Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-process-access-by-python-based-tool-f8be3e82</loc>
    <lastmod>2026-07-31T13:23:36.606Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-process-access-alerts-via-suspicious-source-image-names-d0d2f720</loc>
    <lastmod>2026-07-31T13:23:22.469Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/web-exploitation-attempt-of-cve-2023-46214-against-splunk-enterprise-via-insecur-ba5268de</loc>
    <lastmod>2026-07-31T12:10:29.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cve-2023-46214-rce-probe-against-splunk-enterprise-via-xsl-post-request-04017cd5</loc>
    <lastmod>2026-07-31T12:10:27.802Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wusa-exe-execution-with-parent-in-suspicious-windows-paths-ef64fc9c</loc>
    <lastmod>2026-07-30T05:15:55.402Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-privileged-shell-spawn-via-elevated-logon-powershell-cmd-61065c72</loc>
    <lastmod>2026-07-31T12:23:01.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-ime-file-value-used-from-suspicious-paths-9d8f9bb8</loc>
    <lastmod>2026-07-30T05:20:01.537Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uncommon-ime-file-value-in-keyboard-layouts-path-b888e3f2</loc>
    <lastmod>2026-07-30T05:19:59.765Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-initiated-network-connections-to-visual-studio-code-tunnel-domai-4b657234</loc>
    <lastmod>2026-07-31T13:13:36.889Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-devtunnels-ms-domains-9501f8e6</loc>
    <lastmod>2026-07-31T13:13:10.256Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-lines-query-event-logs-via-wevtutil-wmic-or-powershell-9cd55b6c</loc>
    <lastmod>2026-07-31T12:23:03.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/confluence-webserver-cve-2023-22518-post-requests-to-vulnerable-setup-restore-en-a902d249</loc>
    <lastmod>2026-07-31T12:09:10.501Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-http-post-to-confluence-setup-and-admin-json-endpoints-cve-2023-22518-27d2cdde</loc>
    <lastmod>2026-07-31T12:09:08.603Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-confluence-child-process-spawning-cmd-exe-or-powershell-on-windows-1ddaa9a4</loc>
    <lastmod>2026-07-31T12:09:06.687Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-indicators-for-cve-2023-22518-confluence-exploitation-via-f8987c03</loc>
    <lastmod>2026-07-31T12:09:04.698Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-excel-dcom-child-processes-linked-to-activatemicrosofta-551d9c1f</loc>
    <lastmod>2026-07-30T04:53:34.434Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-use-of-ms-appinstaller-protocol-handler-for-file-downloads-180c7c5c</loc>
    <lastmod>2026-07-30T05:07:57.837Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msxsl-exe-execution-with-http-keyword-in-command-line-75d0a94e</loc>
    <lastmod>2026-07-30T04:52:14.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-download-via-msedge-proxy-exe-using-http-https-urls-e84d89c4</loc>
    <lastmod>2026-07-30T04:51:24.446Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-imewdbld-exe-downloading-files-from-http-https-863218bd</loc>
    <lastmod>2026-07-31T13:35:34.025Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sysaid-user-exe-hash-based-malware-loader-execution-745ea50b</loc>
    <lastmod>2026-07-31T12:13:29.697Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-downloadstring-used-to-fetch-cobalt-strike-aa5b0a40</loc>
    <lastmod>2026-07-31T12:13:27.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-launcher-script-referencing-sysaid-tomcat-paths-and-user-exe--37dc5463</loc>
    <lastmod>2026-07-31T12:13:26.374Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-evidence-cleanup-script-with-cleanll-and-while-1-loop-b377ddab</loc>
    <lastmod>2026-07-31T12:13:24.459Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-file-creation-targeting-specific-sysaidserver-user-fil-e94486ea</loc>
    <lastmod>2026-07-31T12:13:22.456Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/f5-big-ip-icontrol-rest-api-bash-endpoint-command-execution-via-webserver-post-85254a62</loc>
    <lastmod>2026-07-31T12:46:57.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/f5-big-ip-icontrol-rest-api-bash-endpoint-command-execution-via-post-proxy-b59c98c6</loc>
    <lastmod>2026-07-31T12:46:02.327Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/f5-big-ip-webserver-rce-exploit-indicators-post-mgmt-tm-util-bash-and-tmui-form--e9928831</loc>
    <lastmod>2026-07-31T12:10:33.232Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/f5-big-ip-proxy-exploitation-attempt-targeting-mgmt-tm-util-bash-cve-2023-46747-f195b2ff</loc>
    <lastmod>2026-07-31T12:10:31.544Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disabling-antivirus-filter-driver-on-dev-drive-via-fltmgrdevdri-31e124fb</loc>
    <lastmod>2026-07-30T05:18:45.189Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-allowanonymouscallback-enabled-for-anonymous-remote-connection-4d431012</loc>
    <lastmod>2026-07-30T05:17:27.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-executes-unsigned-thor-scanner-binaries-ea5c131b</loc>
    <lastmod>2026-07-31T13:12:32.418Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-s3-bucket-versioning-disabled-via-putbucketversioning-cloudtrail-a136ac98</loc>
    <lastmod>2026-07-31T12:27:39.892Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-parent-with-select-binary-execution-indicative-of-process-hollo-d8937fe7</loc>
    <lastmod>2026-07-31T12:11:23.504Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-discovery-commands-triggered-via-rundll32-and-search-host-parent-698d4431</loc>
    <lastmod>2026-07-31T12:11:21.581Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-vs-code-tunnel-code-tunnel-installed-as-a-service-30bf1789</loc>
    <lastmod>2026-07-30T05:12:32.503Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vs-code-tunnel-launching-powershell-or-wsl-bash-shell-f4a623c2</loc>
    <lastmod>2026-07-30T05:12:28.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-visual-studio-code-tunnel-exe-tunnel-execution-90d6bd71</loc>
    <lastmod>2026-07-30T05:12:26.471Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-code-tunnel-json-indicating-non-vscode-vs-code-tunnelin-d102b8f5</loc>
    <lastmod>2026-07-31T13:08:32.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-node-exe-creates-files-in-vscode-server-history-via-vs-code-server-tunne-56e05d41</loc>
    <lastmod>2026-07-31T13:08:30.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-for-visual-studio-code-tunnels-domain-b3e6418f</loc>
    <lastmod>2026-07-31T13:00:51.551Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-to-devtunnels-devtunnels-ms-1cb0c6ce</loc>
    <lastmod>2026-07-31T13:00:17.605Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-user-lifecycle-create-event-for-new-user-accounts-b6c718dd</loc>
    <lastmod>2026-07-31T12:34:51.027Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-admin-function-access-via-proxy-9058ca8b</loc>
    <lastmod>2026-07-31T12:34:15.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-create-of-code-tunnel-json-indicates-vs-code-tunneling-usage-9661ec9d</loc>
    <lastmod>2026-07-31T12:19:41.887Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-password-health-report-endpoint-accessed-via-reports-password-health-0d58814b</loc>
    <lastmod>2026-07-31T12:18:44.962Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-user-created-activated-for-svc-network-backup-account-00a8e92a</loc>
    <lastmod>2026-07-31T12:13:41.683Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-adfs-inetmgr-exe-path-used-by-onyx-sleet-2fef4fd9</loc>
    <lastmod>2026-07-31T12:13:43.868Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4698-scheduled-task-creation-for-teamcity-settings-ui-3b8e5084</loc>
    <lastmod>2026-07-31T12:13:06.876Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-event-scheduled-taskcache-tree-key-creation-for-teamcity-exploi-9f9f92ba</loc>
    <lastmod>2026-07-31T12:13:04.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detects-command-line-string-utynkfkxhizrx3kj-b5495d8d</loc>
    <lastmod>2026-07-31T12:13:03.165Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-programdata-clip-exe-wsmprovhost-exe-imageload-d1b65d98</loc>
    <lastmod>2026-07-31T12:13:01.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-indicators-for-programdata-payloads-e1212b32</loc>
    <lastmod>2026-07-31T12:12:59.773Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-query-detection-for-diamond-sleet-related-domains-fba38e0f</loc>
    <lastmod>2026-07-31T12:12:58.095Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-findstr-exe-security-tool-keyword-lookup-via-command-line-4fe074b4</loc>
    <lastmod>2026-07-31T13:30:39.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-access-logs-indicate-potential-cve-2023-43261-exploitation-and-informa-a2bcca38</loc>
    <lastmod>2026-07-31T12:10:25.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-get-requests-targeting-lang-log-httpd-log-for-cve-2023-43261-disclosure-f48f5368</loc>
    <lastmod>2026-07-31T12:10:24.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-ios-xe-web-ui-exploitation-indicators-for-cve-2023-20198-2ece8816</loc>
    <lastmod>2026-07-31T12:09:01.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-taskmgr-exe-creating-lsass-dmp-in-temp-directory-69ca12af</loc>
    <lastmod>2026-07-31T13:07:59.352Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-enablescripts-policy-enabled-via-registry-dword-8218c875</loc>
    <lastmod>2026-07-30T05:21:49.849Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-file-download-from-ip-url-via-command-line-9cc85849</loc>
    <lastmod>2026-07-31T13:28:34.211Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certoc-exe-download-via-ip-based-url-getcacaps-b86f6dea</loc>
    <lastmod>2026-07-31T13:25:54.715Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-imageloaded-from-programshared-programdata-and-arm-p-24007168</loc>
    <lastmod>2026-07-31T12:13:31.250Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-explicit-dllregisterserver-export-calls-from-non-standard-p-d81a9fc6</loc>
    <lastmod>2026-07-31T12:22:52.409Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-executes-dlls-with-s-and-e-from-uncommon-paths-implicit-dllregi-ce2c44b5</loc>
    <lastmod>2026-07-31T12:22:40.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-autoit3-exe-execution-with-suspicious-parent-process-f8e9aa1c</loc>
    <lastmod>2026-07-31T12:11:07.202Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-autoit3-exe-by-curl-exe-or-other-uncommon-parent-proces-1a433e1d</loc>
    <lastmod>2026-07-31T12:11:05.518Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-coercedpotato-exe-privilege-escalation-execution-e8d34729</loc>
    <lastmod>2026-07-31T13:32:03.090Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-with-coercedpotato-pipe-name-pattern-4d0083b3</loc>
    <lastmod>2026-07-31T13:14:46.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-failed-logons-event-id-18456-from-external-client-ips-ebfe73c2</loc>
    <lastmod>2026-07-31T12:47:53.562Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-failed-logon-event-id-18456-via-application-provider-name-218d2855</loc>
    <lastmod>2026-07-31T12:47:51.283Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/o365-audit-detect-mail-forwarding-and-redirect-rule-changes-c726e007</loc>
    <lastmod>2026-07-31T12:18:41.559Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-hta-file-creation-in-startup-folder-by-foxitpdfreader-exe-9cae055f</loc>
    <lastmod>2026-07-31T12:09:31.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-rmm-system-command-execution-via-cmd-exe-b1f73849</loc>
    <lastmod>2026-07-30T05:01:44.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/screenconnect-rmm-temporary-file-creation-in-windows-user-documents-connectwisec-0afecb6e</loc>
    <lastmod>2026-07-31T13:06:03.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/screenconnect-rmm-file-transfer-activity-on-windows-event-id-201-5d19eb78</loc>
    <lastmod>2026-07-31T12:48:03.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-remote-command-execution-via-application-event-200-076ebe48</loc>
    <lastmod>2026-07-31T12:48:01.295Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-cli-commandline-references-ntfs-index-allocation-stream-0900463c</loc>
    <lastmod>2026-07-30T05:07:36.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hidden-directory-creation-via-ntfs-index-allocation-stream-in-file-event-a8f866e1</loc>
    <lastmod>2026-07-31T13:06:45.757Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kerberos-kdc-event-39-41-certificate-valid-without-strong-user-mapping-993c2665</loc>
    <lastmod>2026-07-31T12:56:51.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-visual-studio-code-tunnel-execution-with-renamed-binary-2cf29f11</loc>
    <lastmod>2026-07-30T05:12:29.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4663-detects-read-control-read-control-access-to-service-regist-11d00fff</loc>
    <lastmod>2026-07-31T12:54:08.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-detects-aws-identity-center-identity-provider-changes-d3adb3ef</loc>
    <lastmod>2026-07-31T12:28:35.036Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-created-via-registry-key-activity-93ff0ceb</loc>
    <lastmod>2026-07-31T12:23:38.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-created-via-file-creation-in-system-task-directories-a762e74f</loc>
    <lastmod>2026-07-31T12:19:36.905Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-addinutil-exe-execution-from-non-standard-directory-6120ac2a</loc>
    <lastmod>2026-07-31T13:24:14.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-addinutil-exe-with-uncommon-addinroot-pipelineroot-pat-4f2cd9b6</loc>
    <lastmod>2026-07-31T13:24:12.702Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-child-processes-spawned-by-addinutil-exe-b5746143</loc>
    <lastmod>2026-07-31T13:24:10.711Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-addinutil-exe-with-suspicious-addinroot-pipelineroot-pa-631b22a4</loc>
    <lastmod>2026-07-31T13:24:08.958Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-addinutil-exe-initiates-network-connection-5205613d</loc>
    <lastmod>2026-07-31T13:12:51.511Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-audit-new-federated-domain-added-via-domain-add-operation-58f88172</loc>
    <lastmod>2026-07-31T12:33:35.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-audit-disabling-strong-authentication-mfa-60de9b57</loc>
    <lastmod>2026-07-31T12:33:31.054Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-diskshadow-script-mode-s-execution-from-potentially-suspicious-paths-fa1a7e52</loc>
    <lastmod>2026-07-31T13:29:22.069Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-diskshadow-script-mode-execution-with-uncommon-script-extension-1dde5376</loc>
    <lastmod>2026-07-31T13:29:19.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-child-processes-spawned-by-diskshadow-exe-9f546b25</loc>
    <lastmod>2026-07-31T13:29:18.216Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-diskshadow-exe-spawning-child-processes-56b1dde8</loc>
    <lastmod>2026-07-31T12:21:47.626Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-to-hive-and-reg-backups-by-uncommon-applications-337a31c6</loc>
    <lastmod>2026-07-31T12:19:24.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-alert-too-many-global-administrator-accounts-assigned-to-tenant-7bbc309f</loc>
    <lastmod>2026-07-31T12:32:00.856Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-redundant-privileged-role-assignments-not-being-used-8c6ec464</loc>
    <lastmod>2026-07-31T12:31:58.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-role-activation-without-mfa-alert-nomfaonroleactivationalertincident-94a66f46</loc>
    <lastmod>2026-07-31T12:31:56.986Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-role-activated-too-frequently-sequential-activation-renewals-645fd80d</loc>
    <lastmod>2026-07-31T12:31:55.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-alert-for-roles-assigned-outside-privileged-identity-management-b1bc08d1</loc>
    <lastmod>2026-07-31T12:31:52.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-invalid-license-alert-detection-58af08eb</loc>
    <lastmod>2026-07-31T12:31:51.104Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-stale-sign-in-alerts-for-privileged-roles-e402c26a</loc>
    <lastmod>2026-07-31T12:31:49.075Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-chromium-browsers-in-headless-mode-ef9dcfed</loc>
    <lastmod>2026-07-31T13:25:29.160Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wmic-exe-call-terminate-attempt-49d9671b</loc>
    <lastmod>2026-07-30T05:15:19.686Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-execution-of-renamed-curl-exe-via-pe-metadata-7530cd3d</loc>
    <lastmod>2026-07-30T05:02:16.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-chromium-headless-browser-execution-targeting-mockbin-u-1c526788</loc>
    <lastmod>2026-07-31T13:25:34.697Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-dmp-hdmp-file-creation-via-shell-or-scripting-aba15bdd</loc>
    <lastmod>2026-07-31T13:03:01.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-user-session-start-from-anonymizing-proxy-service-bde30855</loc>
    <lastmod>2026-07-31T12:34:52.909Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-user-reports-suspicious-activity-on-their-own-account-via-end-user-activity-07e97cc6</loc>
    <lastmod>2026-07-31T12:34:45.964Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-new-or-positive-admin-console-access-heuristics-via-policy-evaluate-sign-on-a0b38b70</loc>
    <lastmod>2026-07-31T12:34:37.231Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-identity-provider-creation-via-system-idp-lifecycle-create-969c7590</loc>
    <lastmod>2026-07-31T12:34:30.560Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-risk-detection-threat-intelligence-sign-in-investigation-events-a2cb56ff</loc>
    <lastmod>2026-07-31T12:31:43.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-riskdetection-attempted-primary-refresh-token-prt-access-a84fc3b1</loc>
    <lastmod>2026-07-31T12:31:40.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-riskdetection-suspiciousipaddress-sign-in-from-known-malicious-ip-36440e1c</loc>
    <lastmod>2026-07-31T12:31:32.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-risk-detections-malicious-ip-sign-in-failure-rate-a3f55ebd</loc>
    <lastmod>2026-07-31T12:31:30.943Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-dmp-hdmp-memory-dump-files-3a525307</loc>
    <lastmod>2026-07-31T12:19:31.337Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-enabled-tls-1-0-or-tls-1-1-via-schannel-protocols-enabled-1-439957a7</loc>
    <lastmod>2026-07-30T05:22:54.229Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-zonemap-protocoldefaults-downgraded-to-my-computer-for-http-htt-3fd4c8d7</loc>
    <lastmod>2026-07-30T05:19:57.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-commandline-parameters-for-electron-apps-on-windows-378a05d8</loc>
    <lastmod>2026-07-30T05:07:07.234Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-ie-zonemap-protocoldefaults-downgraded-to-my-computer-f-10344bb3</loc>
    <lastmod>2026-07-30T05:00:41.475Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vmmap-loads-signed-dbghelp-dll-from-c-debuggers-path-potential-dll-sideloading-98ffaed4</loc>
    <lastmod>2026-07-31T13:12:07.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-process-deletes-zone-identifier-alternate-data-stream-ads-3109530e</loc>
    <lastmod>2026-07-31T13:02:07.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-of-esxcli-vsan-for-virtual-storage-information-discovery-d54c2f06</loc>
    <lastmod>2026-07-31T12:39:10.689Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-esxcli-vm-kill-shutdown-a-vm-on-esxi-2992ac4d</loc>
    <lastmod>2026-07-31T12:39:08.855Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-monitoring-esxi-vm-discovery-via-esxcli-vm-process-list-5f1573a7</loc>
    <lastmod>2026-07-31T12:39:06.975Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-esxi-esxcli-system-discovery-commands-e80273e1</loc>
    <lastmod>2026-07-31T12:39:03.530Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/esxi-syslog-configuration-change-via-esxcli-on-linux-38eb1dbb</loc>
    <lastmod>2026-07-31T12:39:01.700Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-esxi-esxcli-storage-discovery-f41dada5</loc>
    <lastmod>2026-07-31T12:38:59.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-esxi-esxcli-used-to-set-admin-permission-on-an-account-9691f58d</loc>
    <lastmod>2026-07-31T12:38:58.095Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-esxi-esxcli-network-discovery-commands-33e814e0</loc>
    <lastmod>2026-07-31T12:38:56.294Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-deletion-of-zone-identifier-alternate-data-stream-7eac0a16</loc>
    <lastmod>2026-07-31T12:19:29.729Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-risk-detection-unfamiliar-sign-in-properties-events-128faeef</loc>
    <lastmod>2026-07-31T12:31:47.355Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-saml-token-issuer-anomaly-risk-event-e3393cba</loc>
    <lastmod>2026-07-31T12:31:45.641Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-risk-detection-suspicious-browser-sign-in-activity-across-countries-and-te-944f6adb</loc>
    <lastmod>2026-07-31T12:31:41.821Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-id-risk-detection-successful-password-spray-activity-28ecba0a</loc>
    <lastmod>2026-07-31T12:31:38.453Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-risk-detection-new-country-sign-in-adf9f4d2</loc>
    <lastmod>2026-07-31T12:31:36.372Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-sign-in-risk-malware-infected-ip-address-sign-ins-821b4dc3</loc>
    <lastmod>2026-07-31T12:31:34.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-risk-detection-leaked-credentials-event-leakedcredentials-19128e5e</loc>
    <lastmod>2026-07-31T12:31:28.395Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-risk-detection-suspicious-inbox-manipulation-rules-set-to-delete-or-move-i-ceb55fd0</loc>
    <lastmod>2026-07-31T12:31:26.804Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-risk-detection-suspicious-inbox-forwarding-identity-protection-events-27e4f1d6</loc>
    <lastmod>2026-07-31T12:31:25.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-risk-impossible-travel-sign-in-detection-impossibletravel-b2572bf9</loc>
    <lastmod>2026-07-31T12:31:23.620Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-unlikelytravel-risk-events-indicating-atypical-travel-between-distan-1a41023f</loc>
    <lastmod>2026-07-31T12:31:21.940Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-riskdetection-user-activity-triggered-by-risky-anonymous-proxy-ip-be4d9c86</loc>
    <lastmod>2026-07-31T12:31:18.188Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-risk-detection-anomalous-user-activity-riskeventtype-anomaloususeractiv-258b6593</loc>
    <lastmod>2026-07-31T12:31:14.192Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-spawned-by-winrar-exe-on-windows-146aace8</loc>
    <lastmod>2026-07-30T05:14:18.288Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-qakbot-uninstaller-qbotuninstall-exe-bc309b7a</loc>
    <lastmod>2026-07-31T12:11:40.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-executes-1-dll-dllregisterserver-via-single-digit-dll-2bd8e100</loc>
    <lastmod>2026-07-31T12:11:16.298Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrar-exe-application-error-crash-with-version-below-6-23-e5a29b54</loc>
    <lastmod>2026-07-31T12:10:21.896Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrar-rev-file-creation-potential-exploitation-cve-2023-40477-c3bd6c55</loc>
    <lastmod>2026-07-31T12:10:16.722Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winrar-child-process-execution-attempt-cve-2023-38331-on-windows-ec3a3c2f</loc>
    <lastmod>2026-07-31T12:10:13.890Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-suspicious-double-extension-filename-with-space-via-winrar-e4556676</loc>
    <lastmod>2026-07-31T12:10:08.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lolbin-copy-from-windows-system-directories-using-windows-copy-tools-f5d19838</loc>
    <lastmod>2026-07-30T05:06:49.905Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-local-user-creation-via-net-exe-using-darkgate-and-safemode-arguments-bf906d7b</loc>
    <lastmod>2026-07-31T12:11:08.867Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-command-line-inode-directory-listing-for-container-discovery-43e26eb5</loc>
    <lastmod>2026-07-31T12:40:59.700Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-discovery-by-listing-dockerenv-via-common-file-utilities-11701de9</loc>
    <lastmod>2026-07-31T12:40:43.777Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-container-discovery-via-proc-virtual-filesystem-enumeration-746c86fb</loc>
    <lastmod>2026-07-31T12:40:38.330Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-renamed-cmd-powershell-powershell-ise-as-wermgr-exe-50dbc08b</loc>
    <lastmod>2026-07-31T12:09:50.985Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-creation-of-fake-wermgr-exe-in-uncommon-directories-ad0960eb</loc>
    <lastmod>2026-07-31T12:09:49.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wer-report-wer-creation-in-uncommon-reportarchive-subfolders-possible-cv-92389a99</loc>
    <lastmod>2026-07-31T12:09:47.600Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-watch-pythonfunctionwarnings-disabled-via-excel-security-registr-023c654f</loc>
    <lastmod>2026-07-30T05:00:47.941Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-in-memory-download-and-compile-via-curl-and-osacompile-13db8d2e</loc>
    <lastmod>2026-07-31T12:43:26.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-jamf-cli-command-execution-for-account-mdm-and-framework-changes-be2e3a5c</loc>
    <lastmod>2026-07-31T12:42:33.614Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detect-suspicious-child-processes-spawned-by-jamf-2316929c</loc>
    <lastmod>2026-07-31T12:42:31.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-root-account-enable-via-dsenableroot-821bcf4d</loc>
    <lastmod>2026-07-31T12:42:17.341Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-dseditgroup-used-to-add-a-user-to-the-admin-group-5d0fdb62</loc>
    <lastmod>2026-07-31T12:42:15.638Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/esxi-user-account-creation-via-esxcli-command-execution-b28e4eb3</loc>
    <lastmod>2026-07-31T12:39:05.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-riskdetection-anonymous-ip-address-sign-ins-53acd925</loc>
    <lastmod>2026-07-31T12:31:20.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-triggered-from-webdav-lnk-paths-1412aa78</loc>
    <lastmod>2026-07-30T05:12:55.858Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-webdav-temporary-files-created-with-suspicious-extensions-4c55738d</loc>
    <lastmod>2026-07-31T12:19:45.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-bginfo-userfields-value-enabling-custom-wmi-query-execution-cd277474</loc>
    <lastmod>2026-07-30T05:18:09.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-bginfo-userfields-value-enabling-custom-vbscript-execution-992dd79f</loc>
    <lastmod>2026-07-30T05:18:06.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-new-bginfo-database-path-value-53330955</loc>
    <lastmod>2026-07-30T05:18:04.166Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-processes-spawned-by-bginfo-exe-on-windows-811f459f</loc>
    <lastmod>2026-07-31T13:25:08.648Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-bash-exe-script-launcher-execution-without-command-line-flags-windows-2d22a514</loc>
    <lastmod>2026-07-31T13:25:01.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-aspnet-compiler-exe-from-suspicious-paths-9f50fe98</loc>
    <lastmod>2026-07-31T13:24:38.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-aspnet-compiler-exe-9ccba514</loc>
    <lastmod>2026-07-31T13:24:35.879Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-new-dll-created-by-aspnet-compiler-exe-in-temporary-asp-net-assembly-pat-4c7f49ee</loc>
    <lastmod>2026-07-31T13:02:19.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mftrace-exe-dll-sideloading-of-unsigned-mfdetours-dll-948a0953</loc>
    <lastmod>2026-07-31T13:11:03.843Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-execution-of-renamed-gpg-exe-or-gpg2-exe-ec0722a3</loc>
    <lastmod>2026-07-30T05:02:21.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-encryption-via-gpg4win-gpg-exe-gpg2-exe-with-passphrase-550bbb84</loc>
    <lastmod>2026-07-31T13:31:21.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-decryption-via-gpg4win-gpg-exe-using-passphrase-flag-037dcd71</loc>
    <lastmod>2026-07-31T13:31:19.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-provisioning-registry-key-abuse-leading-to-indirect-execution-via-provla-2a4b3e61</loc>
    <lastmod>2026-07-30T05:00:51.464Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-suspicious-child-processes-spawned-by-provlaunch-exe-f9999590</loc>
    <lastmod>2026-07-30T04:57:34.243Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-remcom-named-pipe-creation-via-remcom-d36f87ea</loc>
    <lastmod>2026-07-31T13:15:05.506Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-csexec-default-csexecsvc-pipe-f318b911</loc>
    <lastmod>2026-07-31T13:15:01.356Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-detects-remcomsvc-service-installation-9e36ed87</loc>
    <lastmod>2026-07-31T12:58:04.700Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-csexec-service-installation-eventid-7045-a27e5fa9</loc>
    <lastmod>2026-07-31T12:57:48.543Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-id-riskdetection-anomalous-token-risk-events-6555754e</loc>
    <lastmod>2026-07-31T12:31:12.577Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/guloader-activity-injected-browser-parent-spawns-rundll32-exe-on-windows-89e1490f</loc>
    <lastmod>2026-07-31T12:11:12.881Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-unusual-gpg-exe-or-gpg2-exe-execution-paths-77df53a5</loc>
    <lastmod>2026-07-31T13:31:23.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remcomsvc-exe-service-file-creation-7eff1a7f</loc>
    <lastmod>2026-07-31T13:05:59.219Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-csexec-service-file-creation-via-csexecsvc-exe-f0e2b768</loc>
    <lastmod>2026-07-31T13:02:50.299Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vsdiagnostics-exe-started-with-launch-parameters-to-proxy-arbitrary-bina-ac1c92b4</loc>
    <lastmod>2026-07-30T05:12:34.634Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-of-vivaldi-elf-dll-suggesting-potential-dll-sideloading-2092cacb</loc>
    <lastmod>2026-07-31T13:12:03.732Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-mfdetours-dll-loaded-from-current-directory-d2605a99</loc>
    <lastmod>2026-07-31T13:11:01.800Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-potential-eacore-dll-sideloading-via-ea-desktop-edd3ddc3</loc>
    <lastmod>2026-07-31T13:10:35.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-avkkid-dll-image-loads-952ed57c</loc>
    <lastmod>2026-07-31T13:10:12.148Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-amazon-ssm-agent-hijacking-via-suspicious-register-code-command-line-f9b3edc5</loc>
    <lastmod>2026-07-31T12:40:36.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-key-abuse-via-provisioning-commands-for-proxy-binary-execution-7021255e</loc>
    <lastmod>2026-07-30T05:21:56.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-amazon-ssm-agent-process-creation-with-registration-and-code-parameters-d20ee2f4</loc>
    <lastmod>2026-07-30T05:06:01.768Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-csc-exe-dynamic-net-compilation-acf2807c</loc>
    <lastmod>2026-07-31T12:21:32.822Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appcompatflags-installedsdb-new-shim-database-in-non-default-path-6b6976a3</loc>
    <lastmod>2026-07-30T05:21:36.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-appcompatflags-custom-shim-databases-targeting-system-proce-bf344fea</loc>
    <lastmod>2026-07-30T05:21:34.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sdbinst-exe-installing-shim-database-with-uncommon-extension-18ee686c</loc>
    <lastmod>2026-07-30T05:05:10.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vmmap-unsigned-dbghelp-dll-image-sideloading-attempt-on-windows-273a8dd8</loc>
    <lastmod>2026-07-31T13:12:09.890Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-thread-creation-in-mstsc-exe-triggered-by-suspicious-source-paths-c0aac16a</loc>
    <lastmod>2026-07-31T12:59:34.891Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-web-logs-indicators-of-cve-2023-27997-exploitation-attempt-31e4e649</loc>
    <lastmod>2026-07-31T12:09:33.335Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-wget-exe-downloading-files-from-an-ip-with-output-flags-17f0c0a8</loc>
    <lastmod>2026-07-30T05:13:32.475Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-curl-exe-reading-local-files-via-file-uri-aa6f6ea6</loc>
    <lastmod>2026-07-31T13:28:44.001Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-insecure-proxy-doh-transfer-using-curl-exe-flags-proxy-insecure-doh-inse-2c1486f5</loc>
    <lastmod>2026-07-31T13:28:42.315Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-downloads-file-from-direct-ip-via-http-s-with-suspicious-extens-5cb299fc</loc>
    <lastmod>2026-07-31T13:28:36.453Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-web-requests-with-custom-user-agent-headers-85de1f22</loc>
    <lastmod>2026-07-31T13:28:32.139Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-curl-exe-cookie-jar-saving-via-c-cookie-jar-5a6e1e16</loc>
    <lastmod>2026-07-31T13:28:30.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-terminal-settings-json-modified-by-an-uncommon-command-line-process-9b64de98</loc>
    <lastmod>2026-07-31T13:07:37.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-net-exe-mounting-smb-over-quic-via-transport-quic-2238d337</loc>
    <lastmod>2026-07-31T12:22:08.937Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winapi-function-calls-from-powershell-script-blocks-9f22ccd5</loc>
    <lastmod>2026-07-31T12:21:12.360Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scripts-calling-winapi-dlls-on-windows-19d65a1c</loc>
    <lastmod>2026-07-31T12:21:10.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-smb-share-mapping-over-quic-new-smbmapping-6df07c3b</loc>
    <lastmod>2026-07-31T12:21:00.352Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-fileexecutabledetected-event-id-29-alerts-on-new-executable-files-693a44e9</loc>
    <lastmod>2026-07-30T05:23:35.772Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sysmon-fileblockshredding-policy-violations-event-id-28-on-windows-c3e5c1b1</loc>
    <lastmod>2026-07-30T05:23:34.300Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-schtasks-exe-creating-scheduled-task-launching-registry-86588b36</loc>
    <lastmod>2026-07-30T05:04:51.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-exe-advanced-firewall-rule-set-modification-a70dcb37</loc>
    <lastmod>2026-07-30T04:52:50.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-one-liner-combining-ping-and-copy-ded2b07a</loc>
    <lastmod>2026-07-31T13:27:11.786Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-sets-file-folder-acl-using-set-acl-cae80281</loc>
    <lastmod>2026-07-31T13:20:33.148Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-redirection-to-appdata-temp-bin-during-explorer-initiated-execut-7aaa5739</loc>
    <lastmod>2026-07-31T12:12:04.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-wmi-win32-nteventlogfile-calls-with-event-log-tampering-metho-caf201a9</loc>
    <lastmod>2026-07-30T05:08:11.631Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-suspicious-wmi-win32-nteventlogfile-usage-in-script-e2812b49</loc>
    <lastmod>2026-07-31T13:22:50.801Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-attempts-ccleanerreactivator-dll-loaded-by-ccleanerreact-3735d5ac</loc>
    <lastmod>2026-07-31T13:10:16.426Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-ccleanerdu-dll-loaded-outside-ccleaner-binaries-1fbc0671</loc>
    <lastmod>2026-07-31T13:10:14.434Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-local-firewall-rule-enumeration-using-get-netfirewallrule-show-netfir-ea207a23</loc>
    <lastmod>2026-07-31T12:20:49.589Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-share-access-mshtml-c7-with-ip-like-naming-pattern-3df95076</loc>
    <lastmod>2026-07-31T12:10:07.292Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-recent-folder-file-drop-c-users-recent-file001-url-8023d3a2</loc>
    <lastmod>2026-07-31T12:09:52.637Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-from-fake-recycle-bin-directories-5ce0f04e</loc>
    <lastmod>2026-07-30T05:08:37.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wordpad-exe-makes-outbound-network-connections-to-uncommon-ports-786cdae8</loc>
    <lastmod>2026-07-31T13:14:29.603Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-apps-initiate-network-connections-to-uncommon-destination-ports-3b5ba899</loc>
    <lastmod>2026-07-31T13:13:47.901Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-creation-in-fake-recycle-bin-folder-paths-cd8b36ac</loc>
    <lastmod>2026-07-31T13:07:05.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/http-get-requests-containing-mshtml-c7-url-marker-proxy-e59f71ff</loc>
    <lastmod>2026-07-31T12:10:05.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-proxy-get-requests-for-file-download-paths-indicative-of-cve-2023-368-6af1617f</loc>
    <lastmod>2026-07-31T12:10:03.841Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detects-suspicious-proxy-get-requests-targeting-ip-parameters-in-url-query-strin-d9365e39</loc>
    <lastmod>2026-07-31T12:10:02.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-detection-of-get-requests-targeting-mshtml-c7-with-ip-parameter-0066d244</loc>
    <lastmod>2026-07-31T12:09:54.691Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-abusable-dlls-from-suspicious-paths-potential-sideloading-799a5f48</loc>
    <lastmod>2026-07-31T13:09:59.097Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-access-to-windows-mailapp-mailbox-data-paths-4e485d01</loc>
    <lastmod>2026-07-31T12:20:56.951Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-recon-command-output-piped-to-findstr-exe-ccb5742c</loc>
    <lastmod>2026-07-31T13:30:36.585Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-registry-reconnaissance-via-script-block-queries-windows-064060aa</loc>
    <lastmod>2026-07-31T12:21:02.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-werfault-exe-executed-with-pr-flag-fabfb3a7</loc>
    <lastmod>2026-07-30T05:13:24.634Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-decryption-like-activity-involving-lnk-file-processing-434c08ba</loc>
    <lastmod>2026-07-30T04:54:59.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-curl-exe-executed-with-insecure-insecure-tls-transfer-cb9cc1d1</loc>
    <lastmod>2026-07-31T13:28:40.538Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uncommon-microsoft-office-trusted-location-path-added-f742bde7</loc>
    <lastmod>2026-07-30T05:20:45.989Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-trustrecords-change-for-macro-enabled-documents-in-suspicious-p-a166f74e</loc>
    <lastmod>2026-07-30T05:20:44.356Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-executable-running-a-document-from-trusted-template-startup-paths-f99abdf0</loc>
    <lastmod>2026-07-30T04:53:36.107Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-microsoft-office-trusted-locations-modified-a0bed973</loc>
    <lastmod>2026-07-31T12:23:40.107Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-using-shellexecute-via-shelldispatch-dll-functionality-82343930</loc>
    <lastmod>2026-07-30T05:03:30.651Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-shelldispatch-dll-image-load-844f8eb2</loc>
    <lastmod>2026-07-31T13:11:36.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-appverifui-dll-loaded-from-non-standard-paths-ee6cea48</loc>
    <lastmod>2026-07-31T13:10:08.329Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4719-important-audit-policy-categories-disabled-ab4561b1</loc>
    <lastmod>2026-07-30T04:13:24.490Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-named-pipe-creation-via-mkfifo-from-tmp-999c3b12</loc>
    <lastmod>2026-07-31T12:39:40.995Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-named-pipe-creation-via-mkfifo-utility-9d779ce8</loc>
    <lastmod>2026-07-31T12:39:39.258Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-of-named-binaries-commonly-used-for-seaspy-deployment-f6a711f3</loc>
    <lastmod>2026-07-31T12:14:08.286Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-wget-downloading-tar-via-untrusted-ip-with-certificate-b-23835beb</loc>
    <lastmod>2026-07-31T12:14:06.667Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-wget-downloads-zip-rar-from-temp-sh-60d050c4</loc>
    <lastmod>2026-07-31T12:14:04.931Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-openssl-s-client-connection-to-ip-port-for-ssl-certificate-exfiltration-60911c07</loc>
    <lastmod>2026-07-31T12:14:03.147Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-indicators-matching-suspected-barracuda-esg-exploitation-artifacts-5627c337</loc>
    <lastmod>2026-07-31T12:14:01.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-creation-with-mail-tmp-3-alnum-3-digits-tar-gz-pattern-0785f462</loc>
    <lastmod>2026-07-31T12:13:59.563Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-virtual-smart-card-created-using-tpmvscmgr-exe-c633622e</loc>
    <lastmod>2026-07-30T05:11:13.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lodctr-exe-rebuilds-performance-counter-registry-values-cc9d3712</loc>
    <lastmod>2026-07-31T13:36:14.160Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vmwaretoolboxcmd-exe-script-set-execution-used-for-vm-state-persistence-236d8e89</loc>
    <lastmod>2026-07-30T05:12:20.992Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vmwaretoolboxcmd-exe-script-set-used-to-configure-vm-state-persistence-7aa4e81a</loc>
    <lastmod>2026-07-30T05:12:19.338Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-monitoring-potential-waveedit-dll-dll-sideloading-71b31e99</loc>
    <lastmod>2026-07-31T13:12:13.824Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-geoserver-sql-injection-exploitation-attempt-via-ows-cql-filter-c0341543</loc>
    <lastmod>2026-07-31T12:09:21.679Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-clickonce-trust-promptinglevel-set-to-enabled-for-multiple-loca-ac9159cc</loc>
    <lastmod>2026-07-30T05:18:24.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-from-clickonce-appdata-local-apps-2-0-windows-67bc0e75</loc>
    <lastmod>2026-07-31T13:29:12.909Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-clickonce-deployment-execution-via-dfsvc-exe-child-process-241d52b5</loc>
    <lastmod>2026-07-31T12:21:41.691Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dfsvc-exe-initiated-network-connection-on-uncommon-destination-ports-windows-4c5fba4a</loc>
    <lastmod>2026-07-31T12:20:13.984Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dfsvc-exe-initiated-network-connections-to-non-local-ip-addresses-on-windows-3c21219b</loc>
    <lastmod>2026-07-31T12:20:07.945Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-child-processes-spawned-by-sndvol-exe-ba42babc</loc>
    <lastmod>2026-07-30T05:05:32.597Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rjvplatform-dll-dll-sideloading-by-systemresetplatform-exe-from-non-defa-0e0bc253</loc>
    <lastmod>2026-07-31T13:11:30.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-side-loading-systemresetplatform-exe-loading-rjvplatform-dll-from-sy-259dda31</loc>
    <lastmod>2026-07-31T13:11:28.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-side-loading-edputil-dll-loaded-from-non-system-paths-e4903324</loc>
    <lastmod>2026-07-31T13:10:37.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-potential-7za-dll-sideloading-via-untrusted-image-paths-4f6edb78</loc>
    <lastmod>2026-07-31T13:09:57.119Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-sshd-flag-failed-curve25519-key-generation-suggesting-libssh-authenticatio-8b244735</loc>
    <lastmod>2026-07-31T12:09:12.203Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-clickonce-loads-unsigned-module-from-appdata-local-apps-2-0-060d5ad4</loc>
    <lastmod>2026-07-31T13:12:23.327Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-com-inprocserver32-hijack-via-psfactory-clsid-default-value-243380fa</loc>
    <lastmod>2026-07-30T05:21:05.552Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-kernel-module-loaded-despite-unmet-whql-requirements-even-2f8cd7a0</loc>
    <lastmod>2026-07-31T12:49:08.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-unsigned-image-loaded-event-id-3037-c92c24e7</loc>
    <lastmod>2026-07-31T12:49:06.823Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-unsigned-kernel-module-loaded-event-id-3001-951f8d29</loc>
    <lastmod>2026-07-31T12:49:05.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-revoked-image-loaded-events-3032-3035-881b7725</loc>
    <lastmod>2026-07-31T12:49:03.467Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-blocked-file-image-load-due-to-revoked-signing-certificat-6f156c48</loc>
    <lastmod>2026-07-31T12:49:01.722Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-operational-revoked-kernel-driver-loaded-event-id-3021-30-320fccbf</loc>
    <lastmod>2026-07-31T12:48:59.851Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-blocks-revoked-driver-loads-event-id-3023-9b72b82d</loc>
    <lastmod>2026-07-31T12:48:58.095Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-blocked-disallowed-file-for-protected-processes-event-id--5daf11c3</loc>
    <lastmod>2026-07-31T12:48:54.285Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-autoit2-autoit3-execution-via-autoit3executescr-f4264e47</loc>
    <lastmod>2026-07-30T05:02:03.326Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-get-requests-to-moveit-human2-aspx-paths-indicating-cve-2023-34362-exp-435e41f2</loc>
    <lastmod>2026-07-31T12:09:45.896Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-wget-downloaded-files-to-tmp-cf610c15</loc>
    <lastmod>2026-07-31T12:41:42.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-script-execution-from-tmp-via-shell-c-30bcce26</loc>
    <lastmod>2026-07-31T12:41:20.271Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-shell-execution-where-parent-process-runs-from-tmp-2fade0b6</loc>
    <lastmod>2026-07-31T12:41:17.625Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-process-execution-from-tmp-directory-312b42b1</loc>
    <lastmod>2026-07-31T12:40:46.888Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-nohupp-execution-from-tmp-457df417</loc>
    <lastmod>2026-07-31T12:39:49.593Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-grep-command-used-to-locate-specific-malware-related-files-process-discove-e34cfa0c</loc>
    <lastmod>2026-07-31T12:39:37.600Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-os-architecture-discovery-using-grep-for-cpu-arch-strings-d27ab432</loc>
    <lastmod>2026-07-31T12:39:24.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-crontab-l-enumeration-403ed92c</loc>
    <lastmod>2026-07-31T12:38:38.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-wget-writes-files-to-tmp-or-var-tmp-35a05c60</loc>
    <lastmod>2026-07-31T12:37:43.397Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-shell-script-creation-under-etc-profile-d-13f08f54</loc>
    <lastmod>2026-07-31T12:37:38.218Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-smadhook32c-dll-or-smadhook64c-dll-image-load-24b6cf51</loc>
    <lastmod>2026-07-31T13:11:38.784Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-core-dll-loaded-by-office-applications-on-windows-bb2ba6fb</loc>
    <lastmod>2026-07-31T13:09:49.805Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-amsi-dll-loaded-by-living-off-the-land-processes-extexport-exe-odbcconf--6ec86d9e</loc>
    <lastmod>2026-07-31T13:09:01.756Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-psscriptpolicytest-random-generated-by-uncommon-process-1027d292</loc>
    <lastmod>2026-07-31T13:05:35.232Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-traffic-to-suspect-c2-domains-matching-operation-triangulation-beaconing-i-aa03c712</loc>
    <lastmod>2026-07-31T12:13:10.381Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-operation-triangulation-dns-c2-beaconing-to-known-domains-7fc30d63</loc>
    <lastmod>2026-07-31T12:13:08.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-csc-exe-launched-by-w3wp-exe-for-moveit-pool-39ac1fb0</loc>
    <lastmod>2026-07-31T12:09:43.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-event-indicators-of-moveit-transfer-cve-2023-34362-exploitation-art-c3b2a774</loc>
    <lastmod>2026-07-31T12:09:41.064Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-executions-editing-sensitive-or-critical-files-via-shell-redirecti-86157017</loc>
    <lastmod>2026-07-31T12:41:15.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ruckus-wireless-admin-http-get-injection-attempt-likely-targeting-cve-2023-25717-043c1609</loc>
    <lastmod>2026-07-31T12:09:29.054Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scripting-engines-spawning-regsvr32-exe-via-parent-process-execution-ab37a6ec</loc>
    <lastmod>2026-07-30T05:01:13.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-execution-from-suspicious-dll-paths-327ff235</loc>
    <lastmod>2026-07-30T05:01:09.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-execution-with-dll-path-in-common-temporary-public-directories-9525dc73</loc>
    <lastmod>2026-07-30T05:01:07.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-execution-with-s-and-calc-keyword-0033cf83</loc>
    <lastmod>2026-07-31T12:11:27.879Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-regsvr32-command-line-uses-ftp-http-to-register-remote-compon-867356ee</loc>
    <lastmod>2026-07-30T05:01:01.739Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-server-failed-dns-zone-transfer-event-id-6004-6d444368</loc>
    <lastmod>2026-07-31T12:49:30.661Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-rundll32-executed-dll-like-path-without-dll-extension-bfd34392</loc>
    <lastmod>2026-07-31T12:11:33.382Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-qakbot-like-rundll32-exports-via-script-or-cmd-parent-339ed3d6</loc>
    <lastmod>2026-07-31T12:11:31.535Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-launched-via-lolbin-chain-from-cmd-cscript-powershell-mshta-cf879ffb</loc>
    <lastmod>2026-07-31T12:11:29.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-odbc-driver-registration-in-suspicious-path-e4d22291</loc>
    <lastmod>2026-07-30T05:20:23.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-odbc-driver-registration-via-odbcinst-ini-3390fbef</loc>
    <lastmod>2026-07-30T05:20:21.613Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-odbcconf-exe-installdriver-use-with-missing-dll-target-cb0fe7c5</loc>
    <lastmod>2026-07-30T04:53:19.546Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-access-to-bluesky-files-and-shares-used-in-bluesky-ransomware-artifacts-eee8311f</loc>
    <lastmod>2026-07-31T12:08:30.421Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-child-process-spawned-by-odbcconf-exe-8e3c7994</loc>
    <lastmod>2026-07-30T04:53:31.154Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-odbcconf-exe-with-f-response-file-flag-2d32dd6f</loc>
    <lastmod>2026-07-30T04:53:29.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-odbcconf-exe-response-file-execution-via-f-flag-5f03babb</loc>
    <lastmod>2026-07-30T04:53:27.957Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-odbcconf-exe-regsvr-usage-with-non-dll-suffixed-target-ba4cfc11</loc>
    <lastmod>2026-07-30T04:53:25.896Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-odbcconf-exe-used-to-register-a-dll-via-regsvr-9f0a8bf3</loc>
    <lastmod>2026-07-30T04:53:24.041Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-odbcconf-exe-with-dll-in-suspicious-path-6b65c28e</loc>
    <lastmod>2026-07-30T04:53:22.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-odbcconf-exe-installdriver-dll-installation-via-process-command-l-3f5491e2</loc>
    <lastmod>2026-07-30T04:53:18.010Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-non-browser-process-connecting-to-api-telegram-org-c3dbbc9f</loc>
    <lastmod>2026-07-31T13:13:35.195Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-password-policy-enumeration-via-event-id-4661-12ba6a38</loc>
    <lastmod>2026-07-31T12:53:48.089Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-run-key-persistence-with-small-sieve-typos-in-value-data-65c6e3c1</loc>
    <lastmod>2026-07-31T12:07:29.806Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-http-get-to-telegram-api-with-small-sieve-indicators-potential-c2-b0422664</loc>
    <lastmod>2026-07-31T12:07:28.103Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-commandline-ends-with-exe-platypus-indicator-21117127</loc>
    <lastmod>2026-07-31T12:07:26.308Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-detect-small-sieve-typo-based-filename-indicators-and-outloo-39466c42</loc>
    <lastmod>2026-07-31T12:07:24.549Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-werfault-reflectdebugger-registry-key-value-targeting-0cf2e1c6</loc>
    <lastmod>2026-07-30T05:21:29.218Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-certificate-export-cmdlets-in-windows-process-creation-9e716b33</loc>
    <lastmod>2026-07-30T04:55:32.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-imageloaded-wwlib-dll-associated-with-winword-e2e01011</loc>
    <lastmod>2026-07-31T13:12:19.589Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-download-indicators-of-suspicious-content-via-zip-tld-0bb4bbeb</loc>
    <lastmod>2026-07-31T13:00:08.897Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-findstr-exe-password-keyword-search-in-multiple-languages-1a0f6f16</loc>
    <lastmod>2026-07-31T12:21:54.601Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-executions-using-obfuscated-ordinal-call-arguments-43fa5350</loc>
    <lastmod>2026-07-30T05:03:16.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-rundll32-execution-of-advpack-dll-with-ordinal-registerocx-ca-a1473adb</loc>
    <lastmod>2026-07-30T05:03:04.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-cloudflared-tunnel-execution-with-config-and-token-flag-9a019ffc</loc>
    <lastmod>2026-07-31T13:26:40.693Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cloudflared-tunnel-cleanup-command-line-execution-7050bba1</loc>
    <lastmod>2026-07-31T13:26:38.517Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-s3-browser-creating-iam-user-or-access-key-db014773</loc>
    <lastmod>2026-07-31T12:28:09.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-s3-browser-creates-inline-iam-policy-with-default-bucket-placehol-db014773</loc>
    <lastmod>2026-07-31T12:28:07.768Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-s3-browser-enumerating-iam-loginprofiles-and-creating-missing-pro-db014773</loc>
    <lastmod>2026-07-31T12:28:05.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-internet-explorer-disablefirstruncustomize-set-via-explorer-or--ab567429</loc>
    <lastmod>2026-07-30T05:20:04.860Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-livekd-kernel-memory-dump-attempt-via-m-flag-c7746f1c</loc>
    <lastmod>2026-07-30T05:10:19.687Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-livekd-driver-file-created-by-non-livekd-executable-059c5af9</loc>
    <lastmod>2026-07-31T13:07:47.414Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-livekd-driver-file-creation-via-livekd-exe-or-livek64-exe-16fe46bb</loc>
    <lastmod>2026-07-31T13:07:45.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-livekd-kernel-memory-dump-file-created-livekd-dmp-814ddeca</loc>
    <lastmod>2026-07-31T13:07:43.749Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-http-get-requests-to-cross-php-with-op-dt-and-uid-parameters-514c50c9</loc>
    <lastmod>2026-07-31T04:26:35.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wscript-cscript-executes-files-with-uncommon-non-script-extensions-99b7460d</loc>
    <lastmod>2026-07-30T05:15:40.195Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-regsvr32-msiexec-child-process-from-windows-script-hosts-csc-b6676963</loc>
    <lastmod>2026-07-30T05:15:37.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-livekd-execution-suggesting-potential-memory-dumping-a85f7765</loc>
    <lastmod>2026-07-30T05:10:17.974Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-execution-of-kd-exe-windows-kernel-debugger-27ee9438</loc>
    <lastmod>2026-07-31T13:35:56.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-googleupdate-exe-84b1ecf9</loc>
    <lastmod>2026-07-31T13:31:15.459Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-certutil-exe-encode-writing-base64-from-suspicious-dire-82a6714f</loc>
    <lastmod>2026-07-31T13:26:19.023Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-encode-base64-of-suspicious-extensions-ea0cdc3e</loc>
    <lastmod>2026-07-31T13:26:14.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-goopdate-dll-imageload-b6188d2f</loc>
    <lastmod>2026-07-31T13:10:47.515Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-used-for-solidpdfcreator-dll-copy-and-run--7806bb49</loc>
    <lastmod>2026-07-31T12:13:40.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-for-goofy-guineapig-backdoor-persistence-via-rundll32-8c15dd74</loc>
    <lastmod>2026-07-31T12:07:13.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-googleupdate-exe-self-spawn-from-uncommon-path-bdbab15a</loc>
    <lastmod>2026-07-31T12:07:10.113Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-recon-via-wscript-cmd-redirection-to-appdata-devil-bait-e8954be4</loc>
    <lastmod>2026-07-31T12:07:01.203Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-by-uncommon-processes-in-appdata-roaming-microsoft-txt-xml-93d5f1b4</loc>
    <lastmod>2026-07-31T12:06:53.544Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-roboform-dll-sideloading-via-image-load-of-roboform-dll-f64c9b2d</loc>
    <lastmod>2026-07-31T13:11:32.095Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-web-requests-to-static-tcplog-com-using-chrome-like-user-agent-for-possibl-4f573bb6</loc>
    <lastmod>2026-07-31T12:07:11.862Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-commandline-matching-choice-t-d-d-y-n-nul-for-potential-backdoor-477a5ed3</loc>
    <lastmod>2026-07-31T12:07:08.164Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-ioc-match-for-goofy-guineapig-backdoor-indicators-f0bafe60</loc>
    <lastmod>2026-07-31T12:07:06.421Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certificate-services-client-exported-certificate-from-local-store-58c0bff0</loc>
    <lastmod>2026-07-31T12:48:50.693Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-capi2-acquire-certificate-private-key-eventid-70-e2b5163d</loc>
    <lastmod>2026-07-31T12:48:49.105Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-excel-loads-xll-add-in-from-uncommon-path-af4c4609</loc>
    <lastmod>2026-07-31T13:09:45.735Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-excel-loads-an-xll-add-in-via-excel-exe-image-load-c5f4b5cb</loc>
    <lastmod>2026-07-31T12:19:58.462Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winsxs-exe-creation-by-non-system-processes-34746e8c</loc>
    <lastmod>2026-07-31T13:07:39.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-events-targeting-security-policy-secrets-for-snake-malware-pers-d0fa35db</loc>
    <lastmod>2026-07-31T12:11:58.123Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-for-werfaultsvc-from-winsxs-werfault-exe-b2e60816</loc>
    <lastmod>2026-07-31T12:12:02.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-uncommon-wav-openwithprogids-value-creation-7e163e96</loc>
    <lastmod>2026-07-31T12:11:59.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-event-non-system-creation-of-werfault-exe-in-winsxs-64827580</loc>
    <lastmod>2026-07-31T12:11:51.140Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-snake-malware-installer-filename-indicators-99eccc2b</loc>
    <lastmod>2026-07-31T12:11:49.301Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-create-write-indicator-for-snake-kernel-driver-comadmin-dat-d6d9d23f</loc>
    <lastmod>2026-07-31T12:11:47.587Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-module-content-sets-get-vmremotefxphysicalvideoadapter-fu-cacef8fc</loc>
    <lastmod>2026-07-31T13:20:16.366Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-module-file-creation-by-non-powershell-process-e3845023</loc>
    <lastmod>2026-07-31T13:05:30.584Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-new-module-file-created-in-modules-directories-e36941d0</loc>
    <lastmod>2026-07-31T13:05:27.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-pwsh-dropping-ps1-files-via-powershell-exe-576426ad</loc>
    <lastmod>2026-07-31T13:05:23.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-process-import-module-execution-in-command-line-4ad74d01</loc>
    <lastmod>2026-07-31T12:22:19.912Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/system-informer-execution-on-windows-process-creation-5722dff1</loc>
    <lastmod>2026-07-30T04:58:42.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-flag-unicode-homoglyphs-in-targetfilename-4f1707b1</loc>
    <lastmod>2026-07-31T13:06:47.549Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-driver-load-for-system-informer-systeminformer-sys-with-known-hashes-10cb6535</loc>
    <lastmod>2026-07-31T13:01:05.469Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-matches-perfect-homoglyph-unicode-characters-32e280f1</loc>
    <lastmod>2026-07-30T05:07:40.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-solidpdfcreator-dll-sideloading-via-imageload-events-a2edbce1</loc>
    <lastmod>2026-07-31T13:11:40.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-fastpass-phishing-blocked-mfa-authentication-failure-ee39a9f7</loc>
    <lastmod>2026-07-31T12:34:28.826Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wget-exe-downloads-from-file-sharing-domains-matching-suspicious-output--a0d7e4d2</loc>
    <lastmod>2026-07-30T05:13:34.260Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-curl-exe-file-downloads-from-file-sharing-domains-56454143</loc>
    <lastmod>2026-07-31T13:28:38.436Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-reads-files-and-resolves-dns-host-entries-fbc5e92f</loc>
    <lastmod>2026-07-31T13:20:20.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-gup-exe-loading-libcurl-dll-from-uncommon-path-e49b5745</loc>
    <lastmod>2026-07-31T13:10:49.827Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-monitor-driver-sys-created-by-non-procmon-executables-a05baa88</loc>
    <lastmod>2026-07-31T13:07:51.159Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-explorer-driver-sys-created-by-non-process-explorer-binaries-de46c52b</loc>
    <lastmod>2026-07-31T13:07:49.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-executable-archive-file-created-in-c-perflogs-bbb7e38c</loc>
    <lastmod>2026-07-31T13:05:19.805Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-ntds-dit-created-0b8baa3f</loc>
    <lastmod>2026-07-31T13:04:39.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-sqlcmd-exe-querying-veeam-backup-databases-696bfb54</loc>
    <lastmod>2026-07-30T05:05:46.171Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-from-veeam-sql-server-service-d55b793d</loc>
    <lastmod>2026-07-30T04:52:02.748Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-credential-dumping-via-veeam-backup-common-protectedstorage-976d6e6f</loc>
    <lastmod>2026-07-31T13:22:46.955Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-traffic-with-suspicious-base64-encoded-user-agent-prefixes-d443095b</loc>
    <lastmod>2026-07-31T12:46:32.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-execution-matching-powertrash-indicators-4e19528a</loc>
    <lastmod>2026-07-31T12:13:17.404Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-executing-powerhold-like-logic-via-wscript-71c432c4</loc>
    <lastmod>2026-07-31T12:13:14.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-file-creation-with-64refl-ps1-or-host-ip-ps1-a88d9f45</loc>
    <lastmod>2026-07-31T12:13:12.127Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-werfault-child-process-from-winsxs-path-f7536642</loc>
    <lastmod>2026-07-31T12:11:56.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-jpinst-exe-jpsetup-exe-binary-used-in-snake-inst-d91ff53f</loc>
    <lastmod>2026-07-31T12:11:54.489Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-jpsetup-exe-cli-argument-hash-iv-sequence-indicator-02cbc035</loc>
    <lastmod>2026-07-31T12:11:52.741Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-non-browser-process-communicating-with-notion-api-7e9cf7b6</loc>
    <lastmod>2026-07-31T13:13:31.650Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-via-service-control-manager-7045-with-svchost-exe-image-3ced239c</loc>
    <lastmod>2026-07-31T12:11:03.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-new-user-profile-created-with-anonymous-and-domainuser-mark-95214813</loc>
    <lastmod>2026-07-31T12:11:01.295Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-svchost-exe-loads-suspicious-dll-from-appdata-roaming-potential-persiste-1d7a57da</loc>
    <lastmod>2026-07-31T12:10:53.657Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-non-browser-network-traffic-to-google-apis-7e9cf7b6</loc>
    <lastmod>2026-07-31T13:13:21.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-svchost-exe-with-specific-k-flags-9f9cd389</loc>
    <lastmod>2026-07-31T12:10:59.289Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-cleanup-export-execution-from-svchost-msupdate-services-88516f06</loc>
    <lastmod>2026-07-31T12:10:57.171Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-by-anonymous-user-with-system32-appdata-parent-image-e01b6eb5</loc>
    <lastmod>2026-07-31T12:10:55.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-persistence-via-appdata-roaming-newdev-dll-file-creation-1fea93a2</loc>
    <lastmod>2026-07-31T12:10:51.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-dllhost-exe-in-public-documents-for-coldsteel-rat-varia-c708a93f</loc>
    <lastmod>2026-07-31T12:10:44.749Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winlogon-exe-initiating-outbound-connections-to-public-ips-7610a4ea</loc>
    <lastmod>2026-07-31T13:14:27.936Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-rubeus-hacktool-execution-flags-3245cd30</loc>
    <lastmod>2026-07-31T13:18:41.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-logs-security-enabled-global-group-deletion-event-id-4730-634-b237c54b</loc>
    <lastmod>2026-07-31T12:50:41.139Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-member-removed-from-a-security-enabled-global-group-02c39d30</loc>
    <lastmod>2026-07-31T12:50:33.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-log-member-added-to-security-enabled-global-group-4728-632-c43c26be</loc>
    <lastmod>2026-07-31T12:50:31.714Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-downloads-setup-msi-via-invoke-webrequest-fo-de1bd0b6</loc>
    <lastmod>2026-07-31T12:13:46.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-external-ip-lookup-service-apis-edf3485d</loc>
    <lastmod>2026-07-31T13:13:19.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-using-xterm-with-display-1-reverse-shell-indicator-4e25af4b</loc>
    <lastmod>2026-07-31T12:41:44.020Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-python-reverse-shell-via-pty-and-socket-imports-32e62bc7</loc>
    <lastmod>2026-07-31T12:40:10.569Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-invoke-webrequest-execution-via-direct-ip-in-command-line-1edff897</loc>
    <lastmod>2026-07-30T04:55:53.990Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msmq-corrupted-packet-detected-event-id-2027-ae94b10d</loc>
    <lastmod>2026-07-31T12:09:02.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-with-schtasks-xml-using-non-xml-file-dd2a821e</loc>
    <lastmod>2026-07-30T05:04:58.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-pc-app-exe-0934ac71</loc>
    <lastmod>2026-07-31T12:13:48.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-manageengine-servicedesk-java-parent-spawns-suspicious-powershell-or-cre-58d8341a</loc>
    <lastmod>2026-07-31T12:13:36.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wstomcatservice-exe-parent-spawning-processes-log4j-wst-7c97c625</loc>
    <lastmod>2026-07-31T12:13:34.607Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-asperafaspex-parent-spawning-suspicious-powershell-lsas-91048c0d</loc>
    <lastmod>2026-07-31T12:13:32.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-client-mstsc-exe-launched-from-uncommon-browser-or-email-parent-proc-ff3b6b39</loc>
    <lastmod>2026-07-30T04:52:10.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mstsc-exe-launched-with-a-local-rdp-file-from-suspicious-paths-6e22722b</loc>
    <lastmod>2026-07-30T04:52:09.197Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mstsc-exe-launched-with-local-rdp-file-argument-5fdce3ac</loc>
    <lastmod>2026-07-30T04:52:07.531Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-file-creation-triggered-by-uncommon-application-fccfb43e</loc>
    <lastmod>2026-07-31T13:05:53.696Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winget-installs-from-zone-identifier-marked-sources-in-temp-winget-a3f5c081</loc>
    <lastmod>2026-07-31T13:00:06.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-winget-enablelocalmanifestfiles-set-to-dword-1-fa277e82</loc>
    <lastmod>2026-07-30T05:23:21.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winget-appinstaller-admin-settings-registry-modification-via-winget-exe-6db5eaf9</loc>
    <lastmod>2026-07-30T05:23:20.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-winget-adds-new-download-source-via-source-add-with-ip-endpoint-c15a46a0</loc>
    <lastmod>2026-07-30T05:14:12.750Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winget-adds-http-package-source-81a0ecb5</loc>
    <lastmod>2026-07-30T05:14:10.937Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winget-exe-adds-new-download-sources-via-source-add-05ebafc8</loc>
    <lastmod>2026-07-30T05:14:09.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-crassus-privilege-escalation-discovery-tool-execution-2c32b543</loc>
    <lastmod>2026-07-30T04:57:54.960Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-execution-stracciatella-exe-process-identified-via-pe-metadata-7a4d9232</loc>
    <lastmod>2026-07-31T13:34:32.698Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-certipy-exe-tool-execution-based-on-pe-and-command-line-6938366d</loc>
    <lastmod>2026-07-31T13:31:53.431Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-certify-exe-for-ad-certificate-abuse-attempts-762f2482</loc>
    <lastmod>2026-07-31T13:31:51.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-hijacking-libvlc-dll-sideloading-via-non-default-image-load-bf9808c4</loc>
    <lastmod>2026-07-31T13:10:59.880Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-unexpected-termination-of-message-queuing-msmq-s-56abae0c</loc>
    <lastmod>2026-07-31T12:58:31.372Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-important-service-terminated-with-error-d6b5520d</loc>
    <lastmod>2026-07-31T12:58:29.551Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-service-terminated-with-error-eventid-7023-acfa2210</loc>
    <lastmod>2026-07-31T12:58:27.825Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-action1-agent-and-remote-session-setup-aa3168fb</loc>
    <lastmod>2026-07-31T12:22:42.751Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-queuejumper-exploitation-attempt-via-mqsvc-exe-spawning-scripting-and-ut-53207cc2</loc>
    <lastmod>2026-07-31T12:07:42.995Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-renamed-visual-studio-nodejstools-pressanykey-exe-execution-65c3ca2c</loc>
    <lastmod>2026-07-30T05:02:43.123Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-ruby-e-scripts-calling-tcpsocket-via-rsocket-b8bdac18</loc>
    <lastmod>2026-07-31T12:40:23.993Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-php-inline-code-using-r-and-fsockopen-for-reverse-shell-s-c6714a24</loc>
    <lastmod>2026-07-31T12:39:56.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-perl-reverse-shell-pattern-via-perl-e-with-socket-inet-and-connect-open-ex-259df6bc</loc>
    <lastmod>2026-07-31T12:39:55.310Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-of-netcat-ncat-with-e-followed-by-shell-invocation-7f734ed0</loc>
    <lastmod>2026-07-31T12:39:44.398Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-bash-launched-in-interactive-mode-via-i-6104e693</loc>
    <lastmod>2026-07-31T12:38:10.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-logged-on-user-password-change-via-ksetup-exe-c9783e20</loc>
    <lastmod>2026-07-31T13:36:04.508Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-password-change-via-ksetup-exe-setcomputerpassword-de16d92c</loc>
    <lastmod>2026-07-31T13:36:02.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-spawned-by-browsers-on-macos-via-shell-and-script-runti-0250638a</loc>
    <lastmod>2026-07-31T12:43:14.163Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-smb-client-failed-smb-session-network-connections-to-internet-facing-ser-de96b824</loc>
    <lastmod>2026-07-31T12:09:17.889Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-changes-for-outlook-task-note-reminder-trigger-fc06e655</loc>
    <lastmod>2026-07-31T12:09:14.115Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rorschach-ransomware-execution-behavior-on-windows-via-command-line-indicators-0e9e6c63</loc>
    <lastmod>2026-07-31T12:11:45.613Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detect-applet-osascript-execution-of-osacompile-via-process-command-line-a753a6af</loc>
    <lastmod>2026-07-31T12:43:34.183Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-failed-login-where-password-like-alternateid-was-provided-91b76b84</loc>
    <lastmod>2026-07-31T12:34:39.167Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-web-requests-downloading-ico-from-3cxdesktopapp-icon-storage-potential-c2--76bc1601</loc>
    <lastmod>2026-07-31T12:12:49.125Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-load-triggered-by-known-compromised-3cxdesktopapp-module-hashes-d0b65ad3</loc>
    <lastmod>2026-07-31T12:12:16.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-logs-potential-beaconing-to-3cx-related-domains-3c4b3bbf</loc>
    <lastmod>2026-07-31T12:12:46.664Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-3cxdesktopapp-updater-fetching-known-compromised-update-e7581747</loc>
    <lastmod>2026-07-31T12:12:44.963Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-child-processes-spawned-by-3cxdesktopapp-exe-63f3605b</loc>
    <lastmod>2026-07-31T04:31:26.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-known-compromised-3cxdesktopapp-binaries-by-hash-93bbde78</loc>
    <lastmod>2026-07-31T12:12:26.623Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-compromised-3cxdesktopapp-beaconing-activity-netcon-51eecf75</loc>
    <lastmod>2026-07-31T12:12:17.923Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-compromised-3cxdesktopapp-beaconing-activity-dns-bd03a0dc</loc>
    <lastmod>2026-07-31T12:12:14.492Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-real-time-protection-feature-error-or-restart-windefend-dd80db93</loc>
    <lastmod>2026-07-31T12:59:09.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sysinternals-pssuspend-targeting-msmpeng-exe-4beb6ae0</loc>
    <lastmod>2026-07-30T05:10:39.520Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysinternals-pssuspend-process-execution-48bbc537</loc>
    <lastmod>2026-07-30T05:10:37.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-iviewers-dll-image-loads-4c21b805</loc>
    <lastmod>2026-07-31T13:10:51.581Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-sign-in-success-from-legacy-client-user-agents-suggesting-mfa-bypass-ri-53bb4f7f</loc>
    <lastmod>2026-07-31T12:32:18.458Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-sysadminctl-used-to-add-user-to-admin-group-652c098d</loc>
    <lastmod>2026-07-31T12:43:37.780Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-dscl-used-to-append-user-to-groups-admin-group-b743623c</loc>
    <lastmod>2026-07-31T12:42:13.809Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-creating-executable-or-script-files-matching-binary-dropper-p-7047d730</loc>
    <lastmod>2026-07-31T13:05:21.631Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-svchost-exe-spawning-rundll32-exe-with-webdav-davclnt-dll-davsetcookie-982e9f2d</loc>
    <lastmod>2026-07-30T05:03:56.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-requests-to-ipfs-urls-containing-email-addresses-eb6c2004</loc>
    <lastmod>2026-07-31T12:46:26.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-termination-via-kill-pkill-killall-commands-64c41342</loc>
    <lastmod>2026-07-31T12:18:49.973Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-outlook-exe-registry-query-for-webclient-lanmanworkstation-network-provi-73c59189</loc>
    <lastmod>2026-07-31T12:09:15.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-hypervisor-enforced-code-integrity-enabled-dword-set-to-0-8b7273a4</loc>
    <lastmod>2026-07-30T05:18:46.818Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sysinternals-adexplorer-snapshot-exports-active-directo-ef61af62</loc>
    <lastmod>2026-07-30T05:10:14.430Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysinternals-adexplorer-invoked-with-snapshot-flag-to-create-ad-database-9212f354</loc>
    <lastmod>2026-07-30T05:10:12.691Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-ldifde-exe-export-of-active-directory-via-f-4f7a6757</loc>
    <lastmod>2026-07-31T13:36:06.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-memory-dump-tool-execution-dotnet-dump-exe-collect-53d8d3e1</loc>
    <lastmod>2026-07-31T13:29:45.488Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-active-directory-export-using-csvde-exe-e5d36acd</loc>
    <lastmod>2026-07-31T13:28:28.595Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-event-for-potential-qakbot-iceid-persistence-key-1c8e96cd</loc>
    <lastmod>2026-07-30T05:16:49.711Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-execution-masquerading-as-image-files-via-image-extensions-4aa6040b</loc>
    <lastmod>2026-07-30T05:03:37.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-downloading-dlls-via-invoke-webrequest-or-invoke-restmethod-0f0450f3</loc>
    <lastmod>2026-07-30T04:55:14.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-gzipstream-decompression-attempts-on-windows-98767d61</loc>
    <lastmod>2026-07-30T04:54:57.668Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-side-loading-indicators-for-wazuh-platform-libraries-via-imageload-e-db77ce78</loc>
    <lastmod>2026-07-31T13:12:15.853Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-imageloads-rcdll-dll-from-non-vs-windows-kits-paths-6e78b74f</loc>
    <lastmod>2026-07-31T13:11:21.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-amsi-dll-loaded-by-uncommon-process-facd1549</loc>
    <lastmod>2026-07-31T12:19:49.380Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-7-zip-extraction-of-password-protected-archives-using-p-b717b8fd</loc>
    <lastmod>2026-07-31T12:21:21.687Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-mshta-powershell-and-system-survey-behavior-36222790</loc>
    <lastmod>2026-07-31T12:01:32.512Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-configuration-update-via-sysmon64-command-line-87911521</loc>
    <lastmod>2026-07-30T05:10:44.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-package-uninstall-commands-via-yum-apt-dpkg-rpm-95d61234</loc>
    <lastmod>2026-07-31T12:40:17.522Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-matches-griffon-malware-execution-pattern-bcc6f179</loc>
    <lastmod>2026-07-31T12:11:10.839Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-execution-with-wmiexec-default-flag-sequence-022eaba8</loc>
    <lastmod>2026-07-31T13:34:47.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-reads-redirected-input-from-stdin-using-operator-241e802a</loc>
    <lastmod>2026-07-31T13:27:28.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-alerts-on-unix-shell-configuration-file-modifications-a94cdd87</loc>
    <lastmod>2026-07-31T12:36:29.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-firewall-rule-deletions-via-iptables-firewall-cmd-ufw-or-nft-323ff3f5</loc>
    <lastmod>2026-07-31T12:35:35.948Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-stop-a-service-with-sc-exe-via-process-creation-sc-exe-stop-81bcb81b</loc>
    <lastmod>2026-07-30T05:04:21.171Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-stop-service-used-to-stop-a-service-c49c5062</loc>
    <lastmod>2026-07-30T04:56:39.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-stop-activity-via-net-exe-command-line-88872991</loc>
    <lastmod>2026-07-30T04:52:20.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-root-certificate-installation-via-addstore-d2125259</loc>
    <lastmod>2026-07-31T13:26:02.348Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certmgr-exe-root-certificate-added-via-add-root-ff992eac</loc>
    <lastmod>2026-07-31T13:25:51.085Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-set-service-startuptype-change-to-disabled-or-manual-62b20d44</loc>
    <lastmod>2026-07-30T04:56:32.886Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-whoami-exe-execution-with-fo-csv-or-output-redirection-c30fb093</loc>
    <lastmod>2026-07-30T05:13:46.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-whoami-exe-group-membership-reconnaissance-via-groups-flag-bd8b828d</loc>
    <lastmod>2026-07-30T05:13:42.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sc-exe-service-security-descriptor-tampering-sdset-98c5aeef</loc>
    <lastmod>2026-07-30T05:04:16.087Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sc-exe-service-security-descriptor-changes-via-sdset-6c8fbee5</loc>
    <lastmod>2026-07-30T05:04:10.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-exception-rule-added-for-application-in-suspicious-file-locatio-9e2575e7</loc>
    <lastmod>2026-07-31T12:49:41.942Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wscript-initiated-dns-queries-to-regex-matched-domains-potential-c2-70761fe8</loc>
    <lastmod>2026-07-31T12:12:06.296Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/joomla-web-endpoint-get-requests-matching-cve-2023-23752-exploitation-parameters-0e1ebc5a</loc>
    <lastmod>2026-07-31T12:09:19.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mounting-internet-hosted-webdav-shares-via-net-exe-7e6237fe</loc>
    <lastmod>2026-07-30T04:52:24.130Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-new-service-creation-via-sc-exe-85ff530b</loc>
    <lastmod>2026-07-30T05:04:04.292Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-creates-windows-service-via-new-service-and-binarypathname-c02e96b7</loc>
    <lastmod>2026-07-30T04:54:56.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-sysadminctl-used-to-enable-guest-account-d7329412</loc>
    <lastmod>2026-07-31T12:43:39.431Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-persistence-attempts-using-plistbuddy-to-configure-launchagents-launchdaem-65d506d3</loc>
    <lastmod>2026-07-31T12:42:54.341Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-installer-script-spawning-suspicious-child-interpreter-processes-e0cfaecd</loc>
    <lastmod>2026-07-31T12:42:28.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-indicators-in-event-viewer-events-asp-links-a1e11042</loc>
    <lastmod>2026-07-30T05:21:09.197Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-of-vsstrace-dll-by-uncommon-executables-48bfd177</loc>
    <lastmod>2026-07-31T13:09:29.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-deletion-of-tomcat-web-server-log-files-270185ff</loc>
    <lastmod>2026-07-31T13:01:59.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-containing-unicode-right-to-left-override-u-202e-ad691d92</loc>
    <lastmod>2026-07-30T05:08:51.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-certificate-export-using-exportpfx-3ffd6f51</loc>
    <lastmod>2026-07-31T13:26:20.760Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-download-from-file-sharing-sites-using-suspicious-url-urlca-42a5f1e7</loc>
    <lastmod>2026-07-31T13:26:10.329Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-certutil-exe-download-from-direct-ip-using-urlcache-verifyctl-fl-13e6fe51</loc>
    <lastmod>2026-07-31T13:26:08.046Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-download-execution-with-url-cache-verify-flags-19b08b1c</loc>
    <lastmod>2026-07-31T13:26:05.873Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-base64-hex-decoding-via-decode-or-decodehex-cc9cbe82</loc>
    <lastmod>2026-07-31T13:26:03.981Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certoc-exe-loading-dll-from-user-writable-paths-84232095</loc>
    <lastmod>2026-07-31T13:25:58.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-console-history-file-deleted-psreadline-consolehost-history-t-ff301988</loc>
    <lastmod>2026-07-31T13:01:49.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-event-log-evtx-file-deletion-from-system32-winevt-logs-63c779ba</loc>
    <lastmod>2026-07-31T13:01:41.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-script-interpreter-execution-from-extracted-compressed-files-7zip-winrar-95724fc1</loc>
    <lastmod>2026-07-31T12:23:18.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-remote-query-execution-via-node-7773b877</loc>
    <lastmod>2026-07-30T05:15:04.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-exe-service-reconnaissance-via-remote-service-queries-76f55eaa</loc>
    <lastmod>2026-07-30T05:14:57.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-exe-product-class-reconnaissance-via-security-product-queries-e568650b</loc>
    <lastmod>2026-07-30T05:14:56.252Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-product-reconnaissance-via-firewall-av-enumeration-15434e33</loc>
    <lastmod>2026-07-30T05:14:54.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-exe-hardware-model-reconnaissance-using-csproduct-3e3ceccd</loc>
    <lastmod>2026-07-30T05:14:47.330Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-localpotato-exe-execution-for-local-privilege-escalation-6bd75993</loc>
    <lastmod>2026-07-31T13:33:31.455Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-execution-of-regasm-regsvcs-with-uncommon-command-line-extens-e9f8f8cc</loc>
    <lastmod>2026-07-30T05:00:21.063Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-filter-driver-unload-triggered-by-fltmc-exe-process-execution-4931188c</loc>
    <lastmod>2026-07-31T13:30:47.637Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detect-post-attempts-to-oracle-e-business-suite-uueupload-endpoints-cv-d033cb8a</loc>
    <lastmod>2026-07-31T12:07:44.934Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/velocity-template-renderer-exceptions-indicating-possible-ssti-via-parseerrorexc-16c86189</loc>
    <lastmod>2026-07-31T12:26:44.912Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/spring-application-logs-potential-spel-injection-causing-expressionexception-err-e9edd087</loc>
    <lastmod>2026-07-31T12:26:41.232Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/node-js-application-error-logs-indicating-potential-rce-via-child-process-97661d9d</loc>
    <lastmod>2026-07-31T12:25:16.946Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/jvm-application-error-logs-indicating-possible-xxe-parsing-failures-c4e06896</loc>
    <lastmod>2026-07-31T12:24:48.647Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/jvm-process-execution-error-messages-indicating-failed-program-launch-d65f37da</loc>
    <lastmod>2026-07-31T12:24:46.703Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/jvm-application-error-logs-ognl-injection-exploitation-indicators-4d0af518</loc>
    <lastmod>2026-07-31T12:24:44.458Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/jvm-application-errors-indicating-local-file-read-path-traversal-attempts-e032f5bc</loc>
    <lastmod>2026-07-31T12:24:42.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/jvm-application-error-logs-indicating-jndi-injection-payloads-bb0e9cec</loc>
    <lastmod>2026-07-31T12:24:41.310Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-onenote-temp-file-creation-with-suspicious-executable-extensions-fcc6d700</loc>
    <lastmod>2026-07-31T13:04:58.594Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-outlook-enableunsafeclientmailrules-set-to-1-6763c6c8</loc>
    <lastmod>2026-07-30T05:20:40.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-process-execution-of-gathernetworkinfo-vbs-via-cscript-wscrip-07aa184a</loc>
    <lastmod>2026-07-30T05:07:34.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/outlook-process-loads-outlvba-dll-microsoft-vba-add-in-on-windows-9a0b8719</loc>
    <lastmod>2026-07-31T13:09:48.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-publisher-attachment-file-created-in-suspicious-directory-3d2a2d59</loc>
    <lastmod>2026-07-31T13:05:09.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-creation-of-outlook-vbaproject-otm-macro-file-117d3d3a</loc>
    <lastmod>2026-07-31T13:05:06.381Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vbs-gathernetworkinfo-output-files-written-to-system32-config-f92a6f1e</loc>
    <lastmod>2026-07-31T13:03:54.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-autohotkey-executable-via-pe-metadata-0f16d9cf</loc>
    <lastmod>2026-07-30T05:02:01.325Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-nltest-exe-execution-for-network-information-discovery-903076ff</loc>
    <lastmod>2026-07-30T04:53:00.003Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmdkey-exe-adds-generic-credentials-via-command-line-flags-b1ec66c6</loc>
    <lastmod>2026-07-31T13:27:38.623Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-onenote-exe-launches-cmd-cscript-mshta-powershell-wscript-with-onenote-e-84b1706c</loc>
    <lastmod>2026-07-30T04:53:37.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-add-appxpackage-attempt-with-allowunsigned-for-appx-installat-37651c2a</loc>
    <lastmod>2026-07-30T04:55:49.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-psscript-attempts-to-install-unsigned-appx-via-add-appxpackage-add-ap-975b2262</loc>
    <lastmod>2026-07-31T13:18:55.270Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-creation-osacompile-run-only-execution-via-inline-e-script-b9d9b652</loc>
    <lastmod>2026-07-31T12:42:50.607Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-suspicious-shell-python-child-processes-spawned-by-microsoft-office-apps-69483748</loc>
    <lastmod>2026-07-31T12:42:48.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-jxa-in-memory-javascript-execution-via-osascript-f1408a58</loc>
    <lastmod>2026-07-31T12:42:35.645Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-osascript-clipboard-access-via-applescript-7794fa3c</loc>
    <lastmod>2026-07-31T12:42:00.974Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-copy-passwd-or-shadow-from-tmp-using-cp-fa4aaed5</loc>
    <lastmod>2026-07-31T12:38:36.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-base64-encoded-wmi-class-invocation-1816994b</loc>
    <lastmod>2026-07-30T04:54:37.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-log-new-org-member-added-or-invited-3908d64a</loc>
    <lastmod>2026-07-31T12:24:22.805Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-organizational-high-risk-security-controls-disabled-8622c92d</loc>
    <lastmod>2026-07-31T12:24:17.549Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-monitor-pendingfilerenameoperations-changes-from-suspicious-ima-4eec988f</loc>
    <lastmod>2026-07-30T05:22:24.106Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-log-self-hosted-runner-configuration-change-alerts-f8ed0e8f</loc>
    <lastmod>2026-07-31T12:24:37.887Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-logs-dependabot-alerts-or-security-updates-disabled-34e1c7d4</loc>
    <lastmod>2026-07-31T12:24:19.292Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-system-information-discovery-via-wmic-exe-recon-9d5a1274</loc>
    <lastmod>2026-07-30T05:14:59.395Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-process-spawned-by-vscode-code-exe-5a3164f2</loc>
    <lastmod>2026-07-30T05:12:24.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-rundll32-launching-nsis-module-via-nsis-uns-5cdbc2e8</loc>
    <lastmod>2026-07-31T12:11:43.833Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-enabling-bpf-kprobes-tracing-via-debugfs-and-probe-enable-7692f583</loc>
    <lastmod>2026-07-31T12:38:13.663Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-ebpf-warning-indicators-bpf-probe-write-user-helper-messages-0fadd880</loc>
    <lastmod>2026-07-31T12:37:05.254Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wsl-process-spawning-uncommon-child-executables-2267fe65</loc>
    <lastmod>2026-07-30T05:15:42.010Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-module-execution-matching-known-offensive-script-names-poshmo-41025fd7</loc>
    <lastmod>2026-07-31T13:16:07.684Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-on-windows-adding-windows-capabilities-via-add-windowscapability-b36d01a3</loc>
    <lastmod>2026-07-30T04:54:14.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-imports-microsoft-activedirectory-management-dll-via-import-m-70bc5215</loc>
    <lastmod>2026-07-30T04:54:12.905Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-appcmd-creates-global-url-rewrite-rules-via-config-commit-7c8af9b2</loc>
    <lastmod>2026-07-31T13:35:23.195Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-capability-installation-via-powershell-add-windowscapability-script-bloc-155c7fd5</loc>
    <lastmod>2026-07-31T13:17:23.289Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-import-module-of-microsoft-activedirectory-management-dll-for-9e620995</loc>
    <lastmod>2026-07-31T13:17:19.958Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-active-directory-module-load-via-import-module-74176142</loc>
    <lastmod>2026-07-31T13:15:39.736Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-search-order-hijacking-via-arubanetsvc-exe-dll-loads-90ae0469</loc>
    <lastmod>2026-07-31T13:10:10.293Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-one-onepkg-file-created-in-suspicious-locations-7fd164ba</loc>
    <lastmod>2026-07-31T13:04:56.610Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-launching-dll-from-alternate-data-stream-ads-paths-9248c7e1</loc>
    <lastmod>2026-07-30T05:03:02.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexec-key-file-creation-via-c-windows-psexec-key-304afd73</loc>
    <lastmod>2026-07-31T13:07:55.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-potential-pre-auth-rce-exploitation-via-dhcpserver-svch-6d5b8176</loc>
    <lastmod>2026-07-31T12:10:43.017Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-match-known-malicious-poshmodule-cmdlets-and-framework-functi-7d0d0329</loc>
    <lastmod>2026-07-31T13:16:52.435Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-outside-collaborator-membership-and-permissions-changed-eaa9ac35</loc>
    <lastmod>2026-07-31T12:24:26.102Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-new-actions-secret-created-organization-environment-codespaces-or-r-f9405037</loc>
    <lastmod>2026-07-31T12:24:24.476Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-centos-web-panel-7-rce-probe-via-post-login-index-php-1b2eeb27</loc>
    <lastmod>2026-07-31T12:08:27.024Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-driverquery-exe-process-execution-for-installed-driver-discovery-a20def93</loc>
    <lastmod>2026-07-31T13:29:49.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-driverquery-exe-used-for-installed-driver-recon-9fc3072c</loc>
    <lastmod>2026-07-31T13:29:47.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-successful-smb-logon-event-id-4624-logontype-3-from-public-ips-78d5cab4</loc>
    <lastmod>2026-07-31T12:50:44.986Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-successful-logon-from-public-ip-event-id-4624-logontype-10-259a9cdf</loc>
    <lastmod>2026-07-31T12:50:43.052Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-admin-role-assignment-created-via-iam-resource-set-binding-add-139bdd4b</loc>
    <lastmod>2026-07-31T12:34:19.359Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-logs-codespaces-and-repo-delete-actions-16a71777</loc>
    <lastmod>2026-07-31T12:24:16.018Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-manageengine-servicedesk-java-serv-cea2b7ea</loc>
    <lastmod>2026-07-31T13:35:43.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-iptables-ufw-chain-flush-commands-enabling-all-network-traffic-3be619f4</loc>
    <lastmod>2026-07-31T12:39:31.787Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-attempt-to-disable-or-stop-ufw-firewall-via-ufw-init-or-ufw-disable-84c9e83c</loc>
    <lastmod>2026-07-31T12:38:50.362Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-rules-deleted-event-id-2033-2059-indicating-defense-impairment-79609c82</loc>
    <lastmod>2026-07-31T12:49:45.671Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-data-exfiltration-via-audio-file-using-powershell-script-block-e4f93c99</loc>
    <lastmod>2026-07-31T13:17:34.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-client-detect-dns-queries-containing-ufile-io-090ffaad</loc>
    <lastmod>2026-07-31T12:49:28.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-client-queries-for-mega-userstorage-subdomains-66474410</loc>
    <lastmod>2026-07-31T12:49:15.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cobalt-strike-dns-beaconing-via-windows-dns-client-event-id-3008-0d18728b</loc>
    <lastmod>2026-07-31T12:49:14.041Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-client-queryname-contains-anonfiles-com-29f171d7</loc>
    <lastmod>2026-07-31T12:49:11.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-packaging-execute-packages-signed-with-a-known-suspicious-certifica-b5aa7d60</loc>
    <lastmod>2026-07-31T12:48:32.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-sysinternals-tools-via-appx-package-d29a20b2</loc>
    <lastmod>2026-07-31T12:48:10.753Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-excel-options-run-entry-point-for-xll-add-in-persistence-961e33d1</loc>
    <lastmod>2026-07-30T05:21:39.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disablerestrictedadmin-value-tampering-to-change-restricted-adm-d6ce7ebd</loc>
    <lastmod>2026-07-30T05:20:09.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-registry-tampering-of-disablerestrictedadmin-in-lsa-key-28ac00d6</loc>
    <lastmod>2026-07-30T04:59:54.320Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-task-scheduler-detect-scheduled-task-deleted-or-disabled-for-key-system--9e3cb244</loc>
    <lastmod>2026-07-31T12:58:45.120Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsa-event-300-standard-user-added-to-privileged-groups-administrator-adm-7ac407cc</loc>
    <lastmod>2026-07-31T12:50:04.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-enabling-developer-features-for-sideloading-and-untruste-b110ebaf</loc>
    <lastmod>2026-07-30T05:22:57.643Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-child-processes-from-windowsapps-directory-f91ed517</loc>
    <lastmod>2026-07-30T05:06:18.025Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-blocked-application-access-enforced-by-software-restriction-polic-b4c8da4a</loc>
    <lastmod>2026-07-31T12:47:35.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-mount-executed-with-hidepid-2-option-ec52985a</loc>
    <lastmod>2026-07-31T12:39:42.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-powershell-executionpolicy-tampering-bypass-unrestricted-fad91067</loc>
    <lastmod>2026-07-30T05:21:51.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-activity-enabling-developer-mode-or-sideloading-via-systemsettin-a383dec4</loc>
    <lastmod>2026-07-30T05:10:55.774Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-execution-policy-registry-tampering-via-comm-cf2e938e</loc>
    <lastmod>2026-07-30T05:00:53.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bits-client-job-downloads-from-direct-ip-addresses-90f138c1</loc>
    <lastmod>2026-07-31T12:48:43.548Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-deployment-server-uncommon-appx-path-added-to-processing-pipeline-c977cb50</loc>
    <lastmod>2026-07-31T12:48:27.400Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-package-deployment-blocked-by-local-policy-appxdeployment-server-e021bbb5</loc>
    <lastmod>2026-07-31T12:48:25.520Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-appx-package-installation-attempts-on-windows-via-appx-deployment-ser-09d3b48b</loc>
    <lastmod>2026-07-31T12:48:23.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-deployment-app-package-from-common-staging-directories-added-to-pro-5cdeaf3d</loc>
    <lastmod>2026-07-31T12:48:19.702Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-deployment-fails-due-to-unsatisfied-signing-requirements-0x80073cff-898d5fc9</loc>
    <lastmod>2026-07-31T12:48:17.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-deployment-server-remote-appx-package-downloaded-from-file-sharing--8b48ad89</loc>
    <lastmod>2026-07-31T12:48:15.593Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-package-deployment-blocked-by-applocker-appxdeployment-server-event-6ae53108</loc>
    <lastmod>2026-07-31T12:48:13.628Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-detect-touch-used-on-service-files-31545105</loc>
    <lastmod>2026-07-31T12:41:29.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-import-module-from-temp-appdata-public-paths-c31364f7</loc>
    <lastmod>2026-07-30T04:55:47.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-risky-success-from-non-registered-device-without-mfa-requirement-572b12d4</loc>
    <lastmod>2026-07-31T12:32:13.342Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-alias-obfuscation-via-value-join-in-script-blocks-e8314f79</loc>
    <lastmod>2026-07-31T13:20:53.650Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/juniper-bgp-missing-md5-digest-a7c0ae48</loc>
    <lastmod>2026-07-31T12:45:04.060Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/huawei-bgp-authentication-failure-events-a557ffe6</loc>
    <lastmod>2026-07-31T12:45:01.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-ldp-authentication-failures-indicating-tcp-md5-auth-rejects-50e606bf</loc>
    <lastmod>2026-07-31T12:44:31.123Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-bgp-authentication-failures-on-tcp-179-56fa3cd6</loc>
    <lastmod>2026-07-31T12:44:29.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-alias-cmdlets-set-alias-new-alias-in-script-block-logging-96cd126d</loc>
    <lastmod>2026-07-31T13:22:10.388Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-double-extension-execution-via-parent-command-line-5e6a80c8</loc>
    <lastmod>2026-07-30T05:06:59.077Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-s3-listbuckets-by-non-assumedrole-accounts-possible-bucket-enumer-f305fd62</loc>
    <lastmod>2026-07-31T12:28:00.942Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-process-creation-suspicious-base64-encoded-and-iex-webclient--536e2947</loc>
    <lastmod>2026-07-30T04:55:51.122Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-security-descriptor-manipulation-for-potential-pe-2f77047c</loc>
    <lastmod>2026-07-31T13:20:49.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-amsi-com-server-hijacking-via-inprocserver32-clsid-modification-160d2780</loc>
    <lastmod>2026-07-30T05:17:37.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-keylogger-indicators-via-keyboard-state-references-windows-965e2db9</loc>
    <lastmod>2026-07-31T13:21:42.819Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-git-clone-with-vulnerability-payload-keywords-aef9d1f1</loc>
    <lastmod>2026-07-31T13:31:09.069Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-match-for-known-hacktool-and-scanning-binaries-a015e032</loc>
    <lastmod>2026-07-31T12:40:58.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-of-git-clone-containing-exploit-or-vulnerability-keyword-cfec9d29</loc>
    <lastmod>2026-07-31T12:40:50.380Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-package-installation-commands-for-potential-recon-tool-deployment-700fb7e8</loc>
    <lastmod>2026-07-31T12:39:29.913Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-eventlog-service-file-location-tampering-0cb8d736</loc>
    <lastmod>2026-07-30T05:19:36.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ruby-inline-code-execution-via-ruby-exe-e-flag-20a5ffa1</loc>
    <lastmod>2026-07-30T05:03:01.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-python-executed-with-the-c-inline-code-flag-899133d5</loc>
    <lastmod>2026-07-30T04:58:56.096Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-powershell-commandlets-used-by-known-exploit-02030f2f</loc>
    <lastmod>2026-07-30T04:56:02.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-inline-php-execution-via-php-exe-r-flag-d81871ef</loc>
    <lastmod>2026-07-30T04:54:00.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-perl-inline-code-execution-via-e-e-f426547a</loc>
    <lastmod>2026-07-30T04:53:59.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-evtx-file-creation-in-non-standard-locations-65236ec7</loc>
    <lastmod>2026-07-31T13:02:25.022Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-child-process-spawned-by-defaultpack-exe-b2309017</loc>
    <lastmod>2026-07-31T13:28:55.627Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-coregen-exe-0fa66f66</loc>
    <lastmod>2026-07-31T13:10:23.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpldapmonitor-hacktool-execution-on-windows-9f8fc146</loc>
    <lastmod>2026-07-31T13:34:10.380Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-executable-command-path-containing-hidden-files-or-hidden-directori-9e1bef8d</loc>
    <lastmod>2026-07-31T12:36:18.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ssh-exe-used-as-proxy-local-command-launcher-via-proxycommand-and-localc-7d6d30b8</loc>
    <lastmod>2026-07-30T05:05:58.244Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-enable-windowsoptionalfeature-enables-suspicious-optional-fea-c740d4cf</loc>
    <lastmod>2026-07-30T04:55:25.569Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-unregmp2-exe-used-as-a-proxy-to-launch-wmpnscfg-exe-727454c0</loc>
    <lastmod>2026-07-31T13:37:44.958Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-runexehelper-exe-used-as-a-proxy-cd71385d</loc>
    <lastmod>2026-07-31T13:37:15.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-execution-of-find-with-setuid-setgid-or-world-writable-permission--85de3a19</loc>
    <lastmod>2026-07-31T12:43:20.257Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-vim-gtfobin-abuse-via-process-execution-flags-and-shell-commands-7ab8f73a</loc>
    <lastmod>2026-07-31T12:41:38.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-discovery-via-find-command-searching-setuid-sgid-and-writable-exec-8344c0e5</loc>
    <lastmod>2026-07-31T12:40:48.517Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-capabilities-discovery-via-getcap-r-d8d97d51</loc>
    <lastmod>2026-07-31T12:38:21.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-via-apt-apt-get-shell-proxy-option-bb382fd5</loc>
    <lastmod>2026-07-31T12:37:55.080Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-session-hijacking-via-tscon-exe-from-system-integrity-224f140f</loc>
    <lastmod>2026-07-30T05:11:18.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-token-obfuscation-via-process-command-line-deb9b646</loc>
    <lastmod>2026-07-30T04:56:49.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpimpersonation-tool-execution-on-windows-via-process-creation-f89b08d0</loc>
    <lastmod>2026-07-31T13:34:07.376Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-matching-htran-natbypass-executable-names-and-cli-flags-f5e3b62f</loc>
    <lastmod>2026-07-31T13:32:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-keyword-matching-drop-truncate-dump-select-d84c0ded</loc>
    <lastmod>2026-07-31T12:27:01.867Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-block-token-obfuscation-via-invoke-obfuscation-patterns-f3a98ce4</loc>
    <lastmod>2026-07-31T12:21:08.592Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detects-web-exploitation-attempts-against-cacti-remote-agent-php-cve-2022-46169--738cb115</loc>
    <lastmod>2026-07-31T12:08:28.720Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-userdel-execution-indicates-account-deletion-08f26069</loc>
    <lastmod>2026-07-31T12:41:34.918Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-groupdel-execution-identified-by-process-creation-8a46f16c</loc>
    <lastmod>2026-07-31T12:39:26.097Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-inline-execution-via-file-reads-and-raw-parameters-ee218c12</loc>
    <lastmod>2026-07-30T04:55:31.108Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-com-clsid-download-cradles-02b64f1b</loc>
    <lastmod>2026-07-30T04:55:11.435Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-com-clsid-download-cradles-suspicious-gettypefromclsid-usage-3c7d1587</loc>
    <lastmod>2026-07-31T13:18:08.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-in-memory-assembly-loading-via-reflection-assembly-load-ddcd88cb</loc>
    <lastmod>2026-07-31T13:18:06.917Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-agentexecutor-exe-powershell-launch-with-executionpolic-c0b40568</loc>
    <lastmod>2026-07-31T13:24:25.631Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-agentexecutor-exe-with-powershell-bypass-7efd2c8d</loc>
    <lastmod>2026-07-31T13:24:23.509Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-copy-move-of-browser-credential-stores-47147b5b</loc>
    <lastmod>2026-07-30T05:06:43.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-x509enrollment-cbinaryconverter-execution-114de787</loc>
    <lastmod>2026-07-30T04:57:01.909Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-frombase64string-decoding-of-base64-gzip-content-in-process-creation--d75d6b6b</loc>
    <lastmod>2026-07-30T04:55:35.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-of-aadinternals-cmdlets-process-creation-c86500e9</loc>
    <lastmod>2026-07-30T04:54:11.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-chromium-headless-remote-debugging-with-user-profile-directory-3e8207c5</loc>
    <lastmod>2026-07-31T13:25:27.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-powershell-x509enrollment-cbinaryconverter-usage-504d63cb</loc>
    <lastmod>2026-07-31T13:23:08.859Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-frombase64string-decoding-of-gzip-archive-in-script-block-df69cb1d</loc>
    <lastmod>2026-07-31T13:18:28.245Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-logging-aadinternals-cmdlets-add-aadint-invoke-a-91e69562</loc>
    <lastmod>2026-07-31T13:17:16.438Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-service-installation-of-remote-access-tools-1a31b18a</loc>
    <lastmod>2026-07-31T12:58:06.483Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-of-remote-access-tools-event-id-4697-c8b00925</loc>
    <lastmod>2026-07-31T12:54:35.767Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-explorer-launched-from-cmd-exe-or-powershell-with-shell-mycomputerfolder-c3d76afc</loc>
    <lastmod>2026-07-31T13:30:22.476Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/owa-ssrf-exploitation-attempt-via-webserver-post-to-owa-mastermailbox-and-powers-92d78c63</loc>
    <lastmod>2026-07-31T12:08:21.128Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-owassrf-exploitation-attempt-via-exchange-owa-backend-webserver-181f49fa</loc>
    <lastmod>2026-07-31T12:08:19.341Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/owa-ssrf-exploitation-attempt-via-proxy-to-owa-mastermailbox-and-powershell-fdd7e904</loc>
    <lastmod>2026-07-31T12:08:17.373Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-http-post-to-owa-powershell-backend-with-encoded-user-info-owassrf-1ddf4596</loc>
    <lastmod>2026-07-31T12:08:15.306Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-impersonate-exe-hacktool-execution-cf0c254b</loc>
    <lastmod>2026-07-31T13:32:52.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-usermod-adds-user-to-root-or-sudoers-group-via-ag-6a50f16c</loc>
    <lastmod>2026-07-31T12:41:36.621Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-new-user-created-with-privileged-uid-gid-values-0ac15ec3</loc>
    <lastmod>2026-07-31T12:37:07.693Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-detection-of-suspicious-environment-variable-commands-966315ef</loc>
    <lastmod>2026-07-30T05:22:41.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-binary-execution-with-renamed-image-path-0b0cd537</loc>
    <lastmod>2026-07-30T05:02:36.635Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sqlite-cli-querying-chromium-browser-profile-databases-24c77512</loc>
    <lastmod>2026-07-30T05:05:49.695Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-attempts-via-comctl32-dll-in-local-directories-6360757a</loc>
    <lastmod>2026-07-31T13:10:22.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-flag-exe-local-dll-sideload-attempts-targeting-system32-comctl32-dll-07a99744</loc>
    <lastmod>2026-07-31T13:07:57.030Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-suspicion-via-image-load-of-jsschhlp-dll-68654bf0</loc>
    <lastmod>2026-07-31T13:10:56.243Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-side-loading-via-classicexplorer32-dll-loaded-from-non-classic-shell-caa02837</loc>
    <lastmod>2026-07-31T13:10:19.849Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-ses-identity-deletion-via-cloudtrail-deleteidentity-event-20f754db</loc>
    <lastmod>2026-07-31T12:27:36.620Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detects-potential-ognl-injection-exploitation-of-confluence-cve-2021-2-38825179</loc>
    <lastmod>2026-07-31T12:05:12.440Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-ransom-note-keyword-changes-in-legalnoticecaption-text-8b9606c9</loc>
    <lastmod>2026-07-30T05:20:06.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-unusual-child-process-of-setres-exe-spawning-choice-executables-835e75bf</loc>
    <lastmod>2026-07-30T05:05:20.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-rcedit-editing-pe-version-resource-metadata-via-set-0c92f2e6</loc>
    <lastmod>2026-07-30T04:58:33.562Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mklink-symlink-from-osk-exe-to-cmd-exe-for-login-screen-privilege-escala-e9b61244</loc>
    <lastmod>2026-07-31T13:27:00.311Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-cve-2021-27905-exploitation-attempt-against-apache-solr-via-specific-h-0bbcd74b</loc>
    <lastmod>2026-07-31T12:05:23.234Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-download-cradle-using-nslookup-and-txt-http-queries-on-windows-999bff6d</loc>
    <lastmod>2026-07-31T13:15:13.148Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-etw-logging-disabled-via-scm-registry-tracingdisabled-key-4f281b83</loc>
    <lastmod>2026-07-30T05:22:12.293Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-disables-etw-for-rpcrt4-dll-via-exterrorinformation-90f342e1</loc>
    <lastmod>2026-07-30T05:22:04.335Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-conhost-exe-forcev1-with-high-integrity-level-3037d961</loc>
    <lastmod>2026-07-31T13:28:00.246Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-loading-from-system-directories-using-specific-phantom-dll-names-6b98b92b</loc>
    <lastmod>2026-07-31T13:11:09.793Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-lsass-full-dump-via-wer-localdumps-dumptype-2-33efc23c</loc>
    <lastmod>2026-07-30T05:20:11.562Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-crash-dump-dmp-present-in-crashdumps-directory-6902955a</loc>
    <lastmod>2026-07-31T13:04:14.857Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-application-error-lsass-lsass-exe-crash-events-event-id-1000-a18e0862</loc>
    <lastmod>2026-07-31T12:47:23.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-configuration-change-alerts-via-microsoft-defender-windefend-ev-801bd44f</loc>
    <lastmod>2026-07-31T12:59:13.580Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-windefend-antimalware-restores-file-from-quarantine-event-id-1009-bc92ca75</loc>
    <lastmod>2026-07-31T12:59:11.498Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-windefend-automatic-sample-submission-disabled-via-antimalware--91903aba</loc>
    <lastmod>2026-07-31T12:59:00.526Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-contains-emoji-characters-225274c4</loc>
    <lastmod>2026-07-30T05:07:17.799Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-contains-emoji-characters-f9578658</loc>
    <lastmod>2026-07-30T05:07:16.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-contains-specific-emoji-characters-c98f2a0d</loc>
    <lastmod>2026-07-30T05:07:14.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-contains-emoji-characters-4a30ac0c</loc>
    <lastmod>2026-07-30T05:07:12.513Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-elevated-powershell-or-cmd-spawned-from-uncommon-parent-location-178e615d</loc>
    <lastmod>2026-07-30T05:07:09.119Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-mavinject32-64-exe-execution-e6474a1b</loc>
    <lastmod>2026-07-30T05:02:25.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-execution-of-uncommon-binaries-via-taskscheduler-f0767f15</loc>
    <lastmod>2026-07-31T12:58:43.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-execution-from-suspicious-paths-424273ea</loc>
    <lastmod>2026-07-31T12:58:41.490Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4702-scheduled-task-content-change-with-suspicious-strings-614cf376</loc>
    <lastmod>2026-07-31T12:55:32.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-scheduled-task-deleted-or-disabled-important-task-names-7595ba94</loc>
    <lastmod>2026-07-31T12:55:30.538Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-suspicious-scheduled-task-creation-via-event-4698-and-taskconte-3a734d25</loc>
    <lastmod>2026-07-31T12:55:28.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmoneop-hacktool-execution-via-sysmoneop-exe-name-and-imphash-8a7e90c5</loc>
    <lastmod>2026-07-31T13:34:34.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-wsudo-with-system-or-trustedinstaller-bdeeabc9</loc>
    <lastmod>2026-07-30T04:58:49.845Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vmguestlib-dll-sideloading-via-wmiapsrv-imageload-70e8e9b4</loc>
    <lastmod>2026-07-31T13:12:05.733Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sidelo-ading-detect-image-loads-of-shellchromeapi-dll-ee4c5d06</loc>
    <lastmod>2026-07-31T13:11:34.696Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-non-existent-system-dlls-in-system32-df6ecb8b</loc>
    <lastmod>2026-07-31T13:02:33.300Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gpg4win-gpg-exe-encrypt-decrypt-using-passphrases-from-suspicious-paths-e1e0b7d7</loc>
    <lastmod>2026-07-31T13:31:25.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powertool-execution-via-powertool-exe-or-powertool64-exe-process-creatio-a34f79a3</loc>
    <lastmod>2026-07-31T13:33:43.346Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-tacticalrmm-agent-service-scm-event-id-7045-4bb79b62</loc>
    <lastmod>2026-07-31T12:58:22.479Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-of-meshagent-exe-via-service-control-manager-event--e0d1ad53</loc>
    <lastmod>2026-07-31T12:57:52.828Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-detect-azurehound-discovery-via-user-agent-after-successful-a-35b781cc</loc>
    <lastmod>2026-07-31T12:32:04.096Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-event-viewer-recentviews-path-in-process-command-line-30fc8de7</loc>
    <lastmod>2026-07-30T05:11:34.189Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-ngenassemblyusagelog-key-tampering-via-net-usage-log-configurat-28036918</loc>
    <lastmod>2026-07-30T05:20:13.114Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-secedit-exe-security-policy-export-or-config-c2c76b77</loc>
    <lastmod>2026-07-30T05:05:15.819Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-powercfg-execution-changing-lock-video-standby-timeout-f8d6a15e</loc>
    <lastmod>2026-07-30T04:54:09.410Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-msbuild-exe-execution-from-uncommon-parent-process-33be4333</loc>
    <lastmod>2026-07-30T04:51:14.533Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-user-discovery-and-export-via-get-aduser-cmdlet-c2993223</loc>
    <lastmod>2026-07-31T13:22:39.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-computer-discovery-and-export-using-get-adcomputer-db885529</loc>
    <lastmod>2026-07-31T13:17:46.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/m365-pst-export-via-new-compliancesearchaction-export-in-securitycompliancecente-6897cd82</loc>
    <lastmod>2026-07-31T12:34:04.449Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-crackmapexec-or-impacket-secretsdump-credential-dumping-temp-6e2a900a</loc>
    <lastmod>2026-07-31T13:03:38.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-driver-load-process-hacker-kernel-driver-processhacker-sys-67add051</loc>
    <lastmod>2026-07-31T13:01:03.500Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-runas-like-command-line-flag-combination-50d66fb0</loc>
    <lastmod>2026-07-30T05:08:30.338Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-get-adcomputer-export-of-active-directory-computer-data-to-file-windo-435e10e4</loc>
    <lastmod>2026-07-30T04:54:52.937Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sftp-exe-lolbin-abuse-via-d-flag-a85ffc3a</loc>
    <lastmod>2026-07-31T13:37:27.926Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-blocked-image-driver-load-due-to-signing-level-or-policy--e4be5675</loc>
    <lastmod>2026-07-31T12:48:56.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-process-creation-where-sysmon-spawned-a-child-process-6d1058a4</loc>
    <lastmod>2026-07-31T12:08:23.046Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-amsi-bypass-pattern-ref-assembly-gettype-and-setvalue-null-tr-e0d6c087</loc>
    <lastmod>2026-07-31T13:17:27.330Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-event-42-kerberos-kdc-rc4-hmac-downgrade-exploit-activity-cve-202-e6f81941</loc>
    <lastmod>2026-07-31T12:08:13.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-appcmd-lists-service-account-passwords-via-command-line-2d3cdeec</loc>
    <lastmod>2026-07-31T13:35:19.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-suspicious-lnk-double-extension-filenames-3215aa19</loc>
    <lastmod>2026-07-31T13:06:58.098Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-potential-access-token-abuse-via-new-credentials-impersonation-02f7c9c1</loc>
    <lastmod>2026-07-31T12:50:25.691Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-ping-delay-followed-by-del-file-deletion-54786ddc</loc>
    <lastmod>2026-07-31T13:27:13.409Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-executable-connects-to-ngrok-tunneling-domains-1d08ac94</loc>
    <lastmod>2026-07-31T13:13:29.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-network-connections-to-ngrok-tunnel-endpoints-19bf6fdb</loc>
    <lastmod>2026-07-31T12:37:51.437Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-kavremover-cleanapi-lolbin-style-command-line-execution-d047726b</loc>
    <lastmod>2026-07-31T13:35:54.759Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-with-guid-like-task-name-ff2fff64</loc>
    <lastmod>2026-07-30T05:04:41.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-of-vssapi-dll-by-uncommon-executables-37774c23</loc>
    <lastmod>2026-07-31T13:09:27.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-utilities-host-service-installation-via-service-control-manager-7-85cce894</loc>
    <lastmod>2026-07-31T12:58:08.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsupport-manager-client32-service-installation-via-service-control-man-2d510d8d</loc>
    <lastmod>2026-07-31T12:57:54.746Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vsls-agent-exe-executed-with-agentextensionpath-suspicious-library-load-43103702</loc>
    <lastmod>2026-07-30T05:12:39.697Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-lines-referencing-dot-suffixed-file-paths-a35c97c8</loc>
    <lastmod>2026-07-31T12:08:48.308Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-paexec-default-named-pipe-creation-via-sysmon-f6451de4</loc>
    <lastmod>2026-07-31T13:15:03.335Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-exchange-powershell-cmdlet-history-log-files-deleted-a55349d8</loc>
    <lastmod>2026-07-31T13:01:43.611Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detects-paexec-service-installation-via-service-control-manager-event-id-de7ce410</loc>
    <lastmod>2026-07-31T12:57:56.571Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-disabling-macroruntimescanscope-runtime-macro-scanning-ab871450</loc>
    <lastmod>2026-07-30T05:18:59.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cli-searching-for-jwt-strings-eyj0ex-eyjhbgci-in-command-line-6d3a3952</loc>
    <lastmod>2026-07-30T05:07:49.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-dll-sideloading-via-dbghelp-dll-image-loads-6414b5cd</loc>
    <lastmod>2026-07-31T13:10:29.374Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-dbgcore-dll-loaded-from-unusual-paths-9ca2bf31</loc>
    <lastmod>2026-07-31T13:10:27.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-openssh-server-starts-listening-on-ssh-socket-3ce8e9a4</loc>
    <lastmod>2026-07-31T12:50:23.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-inveigh-mitm-tool-execution-via-inveigh-exe-flags-b99a1518</loc>
    <lastmod>2026-07-31T13:32:54.311Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-suspicious-set-service-sddl-to-hide-windows-services-from-enumeration-22d80745</loc>
    <lastmod>2026-07-31T13:22:03.262Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-inveigh-hacktool-execution-artefacts-via-dropped-files-bb09dd3e</loc>
    <lastmod>2026-07-31T13:03:24.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msiinstaller-installs-a-remote-msi-from-a-url-5594e67a</loc>
    <lastmod>2026-07-31T12:47:41.548Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ads-creation-with-zone-identifier-markers-outside-browser-downloads-573df571</loc>
    <lastmod>2026-07-31T12:59:53.491Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-electron-apps-f26eb764</loc>
    <lastmod>2026-07-30T05:07:05.675Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-execution-by-microsoft-onenote-on-windows-child-programs-c27515df</loc>
    <lastmod>2026-07-30T04:53:39.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-search-order-hijacking-suspicious-dll-writes-to-appdata-onedrive-tea-dbbd9f66</loc>
    <lastmod>2026-07-31T13:03:44.214Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-script-editor-spawning-unusual-processes-curl-shells-scripting-runtimes-6e4dcdd1</loc>
    <lastmod>2026-07-31T12:43:18.308Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-safetykatz-hacktool-execution-b1876533</loc>
    <lastmod>2026-07-31T13:33:58.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-seatbelt-exe-pua-discovery-command-line-execution-38646daa</loc>
    <lastmod>2026-07-30T04:58:40.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-set-acl-targeting-windows-folder-paths-on-windows-0944e002</loc>
    <lastmod>2026-07-30T04:56:29.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-set-acl-script-execution-changes-file-or-folder-permissions-on-window-bdeb2cff</loc>
    <lastmod>2026-07-30T04:56:27.788Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-set-service-securitydescriptorsddl-dacl-modification-for-windows-serv-a95b9b42</loc>
    <lastmod>2026-07-30T04:56:26.386Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-logs-rclone-user-agent-activity-via-default-rclone-v-prefix-2c03648b</loc>
    <lastmod>2026-07-31T12:46:48.936Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-set-service-sddl-usage-to-hide-services-514e4c3a</loc>
    <lastmod>2026-07-30T04:55:42.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-set-service-sddl-securitydescriptor-to-hide-services-953945c5</loc>
    <lastmod>2026-07-31T13:22:43.278Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-to-dpapi-master-keys-by-uncommon-applications-46612ae6</loc>
    <lastmod>2026-07-31T13:01:30.329Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-credential-history-file-access-by-uncommon-image-paths-7a2a22ea</loc>
    <lastmod>2026-07-31T13:01:26.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-id-5136-msds-keycredentiallink-shadow-credentials-added-f598ea0c</loc>
    <lastmod>2026-07-31T12:55:18.515Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-xcsset-infection-indicators-from-bash-launched-curl-osacompile-plutil-and--47d65ac0</loc>
    <lastmod>2026-07-31T12:44:03.089Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-execution-indicators-for-wizardupdate-associated-malware-f68c4a4f</loc>
    <lastmod>2026-07-31T12:43:58.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-openssl-decodes-and-decrypts-payloads-from-mounted-dmg-volumes-234dc5df</loc>
    <lastmod>2026-07-31T12:42:52.502Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-wermgr-exe-running-outside-standard-system-directories-5394fcc7</loc>
    <lastmod>2026-07-30T05:13:30.343Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-child-process-spawned-by-wermgr-exe-396f6630</loc>
    <lastmod>2026-07-30T05:13:28.455Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4634-4647-user-logoff-events-0badd08f</loc>
    <lastmod>2026-07-31T12:56:01.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4649-flags-kerberos-replay-attempts-krb-ap-err-repeat-5a44727c</loc>
    <lastmod>2026-07-31T12:54:11.788Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-log-device-installation-blocked-by-system-policy-event-id-6423-c9eb55c3</loc>
    <lastmod>2026-07-31T12:51:54.701Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-computer-added-or-removed-from-domain-controller-20d96d95</loc>
    <lastmod>2026-07-31T12:51:20.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-svchost-spawning-office-applications-via-com-instance-creation-9bdaf1e9</loc>
    <lastmod>2026-07-31T12:22:11.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ssh-exe-rdp-tunneling-to-3389-via-ssh-f7d7ebd5</loc>
    <lastmod>2026-07-30T05:05:59.972Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/port-forwarding-via-ssh-exe-on-windows-327f48c1</loc>
    <lastmod>2026-07-30T05:05:56.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-credential-manager-and-vault-access-from-unusual-process-images-407aecb1</loc>
    <lastmod>2026-07-31T13:01:24.408Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-hacker-execution-identified-by-image-metadata-and-hashes-811e0002</loc>
    <lastmod>2026-07-30T04:58:30.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-recon-using-get-localgroupmember-on-local-well-known-groups-c8a180d6</loc>
    <lastmod>2026-07-30T04:55:39.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-pchunter64-pchunter32-execution-fca949cc</loc>
    <lastmod>2026-07-31T13:33:39.509Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-extended-stored-procedure-execution-with-providername-mssqlserver--711ab2fe</loc>
    <lastmod>2026-07-31T12:08:54.276Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-nps-npc-exe-port-forwarding-proxy-execution-via-command-line-parameters-68d37776</loc>
    <lastmod>2026-07-30T04:58:23.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-iox-iex-port-forwarding-tunnel-proxy-tool-via-process-creat-d7654f02</loc>
    <lastmod>2026-07-30T04:58:03.242Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sharpwsus-wsuspendu-process-command-line-execution-b0ce780f</loc>
    <lastmod>2026-07-31T13:34:24.831Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lpe-via-com-clsid-tabtip-exe-invoked-through-dcom-activation-microsoft-w-bc2e25ed</loc>
    <lastmod>2026-07-31T12:56:45.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gmer-exe-execution-rootkit-tool-via-image-path-and-known-hashes-9082ff1f</loc>
    <lastmod>2026-07-31T13:32:36.562Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hh-exe-initiates-http-s-network-connections-468a8cea</loc>
    <lastmod>2026-07-31T12:20:19.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-psasyncshell-asynchronous-tcp-reverse-shell-afd3df04</loc>
    <lastmod>2026-07-31T13:20:10.641Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vulnerable-driver-load-by-known-file-name-72cd00d6</loc>
    <lastmod>2026-07-31T13:01:13.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-malicious-driver-load-identified-by-known-driver-file-names-39b64854</loc>
    <lastmod>2026-07-31T13:01:01.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-privacy-settings-experience-via-disableprivacyexperienc-0372e1f9</loc>
    <lastmod>2026-07-30T05:19:00.801Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-of-ultravnc-vncviewer-vncviewer-exe-145322e4</loc>
    <lastmod>2026-07-30T05:12:03.046Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modify-user-shell-folders-startup-values-for-persistence-9c226817</loc>
    <lastmod>2026-07-30T05:22:37.709Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-china-chopper-webshell-command-pattern-via-w3wp-fa3c117a</loc>
    <lastmod>2026-07-30T05:12:58.115Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-use-of-shutdown-exe-to-log-off-a-user-ec290c06</loc>
    <lastmod>2026-07-30T05:05:29.174Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pdq-deploy-console-execution-d679950c</loc>
    <lastmod>2026-07-30T04:53:55.891Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-registry-settings-modified-to-zero-a2863fbc</loc>
    <lastmod>2026-07-30T05:22:48.245Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/atlassian-bitbucket-archive-api-command-injection-attempt-cve-2022-36804-in-web--65c0a0ab</loc>
    <lastmod>2026-07-31T12:08:11.590Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-anydesk-password-piped-via-cmd-using-set-password-b1377339</loc>
    <lastmod>2026-07-30T05:01:17.747Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-aspnet-regiis-decrypts-connection-strings-via-pdf-97dbf6e2</loc>
    <lastmod>2026-07-31T13:35:24.904Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-conhost-exe-spawned-by-uncommon-parent-process-cbb9e3d1</loc>
    <lastmod>2026-07-31T13:28:08.467Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-matching-mimikatz-credential-certificate-dump-str-189e3b02</loc>
    <lastmod>2026-07-31T13:19:55.743Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-anydesk-binary-writes-except-gcapi-dll-2d367498</loc>
    <lastmod>2026-07-31T13:02:16.503Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-uac-bypass-attempt-via-mmc-windows-firewall-snap-in-hij-e52cb31c</loc>
    <lastmod>2026-07-30T05:11:38.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-ssh-port-forwarding-commands-targeting-rdp-3389-8a3038e8</loc>
    <lastmod>2026-07-30T05:08:49.996Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-unusual-parent-child-execution-involving-imagingdevices-exe-f11f2808</loc>
    <lastmod>2026-07-31T13:35:32.240Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-unusual-child-process-spawned-by-dns-exe-a4e3d776</loc>
    <lastmod>2026-07-31T13:29:34.008Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-desktopimgdownldr-exe-remote-file-download-execution-214641c2</loc>
    <lastmod>2026-07-31T13:29:01.625Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-7-zip-compressing-dmp-dump-files-ec570e53</loc>
    <lastmod>2026-07-31T13:24:03.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-exe-deletes-files-not-targeting-dns-log-8f0b1fb1</loc>
    <lastmod>2026-07-31T13:02:05.299Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-exe-modifies-unexpected-files-9f383dc0</loc>
    <lastmod>2026-07-31T13:01:38.196Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-thread-creation-via-rundll32-exe-from-wabmig-exe-or-wab-exe-994cac2b</loc>
    <lastmod>2026-07-31T12:08:32.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-send-mailmessage-with-attachments-for-possible-smtp-data--9a7afa56</loc>
    <lastmod>2026-07-31T12:21:06.780Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-w32tm-exe-timer-delay-usage-via-stripchart-parameters-6da2c9f5</loc>
    <lastmod>2026-07-30T05:12:42.792Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ultraviewer-desktop-app-execution-88656cec</loc>
    <lastmod>2026-07-30T05:01:56.159Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-netsupport-client-configurator-pcicfgui-exe-758ff488</loc>
    <lastmod>2026-07-30T05:01:31.178Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-parent-process-for-cmd-exe-execution-4b991083</loc>
    <lastmod>2026-07-31T13:27:36.547Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-createdump-exe-used-for-dmp-memory-dumps-1a1ed54a</loc>
    <lastmod>2026-07-30T05:02:14.350Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-wmi-volume-shadow-copy-deletion-21ff4ca9</loc>
    <lastmod>2026-07-30T04:56:35.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-wmi-script-deletion-of-windows-volume-shadow-copies-c1337eb8</loc>
    <lastmod>2026-07-31T13:22:22.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-remote-utilities-renamed-to-rutserv-exe-or-rfusclient-e-9ef27c24</loc>
    <lastmod>2026-07-30T05:02:46.349Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detects-netsupport-rat-client32-exe-execution-using-imphash-and-filename-0afbd410</loc>
    <lastmod>2026-07-30T05:02:32.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rurat-remote-utilities-executed-from-unusual-path-e01fa958</loc>
    <lastmod>2026-07-30T05:01:36.355Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsupport-client32-exe-executed-from-non-standard-directory-37e8d358</loc>
    <lastmod>2026-07-30T05:01:33.065Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-winpeas-peass-ng-execution-98b53e78</loc>
    <lastmod>2026-07-31T13:34:42.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-tampering-channelaccess-permissions-for-winevt-event-channels-7d9263bd</loc>
    <lastmod>2026-07-30T05:18:20.967Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-targets-microsoft-teams-cookies-or-leveldb-d2eb17db</loc>
    <lastmod>2026-07-30T05:11:11.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-exclusions-added-via-powershell-script-block-logging-c1344fa2</loc>
    <lastmod>2026-07-31T13:22:56.453Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-sensitive-file-discovery-via-script-block-enumeration-7d416556</loc>
    <lastmod>2026-07-31T13:20:31.294Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-webserver-access-log-files-deleted-3eb8c339</loc>
    <lastmod>2026-07-31T13:01:46.614Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-access-to-microsoft-teams-token-and-local-storage-objects-466-25cde13e</loc>
    <lastmod>2026-07-31T12:55:43.483Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sharpersist-hacktool-execution-26488ad0</loc>
    <lastmod>2026-07-31T13:34:12.395Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installed-by-system-process-with-pid-0-71c276aa</loc>
    <lastmod>2026-07-31T12:58:14.164Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-via-unusual-client-clientprocessid-or-parentprocess-c4e92a97</loc>
    <lastmod>2026-07-31T12:54:38.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-user-agent-changes-on-linux-via-process-creation-b86d356d</loc>
    <lastmod>2026-07-31T12:40:41.931Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-curl-process-uploads-files-via-form-upload-flags-00b90cc1</loc>
    <lastmod>2026-07-31T12:40:40.189Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-service-management-tool-usage-to-stop-or-disable-services-de25eeb8</loc>
    <lastmod>2026-07-31T12:40:30.952Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-curl-execution-observed-via-process-start-ea34fb97</loc>
    <lastmod>2026-07-31T12:38:43.002Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-crontab-r-removes-current-user-crontab-c2e234de</loc>
    <lastmod>2026-07-31T12:38:39.715Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-chattr-i-used-to-remove-immutable-file-attribute-34979410</loc>
    <lastmod>2026-07-31T12:38:25.172Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-base64-encoded-shebang-in-command-line-fe2f9663</loc>
    <lastmod>2026-07-31T12:38:08.753Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cli-processes-using-common-weak-or-abused-passwords-91edcfb1</loc>
    <lastmod>2026-07-30T05:09:53.308Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-disables-windows-firewall-profiles-via-set-netfirewallprofile-12f6b752</loc>
    <lastmod>2026-07-30T04:55:06.789Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntdsutil-exe-use-for-ad-snapshot-mount-or-activation-windows-process--a58353df</loc>
    <lastmod>2026-07-30T04:53:14.493Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-elevated-com-interface-using-icmluautil-49f2f17b</loc>
    <lastmod>2026-07-30T05:11:41.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-taskkill-used-to-terminate-ccsvchst-exe-symantec-endpoint-protection-ser-4a6713f6</loc>
    <lastmod>2026-07-30T05:11:04.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-chisel-tunneling-tool-chisel-exe-execution-8b0e12da</loc>
    <lastmod>2026-07-30T04:57:51.789Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-3proxy-proxy-server-execution-f38a82d2</loc>
    <lastmod>2026-07-30T04:57:38.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-attempts-to-clear-windows-event-logs-via-clear-eventlog-and-related-c-0f017df3</loc>
    <lastmod>2026-07-31T13:20:55.388Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-enable-windowsoptionalfeature-online-with-potentially-risky-featurena-55c925c1</loc>
    <lastmod>2026-07-31T13:18:18.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-disable-windowsoptionalfeature-online-featurename-targeting-windows-d-99c4658d</loc>
    <lastmod>2026-07-31T13:18:05.153Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-winlogon-allowmultipletssessions-enabled-f7997770</loc>
    <lastmod>2026-07-30T05:23:23.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-recon-via-event-log-query-tools-and-event-id-searches-beaa66d6</loc>
    <lastmod>2026-07-30T05:07:25.781Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-scheduled-task-creation-or-modification-with-suspicious-sch-24c8392b</loc>
    <lastmod>2026-07-30T05:04:54.887Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-delete-all-scheduled-tasks-via-tn-delete-f-220457c1</loc>
    <lastmod>2026-07-30T05:04:34.613Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-used-to-delete-scheduled-tasks-for-system-and-security-comp-dbc1f800</loc>
    <lastmod>2026-07-30T05:04:32.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vmnat-exe-renamed-execution-for-possible-dll-side-loading-7b4f794b</loc>
    <lastmod>2026-07-30T05:02:55.864Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-user-discovery-and-export-with-get-aduser-1114e048</loc>
    <lastmod>2026-07-30T04:56:52.780Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-root-certificate-installation-from-suspicious-paths-via-powershell-impor-5f6a601c</loc>
    <lastmod>2026-07-30T04:55:46.003Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-email-address-exfiltration-via-exif-style-recipient-harvesting-on-win-312d0384</loc>
    <lastmod>2026-07-30T04:55:23.680Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-node-exe-execution-with-e-eval-and-suspicious-child-process-usage-6640f31c</loc>
    <lastmod>2026-07-30T04:53:03.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-suspicious-samtheadmin-computer-account-names-39698b3f</loc>
    <lastmod>2026-07-31T12:54:47.508Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-system-reconnaissance-using-computersystem-flag-9d7ca793</loc>
    <lastmod>2026-07-30T05:14:45.622Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpevtmute-execution-via-process-creation-on-windows-bedfc8ad</loc>
    <lastmod>2026-07-31T13:34:13.972Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-integrity-attack-tool-execution-sysmonente-via-sysmon-process-acc-d29ada0f</loc>
    <lastmod>2026-07-31T13:23:28.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-load-sharpevtmute-evtmutehook-dll-imphash-49329257</loc>
    <lastmod>2026-07-31T13:09:30.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-downloads-from-direct-ip-urls-with-executable-attachment-025bd229</loc>
    <lastmod>2026-07-31T13:00:03.214Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-winapi-function-names-in-command-line-ba3f5c1b</loc>
    <lastmod>2026-07-30T05:07:46.788Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-sysinternals-sdelete-execution-c1d867fe</loc>
    <lastmod>2026-07-30T05:02:54.341Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-dns-txt-download-cradle-via-nslookup-process-creation-1b3b01c7</loc>
    <lastmod>2026-07-30T04:53:12.518Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sharpchisel-hacktool-execution-via-process-name-or-product-metadata-cf93e05e</loc>
    <lastmod>2026-07-31T13:34:03.610Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-quarkspwdump-exe-credential-dumping-via-command-line-flags-0685b176</loc>
    <lastmod>2026-07-31T13:33:49.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-executable-file-creation-via-malicious-filenames-and-extensio-74babdd6</loc>
    <lastmod>2026-07-31T13:06:37.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-tampering-targeting-sophos-av-tamper-protection-enabled-flags-9f4662ac</loc>
    <lastmod>2026-07-30T05:22:17.458Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-reg-exe-adds-or-copies-safeboot-registry-keys-d7662ff6</loc>
    <lastmod>2026-07-30T04:59:17.709Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-fast-reverse-proxy-frp-frpc-exe-or-frps-exe-32410e29</loc>
    <lastmod>2026-07-30T04:58:01.388Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ldifde-exe-ldap-import-i-f-execution-6f535e01</loc>
    <lastmod>2026-07-31T13:36:07.824Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-initiating-network-connections-to-common-service-ports-0dba975d</loc>
    <lastmod>2026-07-31T13:12:55.470Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-service-stop-pause-delete-disable-via-net-sc-ce72ef99</loc>
    <lastmod>2026-07-30T05:09:04.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-shellexec-rundll-command-line-usage-d87bd452</loc>
    <lastmod>2026-07-30T05:03:39.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-net-exe-commands-manipulating-built-in-default-accounts-administrator-gu-5b768e71</loc>
    <lastmod>2026-07-30T04:52:34.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-cmd-exe-execution-from-internet-hosted-webdav-via-net-use-f0507c0f</loc>
    <lastmod>2026-07-31T13:27:04.579Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-guid-like-folder-paths-in-command-line-90b63c33</loc>
    <lastmod>2026-07-31T12:23:05.155Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-scheduled-task-creation-or-modification-with-high-privilege-7a02e22e</loc>
    <lastmod>2026-07-30T05:04:56.774Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wscript-shell-run-keyword-sequence-in-commandline-2c28c248</loc>
    <lastmod>2026-07-30T04:51:27.911Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-defendercheck-exe-execution-pua-signature-evasion-f0ca6c24</loc>
    <lastmod>2026-07-30T04:57:58.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-initiated-by-cmstp-exe-efafe0bf</loc>
    <lastmod>2026-07-31T13:12:57.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmstp-loads-dll-ocx-from-suspicious-paths-75e508f7</loc>
    <lastmod>2026-07-31T13:08:58.557Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rtcore64-service-installation-event-id-7045-91c49341</loc>
    <lastmod>2026-07-31T12:58:33.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpldapwhoami-tool-execution-on-windows-via-process-creation-d9367cbb</loc>
    <lastmod>2026-07-31T13:34:15.880Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-dll-sideloading-via-deviceenroller-exe-phonedeeplink-parameter-windows-e173ad47</loc>
    <lastmod>2026-07-31T13:29:09.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-detection-com-treatas-default-hijacking-dc5c24af</loc>
    <lastmod>2026-07-30T05:22:56.164Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-nimgrab-exe-execution-nim-tool-download-behavior-74a12f18</loc>
    <lastmod>2026-07-30T04:58:14.559Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-script-interpreter-initiates-outbound-network-connections-to-non-local-i-992a6cae</loc>
    <lastmod>2026-07-31T13:14:35.133Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wscript-cscript-script-interpreter-initiated-local-network-connection-08249dc0</loc>
    <lastmod>2026-07-31T13:14:33.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-index-registry-tampering-hiding-tasks-from-query-tools-5b16df71</loc>
    <lastmod>2026-07-30T05:19:54.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-scheduled-task-index-value-removal-to-hide-task-taskcache-526cc8bc</loc>
    <lastmod>2026-07-30T05:16:26.793Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysaidserver-spawns-suspicious-java-child-processes-60bfeac3</loc>
    <lastmod>2026-07-31T13:35:51.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detects-suspicious-powershell-command-line-for-mercury--a62298a3</loc>
    <lastmod>2026-07-31T12:08:57.961Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-regasm-regsvcs-from-uncommon-directories-cc368ed0</loc>
    <lastmod>2026-07-30T05:00:22.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-commandline-pattern-for-sliver-c2-implant-activity-42333b2c</loc>
    <lastmod>2026-07-31T13:34:28.236Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-detects-sliver-service-installation-via-default--31c51af6</loc>
    <lastmod>2026-07-31T12:58:10.154Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registryset-eulaaccepted-set-for-renamed-sysinternals-tools-8023f872</loc>
    <lastmod>2026-07-30T05:22:02.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-sysinternals-eula-accepted-key-for-pua-tool-execution-c7da8edc</loc>
    <lastmod>2026-07-30T05:22:00.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-sysinternals-renamed-tool-execution-indicator-via-eulaaccepted--f50f3c09</loc>
    <lastmod>2026-07-30T05:21:59.244Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-vs-code-powershell-profile-script-creation-or-modification-3a9fa2ec</loc>
    <lastmod>2026-07-31T13:07:18.746Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msdt-exe-creating-files-in-suspicious-directories-318557a5</loc>
    <lastmod>2026-07-31T13:04:28.565Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-stream-creation-matching-hack-tool-imphash-19b041f6</loc>
    <lastmod>2026-07-31T12:59:59.311Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-stream-downloads-from-file-sharing-domains-with-script-e-ae02ed70</loc>
    <lastmod>2026-07-31T12:59:57.343Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-download-via-file-sharing-domains-using-sysmon-stream-ha-52182dfb</loc>
    <lastmod>2026-07-31T12:59:55.518Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-networkprovider-service-keys-indicative-of-credential-dumpi-0442defa</loc>
    <lastmod>2026-07-30T05:20:19.949Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-using-the-sysnative-directory-path-3c1b5fb0</loc>
    <lastmod>2026-07-30T05:09:11.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-cli-networkprovider-addition-for-credential--baef1ec6</loc>
    <lastmod>2026-07-30T05:00:46.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-process-creation-missing-space-around-c-k-r-execution-parameters-a16980c2</loc>
    <lastmod>2026-07-31T13:27:06.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-risk-typedpaths-key-modified-by-non-explorer-proces-086ae989</loc>
    <lastmod>2026-07-30T05:21:37.793Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-masquerading-dllregisterserver-commandline-not-using-rundll32-e-2569ed8c</loc>
    <lastmod>2026-07-30T05:02:44.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-persistence-via-typedpaths-registry-modification-ec88289a</loc>
    <lastmod>2026-07-30T05:00:56.394Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pua-csexec-execution-via-process-creation-d08a2711</loc>
    <lastmod>2026-07-30T04:57:56.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-uncommon-parent-process-for-link-exe-6e968eb1</loc>
    <lastmod>2026-07-31T13:36:09.465Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-adfind-exe-executions-df55196f</loc>
    <lastmod>2026-07-30T05:01:59.657Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-removing-psreadline-via-remove-module-to-disable-comma-602f5669</loc>
    <lastmod>2026-07-31T13:18:03.642Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-suspicious-legitimate-apps-dropping-script-files-7d604714</loc>
    <lastmod>2026-07-31T13:06:55.537Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-executable-dropping-by-known-apps-and-lolbins-f0540f7e</loc>
    <lastmod>2026-07-31T13:06:51.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-executable-process-dropping-archive-files-zip-rar-7z-cab-appx-654fcc6d</loc>
    <lastmod>2026-07-31T13:06:49.372Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-com-hijacking-via-scrobj-dll-inprocserver32-default-persistence-fe20dda1</loc>
    <lastmod>2026-07-30T05:21:30.869Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-webbrowserpassview-exe-execution-d0dae994</loc>
    <lastmod>2026-07-30T04:58:48.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-execution-via-pester-bat-spawned-by-powershell-18988e1b</loc>
    <lastmod>2026-07-31T13:37:00.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-trufflesnout-exe-process-execution-detection-69ca006d</loc>
    <lastmod>2026-07-31T13:34:36.190Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpup-privesc-tool-execution-on-windows-via-process-creation-c484e533</loc>
    <lastmod>2026-07-31T13:34:21.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dirlister-exe-execution-for-directory-and-file-discovery-b4dc61f5</loc>
    <lastmod>2026-07-31T13:29:14.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-server-discovery-via-ldap-query-to-ldap-domain-a21bcd7e</loc>
    <lastmod>2026-07-31T13:00:19.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modification-suppress-windows-security-center-notifications-0c93308a</loc>
    <lastmod>2026-07-30T05:22:20.784Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-disallowrun-dword-to-0x1-to-block-user-program-execution-275641a5</loc>
    <lastmod>2026-07-30T05:19:19.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-firewall-via-enablefirewall-dword-policies-e78c408a</loc>
    <lastmod>2026-07-30T05:19:09.465Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-windows-security-center-notifications-via-useactioncent-3ae1a046</loc>
    <lastmod>2026-07-30T05:19:02.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-enable-rdp-remote-assistance-via-fallowtogethelp-37b437cf</loc>
    <lastmod>2026-07-30T05:17:35.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-child-processes-spawned-by-sigverif-exe-7d4aaec2</loc>
    <lastmod>2026-07-30T05:05:30.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-adds-or-modifies-suspicious-registry-locations-via-command-line-b7e2a8d4</loc>
    <lastmod>2026-07-30T05:00:09.392Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-reg-exe-modifying-group-policy-registry-settings-ada4b0c4</loc>
    <lastmod>2026-07-30T04:59:57.430Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-presentationhost-exe-downloading-files-via-url-in-command-line-b124ddf4</loc>
    <lastmod>2026-07-30T04:57:07.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mspub-exe-downloading-arbitrary-files-via-http-ftp-uris-3b3c7f55</loc>
    <lastmod>2026-07-30T04:51:54.305Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msohtmed-exe-arbitrary-file-download-using-http-ftp-urls-459f2f98</loc>
    <lastmod>2026-07-30T04:51:52.825Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-register-app-vbs-vss-vds-com-provider-registration-via-register-1c8774a0</loc>
    <lastmod>2026-07-31T13:37:09.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-launch-vsdevshell-ps1-proxy-command-execution-45d3a03d</loc>
    <lastmod>2026-07-31T13:36:38.480Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-installutil-exe-used-to-download-remote-files-75edd216</loc>
    <lastmod>2026-07-31T13:35:37.948Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-devicecredentialdeployment-exe-execution-b8b1b304</loc>
    <lastmod>2026-07-31T13:29:06.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-customshellhost-exe-execution-from-non-explorer-parent-84b14121</loc>
    <lastmod>2026-07-31T13:28:51.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-detect-scriptblock-text-modifying-group-policy-settings-b7216a7d</loc>
    <lastmod>2026-07-31T13:19:38.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-handlekatz-lsass-dump-execution-via-loader-exe-and-obfuscated-obf-output-ca621ba5</loc>
    <lastmod>2026-07-31T13:32:38.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacksys-extreme-vulnerable-driver-hevd-sys-load-detection-295c9289</loc>
    <lastmod>2026-07-31T13:01:15.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-malicious-driver-load-by-known-hash-match-05296024</loc>
    <lastmod>2026-07-31T13:00:58.655Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-dead-drop-resolver-domains-from-non-browser-execu-297ae038</loc>
    <lastmod>2026-07-31T13:13:08.599Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-imageload-from-lenovo-and-toshiba-third-party-direct-f9df325d</loc>
    <lastmod>2026-07-31T13:11:42.888Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-dll-sideloading-via-outllib-dll-image-load-outside-expected-offic-829a3bdf</loc>
    <lastmod>2026-07-31T13:11:14.149Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-chrome-frame-helper-dll-sideloading-via-imageload-of-chrome-frame-helper-72ca7c75</loc>
    <lastmod>2026-07-31T13:10:18.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-alerts-for-dll-sideloading-from-security-product-directories-552b6b65</loc>
    <lastmod>2026-07-31T13:10:06.359Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zimbra-webmail-server-unauthenticated-post-to-mboximport-backup-servlet-leading--dd218fb6</loc>
    <lastmod>2026-07-31T12:07:56.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sysmon-fileblockexecutable-event-blocked-executable-execution-attempts-on-window-23b71bc5</loc>
    <lastmod>2026-07-30T05:23:32.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-write-eventlog-with-rawdata-flag-35f41cd7</loc>
    <lastmod>2026-07-31T13:22:26.705Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-user-profiles-service-events-1511-indicating-possible-lpe-attempts-tied--52a85084</loc>
    <lastmod>2026-07-31T12:07:47.025Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-mshtml-dll-runhtmlapplication-execution-via-protocol-ha-4782eb5a</loc>
    <lastmod>2026-07-30T05:03:11.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-rule-deleted-via-netsh-exe-command-line-1a5fefe6</loc>
    <lastmod>2026-07-30T04:52:42.592Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-indicators-via-imageloaded-of-system-dll-names-4fc0deee</loc>
    <lastmod>2026-07-31T13:10:39.553Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-loads-renamed-comsvcs-dll-for-process-memory-dump-8cde342c</loc>
    <lastmod>2026-07-31T13:09:05.809Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-shell-core-suspicious-shortcut-app-resolver-cache-entries-zenmap-anydesk-83c161b6</loc>
    <lastmod>2026-07-31T12:56:24.229Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-esent-new-database-creation-for-ntds-dit-in-suspicious-paths-94dc4390</loc>
    <lastmod>2026-07-31T12:47:29.998Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ntdsutil-abuse-via-esent-events-containing-ntds-dit-e6e88853</loc>
    <lastmod>2026-07-31T12:47:28.059Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/advanced-ip-port-scanner-update-check-over-http-proxy-1a9bb21a</loc>
    <lastmod>2026-07-31T12:46:19.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-unusual-process-tree-for-wab-exe-and-wabmig-exe-63d1ccc0</loc>
    <lastmod>2026-07-30T05:12:46.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wab-exe-or-wabmig-exe-run-from-non-default-paths-395907ee</loc>
    <lastmod>2026-07-30T05:12:44.354Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-user-added-to-local-administrators-group-via-net-or-add-localgroupmember-ad720b90</loc>
    <lastmod>2026-07-30T05:06:09.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-process-reconnaissance-using-findstr-exe-or-find-exe-fe63010f</loc>
    <lastmod>2026-07-31T13:30:32.944Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-executables-writing-files-with-suspicious-extensions-b8fd0e93</loc>
    <lastmod>2026-07-31T13:06:14.876Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-malicious-dll-dropped-to-onedrive-teams-appdata-path-containing-iphlpapi-1908fcc1</loc>
    <lastmod>2026-07-31T13:03:48.736Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-time-changed-to-an-earlier-year-possible-timestomping-558eebe5</loc>
    <lastmod>2026-07-31T12:19:28.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-cve-2022-31659-rce-activity-via-post-to-workspace-one-access-tenant-mi-efdb2003</loc>
    <lastmod>2026-07-31T12:08:06.132Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-attempts-exploiting-cve-2022-31656-in-vmware-workspace-one-access-fcf1101d</loc>
    <lastmod>2026-07-31T12:08:04.212Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-of-anydesk-service-event-id-7045-530a6faa</loc>
    <lastmod>2026-07-31T12:57:46.789Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-successful-admin-account-creation-via-add-user-to-role-f7b5b004</loc>
    <lastmod>2026-07-31T12:30:57.009Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-audit-logs-user-account-added-and-deleted-quickly-6f583da0</loc>
    <lastmod>2026-07-31T12:29:50.206Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-to-services-winsock2-parameters-autodialdll-for-dll-pers-e6fe26ee</loc>
    <lastmod>2026-07-30T05:20:58.215Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-app-paths-default-property-change-using-suspicious-values-707e097c</loc>
    <lastmod>2026-07-30T05:20:54.881Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-startup-folder-file-creation-with-suspicious-script-executable-extension-28208707</loc>
    <lastmod>2026-07-31T13:07:11.238Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-rule-for-bpfdoor-related-pid-and-lock-file-access-under-var-run-808146b2</loc>
    <lastmod>2026-07-31T12:36:15.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-iptables-nat-redirect-from-attacker-ports-via-bpfdoor-tcp-redirecti-70b4156e</loc>
    <lastmod>2026-07-31T12:34:59.983Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-temporary-access-pass-added-to-an-account-fa84aaf5</loc>
    <lastmod>2026-07-31T12:31:03.893Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-failed-guest-invitation-by-non-authorized-inviter-0b4b72e3</loc>
    <lastmod>2026-07-31T12:30:41.536Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-mycomputer-default-value-modification-8fbe98a8</loc>
    <lastmod>2026-07-30T05:21:20.859Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-persistence-file-drop-errorhandler-cmd-in-c-windows-setup-scripts-15904280</loc>
    <lastmod>2026-07-31T13:03:03.408Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-for-sharphound-bloodhound-collection-output-filenames-02773bed</loc>
    <lastmod>2026-07-30T04:22:03.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-pim-role-setting-updates-db6c06c4</loc>
    <lastmod>2026-07-31T12:30:52.060Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-alert-disablement-in-audit-logs-aeaef14c</loc>
    <lastmod>2026-07-31T12:30:50.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-privileged-identity-management-pim-elevation-approval-or-denial-audit-e-039a7469</loc>
    <lastmod>2026-07-31T12:30:48.618Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-safeboot-registry-key-deletion-via-reg-exe-command-line-fc0e89b5</loc>
    <lastmod>2026-07-30T04:59:31.773Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mshta-exe-launched-with-url-based-arguments-http-https-ftp-b98d0db6</loc>
    <lastmod>2026-07-30T04:51:26.164Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-dbgmanageddebugger-debugger-value-added-9827ae57</loc>
    <lastmod>2026-07-30T05:18:39.345Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-use-of-8-3-short-name-in-image-path-1-2-a96970af</loc>
    <lastmod>2026-07-30T05:08:13.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-lines-using-8-3-short-name-paths-1-2-349d891d</loc>
    <lastmod>2026-07-31T12:23:13.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-rdp-terminal-services-sensitive-settings-tampering-3f6b7b62</loc>
    <lastmod>2026-07-30T05:22:49.942Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-image-contains-ntfs-8-3-short-filename-patterns-3ef5605c</loc>
    <lastmod>2026-07-30T05:08:17.531Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-user-added-to-privileged-role-49a268a4</loc>
    <lastmod>2026-07-31T12:30:53.836Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-exploit-guard-controlled-folder-access-added-allowed-application-for-blo-42205c73</loc>
    <lastmod>2026-07-30T05:19:38.204Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-exploit-guard-protectedfolders-value-deleted-272e55a4</loc>
    <lastmod>2026-07-30T05:16:18.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wusa-exe-cab-extraction-from-suspicious-directory-paths-c74c0390</loc>
    <lastmod>2026-07-30T05:15:53.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-contains-ntfs-8-3-short-filename-patterns-1-2-dd6b39d9</loc>
    <lastmod>2026-07-30T05:08:15.691Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-remove-mppreference-used-to-tamper-windows-defender-set-07e3cb2c</loc>
    <lastmod>2026-07-30T04:56:14.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-logging-remove-mppreference-tampering-for-defende-ae2bdd58</loc>
    <lastmod>2026-07-31T13:22:31.592Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-script-executable-file-creation-in-non-standard-appdata-paths-d7b50671</loc>
    <lastmod>2026-07-31T13:04:34.361Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-exploit-guard-tamper-via-protectedfolders-or-allowedapplication-a3ab73f1</loc>
    <lastmod>2026-07-31T12:58:58.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-bulk-removal-of-privileged-role-members-102e11e3</loc>
    <lastmod>2026-07-31T12:30:55.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-tunneling-using-plink-exe-on-local-port-3389-f38ce0b9</loc>
    <lastmod>2026-07-30T04:54:07.836Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-module-registration-via-appcmd-and-powershell-043c4b8b</loc>
    <lastmod>2026-07-31T13:35:28.606Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexec-named-pipe-creation-from-suspicious-image-locations-pipename-psex-41504465</loc>
    <lastmod>2026-07-31T13:15:11.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-detect-member-removal-from-group-with-conditional-access-policy-modi-665e2d43</loc>
    <lastmod>2026-07-31T12:30:39.702Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-id-added-user-to-group-granted-conditional-access-policy-modificatio-91c95675</loc>
    <lastmod>2026-07-31T12:30:38.002Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wusa-exe-cab-extraction-using-unsupported-extract-flag-59b39960</loc>
    <lastmod>2026-07-31T12:23:36.946Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cli-usage-of-obfuscated-ip-address-patterns-in-ping-arp-commands-56d19cb4</loc>
    <lastmod>2026-07-30T05:08:21.166Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-obfuscated-ip-address-in-download-command-urls-cb5a2333</loc>
    <lastmod>2026-07-30T05:08:19.238Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-detect-default-diagtrackeop-poc-pipe-name-1f7025a6</loc>
    <lastmod>2026-07-31T13:14:48.129Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-mitigations-blocked-unsigned-dlls-loaded-from-suspicious-paths-8289bf8c</loc>
    <lastmod>2026-07-31T12:56:20.469Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-diagtrackeop-default-logon-username-eventid-4624-logontype-9-2111118f</loc>
    <lastmod>2026-07-31T12:50:30.052Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-successful-password-reset-by-user-account-340ee172</loc>
    <lastmod>2026-07-31T12:31:10.222Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-tools-performing-web-post-exfiltration-via-iwr-curl-wget-7d1aaf3d</loc>
    <lastmod>2026-07-30T05:06:53.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-invoke-webrequest-download-to-suspicious-paths-5e3cc4d8</loc>
    <lastmod>2026-07-30T04:55:57.299Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vmware-xfer-utility-dll-sideloading-via-vmwarexferlogs-exe-in-non-defaul-ebea773c</loc>
    <lastmod>2026-07-31T13:29:27.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mpclient-dll-side-loading-via-mpcmdrun-exe-or-nissrv-exe-from-non-defaul-418dc89a</loc>
    <lastmod>2026-07-31T13:12:17.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-flag-vmwarexferlogs-exe-loading-glib-2-0-dll-from-non-default-path-9313dc13</loc>
    <lastmod>2026-07-31T13:12:12.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-blocked-mpcmdrun-and-nissrv-from-loading-unsigned-dlls-0b0ea3cc</loc>
    <lastmod>2026-07-31T12:56:18.521Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-to-disable-windows-defender-components-0eb46774</loc>
    <lastmod>2026-07-30T05:23:18.282Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-attachment-manager-policy-tampering-via-attachments-settings-va-ee77a5db</loc>
    <lastmod>2026-07-30T05:21:42.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-tampering-attachment-manager-associations-default-file-type-ris-a9b6c011</loc>
    <lastmod>2026-07-30T05:21:41.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-disabling-windefend-service-windefend-start-4-e1aa95de</loc>
    <lastmod>2026-07-30T05:19:06.004Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-autologger-session-disable-start-tampering-via-event-log-target-f37b4bce</loc>
    <lastmod>2026-07-30T05:18:53.687Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sc-exe-service-startuptype-change-to-disabled-or-demand-85c312b7</loc>
    <lastmod>2026-07-30T05:04:05.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-importing-reg-files-from-common-user-and-temp-directories-62e0298b</loc>
    <lastmod>2026-07-30T04:59:52.793Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-deletes-service-registry-keys-using-the-delete-flag-05b2aa93</loc>
    <lastmod>2026-07-30T04:59:33.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-query-exe-used-to-enumerate-sessions-and-processes-possible-data-exfil-s-53ef0cef</loc>
    <lastmod>2026-07-30T04:59:01.098Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-mpclient-dll-side-loading-mpcmdrun-exe-or-nissrv-exe-from-non-d-7002aa10</loc>
    <lastmod>2026-07-30T04:51:09.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dnscmd-exe-dns-zone-and-record-enumeration-process-creation-b6457d63</loc>
    <lastmod>2026-07-31T13:29:36.259Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iso-file-creation-in-user-temporary-folders-2f9356ae</loc>
    <lastmod>2026-07-31T13:03:50.606Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-search-order-hijacking-via-additional-space-in-dll-path-b6f91281</loc>
    <lastmod>2026-07-31T13:02:59.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-driver-altitude-registry-changes-4916a35e</loc>
    <lastmod>2026-07-30T05:18:19.359Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-scheduled-task-create-modify-running-as-system-89ca78fd</loc>
    <lastmod>2026-07-30T05:05:01.867Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-scheduled-task-modification-via-schtasks-change-tn-1c0e41cd</loc>
    <lastmod>2026-07-30T05:04:25.621Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-dll-exe-sys-creation-in-spool-drivers-color-folder-ce7066a6</loc>
    <lastmod>2026-07-31T13:07:09.249Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-admin-adds-privileged-delegated-or-app-role-permissions-to-serv-5aecf3d5</loc>
    <lastmod>2026-07-31T12:30:20.368Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-end-user-consent-to-application-9b2cc4c4</loc>
    <lastmod>2026-07-31T12:30:09.414Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-delegated-permissions-granted-for-all-users-a6355fbe</loc>
    <lastmod>2026-07-31T12:30:07.821Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-appx-debugpath-key-for-potential-persistence-df4dc653</loc>
    <lastmod>2026-07-30T05:20:56.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-browser-started-with-remote-debugging-flags-b3d34dc5</loc>
    <lastmod>2026-07-31T13:25:40.229Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-sign-in-success-without-mfa-required-single-factor-authentication-28eea407</loc>
    <lastmod>2026-07-31T12:32:11.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winring0-driver-load-via-imphash-or-image-path-match-1a42dfa6</loc>
    <lastmod>2026-07-31T13:01:19.568Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-processes-using-base64-input-piped-to-shell-bash-sh-ba592c6d</loc>
    <lastmod>2026-07-31T12:38:06.410Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-selectmyparent-exe-execution-for-ppid-spoofing-52ff7941</loc>
    <lastmod>2026-07-31T13:34:01.845Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pdqdeployrunner-execution-on-windows-with-encoded-download-indicators-12b8e9f5</loc>
    <lastmod>2026-07-30T04:53:57.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-pdqdeployrunner-service-installation-pdqdeploy-b98a10af</loc>
    <lastmod>2026-07-31T12:58:01.199Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-of-pdqdeploy-service-service-control-manager-event--ee9ca27c</loc>
    <lastmod>2026-07-31T12:57:59.041Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-sip-persistence-via-new-cryptography-provider-registration-5a2b21ee</loc>
    <lastmod>2026-07-30T05:22:15.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-detect-dllpathoverride-persistence-in-contentindex-natural-lang-a1b1fd53</loc>
    <lastmod>2026-07-30T05:21:22.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-mpnotify-sip-provider-persistence-via-winlogon-92772523</loc>
    <lastmod>2026-07-30T05:21:19.298Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-lsa-extensions-multi-sz-dll-persistence-reg-multi-sz-41f6531d</loc>
    <lastmod>2026-07-30T05:21:17.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-ifilter-registration-via-persistenthandler-clsid-keys-b23818c7</loc>
    <lastmod>2026-07-30T05:21:14.523Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-htmlhelp-author-location-modification-976dd1f2</loc>
    <lastmod>2026-07-30T05:20:59.884Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-amsi-provider-persistence-via-providers-key-33efc23c</loc>
    <lastmod>2026-07-30T05:20:51.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-hhctrl-clsid-inprocserver32-default-modificatio-f10ed525</loc>
    <lastmod>2026-07-30T05:19:48.353Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-add-debugger-value-under-windows-error-reporting-hangs-key-833ef470</loc>
    <lastmod>2026-07-30T05:19:46.690Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-disk-cleanup-handler-autorun-keys-d4e2745c</loc>
    <lastmod>2026-07-30T05:19:21.549Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-add-debugger-value-under-aedebug-for-crash-time-execution-persi-092af964</loc>
    <lastmod>2026-07-30T05:17:33.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disk-cleanup-handler-persistence-via-volumecaches-key-creation-d4f4e0be</loc>
    <lastmod>2026-07-30T05:16:09.995Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexesvc-launched-child-process-running-as-local-system-7c0dcd3d</loc>
    <lastmod>2026-07-30T05:10:32.748Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexec-service-binary-renamed-execution-via-psexesvc-exe-51ae86a2</loc>
    <lastmod>2026-07-30T05:02:52.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-detect-explorer-expanded-lnk-persistence-in-startup-folder-w-a6976974</loc>
    <lastmod>2026-07-31T13:06:05.108Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-processcreation-apache-spark-shell-command-injection-indicators-via-id-gn-c8a5f584</loc>
    <lastmod>2026-07-31T12:08:08.120Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detection-user-agent-contains-known-recon-and-scanning-tool-strings-19aa4f58</loc>
    <lastmod>2026-07-31T12:47:12.695Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-service-principal-assigned-azure-rbac-microsoft-entra-roles-b04934b2</loc>
    <lastmod>2026-07-31T12:30:22.173Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-conditional-access-policy-updated-by-non-approved-actor-50a3c7aa</loc>
    <lastmod>2026-07-31T12:29:47.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-conditional-access-policy-deleted-by-non-approved-actor-26e7c5e2</loc>
    <lastmod>2026-07-31T12:29:45.503Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/apache-spark-shell-command-injection-attempt-in-web-server-logs-doas-1a9a04fd</loc>
    <lastmod>2026-07-31T12:08:09.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rejetto-hfs-exploit-attempt-http-search-query-probing-for-command-or-script-exec-a133193c</loc>
    <lastmod>2026-07-31T12:00:05.428Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uefi-persistence-detect-wpbbin-exe-execution-4abc0ec4</loc>
    <lastmod>2026-07-30T05:15:31.798Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-c-windows-system32-wpbbin-exe-for-uefi-persistence-indi-e94b9ddc</loc>
    <lastmod>2026-07-31T13:08:49.992Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-conditional-access-policy-added-by-non-approved-actor-0922467f</loc>
    <lastmod>2026-07-31T12:29:48.568Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-fax-device-provider-imagename-changed-to-load-external-dll-9e3357ba</loc>
    <lastmod>2026-07-30T05:19:41.480Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-user-account-changed-for-fax-service-e3fdf743</loc>
    <lastmod>2026-07-30T05:19:39.804Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-iscsicpl-exe-loading-malicious-dll-from-path-9ed5959a</loc>
    <lastmod>2026-07-31T13:12:34.210Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-process-loads-dll-from-suspicious-or-permissive-path-9e9a9002</loc>
    <lastmod>2026-07-31T13:12:25.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-ntvdm-ntvdm-exe-csrstub-exe-start-for-16-bit-app-compat-16905e21</loc>
    <lastmod>2026-07-30T05:06:05.627Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-initiated-to-ngrok-domains-18249279</loc>
    <lastmod>2026-07-31T13:13:26.950Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-triggered-once-at-00-00-using-scripted-commands-970823b7</loc>
    <lastmod>2026-07-30T05:04:43.846Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-dns-query-for-anonfiles-com-domain-065cceea</loc>
    <lastmod>2026-07-31T13:00:10.555Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-service-creation-via-sc-exe-or-powershell-new-service-with-ab-17a1be64</loc>
    <lastmod>2026-07-30T05:08:59.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-sc-exe-creating-kernel-driver-services-431a1fdb</loc>
    <lastmod>2026-07-30T05:04:07.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mssql-sp-procoption-startup-execution-changed-via-exec-eventid-33205-b3d57a5c</loc>
    <lastmod>2026-07-31T12:47:55.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-audit-policy-tampering-via-alter-drop-server-audit-350dfb37</loc>
    <lastmod>2026-07-31T12:47:48.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-add-member-to-sysadmin-role-server-role-alter-eventid-33205-08200f85</loc>
    <lastmod>2026-07-31T12:47:45.300Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-hidden-user-via-winlogon-specialaccounts-userlist-value-0-f8aebc67</loc>
    <lastmod>2026-07-30T05:22:19.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-base64-encoded-pe-mz-header-present-in-command-line-22e58743</loc>
    <lastmod>2026-07-30T05:07:43.402Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-local-user-creation-via-net-exe-with-expires-never-b9f0e6f5</loc>
    <lastmod>2026-07-30T04:52:32.002Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-suspicious-mofcomp-exe-execution-from-scripts-or-temp-paths-1dd05363</loc>
    <lastmod>2026-07-30T04:51:07.663Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-command-line-output-redirection-to-suspicious-user-or-system-pat-8e0bb260</loc>
    <lastmod>2026-07-31T13:27:18.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-xp-cmdshell-configuration-change-event-id-15457-d08dd86f</loc>
    <lastmod>2026-07-31T12:47:58.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-xp-cmdshell-execution-via-eventid-33205-7f103213</loc>
    <lastmod>2026-07-31T12:47:57.321Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-detect-command-lines-with-suspicious-utf-16-base64-obfuscatio-8d01b53f</loc>
    <lastmod>2026-07-30T04:54:24.188Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-to-remote-access-remote-support-domains-from-non-browser-pro-4d07b1f4</loc>
    <lastmod>2026-07-31T13:00:41.214Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-app-granted-microsoft-graph-exchange-sharepoint-azure-ad-per-c1d147ae</loc>
    <lastmod>2026-07-31T12:30:18.772Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-end-user-consent-blocked-for-risky-apps-by-risk-based-consent-7091372f</loc>
    <lastmod>2026-07-31T12:30:12.809Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-tcp-tunnel-indicators-on-windows-via-net-socket-apis-bd33d2aa</loc>
    <lastmod>2026-07-31T13:21:57.377Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-koh-default-named-pipe-creation-by-pipe-name-0adc67e0</loc>
    <lastmod>2026-07-31T13:14:54.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-user-agent-ending-with-indicating-potential-base64-encoding-894a8613</loc>
    <lastmod>2026-07-31T12:46:53.386Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-imports-modules-from-temp-or-public-paths-21f9162c</loc>
    <lastmod>2026-07-31T13:18:49.009Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-of-triple-cross-ebpf-rootkit-install-commands-via-sudo-t-22236d75</loc>
    <lastmod>2026-07-31T12:41:33.211Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-execve-hijack-execution-via-sudo-0326c3c8</loc>
    <lastmod>2026-07-31T12:41:31.278Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-ebpf-backdoor-file-creation-in-cron-d-and-sudoers-d-for-persistence-1a2ea919</loc>
    <lastmod>2026-07-31T12:37:41.556Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-alert-on-tmp-rootlog-creation-associated-with-triplecross-ebpf-rootkit-sta-c0239255</loc>
    <lastmod>2026-07-31T12:37:39.806Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-persistence-attempts-by-creating-modifying-etc-sudoers-d-files-ddb26b76</loc>
    <lastmod>2026-07-31T12:37:32.751Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-process-execution-for-remote-file-transfer-bbeaed61</loc>
    <lastmod>2026-07-31T12:21:36.032Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-file-download-via-o-remote-name-or-output-9a517fca</loc>
    <lastmod>2026-07-31T12:21:34.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-changes-disabling-windows-defender-event-log-channel-fcddca7c</loc>
    <lastmod>2026-07-30T05:19:14.669Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-event-log-tampering-by-disabling-winevt-channel-enabled-key-2f78da12</loc>
    <lastmod>2026-07-30T05:19:11.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-idiagnosticprofileuac-triggered-from-dllhost-exe-4cbef972</loc>
    <lastmod>2026-07-30T05:11:43.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-idiagnosticprofileuac-dllhost-exe-writing-dll-in-system32-48ea844d</loc>
    <lastmod>2026-07-31T13:08:09.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-xbap-via-presentationhost-exe-from-uncommon-paths-d22e2925</loc>
    <lastmod>2026-07-30T04:57:09.301Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scriptrunner-exe-process-execution-with-app-v-script-parameters-64760eef</loc>
    <lastmod>2026-07-31T13:37:18.624Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-user-type-changed-from-guest-to-member-8dee7a0d</loc>
    <lastmod>2026-07-31T12:30:43.120Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-handle-access-from-svchost-exe-via-seclogon-dll-windows-process-472159c5</loc>
    <lastmod>2026-07-31T13:23:40.400Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-assoc-exe-changing-file-associations-to-exefile-ae6f14e6</loc>
    <lastmod>2026-07-31T13:26:44.118Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-bitsadmin-downloading-to-suspicious-target-folders-2ddef153</loc>
    <lastmod>2026-07-31T13:25:22.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-bitsadmin-download-of-files-with-suspicious-extensions-5b80a791</loc>
    <lastmod>2026-07-31T13:25:20.873Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bitsadmin-download-from-file-sharing-domains-using-suspicious-transfer-c-8518ed3d</loc>
    <lastmod>2026-07-31T13:25:19.131Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-bitsadmin-download-using-direct-ip-url-99c840f2</loc>
    <lastmod>2026-07-31T13:25:17.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-attrib-exe-s-used-to-mark-executables-scripts-in-common-drop-locations-a-efec536f</loc>
    <lastmod>2026-07-31T13:24:47.254Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-disables-or-removes-etw-trace-providers-via-etw-cmdlets-115fdba9</loc>
    <lastmod>2026-07-31T13:18:24.702Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bits-client-job-downloads-to-suspicious-saved-file-locations-f8a56cb7</loc>
    <lastmod>2026-07-31T12:48:47.179Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bits-client-download-from-file-sharing-domains-d635249d</loc>
    <lastmod>2026-07-31T12:48:40.266Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-sign-ins-by-unknown-devices-from-non-trusted-locations-4d136857</loc>
    <lastmod>2026-07-31T12:32:16.804Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-sign-ins-from-non-compliant-devices-4f77e1d7</loc>
    <lastmod>2026-07-31T12:32:14.907Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-device-registration-or-join-successful-without-mfa-5afa454e</loc>
    <lastmod>2026-07-31T12:32:05.934Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-user-added-to-global-or-device-administrator-roles-11c767ae</loc>
    <lastmod>2026-07-31T12:30:00.974Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-device-registration-policy-changes-via-audit-logs-9494bff8</loc>
    <lastmod>2026-07-31T12:29:55.257Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-bitlocker-key-retrieval-via-read-bitlocker-key-a0413867</loc>
    <lastmod>2026-07-31T12:29:51.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dllhost-exe-spawn-without-command-line-arguments-e7888eb1</loc>
    <lastmod>2026-07-31T13:29:30.446Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-handlekatz-usage-duplicate-lsass-handle-via-process-dup-handle-b1bd3a59</loc>
    <lastmod>2026-07-31T13:23:24.334Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-werfault-creates-dump-files-referencing-lsass-process-memory-c3e76af5</loc>
    <lastmod>2026-07-31T13:04:17.022Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-process-injection-via-msra-exe-spawning-suspicious-child-proce-744a188b</loc>
    <lastmod>2026-07-30T04:51:55.764Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-containing-ufile-io-1cbbeaaf</loc>
    <lastmod>2026-07-31T13:00:49.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-msdt-exe-launched-with-cab-flag-dc4576d4</loc>
    <lastmod>2026-07-30T04:51:20.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-of-troubleshootingpack-cmdlet-for-unattended-troubl-03409c93</loc>
    <lastmod>2026-07-31T13:21:06.966Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-hotfix-enumeration-via-win32-quickfixengineering-f5d1def8</loc>
    <lastmod>2026-07-31T13:18:44.746Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-exe-used-to-start-or-stop-services-0b7163dc</loc>
    <lastmod>2026-07-30T05:15:06.214Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-process-creation-recon-for-unquoted-service-paths-68bcd73b</loc>
    <lastmod>2026-07-30T05:15:01.253Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hotfix-inventory-recon-via-wmic-exe-qfe-dfd2fcb7</loc>
    <lastmod>2026-07-30T05:14:51.135Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cli-enumeration-of-3rd-party-credential-registry-keys-87a476dc</loc>
    <lastmod>2026-07-30T05:00:38.019Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-password-spraying-attempt-via-dsacls-exe-bac9fb54</loc>
    <lastmod>2026-07-31T13:29:53.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dsacls-exe-granting-over-permissive-acl-permissions-via-g-01c42d3c</loc>
    <lastmod>2026-07-31T13:29:51.473Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-wmi-service-enumeration-for-unquoted-service-path-recon-09658312</loc>
    <lastmod>2026-07-31T13:23:04.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-recon-command-line-indicators-for-suid-htpasswd-discovery-0cf7a157</loc>
    <lastmod>2026-07-31T12:41:11.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-reading-etc-sudoers-via-file-content-inspection-utilities-0f79c4d2</loc>
    <lastmod>2026-07-31T12:41:09.624Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-command-line-printing-of-shell-history-files-d7821ff1</loc>
    <lastmod>2026-07-31T12:40:56.467Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-history-file-deletion-via-rm-unlink-shred-commands-1182f3b3</loc>
    <lastmod>2026-07-31T12:40:52.364Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-w32time-timeprovider-dllname-values-set-under-services-w32t-e88a6ddc</loc>
    <lastmod>2026-07-30T05:22:51.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chromium-based-browser-launched-with-custom-extension-via-load-extens-27ba3207</loc>
    <lastmod>2026-07-31T13:25:36.567Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-chromium-based-browser-launched-with-load-extension-custom-flag-88d6e60c</loc>
    <lastmod>2026-07-31T13:25:33.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-suspicious-double-extension-filenames-b4926b47</loc>
    <lastmod>2026-07-31T13:06:32.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msdt-exe-loading-sdiageng-dll-via-imageload-telemetry-ec8c4047</loc>
    <lastmod>2026-07-31T13:09:17.151Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-legacy-authentication-protocols-used-by-account-60f6535a</loc>
    <lastmod>2026-07-31T12:32:28.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-sign-in-logs-account-disabled-or-blocked-on-failed-login-attempts-4afac85c</loc>
    <lastmod>2026-07-31T12:32:24.202Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sysinternals-psservice-psservice-exe-execution-3371f518</loc>
    <lastmod>2026-07-30T05:10:36.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-openconsole-exe-used-as-lolbin-to-launch-other-executab-814c95cc</loc>
    <lastmod>2026-07-31T13:36:48.317Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-socgholish-fakeupdates-execution-via-wscript-launching-cmd-or-powershell-97805087</loc>
    <lastmod>2026-07-31T12:08:52.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-enable-scripteddiagnostics-turnoffcheck-dword-via-policies-7d995e63</loc>
    <lastmod>2026-07-30T05:19:35.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pcalua-exe-flag-a-command-execution-0955e4e1</loc>
    <lastmod>2026-07-31T13:36:52.035Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-forfiles-exe-executed-with-c-flag-9aa5106d</loc>
    <lastmod>2026-07-31T13:30:53.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-conhost-exe-path-traversal-in-command-line-ee5e119b</loc>
    <lastmod>2026-07-31T13:28:02.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/web-server-ssti-probe-strings-in-get-requests-ada3bc4f</loc>
    <lastmod>2026-07-31T12:47:11.133Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msdt-exe-execution-using-pcwdiagnostic-xml-answer-file-9c8c7000</loc>
    <lastmod>2026-07-30T04:51:16.689Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pcwrun-exe-indirect-command-execution-via-path-traversal-6004abd0</loc>
    <lastmod>2026-07-31T13:36:55.833Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-custom-file-open-handler-executes-powershell-7530b96f</loc>
    <lastmod>2026-07-30T05:18:37.511Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-notepad-gup-gup-exe-file-downloads-via-http-when-parent-is-not-notepad-e-44143844</loc>
    <lastmod>2026-07-31T13:31:31.910Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gup-utility-used-by-notepad-updater-to-execute-arbitrary-binaries-d65aee4d</loc>
    <lastmod>2026-07-31T13:31:29.501Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-new-notepad-plugin-dll-creation-outside-gup-exe-54127bd4</loc>
    <lastmod>2026-07-31T13:04:37.821Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bits-transfer-job-using-uncommon-or-suspicious-remote-domain-6d44fb93</loc>
    <lastmod>2026-07-31T12:48:45.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-bits-proxy-traffic-to-ip-like-hostnames-uncommon-server-address-8ccd35a2</loc>
    <lastmod>2026-07-31T12:46:34.102Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-via-squirrel-exe-proxy-arguments-45239e6a</loc>
    <lastmod>2026-07-30T05:05:54.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-squirrel-exe-using-download-update-flags-to-fetch-files-1e75c1cc</loc>
    <lastmod>2026-07-30T05:05:53.147Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-mftrace-exe-child-process-execution-3d48c9d3</loc>
    <lastmod>2026-07-30T04:50:57.132Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-vsiisexelauncher-exe-used-with-p-and-a-parameters-18749301</loc>
    <lastmod>2026-07-31T13:37:52.325Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-execution-of-adplus-exe-with-memory-dump-and-inline-command-switc-2f869d59</loc>
    <lastmod>2026-07-31T13:24:19.338Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-creation-of-diagcab-files-3d0ed417</loc>
    <lastmod>2026-07-31T13:06:30.051Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iso-image-opened-by-archiver-utilities-winrar-7-zip-peazip-fcdf69e5</loc>
    <lastmod>2026-07-30T05:06:21.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dns-queries-to-oast-callback-service-domains-external-dns-interactions-aff715fa</loc>
    <lastmod>2026-07-31T12:44:32.912Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-ecs-task-definitions-that-reference-container-credential-endpoint-uri-b94bf91e</loc>
    <lastmod>2026-07-31T12:27:49.196Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-plink-plink-exe-with-ssh-port-forwarding-flags-1c12727d</loc>
    <lastmod>2026-07-30T05:02:41.546Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detect-suspicious-windows-path-strings-in-web-uri-query-windows-exfil-webshell-c-9f6a34b4</loc>
    <lastmod>2026-07-31T12:47:14.442Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-nohup-execution-via-process-creation-nohu-p-command-path-e4ffe466</loc>
    <lastmod>2026-07-31T12:39:47.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-msiexec-exe-under-manageengine-supportcenter-plus-bin-7b501acf</loc>
    <lastmod>2026-07-31T12:06:22.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-startup-folder-file-creation-with-uncommon-extension-a10a2c40</loc>
    <lastmod>2026-07-31T13:05:15.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-locks-workstation-via-user32-dll-lockworkstation-3b5b0213</loc>
    <lastmod>2026-07-30T05:03:53.144Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-suspicious-gpo-enumeration-via-get-gpo-eb2fd349</loc>
    <lastmod>2026-07-31T13:21:26.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/java-payload-indicators-in-web-access-logs-583aa0a2</loc>
    <lastmod>2026-07-31T12:47:01.852Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-msdt-exe-execution-bd1c6866</loc>
    <lastmod>2026-07-30T05:02:29.098Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/python-process-spawning-a-pretty-tty-via-pty-spawn-on-windows-480e7e51</loc>
    <lastmod>2026-07-30T04:58:58.059Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-java-process-spawning-shells-and-downloaders-d292e0af</loc>
    <lastmod>2026-07-31T12:41:03.447Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-python-imports-pty-and-spawns-a-pseudo-tty-c4042d54</loc>
    <lastmod>2026-07-31T12:40:08.764Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-chmod-process-creation-targeting-sensitive-directory-paths-6419afd1</loc>
    <lastmod>2026-07-31T12:38:27.108Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-atlassian-confluence-spawning-shell-utility-child-process-7fb14105</loc>
    <lastmod>2026-07-31T12:07:52.950Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-browsercore-exe-renamed-execution-for-azure-token-theft-8a4519e8</loc>
    <lastmod>2026-07-30T05:02:10.229Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-remote-exe-windbg-execution-4eddc365</loc>
    <lastmod>2026-07-31T13:37:11.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-f-interpreters-fsi-exe-and-fsianycpu-exe-b96b2031</loc>
    <lastmod>2026-07-31T13:30:57.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmiexec-default-output-file-creation-via-file-events-8d5aca11</loc>
    <lastmod>2026-07-31T13:08:45.210Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-document-drop-into-startup-folders-for-persistence-0e20c89d</loc>
    <lastmod>2026-07-31T13:05:11.538Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-app-uri-updates-in-audit-logs-appaddress-property-changes-0055ad1f</loc>
    <lastmod>2026-07-31T12:30:23.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-log-owner-added-to-application-74298991</loc>
    <lastmod>2026-07-31T12:30:14.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-appid-uri-configuration-updates-for-applications-or-service--1b45b0d1</loc>
    <lastmod>2026-07-31T12:30:03.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-applications-spawning-child-processes-with-directory-traversal-st-868955d9</loc>
    <lastmod>2026-07-31T12:05:43.628Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sdiagnhost-exe-spawns-suspicious-child-process-powershell-cmd-mshta-etc-f3d39c45</loc>
    <lastmod>2026-07-30T05:05:14.164Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msdt-exe-execution-with-suspicious-parent-process-7a74da6b</loc>
    <lastmod>2026-07-30T04:51:22.030Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wfc-exe-execution-for-workflow-command-line-compiler-ab-49be8799</loc>
    <lastmod>2026-07-30T04:50:49.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/process-creation-of-visualuiaverifynative-exe-on-windows-b30a8bc5</loc>
    <lastmod>2026-07-31T13:37:50.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-failure-blocked-by-conditional-access-requirement-not-met-b4a6d707</loc>
    <lastmod>2026-07-31T12:32:26.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-detect-ropc-authentication-flow-use-in-applications-55695bc0</loc>
    <lastmod>2026-07-31T12:32:22.189Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-application-using-device-code-authentication-flow-248649b7</loc>
    <lastmod>2026-07-31T12:32:20.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-custom-url-protocol-handler-persistence-via-hkcr-protocol-regis-fdbf0b9d</loc>
    <lastmod>2026-07-30T05:21:07.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msdt-exe-ms-msdt-handler-arbitrary-command-execution-attempts-258fc8ce</loc>
    <lastmod>2026-07-30T04:51:18.462Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-onedrivestandaloneupdater-exe-url-from-updateofficeconfig-for-p-3aff0be0</loc>
    <lastmod>2026-07-30T05:20:08.362Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-utilityfunctions-ps1-loading-managed-dll-via-proxy-0403d67d</loc>
    <lastmod>2026-07-31T13:37:46.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pubprn-vbs-signed-script-proxy-execution-via-script-command-line-1fb76ab8</loc>
    <lastmod>2026-07-31T13:37:06.405Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-detects-obfuscated-net-webclient-casing-anomalies-in-command--c86133ad</loc>
    <lastmod>2026-07-30T04:57:00.217Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-process-command-lines-with-encoded-command-flags-b9d9cc83</loc>
    <lastmod>2026-07-30T04:54:22.551Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-jlaive-in-memory-assembly-execution-via-powershell-and--0a99eb3e</loc>
    <lastmod>2026-07-31T13:33:18.547Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-launched-by-explorer-exe-parent-process-1723e720</loc>
    <lastmod>2026-07-30T05:03:18.480Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-proxy-execution-via-cl-mutexverifiers-ps1-1e0e1a81</loc>
    <lastmod>2026-07-30T04:54:42.672Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-assembly-loading-via-cl-loadassembly-ps1-functions-c57872c7</loc>
    <lastmod>2026-07-30T04:54:41.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-anydesk-executed-from-suspicious-directory-065b00ca</loc>
    <lastmod>2026-07-30T05:01:22.692Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-base64-encoded-commands-containing-invoke-e-6385697e</loc>
    <lastmod>2026-07-30T04:54:30.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-grpconv-utility-execution-for-grp-conversion-or-persistence-f14e169e</loc>
    <lastmod>2026-07-31T13:37:31.483Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-applications-downloading-files-via-http-https-4ae3e30b</loc>
    <lastmod>2026-07-30T04:53:32.796Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-eventlog-cleared-event-id-104-100ef69e</loc>
    <lastmod>2026-07-31T12:56:49.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-ttdinject-exe-ttdinject-exe-b27077d6</loc>
    <lastmod>2026-07-31T13:37:40.892Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gpscript-exe-execution-with-logon-or-startup-parameters-1e59c230</loc>
    <lastmod>2026-07-31T13:36:34.125Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ieexec-exe-download-and-execute-execution-via-process-creation-9801abb8</loc>
    <lastmod>2026-07-31T13:35:13.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/certoc-exe-file-download-via-getcacaps-http-on-windows-70ad0861</loc>
    <lastmod>2026-07-31T13:25:52.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-createremotethread-using-ttdinject-exe-as-proxy-c15e99a3</loc>
    <lastmod>2026-07-31T12:59:49.259Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-reg-exe-adds-winlogon-specialaccounts-userlist-value-0-9ec9fb1b</loc>
    <lastmod>2026-07-30T05:00:54.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-ransomware-signature-alert-based-on-known-family-name-strings-4c6ca276</loc>
    <lastmod>2026-07-31T12:26:54.736Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-for-krbscm-via-krbrelayup-tool-e97d9903</loc>
    <lastmod>2026-07-31T12:57:37.580Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-of-obfuscated-one-liner-for-in-memory-module-downlo-44e24481</loc>
    <lastmod>2026-07-30T04:55:13.199Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-werfault-exe-wer-dll-created-in-uncommon-directory-28a452f3</loc>
    <lastmod>2026-07-31T13:08:35.547Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-password-protected-zip-opened-from-outlook-attachment-571498c8</loc>
    <lastmod>2026-07-31T12:55:14.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-opened-encrypted-zip-files-with-suspicious-invoice-order-filena-54f0434b</loc>
    <lastmod>2026-07-31T12:55:13.061Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-password-protected-zip-opened-eventid-5379-00ba9da1</loc>
    <lastmod>2026-07-31T12:55:11.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ie4uinit-exe-executed-from-unusual-currentdirectory-invalid-path-d3bf399f</loc>
    <lastmod>2026-07-31T13:36:36.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-ilasm-exe-compiling-c-il-to-exe-or-dll-850d55f9</loc>
    <lastmod>2026-07-31T13:35:30.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-contains-cobalt-strike-module-commands-entered-in-cmd-exe-4f154fb6</loc>
    <lastmod>2026-07-31T13:31:57.330Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-cobalt-strike-command-strings-entered-in-cmd-exe-647c7b9e</loc>
    <lastmod>2026-07-31T13:31:55.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-raspberry-robin-initial-execution-via-cmd-exe-launching-msiexec--2c6bea3a</loc>
    <lastmod>2026-07-31T12:08:46.426Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-raspberry-robin-command-execution-via-fodhelper-rundll32-and-regsvr32-d52d2e87</loc>
    <lastmod>2026-07-31T12:08:44.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-child-processes-spawned-by-regsvr32-exe-6f0947a4</loc>
    <lastmod>2026-07-30T05:01:05.031Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-by-rundll32-for-screen-saver-execution-via-scrnsave-exe-40b6e656</loc>
    <lastmod>2026-07-30T05:22:07.665Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-calls-davsetcookie-for-ntlm-coercion-via-spoolss-srvsvc-bb76d96b</loc>
    <lastmod>2026-07-30T05:03:15.186Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-nimbuspwn-path-traversal-attempts-targeting-networkd-dispatcher-7ba05b43</loc>
    <lastmod>2026-07-31T12:08:00.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-service-configured-with-image-path-in-suspicious-public-temp-fo-a07f0359</loc>
    <lastmod>2026-07-30T05:18:34.217Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-printbrm-exe-zip-creation-extraction-via-command-line-flags-cafeeba3</loc>
    <lastmod>2026-07-31T13:37:03.795Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-jscript-compiler-jsc-exe-process-execution-52788a70</loc>
    <lastmod>2026-07-31T13:35:52.862Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-imagepath-set-to-user-controlled-directory-via-registry-277dc340</loc>
    <lastmod>2026-07-31T12:23:46.103Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gpresult-exe-used-to-display-group-policy-resultant-set-rsop-e56d3073</loc>
    <lastmod>2026-07-31T13:31:27.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-tcp-3389-initiated-connections-to-http-https-ports-80-443-b1e5da3b</loc>
    <lastmod>2026-07-31T13:13:55.494Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ngrok-forwarding-to-local-rdp-port-via-terminalservices-eventid-21-64d51a51</loc>
    <lastmod>2026-07-31T12:58:46.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-executing-installscreensaver-via-desk-cpl-scr-file-15bd98ea</loc>
    <lastmod>2026-07-30T05:03:07.661Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-sync-center-mobsync-exe-network-connections-to-non-private-ips-9f2cc74d</loc>
    <lastmod>2026-07-31T13:14:22.456Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-copied-suspicious-exe-dll-files-into-default-gpo-storage-path-5f87308a</loc>
    <lastmod>2026-07-31T13:06:25.772Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-files-created-by-microsoft-sync-center-mobsync-exe-409f8a98</loc>
    <lastmod>2026-07-31T13:06:24.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-spawning-explorer-exe-child-process-shell32-control-rundll-caa06de8</loc>
    <lastmod>2026-07-30T05:03:32.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-krbrelay-relaying-tool-e96253b8</loc>
    <lastmod>2026-07-31T13:33:23.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-execution-via-pe-company-metadata-cube0x0-37c1333a</loc>
    <lastmod>2026-07-31T13:32:34.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-event-viewer-recentviews-file-writes-63e4f530</loc>
    <lastmod>2026-07-31T13:08:07.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scr-screen-saver-file-created-outside-system-directories-c048f047</loc>
    <lastmod>2026-07-31T13:04:36.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detects-suspicious-local-kerberos-logon-of-built-in-administrator-potent-749c9f5e</loc>
    <lastmod>2026-07-31T12:50:50.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-krbrelayup-exe-process-execution-with-relay-domain-and-scm-spawn--12827a56</loc>
    <lastmod>2026-07-31T13:33:27.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-ntlmv1-logon-reported-between-client-and-server-lsasrv-6038-6039-e9d4ab66</loc>
    <lastmod>2026-07-31T12:56:33.830Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-application-error-popups-application-popup-event-id-26-4d7f1827</loc>
    <lastmod>2026-07-31T12:56:31.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-powershell-child-processes-spawned-by-powershell-exe-pwsh-exe-e4b6d2a7</loc>
    <lastmod>2026-07-31T04:40:42.696Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-rule-for-powershell-cmd-spawned-by-prunsrv-exe-vmware-w-5660d8db</loc>
    <lastmod>2026-07-31T12:07:48.786Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msiexec-exe-command-line-loading-a-dll-and-calling-dllunregisterserver-84f52741</loc>
    <lastmod>2026-07-30T04:51:38.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-wmi-win32-product-msi-installation-via-invoke-cimmethod-91109523</loc>
    <lastmod>2026-07-31T13:22:52.535Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-suspicious-get-variable-exe-under-windowsapps-0c3fac91</loc>
    <lastmod>2026-07-31T13:06:43.613Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-thread-created-in-keepass-exe-77564cc2</loc>
    <lastmod>2026-07-31T12:59:32.926Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lnk-emotet-loader-execution-via-cmd-powershell-process-creation-1f32d820</loc>
    <lastmod>2026-07-31T12:08:36.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-key-manager-launch-keymgr-krshowkeymgr-credential-access-a4694263</loc>
    <lastmod>2026-07-30T05:03:09.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dns-nkn-seed-domain-lookups-for-potential-c2-over-nkn-org-fa7703d6</loc>
    <lastmod>2026-07-31T12:45:18.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-dropbox-api-network-connections-from-non-dropbox-executables-25eabf56</loc>
    <lastmod>2026-07-31T13:13:15.260Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-command-execution-spawned-by-7zfm-exe-for-cve-2022-29072-9a4ccd1a</loc>
    <lastmod>2026-07-31T12:07:58.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-msiexec-exe-embedding-spawned-by-powershell-cmd-pwsh-4a2a2c3e</loc>
    <lastmod>2026-07-30T04:51:40.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-cron-suspicious-crontab-modification-via-replace-af202fd3</loc>
    <lastmod>2026-07-31T12:36:53.540Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-delete-sd-value-under-schedule-taskcache-tree-to-impair-schedul-acd74772</loc>
    <lastmod>2026-07-30T05:16:28.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-scheduled-task-creation-from-suspicious-folders-8a8379b8</loc>
    <lastmod>2026-07-30T05:04:39.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-from-eqnedt32-exe-equation-editor-a66bc059</loc>
    <lastmod>2026-07-31T13:13:38.696Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-svchost-rpcss-service-spawns-suspicious-child-process-attempt-a7cd7306</loc>
    <lastmod>2026-07-31T12:07:54.643Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-webadministration-psm1-during-cve-2022-24527-lpe-attemp-e0a41412</loc>
    <lastmod>2026-07-31T12:07:51.125Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hyper-v-powershell-cmdlets-usage-on-windows-42d36aa1</loc>
    <lastmod>2026-07-31T13:21:33.618Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-to-browser-credential-stores-by-uncommon-processes-91cb43db</loc>
    <lastmod>2026-07-31T12:19:18.864Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-credential-manager-enumeration-via-vaultcmd-exe-listcreds-58f50261</loc>
    <lastmod>2026-07-30T05:12:11.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sqlite-access-to-firefox-profile-databases-4833155a</loc>
    <lastmod>2026-07-30T05:05:51.439Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-task-scheduler-persistence-using-svchost-launched-powershell-with-hidden-b66474aa</loc>
    <lastmod>2026-07-30T05:04:49.521Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-from-c-users-public-fb9d3ff7</loc>
    <lastmod>2026-07-30T04:56:09.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-node-js-executions-from-adobe-creative-cloud-df1f26d3</loc>
    <lastmod>2026-07-30T04:53:05.003Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dumpminitool-exe-execution-on-windows-eb1c4225</loc>
    <lastmod>2026-07-31T13:30:03.392Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-dumpminitool-exe-memory-dump-tool-execution-dee0a7a3</loc>
    <lastmod>2026-07-31T13:30:01.409Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4624-logontype-9-using-new-credentials-def8b624</loc>
    <lastmod>2026-07-31T12:50:48.548Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-root-ca-or-authroot-certificates-added-to-certificate-store-d223b46b</loc>
    <lastmod>2026-07-30T05:20:03.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-key-change-disabling-system-restore-5de03871</loc>
    <lastmod>2026-07-30T05:19:04.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-service-persistence-via-safeboot-control-keys-1547e27c</loc>
    <lastmod>2026-07-30T05:17:29.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-user-discovery-via-getcurrent-user-and-environment-variables-4096a49c</loc>
    <lastmod>2026-07-31T13:21:25.339Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-key-changes-disabling-powershell-logging-for-current-user-fecfd1a1</loc>
    <lastmod>2026-07-30T05:21:54.683Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-disabling-hidden-and-system-file-display-5a5152f1</loc>
    <lastmod>2026-07-30T05:19:51.493Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-gettypefromclsid-shellexecute-usage-8bc063d5</loc>
    <lastmod>2026-07-31T13:21:31.957Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-fsutil-drive-enumeration-via-drives-argument-63de06b9</loc>
    <lastmod>2026-07-31T13:30:58.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-iex-invocation-patterns-in-process-creation-command-lines-09576804</loc>
    <lastmod>2026-07-30T04:55:44.118Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-download-and-execution-cradles-85b0b087</loc>
    <lastmod>2026-07-30T04:55:16.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-mfa-denied-authenticationrequirement-e40f4962</loc>
    <lastmod>2026-07-31T12:32:32.467Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-registry-tampering-of-windows-defender-policy-keys-452bce90</loc>
    <lastmod>2026-07-30T05:00:16.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsa-ppl-protection-setting-modification-via-reg-exe-or-powershell-comman-8c0eca51</loc>
    <lastmod>2026-07-30T04:50:53.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-parent-processes-unusual-child-creation-by-system-utilities-cbec226f</loc>
    <lastmod>2026-07-30T05:08:23.108Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-hacktool-service-registration-or-execution-d26ce60c</loc>
    <lastmod>2026-07-31T12:57:50.619Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-payload-execution-via-cmd-powershell-system-eventid-wrapp-d5eb7432</loc>
    <lastmod>2026-07-31T12:08:50.487Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-policy-modification-for-explorer-ui-function-disabling-1c3121ed</loc>
    <lastmod>2026-07-30T05:22:14.240Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-defense-impairment-via-explorer-hide-policy-values-5a93eb65</loc>
    <lastmod>2026-07-30T05:19:53.001Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-policy-change-to-disable-impair-internal-tools-and-ui-features-e2482f8d</loc>
    <lastmod>2026-07-30T05:18:57.544Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-using-script-host-execution-event-id-7045-70f00d10</loc>
    <lastmod>2026-07-31T12:58:39.577Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-referencing-suspicious-programdata-root-exe-paths-e-1b2ae822</loc>
    <lastmod>2026-07-31T12:58:37.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-via-suspicious-command-line-imagepath-event-id-7045-1d61f71d</loc>
    <lastmod>2026-07-31T12:58:18.551Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-run-key-entries-containing-powershell-execution-strings-8d85cf08</loc>
    <lastmod>2026-07-30T05:21:53.043Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-webserver-parent-process-launching-credential-dumping-and-exfiltration-c-4ebc877f</loc>
    <lastmod>2026-07-30T05:13:00.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pktmon-exe-process-execution-pktmon-exe-pktmon-exe-f956c7c1</loc>
    <lastmod>2026-07-30T04:54:04.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-logs-get-process-process-discovery-af4c87ce</loc>
    <lastmod>2026-07-31T13:21:28.661Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-ad-password-policy-discovery-via-get-addefaultdomainpasswordpolicy-bbb9495b</loc>
    <lastmod>2026-07-31T13:21:23.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-directory-enumeration-via-get-childitem-script-block-162e69a7</loc>
    <lastmod>2026-07-31T13:20:57.808Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-ad-group-enumeration-via-get-adgroup-cmdlet-8c3a6607</loc>
    <lastmod>2026-07-31T13:18:33.438Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-ad-computer-enumeration-via-get-adcomputer-36bed6b2</loc>
    <lastmod>2026-07-31T13:18:31.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-get-aduser-enumeration-via-useraccountcontrol-dont-req-preaut-96c982fe</loc>
    <lastmod>2026-07-31T13:17:33.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-suspicious-get-addbaccount-reads-ntds-dit-via-bootkey-b140afd9</loc>
    <lastmod>2026-07-31T13:16:09.651Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-thread-creation-targeting-uncommon-image-processes-a1a144b7</loc>
    <lastmod>2026-07-31T12:59:47.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-create-executes-file-from-appdata-local-c5c00f49</loc>
    <lastmod>2026-07-30T05:04:23.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-shell-command-piped-into-another-shell-880973f3</loc>
    <lastmod>2026-07-31T12:41:07.976Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-interactive-bash-launching-suspicious-child-commands-ea3ecad2</loc>
    <lastmod>2026-07-31T12:41:01.606Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-for-foreach-scan-loop-with-nslookup-or-ping-f8ad2e2c</loc>
    <lastmod>2026-07-30T05:08:01.068Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-pattern-indicating-crackmapexec-lsass-dumping-via-tasklist-cmd-a-f26307d8</loc>
    <lastmod>2026-07-31T13:32:10.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-ntds-dit-and-registry-hive-exfiltration-tooling-8bc64091</loc>
    <lastmod>2026-07-30T05:08:10.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-with-ntds-dit-exfiltration-filename-patterns-3a8da4e0</loc>
    <lastmod>2026-07-31T13:04:45.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-with-high-grantedaccess-to-wmi-provider-and-lsass-250ae82f</loc>
    <lastmod>2026-07-31T12:21:19.774Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-executable-file-creation-where-a-parent-executable-writes-another-exe-297afac9</loc>
    <lastmod>2026-07-31T12:19:38.655Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-offlinescannershell-exe-mpclient-dll-dll-sideloading-ri-02b18447</loc>
    <lastmod>2026-07-30T04:53:54.350Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-replace-exe-with-a-argument-9292293b</loc>
    <lastmod>2026-07-31T13:37:13.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-ultravnc-command-line-with-auto-reconnect-flags-871b9555</loc>
    <lastmod>2026-07-30T05:12:05.044Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-base64-encoded-mppreference-command-lines-for-windows-defender-modifi-c6fb44c6</loc>
    <lastmod>2026-07-30T04:54:32.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-execution-via-imphash-matches-renamed-files-24e3e58a</loc>
    <lastmod>2026-07-31T13:32:33.289Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-disable-microsoft-defender-scanning-via-set-mppreference-1ec65a5f</loc>
    <lastmod>2026-07-30T04:55:01.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-fsutil-symlinkevaluation-behavior-change-via-cmd-or-powershell-c0b2768a</loc>
    <lastmod>2026-07-31T13:31:00.924Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-base64-obfuscated-net-reflection-assembly-load-call-9c0295ce</loc>
    <lastmod>2026-07-30T04:54:35.828Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-base64-encoded-reflective-net-assembly-load-62b7ccc9</loc>
    <lastmod>2026-07-30T04:54:34.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bits-transfer-job-writing-files-with-suspicious-executable-extensions-b85e5894</loc>
    <lastmod>2026-07-31T12:48:38.257Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-created-new-bits-job-event-id-3-fe3a2d49</loc>
    <lastmod>2026-07-31T12:48:36.380Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bits-job-created-via-bitsadmin-exe-bits-client-eventid-3-1ff315dc</loc>
    <lastmod>2026-07-31T12:48:34.650Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-commandline-downloads-and-executes-via-webclient-with-iex-or--e6c54d94</loc>
    <lastmod>2026-07-30T04:56:41.040Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-process-spawn-by-outlook-parent-208748f7</loc>
    <lastmod>2026-07-30T04:53:45.987Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-enable-microsoft-dde-in-word-or-excel-security-settings-63647769</loc>
    <lastmod>2026-07-30T05:20:35.320Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wuauclt-exe-process-creation-on-windows-with-empty-command-line-flags-52d097e2</loc>
    <lastmod>2026-07-30T05:15:51.326Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-parent-process-execution-from-users-public-spawning-scripting-69bd9b97</loc>
    <lastmod>2026-07-30T05:07:27.434Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-client-service-spawning-suspicious-utility-commands-7b582f1a</loc>
    <lastmod>2026-07-30T05:01:46.623Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-crackmapexec-execution-via-distinctive-command-line-fla-42a993dd</loc>
    <lastmod>2026-07-31T13:32:06.714Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msexchangemailboxreplication-writes-asp-aspx-files-7280c9f3</loc>
    <lastmod>2026-07-31T13:06:35.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-patterns-indicating-hermetic-wiper-style-execution-and-powershel-2f974656</loc>
    <lastmod>2026-07-31T12:08:42.499Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-indicators-of-blackbyte-ransomware-activity-999e8307</loc>
    <lastmod>2026-07-31T12:06:41.061Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-crashdump-via-crashcontrol-dword-value-2ff692c2</loc>
    <lastmod>2026-07-30T05:18:29.739Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-via-schtasks-with-suspicious-command-line-patter-f2c64357</loc>
    <lastmod>2026-07-30T05:05:00.159Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-explorer-spawned-with-nouaccheck-flag-534f2ef7</loc>
    <lastmod>2026-07-31T13:30:24.587Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-via-schtasks-exe-from-suspicious-parent-paths-9494479d</loc>
    <lastmod>2026-07-31T12:22:56.189Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-task-creation-targeting-suspicious-paths-or-env-variables-81325ce1</loc>
    <lastmod>2026-07-30T05:04:37.978Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-chcp-console-command-used-for-code-page-locale-lookup-discovery-7090adee</loc>
    <lastmod>2026-07-31T13:26:24.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-reset-computermachinepassword-computer-account-password-chang-e3818659</loc>
    <lastmod>2026-07-31T13:17:08.958Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-tor-or-tor-browser-process-execution-via-tor-and-tor-browser-binaries-62f7c9bf</loc>
    <lastmod>2026-07-31T13:25:43.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-detect-dns-queries-for-onion-and-tor-gateway-proxy-domains-b55ca2a3</loc>
    <lastmod>2026-07-31T13:00:48.464Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-client-query-for-tor-onion-or-tor2web-hidden-service-domains-8384bd26</loc>
    <lastmod>2026-07-31T12:49:26.276Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-configuration-changed-event-ids-2002-2003-2008-2082-2083-00bb5bd5</loc>
    <lastmod>2026-07-31T12:49:52.725Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-firewall-reset-to-default-configuration-firewall-as-log-04b60639</loc>
    <lastmod>2026-07-31T12:49:50.752Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-service-failed-to-load-group-policy-event-id-2009-7ec15688</loc>
    <lastmod>2026-07-31T12:49:49.206Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-exception-rule-deletion-eventid-2006-2052-c187c075</loc>
    <lastmod>2026-07-31T12:49:47.595Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-exception-rule-added-unusual-via-firewall-as-events-cde0a575</loc>
    <lastmod>2026-07-31T12:49:39.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-exception-rule-modified-event-ids-2005-2073-5570c4d9</loc>
    <lastmod>2026-07-31T12:19:03.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wlrmdr-exe-with-u-flag-or-uncommon-child-process-execut-9cfc00b6</loc>
    <lastmod>2026-07-30T05:14:33.553Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-dosfuscation-obfuscation-indicators-a77c1610</loc>
    <lastmod>2026-07-31T13:26:54.876Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-executing-registered-com-local-servers-via-command-line-f1edd233</loc>
    <lastmod>2026-07-30T05:03:22.099Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-screenconnect-service-execution-57bff678</loc>
    <lastmod>2026-07-30T05:01:37.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-matching-goto-opener-logmein-for-remote-access-tooling-b6d98a4f</loc>
    <lastmod>2026-07-30T05:01:24.603Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-adds-windows-defender-exclusion-paths-via-registry-value-update-48917adc</loc>
    <lastmod>2026-07-30T04:59:28.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-esentutl-exe-usage-to-collect-browser-cache-data-6a69f62d</loc>
    <lastmod>2026-07-31T13:30:12.183Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/screenconnect-temporary-installation-artefact-creation-windows-file-events-fec96f39</loc>
    <lastmod>2026-07-31T13:06:01.015Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gotoassist-temporary-installation-artefact-file-creation-windows-5d756aee</loc>
    <lastmod>2026-07-31T13:03:09.295Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-creates-registry-backed-base64-powershell-payload-via-encoded-c-c4eeeeae</loc>
    <lastmod>2026-07-30T05:04:53.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-used-to-modify-rdp-terminal-server-registry-values-0d5675be</loc>
    <lastmod>2026-07-30T05:00:02.675Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-directorysearcher-active-directory-enumeration-via-directoryservices-1f6399cf</loc>
    <lastmod>2026-07-31T13:17:59.390Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-zerologon-poc-execution-via-cmd-exe-launching-cool-exe-or-zero-exe-dcc6a01e</loc>
    <lastmod>2026-07-31T12:03:09.359Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-flag-suspicious-program-names-and-powershell-script-ind-efdd8dd5</loc>
    <lastmod>2026-07-30T05:08:34.222Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-logmein-lmiguardiansvc-execution-associated-with-remote-access-tools-d85873ef</loc>
    <lastmod>2026-07-30T05:01:26.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/anydesk-executable-execution-on-windows-b52e84a3</loc>
    <lastmod>2026-07-30T05:01:16.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-potential-local-sam-database-export-artifact-4e87b8e2</loc>
    <lastmod>2026-07-31T13:06:07.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-recent-items-shows-iso-img-vhd-image-mount-shortcut-lnk-usage-4358e5a5</loc>
    <lastmod>2026-07-31T13:03:52.744Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/anydesk-temporary-artefact-file-writes-on-windows-0b9ad457</loc>
    <lastmod>2026-07-31T13:02:14.350Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-bpftrace-commandline-use-of-unsafe-option-f8341cb2</loc>
    <lastmod>2026-07-31T12:38:15.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-trolleyexpress-exe-path-used-to-dump-lsass-memory-4c0aaedc</loc>
    <lastmod>2026-07-31T13:26:30.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-memory-access-from-specific-process-images-4be8b654</loc>
    <lastmod>2026-07-31T13:23:46.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-memory-access-triggered-by-process-name-containing-dump-9bd012ee</loc>
    <lastmod>2026-07-31T13:23:32.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-script-interpreter-execution-from-suspicious-folders-via-command-line-fl-1228c958</loc>
    <lastmod>2026-07-30T05:08:54.299Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-ediscovery-pst-export-alert-securitycompliancecenter-success-event-18b88d08</loc>
    <lastmod>2026-07-31T12:34:02.090Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/exchange-added-federated-domain-successfully-via-add-federateddomain-42127bdd</loc>
    <lastmod>2026-07-31T12:33:38.976Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-successful-disable-strong-authentication-mfa-user-action-7ea78478</loc>
    <lastmod>2026-07-31T12:30:45.026Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-network-recon-via-nslookup-ldap-srv-query-e6313acd</loc>
    <lastmod>2026-07-30T04:53:11.060Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-scheduled-task-persistence-via-schtasks-create-and-vbsc-e1118a8f</loc>
    <lastmod>2026-07-31T12:08:56.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-cmd-exe-launching-with-powershell-in-lnk-link-command-30e92f50</loc>
    <lastmod>2026-07-30T05:07:10.885Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-suspicious-get-adreplaccount-enumeration-with-all-and-server--060c3ef1</loc>
    <lastmod>2026-07-31T13:18:35.058Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-servicedll-hijack-via-service-parameters-servicedll-612e47e9</loc>
    <lastmod>2026-07-30T05:22:10.760Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-attrib-exe-run-with-s-flag-to-mark-files-as-system-files-bb19e94c</loc>
    <lastmod>2026-07-31T12:21:23.361Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-creation-of-systemd-unit-files-in-system-user-directories-1bac86ba</loc>
    <lastmod>2026-07-31T12:36:28.071Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ntlm-brute-force-via-common-spoofed-workstationname-values-9c8acf1a</loc>
    <lastmod>2026-07-31T12:50:20.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-unblock-file-attempts-to-remove-zone-identifier-ads-5947497f</loc>
    <lastmod>2026-07-31T13:22:16.986Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-mount-diskimage-using-imagepath-parameter-windows-29e1c216</loc>
    <lastmod>2026-07-31T13:21:50.243Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invoke-item-after-mount-diskimage-from-mounted-drive-lette-902cedee</loc>
    <lastmod>2026-07-31T13:20:24.038Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-takeown-exe-recursive-ownership-change-554601fb</loc>
    <lastmod>2026-07-30T05:10:57.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-access-to-browser-credential-database-files-fc028194</loc>
    <lastmod>2026-07-31T13:17:18.411Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-teamviewer-remote-session-log-file-creation-vprint-db-and-tvnetwork-log-162ab1e4</loc>
    <lastmod>2026-07-31T13:07:16.987Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-teamviewer-domain-queried-by-non-teamviewer-named-process-778ba9a8</loc>
    <lastmod>2026-07-31T13:00:46.390Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-application-uninstall-via-wmic-exe-wmic-call-uninstall-b53317a0</loc>
    <lastmod>2026-07-30T05:15:21.479Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-whoami-exe-executed-by-privileged-accounts-79ce34ca</loc>
    <lastmod>2026-07-30T05:13:41.144Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-xordump-lsass-memory-dump-via-specific-command-line-switches-66e563f9</loc>
    <lastmod>2026-07-31T13:34:52.110Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-teamviewer-desktop-exe-during-installation-9711de76</loc>
    <lastmod>2026-07-31T13:03:46.915Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-installer-application-removal-msiinstaller-event-1034-11724-570ae5ec</loc>
    <lastmod>2026-07-31T12:47:37.616Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auth-logs-keyword-match-for-pwnkit-cve-2021-4034-pkexec-exploitation-indic-0506a799</loc>
    <lastmod>2026-07-31T12:05:37.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-hollowing-suspected-via-replaced-in-memory-image-c4b890e5</loc>
    <lastmod>2026-07-30T05:16:00.671Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lolbin-execution-from-abnormal-drive-calc-certutil-mshta-regsvr32-rundll-d4ca7c59</loc>
    <lastmod>2026-07-30T05:07:54.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-runxcmd-command-line-execution-with-system-or-trustedinstaller-accounts-93199800</loc>
    <lastmod>2026-07-30T04:58:38.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-nsudo-nsudo-exe-nsudolc-nsudolg-771d1eb5</loc>
    <lastmod>2026-07-30T04:58:24.941Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-nircmd-runassystem-commandline-usage-d9047477</loc>
    <lastmod>2026-07-30T04:58:19.627Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-nircmd-command-execution-4e2ed651</loc>
    <lastmod>2026-07-30T04:58:17.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/blackbyte-ransomware-registry-modifications-on-windows-83314318</loc>
    <lastmod>2026-07-31T12:06:42.874Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-installutil-exe-execution-missing-logfile-parameter-d042284c</loc>
    <lastmod>2026-07-31T13:35:39.677Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-testing-for-uncommon-network-ports-via-test-netconnection-adf876b3</loc>
    <lastmod>2026-07-31T13:22:35.289Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-uses-sslstream-with-client-authentication-and-cert-val-195626f3</loc>
    <lastmod>2026-07-31T13:22:13.504Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-webrequest-user-agent-modification-d4488827</loc>
    <lastmod>2026-07-31T13:21:39.470Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-macro-file-creation-triggered-by-script-execution-binaries-b1c50487</loc>
    <lastmod>2026-07-31T13:04:53.979Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-macro-file-creation-via-browser-or-email-client-0e29e3a7</loc>
    <lastmod>2026-07-31T13:04:51.977Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-macro-file-creation-docm-xlsm-pptm-by-microsoft-office-executable-91174a41</loc>
    <lastmod>2026-07-31T13:04:49.041Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-execution-using-custom-user-agent-option-3286d37a</loc>
    <lastmod>2026-07-31T12:21:40.039Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-internet-settings-zone-and-cache-related-key-modifications-d88d0ab2</loc>
    <lastmod>2026-07-30T05:21:12.784Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-to-hide-file-extensions-via-explorer-advanced-keys-5df86130</loc>
    <lastmod>2026-07-30T05:19:49.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-ie-zonemap-domain-zone-change-via-zonemap-domains-45e112d0</loc>
    <lastmod>2026-07-30T05:18:17.760Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/radmin-viewer-utility-execution-on-windows-process-creation-5817e76f</loc>
    <lastmod>2026-07-30T04:58:31.828Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/imewdbld-exe-initiated-network-connections-on-windows-8d7e392e</loc>
    <lastmod>2026-07-31T13:13:42.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-service-stop-firewalld-iptables-or-ufw-firewall-disabled-53059bc0</loc>
    <lastmod>2026-07-31T12:36:32.319Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-colorcpl-exe-file-creation-targeting-system32-spool-drivers-p-e15b518d</loc>
    <lastmod>2026-07-31T13:06:22.382Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4769-kerberoasting-precursor-query-rc4-tgt-service-requests-d04ae2b8</loc>
    <lastmod>2026-07-31T12:53:02.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-advancedrun-executed-with-runas-ids-under-high-privilege-service-account-fa00b701</loc>
    <lastmod>2026-07-30T04:57:49.645Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pua-advancedrun-exe-execution-d2b749ee</loc>
    <lastmod>2026-07-30T04:57:47.970Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-operational-logs-file-load-rejected-for-unsatisfied-signi-f8931561</loc>
    <lastmod>2026-07-31T12:48:52.638Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-doas-tool-execution-process-creation-067d8238</loc>
    <lastmod>2026-07-31T12:38:52.366Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-doas-conf-file-creation-00eee2a5</loc>
    <lastmod>2026-07-31T12:37:30.647Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-abuse-via-system-xml-xmldocument-load-6c6c6282</loc>
    <lastmod>2026-07-31T13:23:10.897Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-msxml2-xmlhttp-via-com-object-creation-78aa1347</loc>
    <lastmod>2026-07-31T13:19:40.065Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-administrative-share-creation-via-lanmanserver-paramete-c7dcacd0</loc>
    <lastmod>2026-07-30T05:18:51.494Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msiexec-exe-quiet-msi-installation-with-installer-arguments-79a87aa6</loc>
    <lastmod>2026-07-30T04:51:44.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-msiexec-exe-command-line-writes-install-logs-with-y-6f4191bb</loc>
    <lastmod>2026-07-30T04:51:42.160Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dism-disable-feature-online-execution-dismhost-dism-exe-43e32da2</loc>
    <lastmod>2026-07-31T13:29:26.259Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblocklogging-disable-lower-windows-defender-monitoring-via-set--14c71865</loc>
    <lastmod>2026-07-31T13:22:33.518Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-teamviewer-log-file-deletion-b1decb61</loc>
    <lastmod>2026-07-31T13:01:57.884Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msiexec-exe-initiated-outbound-http-s-connection-on-ports-80-443-8e5e38e4</loc>
    <lastmod>2026-07-31T12:20:21.533Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rmdir-command-execution-for-directory-removal-41ca393d</loc>
    <lastmod>2026-07-31T13:27:20.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-deletion-using-cmd-exe-del-erase-commands-379fa130</loc>
    <lastmod>2026-07-31T13:26:49.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-start-process-with-passthru-and-filepath-in-scriptblock-logging-windo-0718cd72</loc>
    <lastmod>2026-07-31T13:22:15.373Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-remove-item-used-to-delete-files-or-folders-b8af5f36</loc>
    <lastmod>2026-07-31T12:21:04.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-vmware-horizon-tomcat-service-spawning-cmd-exe-or-power-3eb91f0a</loc>
    <lastmod>2026-07-31T12:06:24.705Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-execution-with-uncommon-dll-cpl-inf-extension-in-command-line-c3a99af4</loc>
    <lastmod>2026-07-30T05:03:51.252Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-configuration-change-event-id-16-8ac03a65</loc>
    <lastmod>2026-07-30T05:23:26.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-event-for-sysmon-uninstall-using-sysmon-u-6a5f68d1</loc>
    <lastmod>2026-07-30T05:10:46.345Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-creates-volume-shadow-copy-via-win32-shadowcopy-class-afd12fed</loc>
    <lastmod>2026-07-31T13:17:55.445Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-procdump-renamed-copied-or-moved-for-stealth-evasion-79b06761</loc>
    <lastmod>2026-07-30T05:10:23.119Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-downloads-remote-dlls-via-http-https-ip-in-i-parameter-2dd2c217</loc>
    <lastmod>2026-07-30T05:01:00.026Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-microsoft-nodejstools-pressanykey-exe-child-spawns-a20391f8</loc>
    <lastmod>2026-07-30T04:57:10.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mpiexec-exe-lolbin-usage-with-n-1-n-1-flag-combination-729ce0ea</loc>
    <lastmod>2026-07-31T13:36:44.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-devinit-exe-msi-download-flag-abuse-90d50722</loc>
    <lastmod>2026-07-31T13:29:10.901Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-browser-process-file-download-via-inline-url-and-suspicious-extension-94771a71</loc>
    <lastmod>2026-07-31T13:25:38.352Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-ntds-dit-by-uncommon-or-suspicious-processes-11b1ed55</loc>
    <lastmod>2026-07-31T13:04:43.505Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wscript-cscript-script-file-dropper-via-file-write-to-scripting-extensio-002bdb95</loc>
    <lastmod>2026-07-31T13:02:48.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-chromeloader-execution-via-scheduled-task-and-chrome-extension-loading-0a74c5a9</loc>
    <lastmod>2026-07-31T12:08:34.814Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-microsoft-defender-firewall-by-setting-enablefirewall-t-974515da</loc>
    <lastmod>2026-07-30T05:18:55.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-enables-defender-firewall-group-rules-via-advfirewall-set-rule-gro-347906f3</loc>
    <lastmod>2026-07-30T04:52:46.160Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-http-logging-disabled-via-appcmd-exe-e4ed6030</loc>
    <lastmod>2026-07-31T13:35:17.715Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dynamic-c-compilation-creates-cmdline-artefact-e4a74e34</loc>
    <lastmod>2026-07-31T13:02:52.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-mstsc-exe-remote-desktop-connection-via-v-flag-954f0af7</loc>
    <lastmod>2026-07-30T04:52:06.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-evil-winrm-ruby-process-parameters-for-winrm-login-a197e378</loc>
    <lastmod>2026-07-31T13:32:31.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-uses-invoke-webrequest-with-post-or-put-to-upload-data-d2e3f2f6</loc>
    <lastmod>2026-07-31T13:20:25.748Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-dnsexfiltrator-via-invoke-dnsexfiltrator-with-doh-exfil-parameters-d59d7842</loc>
    <lastmod>2026-07-31T13:18:58.788Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-invoke-command-for-remote-host-execution-via-script-block-log-7b836d7f</loc>
    <lastmod>2026-07-31T13:18:56.979Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-enable-psremoting-command-execution-991a9744</loc>
    <lastmod>2026-07-31T13:18:14.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-outbound-smtp-connections-on-ports-25-465-587-2525-9976fa64</loc>
    <lastmod>2026-07-31T13:14:24.441Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-detect-windir-environment-key-changes-for-silentcleanup-uac-byp-724ea201</loc>
    <lastmod>2026-07-30T05:18:14.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-dumpstack-log-used-to-evade-microsoft-defender-4f647cfa</loc>
    <lastmod>2026-07-30T05:07:02.043Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-acccheckconsole-execution-with-injection-capable-command-line-parameters-0f6da907</loc>
    <lastmod>2026-07-31T13:24:07.061Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-new-pssession-remote-session-creation-a0edd39f</loc>
    <lastmod>2026-07-31T13:20:14.420Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-user-account-control-by-setting-enablelua-to-0-48437c39</loc>
    <lastmod>2026-07-30T05:23:06.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/registry-modification-for-uac-bypass-via-event-viewer-command-handler-windows-674202d0</loc>
    <lastmod>2026-07-30T05:18:12.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-detect-delegateexecute-uac-bypass-via-targetobject-path-46dd5308</loc>
    <lastmod>2026-07-30T05:18:11.001Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-pypykatz-live-registry-credential-dumping-a29808fd</loc>
    <lastmod>2026-07-31T13:33:47.403Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrar-compression-of-dmp-dump-files-via-command-line-1ac14d38</loc>
    <lastmod>2026-07-30T05:14:16.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-format-com-invoked-with-uncommon-fs-filesystem-parameter-9fb6b26e</loc>
    <lastmod>2026-07-31T13:30:55.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-createdump-exe-used-to-dump-process-memory-515c8be5</loc>
    <lastmod>2026-07-31T13:28:14.398Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-headless-chromium-file-download-via-dump-dom-in-browser-brave-chrome-edg-0e8cfe08</loc>
    <lastmod>2026-07-31T13:25:31.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-execution-of-gathernetworkinfo-vbs-via-cscript-exe-or-wscript-exe-575dce0c</loc>
    <lastmod>2026-07-31T13:36:32.172Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-execution-with-base64-encoded-command-windows-fb843269</loc>
    <lastmod>2026-07-30T04:55:27.696Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-starts-processes-using-batch-script-bat-cmd-on-windows-b5522a23</loc>
    <lastmod>2026-07-31T13:21:03.195Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-deletion-of-backup-file-extensions-via-command-line-binaries-06125661</loc>
    <lastmod>2026-07-31T13:01:40.338Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-rdp-portnumber-changed-from-default-3389-509e84b9</loc>
    <lastmod>2026-07-30T05:18:16.064Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-process-flag-execution-indicating-process-reconnaissance-221b251a</loc>
    <lastmod>2026-07-30T05:14:52.663Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-systeminfo-exe-execution-0ef56343</loc>
    <lastmod>2026-07-30T05:10:51.739Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-shutdown-or-reboot-via-shutdown-exe-command-line-34ebb878</loc>
    <lastmod>2026-07-30T05:05:27.460Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-reg-exe-query-for-machineguid-f5240972</loc>
    <lastmod>2026-07-30T04:59:55.786Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-adidnsdump-execution-via-python-exe-26d3f0a2</loc>
    <lastmod>2026-07-30T04:58:52.940Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-hostname-exe-run-matching-7be5fb68</loc>
    <lastmod>2026-07-31T13:34:57.393Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharphound-discovery-via-rpc-firewall-opnum-12-sessions-6d580420</loc>
    <lastmod>2026-07-31T12:26:36.030Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharphound-account-discovery-via-rpc-firewall-blocking-opnum-2-interface-uuid-ma-65f77b1e</loc>
    <lastmod>2026-07-31T12:26:33.936Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-sasec-scheduled-task-reconnaissance-opnum-0-1-via-ms-tsch-0a3ff354</loc>
    <lastmod>2026-07-31T12:26:31.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rpc-firewall-alerts-on-remote-scheduled-task-creation-or-execution-via-s-aff229ab</loc>
    <lastmod>2026-07-31T12:26:30.127Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-remote-efsr-encryption-service-calls-for-lateral-movement-10018e73</loc>
    <lastmod>2026-07-31T12:26:28.339Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-rpcfw-eventid-3-ms-srvs-interfaceuuid-abuse-indicators-b6ea3cc7</loc>
    <lastmod>2026-07-31T12:26:26.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-registry-remote-recon-via-rrp-interface-uuid-d8ffe17e</loc>
    <lastmod>2026-07-31T12:26:24.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-detects-remote-registry-modification-via-microsoft-rrp-interface-ca-35c55673</loc>
    <lastmod>2026-07-31T12:26:22.964Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detect-remote-dcom-wmi-rpc-connections-via-rpc-firewall-event-id-3-68050b10</loc>
    <lastmod>2026-07-31T12:26:21.061Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-rpc-firewall-remote-printing-rpc-interface-calls-bc3a4b0c</loc>
    <lastmod>2026-07-31T12:26:18.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-rpc-scheduled-task-recon-via-itaskschedulerservice-7f7c49eb</loc>
    <lastmod>2026-07-31T12:26:14.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-task-scheduler-lateral-movement-via-itaskschedulerservice-rpc-ace3ff54</loc>
    <lastmod>2026-07-31T12:26:12.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-detects-remote-windows-event-log-recon-via-even-even6-eventid-3-2053961f</loc>
    <lastmod>2026-07-31T12:26:09.679Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-detection-for-remote-ms-efsr-encrypting-file-system-abuse-5f92fff9</loc>
    <lastmod>2026-07-31T12:26:07.889Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-ms-drsr-opcode-detections-from-non-domain-controllers-56fda488</loc>
    <lastmod>2026-07-31T12:26:06.411Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-detects-remote-scheduled-task-reconnaissance-via-atscv-f177f2bc</loc>
    <lastmod>2026-07-31T12:26:04.595Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-atsvc-remote-schedule-task-execution-opnum-0-1-detection-0fcd1c79</loc>
    <lastmod>2026-07-31T12:26:02.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winlogon-notify-registry-key-dll-persistence-logon-bbf59793</loc>
    <lastmod>2026-07-30T05:23:25.102Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modification-of-application-shim-database-installedsdb-custom-f-dfb5b4e8</loc>
    <lastmod>2026-07-30T05:21:32.522Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-add-print-port-monitor-dll-persistence-944e8941</loc>
    <lastmod>2026-07-30T05:17:31.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-modifies-service-imagepath-in-hklm-system-currentcontrolset-serv-9b0b7ac3</loc>
    <lastmod>2026-07-30T05:00:05.966Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-block-monitoring-for-service-registry-permission-weakness-chec-95afc12e</loc>
    <lastmod>2026-07-31T13:18:30.127Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-registry-free-cor-profiler-environment-variable--23590215</loc>
    <lastmod>2026-07-31T13:17:50.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-executing-program-exe-via-unquoted-file-path-8c3c76ca</loc>
    <lastmod>2026-07-31T13:02:44.632Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-scr-screensaver-binary-file-creation-97aa2e88</loc>
    <lastmod>2026-07-31T13:02:38.537Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-new-custom-apppatch-shim-database-files-created-ee63c85c</loc>
    <lastmod>2026-07-31T13:02:36.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-changes-to-outlook-security-settings-c3cefdf4</loc>
    <lastmod>2026-07-30T05:20:42.569Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-startup-chrome-vpn-extensions-installed-via-extension-registry--b64a026b</loc>
    <lastmod>2026-07-30T05:18:22.753Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-kernel-dump-via-dtrace-exe-lkd-process-creation-7124aebe</loc>
    <lastmod>2026-07-31T13:29:57.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-kerberos-ticket-requests-via-system-identitymodel-tokens--a861d835</loc>
    <lastmod>2026-07-31T13:20:18.397Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-invokes-office-registerxll-via-com-automation-36fbec91</loc>
    <lastmod>2026-07-31T13:19:52.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-local-user-account-manipulation-via-scriptblock-logging-on-windows-4fdc44df</loc>
    <lastmod>2026-07-31T13:19:23.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-ad-account-management-net-usage-for-group-computer-principal--b29a93fb</loc>
    <lastmod>2026-07-31T13:18:01.253Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scheduled-task-creation-via-scheduledtasks-cmdlets-and-cim-wmi-calls--363eccc0</loc>
    <lastmod>2026-07-31T13:17:44.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-screen-capture-via-copyfromscreen-d4a11f63</loc>
    <lastmod>2026-07-31T13:17:38.499Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-downloads-from-outlook-onenote-attachment-domains-via-co-00d49ed5</loc>
    <lastmod>2026-07-30T05:07:00.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hashcat-exe-password-cracking-execution-via-registry-sourced-sam-39b31e81</loc>
    <lastmod>2026-07-31T13:32:40.559Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-findstr-searches-for-gpp-cpassword-in-sysvol-xml-91a2c315</loc>
    <lastmod>2026-07-31T13:30:28.229Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-suspicious-ldap-credential-handling-for-remote-access-1883444f</loc>
    <lastmod>2026-07-31T13:21:53.827Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-copies-or-installs-dlls-into-windows-system32-or-syswow64-63bf8794</loc>
    <lastmod>2026-07-31T13:17:48.350Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-disable-used-to-disable-security-critical-scheduled-tasks-9ac94dc8</loc>
    <lastmod>2026-07-30T05:04:36.285Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cipher-exe-overwrite-deleted-data-using-w-4b046706</loc>
    <lastmod>2026-07-31T13:26:28.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-wallpaper-replacement-via-control-panel-desktop-registry-upda-c5ac6a1e</loc>
    <lastmod>2026-07-31T13:22:18.821Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-remove-adgroupmember-removing-account-from-domain-admin-group-48a45d45</loc>
    <lastmod>2026-07-31T13:22:01.287Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-termination-using-taskkill-exe-86085955</loc>
    <lastmod>2026-07-31T12:23:20.966Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-txt-creation-in-user-desktop-via-cmd-exe-caf02a0a</loc>
    <lastmod>2026-07-31T12:19:40.358Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-keytool-exe-spawns-suspicious-command-line-shell-processes-90fb5e62</loc>
    <lastmod>2026-07-31T13:35:41.471Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-computer-account-renamed-to-missing-suffix-45eb2ae2</loc>
    <lastmod>2026-07-31T12:06:08.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-requests-for-class-uri-extensions-53c15703</loc>
    <lastmod>2026-07-31T12:18:59.106Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-sysinternals-tool-name-impersonation-by-executab-7cce6fc8</loc>
    <lastmod>2026-07-30T05:10:48.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-process-creation-as-system-user-with-likely-credential-defens-2617e7ed</loc>
    <lastmod>2026-07-30T05:09:14.884Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-and-powershell-modification-of-ms-settings-protocol-handler-dd3ee8cc</loc>
    <lastmod>2026-07-30T05:08:48.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sqlcmd-exe-credential-dump-query-against-veeambackup-dbo-b57ba453</loc>
    <lastmod>2026-07-30T05:05:47.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-sc-exe-service-creation-with-dacl-modification-sdset-dclcwpdtsd-a537cfc3</loc>
    <lastmod>2026-07-30T05:04:14.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-credential-enumeration-via-registry-query-hklm-hkcu-e0b0c2ab</loc>
    <lastmod>2026-07-30T04:59:50.945Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-enumerates-stored-windows-credential-manager-entries-via-vaultcmd-lis-603c6630</loc>
    <lastmod>2026-07-31T13:18:19.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-credential-manager-credential-dumping-via-get-passwordvaultcredential-99c49d9c</loc>
    <lastmod>2026-07-31T13:18:12.127Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-block-information-discovery-via-recursive-listing-and-credenti-bd5971a7</loc>
    <lastmod>2026-07-31T13:21:05.113Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-psloglist-with-event-log-dump-export-flags-aae1243f</loc>
    <lastmod>2026-07-30T05:10:34.471Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cleanwipe-like-pua-execution-via-system-tool-uninstall-switches-f44800ac</loc>
    <lastmod>2026-07-30T04:57:53.434Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-advanced-port-scanner-pua-execution-via-portable-lng-54773c5f</loc>
    <lastmod>2026-07-30T04:57:46.364Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-audit-policy-tampering-using-auditpol-from-nt-resource-kit-c6c56ada</loc>
    <lastmod>2026-07-31T13:24:49.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-java-exe-spawning-command-shell-processes-dff1e1cc</loc>
    <lastmod>2026-07-31T13:35:49.256Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-suspicious-child-processes-spawned-by-java-exe-0d34ed8b</loc>
    <lastmod>2026-07-31T13:35:47.592Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-findstr-exe-used-with-argument-385201-sysmon-default-dr-37db85d1</loc>
    <lastmod>2026-07-31T13:30:44.151Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-security-software-discovery-via-get-process-piped-to-where-object-on--904e8e61</loc>
    <lastmod>2026-07-31T13:18:39.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-containing-get-smbshare-95f0643a</loc>
    <lastmod>2026-07-31T13:22:11.938Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-enumeration-of-ad-group-membership-and-users-88f0884b</loc>
    <lastmod>2026-07-31T13:20:51.519Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-module-get-smbshare-used-for-smb-share-enumeration-6942bd25</loc>
    <lastmod>2026-07-31T13:17:10.603Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-ad-enumeration-via-poshmodule-get-adprincipalgroupmembership-and-get--815bfc17</loc>
    <lastmod>2026-07-31T13:16:58.607Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-directory-services-sam-account-name-validation-failures-indicative-of-cv-e80a0fee</loc>
    <lastmod>2026-07-31T12:06:15.253Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kerberos-kdc-pac-requestor-anomaly-cve-2021-42278-exploitation-attempts-44bbff3e</loc>
    <lastmod>2026-07-31T12:06:06.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-where-exe-with-browser-bookmark-database-or-history-725a9768</loc>
    <lastmod>2026-07-30T05:13:37.988Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-delete-backup-or-system-state-backups-via-wbadmin-exe-89f75308</loc>
    <lastmod>2026-07-30T05:12:49.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wbadmin-exe-deletes-all-backup-copies-keepversions-0-639c9081</loc>
    <lastmod>2026-07-30T05:12:47.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pua-suspicious-active-directory-enumeration-using-adfind-exe-flags-455b9d50</loc>
    <lastmod>2026-07-30T04:57:39.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-dir-enumeration-using-s-subdirectory-flag-7c9340a9</loc>
    <lastmod>2026-07-31T13:26:53.288Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-block-get-childitem-recursive-bookmark-collection-from-browser-e0565f5d</loc>
    <lastmod>2026-07-31T13:18:36.911Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-discovery-via-wmic-exe-group-flag-164eda96</loc>
    <lastmod>2026-07-30T05:14:49.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-suspicious-local-group-discovery-via-get-localgroup-and-get-localgrou-fa6a5a45</loc>
    <lastmod>2026-07-31T13:21:46.874Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-discovery-of-local-groups-via-get-localgroup-and-get-localgroupmember-cef24b90</loc>
    <lastmod>2026-07-31T13:17:07.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detection-for-jndi-exploit-kit-exploit-and-memshell-url-path-patterns-412d55bc</loc>
    <lastmod>2026-07-31T12:47:03.733Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-tasklist-exe-process-discovery-via-command-line-63332011</loc>
    <lastmod>2026-07-31T12:23:22.761Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-nmap-zenmap-nmap-exe-or-zennmap-exe-execution-f6ecd1cf</loc>
    <lastmod>2026-07-30T04:58:21.620Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-net-exe-network-connections-discovery-via-use-sessions-query-1c67a717</loc>
    <lastmod>2026-07-30T04:52:27.240Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sharpview-exe-recon-and-discovery-commands-execution-b2317cfa</loc>
    <lastmod>2026-07-31T13:34:23.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-get-nettcpconnection-module-use-for-network-connection-discovery-wind-aff815cc</loc>
    <lastmod>2026-07-31T13:17:01.924Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-get-nettcpconnection-invocation-for-network-connection-discov-b366adb4</loc>
    <lastmod>2026-07-31T13:15:32.260Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-dev-tcp-shell-redirection-and-file-descriptor-usage-6cc5fceb</loc>
    <lastmod>2026-07-31T12:37:18.720Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-log-detection-of-log4j-cve-2021-44228-jndi-strings-in-user-agent-uri-q-9be472ed</loc>
    <lastmod>2026-07-31T12:06:28.787Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detections-for-log4shell-cve-2021-44228-jndi-injection-exploit-strings-5ea8faa8</loc>
    <lastmod>2026-07-31T12:06:26.622Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-executable-image-extension-c09dad97</loc>
    <lastmod>2026-07-30T05:08:06.009Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-executable-image-missing-absolute-path-possible-process-71158e3f</loc>
    <lastmod>2026-07-30T05:07:41.822Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/grafana-webserver-path-traversal-exploitation-cve-2021-43798-via-uri-query-7b72b328</loc>
    <lastmod>2026-07-31T12:06:20.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-network-configuration-and-discovery-commands-a29c1813</loc>
    <lastmod>2026-07-30T05:07:59.525Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-exe-firewall-configuration-discovery-show-firewall-rule-state-name-0e4164da</loc>
    <lastmod>2026-07-30T04:52:48.472Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-command-line-uses-dinjector-am51-and-password-flags-on-windows-d78b5d61</loc>
    <lastmod>2026-07-31T13:32:17.058Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-writes-indicating-interactive-powershell-history-as-system-5b40a734</loc>
    <lastmod>2026-07-31T13:07:13.259Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-user-added-to-local-remote-desktop-users-group-via-net-or-powershell-ffa28e60</loc>
    <lastmod>2026-07-30T05:06:12.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-api-mega-co-nz-or-mega-nz-fdeebdf0</loc>
    <lastmod>2026-07-31T13:13:25.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-5145-remote-writes-to-desktop-ini-via-unc-share-35bc7e28</loc>
    <lastmod>2026-07-31T12:53:42.234Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sc-exe-service-query-execution-via-command-line-57712d7a</loc>
    <lastmod>2026-07-31T12:22:54.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-log-windows-update-client-errors-installation-connection-revert-13cfeb75</loc>
    <lastmod>2026-07-31T12:57:01.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-containing-whoami-as-first-parameter-e9142d84</loc>
    <lastmod>2026-07-30T05:09:56.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-exe-executed-with-suspicious-file-extension-masquerading-as-dll-089fc3d2</loc>
    <lastmod>2026-07-30T05:01:10.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-writes-to-nppspy-txt-or-nppspy-dll-indicates-hacktool-credential-du-cad1fe90</loc>
    <lastmod>2026-07-31T13:03:33.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-getcap-scans-for-capability-files-on-the-root-path-fe10751f</loc>
    <lastmod>2026-07-31T12:35:07.106Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-process-clone-execution-observed-c8da0dfd</loc>
    <lastmod>2026-07-30T04:50:55.276Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-to-lsass-from-suspicious-source-folders-fa34b441</loc>
    <lastmod>2026-07-31T12:21:15.985Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-extrac32-exe-execution-with-alternate-data-stream-targeting-4b13db67</loc>
    <lastmod>2026-07-31T13:36:30.321Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-diantz-alternate-data-stream-ads-cab-execution-via-command-line-6b369ced</loc>
    <lastmod>2026-07-31T13:36:25.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspected-defender-av-bypass-by-renaming-dump64-exe-in--129966c9</loc>
    <lastmod>2026-07-31T13:29:59.472Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-configsecuritypolicy-exe-arbitrary-file-transfer-via-ur-1f0f6176</loc>
    <lastmod>2026-07-31T13:27:55.818Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-authentication-interruption-via-device-and-external-security-chall-8366030e</loc>
    <lastmod>2026-07-31T12:32:35.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-auditlogs-permission-elevation-to-user-access-administrator-for-subscripti-ca9bf243</loc>
    <lastmod>2026-07-31T12:31:02.208Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-permission-elevation-to-manage-all-subscriptions-09438caa</loc>
    <lastmod>2026-07-31T12:29:38.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-extexport-exe-execution-indicative-of-dll-sideloading-fb0b815b</loc>
    <lastmod>2026-07-31T12:21:53.068Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-clears-console-history-via-clear-history-or-psreadline-history-path-d-bde47d4b</loc>
    <lastmod>2026-07-31T13:17:42.018Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-kubernetes-admission-webhook-configuration-changes-via-audit-logs-6ad91e31</loc>
    <lastmod>2026-07-31T12:32:54.077Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-kubernetes-admission-webhook-configuration-write-a61a3c56</loc>
    <lastmod>2026-07-31T12:29:09.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-loading-shell32-dll-via-control-rundll-from-user-temp-paths-32b96012</loc>
    <lastmod>2026-07-30T05:03:28.412Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certreq-exe-certreq-post-download-execution-4480827a</loc>
    <lastmod>2026-07-31T13:26:00.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-indirect-execution-of-bash-exe-with-c-flag-5edc2273</loc>
    <lastmod>2026-07-31T13:24:59.364Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-aspnet-compiler-exe-execution-via-net-framework-paths-a01b8329</loc>
    <lastmod>2026-07-31T13:24:33.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appinstaller-exe-dns-queries-during-ms-appinstaller-package-installation-7cff77e1</loc>
    <lastmod>2026-07-31T13:00:12.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexec-paexec-command-line-flags-escalating-to-local-system-8834e2f7</loc>
    <lastmod>2026-07-30T05:10:28.262Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-to-lsass-with-suspicious-grantedaccess-flags-a18dd26b</loc>
    <lastmod>2026-07-31T13:23:42.128Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-detects-kubernetes-cronjob-and-job-creation-requests-cd3a808c</loc>
    <lastmod>2026-07-31T12:32:56.227Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-kubernetes-cronjob-or-job-write-operations-1c71e254</loc>
    <lastmod>2026-07-31T12:29:13.733Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msi-installer-event-logs-for-poc-strings-indicating-cve-2021-41379-explo-7dbb86de</loc>
    <lastmod>2026-07-31T12:06:01.064Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-cve-2021-41379-installerfiletakeover-privilege-escalation-atte-af8bbce4</loc>
    <lastmod>2026-07-31T12:05:59.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-create-msiexec-creating-elevation-service-exe-under-edge-applicatio-3be82d5d</loc>
    <lastmod>2026-07-31T12:05:50.361Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scripting-binaries-writing-files-to-suspicious-directories-1277f594</loc>
    <lastmod>2026-07-31T13:06:11.631Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-command-line-and-image-with-trailing-space-after-filename-b6e2a2e3</loc>
    <lastmod>2026-07-31T12:43:08.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-file-association-via-exefile-handler-classes-exefile-44a22d59</loc>
    <lastmod>2026-07-30T05:19:43.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-wget-exfiltration-via-post-file-command-line-cb39d16b</loc>
    <lastmod>2026-07-31T12:35:20.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msexchange-management-indicators-of-exchange-rce-attempt-for-cve-2021-42-c92f1896</loc>
    <lastmod>2026-07-31T12:06:18.518Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrar-or-rar-utility-execution-from-non-default-installation-paths-4ede543c</loc>
    <lastmod>2026-07-30T05:14:19.830Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-adcs-certificate-template-changes-with-risky-eku-and-enrollee-provided-s-bfbd3291</loc>
    <lastmod>2026-07-31T12:51:18.406Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ad-cs-detect-enrollment-template-using-ct-flag-enrollee-supplies-subject-5ee3a654</loc>
    <lastmod>2026-07-31T12:51:14.113Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sitecore-pre-auth-rce-exploitation-attempts-via-report-ashx-cve-2021-42237-on-we-20c6ed1c</loc>
    <lastmod>2026-07-31T12:06:04.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-file-writes-to-system32-tasks-from-suspicious-paths-80e1f67a</loc>
    <lastmod>2026-07-31T13:07:15.356Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-adds-bitlocker-policy-registry-values-0e0255bf</loc>
    <lastmod>2026-07-30T04:59:19.245Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-memory-dump-file-creation-a5a2d357</loc>
    <lastmod>2026-07-30T04:23:20.611Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-apps-initiating-network-connections-to-external-non-private-ips-75e33ce3</loc>
    <lastmod>2026-07-31T13:13:46.277Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cobalt-strike-style-dns-beaconing-via-sysmon-on-windows-f356a9c4</loc>
    <lastmod>2026-07-31T13:00:31.905Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-file-creation-mimikatz-kirbi-and-mimilsa-log-detection-9e099d99</loc>
    <lastmod>2026-07-31T13:03:29.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-zipexec-style-password-protected-zip-executi-90dcf730</loc>
    <lastmod>2026-07-31T13:34:55.597Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-cscript-wscript-register-app-vbs-com-registration-28c8f68b</loc>
    <lastmod>2026-07-30T04:50:51.551Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmdl32-exe-executed-with-vpn-and-lan-flags-f37aba28</loc>
    <lastmod>2026-07-31T13:27:42.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-kernel-module-load-via-insmod-kmod-106d7cbd</loc>
    <lastmod>2026-07-31T12:36:38.252Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-executionpolicy-set-to-bypass-unrestricted-87e3c4e8</loc>
    <lastmod>2026-07-30T04:56:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-indicators-of-crypto-mining-66c3b204</loc>
    <lastmod>2026-07-30T05:06:51.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-command-line-path-traversal-evasion-strings-1327381e</loc>
    <lastmod>2026-07-30T05:06:41.383Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-known-crypto-mining-pool-hostnames-fa5b1358</loc>
    <lastmod>2026-07-31T13:13:06.574Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-crypto-miner-command-line-indicators-9069ea3c</loc>
    <lastmod>2026-07-31T12:38:41.428Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-network-connections-to-known-monero-mining-pool-hosts-a46c93b7</loc>
    <lastmod>2026-07-31T12:37:47.196Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-browser-processes-creating-vhd-vhdx-files-8468111a</loc>
    <lastmod>2026-07-31T13:08:28.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-creating-startup-shortcut-lnk-files-for-persistence-92fa78e7</loc>
    <lastmod>2026-07-31T13:05:32.252Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-lookups-for-monero-mining-pool-domains-b593fd50</loc>
    <lastmod>2026-07-31T12:44:36.069Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certoc-exe-loads-dll-via-loaddll-argument-242301bc</loc>
    <lastmod>2026-07-31T13:25:56.440Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-via-workfolders-exe-launching-control-exe-0bbc6369</loc>
    <lastmod>2026-07-30T05:09:59.082Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-via-stordiag-exe-launching-schtasks-exe-systeminfo-exe-961e0abb</loc>
    <lastmod>2026-07-30T05:06:03.707Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-suspicious-windowstyle-hidden-usage-in-script-block-text-313fbb0a</loc>
    <lastmod>2026-07-31T13:22:24.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-set-executionpolicy-changed-to-unrestricted-or-bypass-61d0475c</loc>
    <lastmod>2026-07-31T13:20:36.798Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-clearing-rdp-client-connection-history-via-mru-and-server-keys--07bdd2f5</loc>
    <lastmod>2026-07-30T05:16:19.852Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-reverse-shell-via-bin-bash-connecting-to-external-ips-83dcd9f6</loc>
    <lastmod>2026-07-31T12:37:45.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-web-server-process-child-commands-indicative-of-webshell-activity-818f7b24</loc>
    <lastmod>2026-07-31T12:41:40.536Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-dd-file-overwrite-deletion-attempt-via-of-and-dev-zero-dev-null-2953194b</loc>
    <lastmod>2026-07-31T12:38:46.830Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-clipboard-collection-via-xclip-with-select-clip-output-sel-clip-o-ec127035</loc>
    <lastmod>2026-07-31T12:38:34.407Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-syslog-file-clearing-or-removal-via-common-system-utilities-3fcc9b35</loc>
    <lastmod>2026-07-31T12:38:32.748Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-cron-file-creation-in-cron-directories-6c4e2f43</loc>
    <lastmod>2026-07-31T12:37:34.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-cloud-sql-database-or-user-modified-deleted-via-audit-api-f346bbd5</loc>
    <lastmod>2026-07-31T12:33:05.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-windows-firewall-profile-disabled-via-set-netfirewallprofile-488b44e7</loc>
    <lastmod>2026-07-31T13:22:58.215Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/onelogin-user-account-lock-or-suspension-via-api-events-a717c561</loc>
    <lastmod>2026-07-31T12:34:56.039Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/onelogin-events-user-assumed-another-user-account-event-type-id-3-62fff148</loc>
    <lastmod>2026-07-31T12:34:54.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-blocked-by-conditional-access-policy-token-issuance-denied-9a60e676</loc>
    <lastmod>2026-07-31T12:32:37.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-mfa-strong-authentication-failures-strong-auth-interrupted-5496ff55</loc>
    <lastmod>2026-07-31T12:32:34.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-sign-in-attempts-to-disabled-accounts-908655e0</loc>
    <lastmod>2026-07-31T12:32:29.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-detect-account-lockout-after-too-many-failed-password-or-user-2b7d6fc0</loc>
    <lastmod>2026-07-31T12:32:02.427Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-user-registers-new-security-info-authentication-method-change-4d78a000</loc>
    <lastmod>2026-07-31T12:30:32.065Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-processes-using-cpu-priority-command-line-option-071d5e5a</loc>
    <lastmod>2026-07-31T12:35:16.810Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vmtoolsd-exe-child-process-spawn-via-scripting-utility-binaries-5687f942</loc>
    <lastmod>2026-07-30T05:12:23.010Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-to-ad-fs-wid-sql-query-path-by-uncommon-process-1ea13e8c</loc>
    <lastmod>2026-07-31T13:14:38.714Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-indicators-for-netwire-related-keys-1d218616</loc>
    <lastmod>2026-07-31T12:07:17.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/successful-iis-shortname-fuzzing-scans-via-1-and-a-aspx-probe-http-7cb02516</loc>
    <lastmod>2026-07-31T12:47:00.253Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/apache-webserver-path-traversal-attempt-for-cve-2021-41773-patterns-3007fec6</loc>
    <lastmod>2026-07-31T12:06:02.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-user-added-to-administrator-role-ebbeb024</loc>
    <lastmod>2026-07-31T12:29:58.998Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-glue-development-endpoint-management-via-cloudtrail-api-4990c2e3</loc>
    <lastmod>2026-07-31T12:28:16.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-clipboard-image-data-collection-via-xclip-f200dc3f</loc>
    <lastmod>2026-07-31T12:35:14.159Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pnputil-exe-driver-installation-via-inf-on-windows-a2ea3ae7</loc>
    <lastmod>2026-07-31T13:37:29.642Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-data-exfiltration-via-datasvcutil-exe-with-in-out-uri-arguments-e290b10b</loc>
    <lastmod>2026-07-31T13:36:21.957Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-firmwarepasswd-password-manipulation-via-setpasswd-full-delete-check-7ed2c9f7</loc>
    <lastmod>2026-07-31T12:43:28.175Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-prefetch-pf-file-deletion-via-filedelete-0a1f9d29</loc>
    <lastmod>2026-07-31T13:01:51.502Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-foggyweb-backdoor-dll-hijacking-via-loading-version-dll-640dc51c</loc>
    <lastmod>2026-07-31T12:07:04.565Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-path-traversal-exploitation-attempts-via-suspicious-uri-query-encoding-7745c2ea</loc>
    <lastmod>2026-07-31T12:47:05.506Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-memory-dump-using-rdrleakdiag-exe-memdmp-fullmemdmp-edadb1e5</loc>
    <lastmod>2026-07-30T04:59:12.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-xclip-clipboard-collection-via-selection-and-output-option-214e7e6c</loc>
    <lastmod>2026-07-31T12:35:12.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vmware-vcenter-server-file-upload-exploitation-attempt-cve-2021-22005-via-web-po-b014ea07</loc>
    <lastmod>2026-07-31T12:04:49.130Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-detects-lambda-layer-attach-via-updatefunctionconfiguration-97fbabf8</loc>
    <lastmod>2026-07-31T12:28:14.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-suspicious-saml-provider-updates-and-assumerolewithsaml-f43f5d2f</loc>
    <lastmod>2026-07-31T12:28:42.631Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-live-memory-dump-via-get-storagediagnosticinfo-with-includelivedump-w-cd185561</loc>
    <lastmod>2026-07-31T13:19:34.796Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-screen-capture-via-imagemagick-import-tool-outputting-desktop-images-dbe4b9c5</loc>
    <lastmod>2026-07-31T12:35:39.475Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-mfa-factor-deactivation-or-reset-detection-50e068d7</loc>
    <lastmod>2026-07-31T12:34:32.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-cloud-shell-created-via-microsoft-portal-consoles-write-72af37e2</loc>
    <lastmod>2026-07-31T12:29:35.305Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-xwizard-exe-execution-from-non-default-directory-193d5ccd</loc>
    <lastmod>2026-07-30T05:15:57.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/adselfservice-exploitation-attempts-via-suspicious-web-url-paths-cve-2021-40539-6702b13c</loc>
    <lastmod>2026-07-31T12:05:46.238Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-http-post-to-wsman-without-authorization-header-indicates-omigod-rce-attemp-ab6b1a39</loc>
    <lastmod>2026-07-31T12:05:36.009Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-add-dnsclientnrptrule-changes-nrpt-namespace-4368354e</loc>
    <lastmod>2026-07-31T13:17:21.585Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-screen-capture-via-xwd-writing-xwd-output-files-e2f17c5d</loc>
    <lastmod>2026-07-31T12:35:41.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-account-locked-out-after-max-sign-in-attempts-14701da0</loc>
    <lastmod>2026-07-31T12:34:49.360Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-unauthorized-app-access-attempt-via-system-log-display-message-6cc2b61b</loc>
    <lastmod>2026-07-31T12:34:47.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-detects-security-threat-detected-events-from-threat-insight-5c82f0b9</loc>
    <lastmod>2026-07-31T12:34:43.940Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-policy-rule-updated-or-deleted-via-policy-rule-api-events-0c97c1d3</loc>
    <lastmod>2026-07-31T12:34:42.287Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-policy-lifecycle-update-or-deletion-events-1667a172</loc>
    <lastmod>2026-07-31T12:34:40.906Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-network-zone-deactivated-or-deleted-9f308120</loc>
    <lastmod>2026-07-31T12:34:34.892Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-sign-on-policy-update-or-rule-deletion-8f668cc4</loc>
    <lastmod>2026-07-31T12:34:27.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-application-lifecycle-update-or-deletion-7899144b</loc>
    <lastmod>2026-07-31T12:34:25.217Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-detect-api-token-revocation-via-system-api-token-revoke-events-cf1dbc6b</loc>
    <lastmod>2026-07-31T12:34:23.538Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-api-token-creation-via-system-api-token-create-event-19951c21</loc>
    <lastmod>2026-07-31T12:34:21.054Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-administrator-privilege-granted-to-user-or-group-413d4a81</loc>
    <lastmod>2026-07-31T12:34:17.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-steghide-steganography-extraction-via-steghide-extract-targeting-jpg-png-a5a827d9</loc>
    <lastmod>2026-07-31T12:35:44.979Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-detect-steghide-file-embedding-via-embed-command-ce446a9e</loc>
    <lastmod>2026-07-31T12:35:43.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-commands-clearing-or-removing-var-log-syslog-e09eb557</loc>
    <lastmod>2026-07-31T12:37:00.085Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detects-cve-2021-40539-zoho-manageengine-adselfservice-plus-rest-api-auth-bypass-fcbb4a77</loc>
    <lastmod>2026-07-31T12:05:48.319Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winword-creates-inetcache-cab-and-temp-inf-files-60c0a111</loc>
    <lastmod>2026-07-31T12:05:40.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-unzip-extraction-from-jpg-png-files-for-hidden-data-edd595d7</loc>
    <lastmod>2026-07-31T12:35:53.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-cat-command-appends-zip-data-to-jpg-png-45810b50</loc>
    <lastmod>2026-07-31T12:35:31.403Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cve-2021-40444-control-exe-and-office-parent-process-exploitation-attemp-894397c6</loc>
    <lastmod>2026-07-31T12:05:41.853Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-atlassian-confluence-java-spawning-suspicious-child-processes-cve-245f92e3</loc>
    <lastmod>2026-07-31T12:04:54.970Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-privatelog-image-load-svchost-exe-loading-clfsw32-dll-33a2d1dd</loc>
    <lastmod>2026-07-31T12:07:37.728Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-hidden-file-or-directory-creation-via-dot-prefixed-paths-d08722cd</loc>
    <lastmod>2026-07-31T12:35:29.491Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-federation-settings-modified-via-audit-logs-352a54e1</loc>
    <lastmod>2026-07-31T12:30:35.410Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-audio-capture-via-arecord-and-ecasound-memfd-create-a7af2487</loc>
    <lastmod>2026-07-31T12:35:57.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-system-information-discovery-via-auditd-uname-uptime-lsmod-hostname-env-f34047d9</loc>
    <lastmod>2026-07-31T12:36:07.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-service-principal-removal-448fd1ea</loc>
    <lastmod>2026-07-31T12:31:00.294Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-owner-removed-from-application-or-service-principal-636e30d5</loc>
    <lastmod>2026-07-31T12:30:46.897Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-device-no-longer-managed-or-compliant-542b9912</loc>
    <lastmod>2026-07-31T12:30:33.748Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-application-deletion-via-entra-admin-operations-410d2a41</loc>
    <lastmod>2026-07-31T12:30:26.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-log-device-or-device-configuration-modified-or-deleted-46530378</loc>
    <lastmod>2026-07-31T12:28:56.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-stores-command-output-in-alternate-data-streams-via-start-pro-a699b30e</loc>
    <lastmod>2026-07-31T13:20:47.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-suspicious-kerberos-tgt-requests-with-certificate-thumbprints-e-6a53d871</loc>
    <lastmod>2026-07-31T12:53:53.884Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-service-principal-added-via-add-service-principal-operation-0ddcff6d</loc>
    <lastmod>2026-07-31T12:30:58.661Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-network-firewall-policy-modified-or-deleted-via-activity-logs-83c17918</loc>
    <lastmod>2026-07-31T12:29:26.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-event-consumer-with-encoded-payload-containing-suspicious-strings-83844185</loc>
    <lastmod>2026-07-30T05:23:39.876Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-execution-commandlines-involving-ntfs-alternate-data-st-7f43c430</loc>
    <lastmod>2026-07-30T05:06:14.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-event-consumer-scrcons-exe-created-named-pipe-493fb4ab</loc>
    <lastmod>2026-07-31T13:15:07.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-successful-installation-of-atera-remote-monitoring-agent-via-msi-87261fb2</loc>
    <lastmod>2026-07-31T12:47:43.487Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-computerdefaults-exe-with-elevated-integrity-parent-proce-3c05e90d</loc>
    <lastmod>2026-07-30T05:11:28.055Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uac-bypass-via-winsat-exe-lowercaselongpath-and-uacme-path-pars-6597be7b</loc>
    <lastmod>2026-07-30T05:23:02.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-uac-bypass-via-winsat-exe-path-parsing-7a01183d</loc>
    <lastmod>2026-07-30T05:11:56.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-ntfs-reparse-point-wusa-exe-dll-hijacking-process-behavio-39ed3c80</loc>
    <lastmod>2026-07-30T05:11:49.368Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-msconfig-token-modification-msconfig-exe-5-process-creati-ad92e3f9</loc>
    <lastmod>2026-07-30T05:11:47.791Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-ieinstal-exe-launching-consent-exe-from-temp-with-elevate-80fc36aa</loc>
    <lastmod>2026-07-30T05:11:45.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-dismhost-exe-dll-hijacking-853e74f9</loc>
    <lastmod>2026-07-30T05:11:32.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-disk-cleanup-cleanmgr-exe-run-from-scheduled-task-b697e69c</loc>
    <lastmod>2026-07-30T05:11:22.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-uacme-akagi-exe-akagi64-exe-via-pe-metadata-indicators-d38d2fa4</loc>
    <lastmod>2026-07-31T13:34:38.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-event-detect-uac-bypass-attempt-via-winsat-exe-path-parsing-in-temp-155dbf56</loc>
    <lastmod>2026-07-31T13:08:24.986Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-attempt-via-ntfs-reparse-point-targeting-temp-dll-path-7fff6773</loc>
    <lastmod>2026-07-31T13:08:20.739Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-write-to-temp-pkgmgr-exe-via-msconfig-token-modification-uac-bypass-41bb431f</loc>
    <lastmod>2026-07-31T13:08:19.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-attempt-via-ieinstal-exe-writing-consent-exe-to-temp-bdd8157d</loc>
    <lastmod>2026-07-31T13:08:13.962Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-net-code-profiler-and-mmc-exe-dll-write-to-temp-pe386-dll-93a19907</loc>
    <lastmod>2026-07-31T13:08:05.226Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-telemetry-detects-exchange-proxytoken-exploitation-attempts-targeting--56973b50</loc>
    <lastmod>2026-07-31T12:05:27.206Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-matching-trustedpath-uac-bypass-directory-mocking-strin-4ac47ed3</loc>
    <lastmod>2026-07-30T05:11:54.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/exchange-management-remove-mailboxexportrequest-triggered-with-confirm-false-09570ae5</loc>
    <lastmod>2026-07-31T12:50:11.570Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-registry-access-to-azure-ad-health-agent-keys-1d2ab8ac</loc>
    <lastmod>2026-07-31T12:51:00.657Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-detection-access-to-azure-ad-health-monitoring-agent-regi-ff151c33</loc>
    <lastmod>2026-07-31T12:50:58.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-workspace-admin-api-mfa-enforcement-relaxed-by-setting-to-false-780601d1</loc>
    <lastmod>2026-07-31T12:33:14.306Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-workspace-admin-audit-application-removed-from-domain-ee2803f0</loc>
    <lastmod>2026-07-31T12:33:10.432Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-deletion-of-azure-ad-hybrid-health-ad-fs-service-48739819</loc>
    <lastmod>2026-07-31T12:28:47.686Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-hybrid-health-ad-fs-new-updated-service-member-server-via-administrativ-288a39fc</loc>
    <lastmod>2026-07-31T12:28:46.070Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/web-exploitation-attempt-modx-manager-lfi-traversal-in-tvs-php-class-key-cve-201-a4a899e8</loc>
    <lastmod>2026-07-31T12:00:03.023Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-workspace-admin-role-privilege-removed-via-remove-privilege-bf638ef7</loc>
    <lastmod>2026-07-31T12:33:19.146Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-workspace-admin-role-modified-or-deleted-via-admin-api-audit-events-6aef64e3</loc>
    <lastmod>2026-07-31T12:33:17.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/arcadyan-router-exploit-attempts-via-web-path-traversal-and-unauthenticated-conf-f0500377</loc>
    <lastmod>2026-07-31T12:04:40.744Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uac-bypass-attempt-via-windows-media-player-osk-exe-appcompatfl-5f9db380</loc>
    <lastmod>2026-07-30T05:23:04.755Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmiprvse-exe-spawning-suspicious-script-and-lolbin-child-processes-8a582fe2</loc>
    <lastmod>2026-07-30T05:15:30.132Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-office-launched-wmic-with-lolbin-style-command-argument-e1693bc8</loc>
    <lastmod>2026-07-30T05:15:16.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-using-wsreset-exe-with-high-system-integrity-89a9a0e0</loc>
    <lastmod>2026-07-30T05:12:01.275Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-uac-bypass-via-windows-media-player-osksupport-dll-osk-exe-cmd-e-0058b9e5</loc>
    <lastmod>2026-07-30T05:11:58.065Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-pkgmgr-exe-launching-dism-exe-high-system-integrity-a743ceba</loc>
    <lastmod>2026-07-30T05:11:51.335Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-consent-exe-and-werfault-exe-with-comctl32-dll-related-be-1ca6bd18</loc>
    <lastmod>2026-07-30T05:11:29.887Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-changepk-exe-launched-from-slui-exe-with-elevated-integri-503d581c</loc>
    <lastmod>2026-07-30T05:11:20.326Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-splwow64-exe-missing-command-line-parameters-1f1a8509</loc>
    <lastmod>2026-07-30T05:05:37.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-wow64-logger-dll-hijack-uacme-30-pattern-4f6c43e2</loc>
    <lastmod>2026-07-31T13:24:00.214Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-suspicious-win32-pnpentity-wmi-query-on-windows-b26647de</loc>
    <lastmod>2026-07-31T13:22:20.637Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-with-pipe-and-pipe-srvsvc-pattern-efspotato-637f689e</loc>
    <lastmod>2026-07-31T13:14:50.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uac-bypass-using-windows-media-player-osksupport-dll-via-dllhost-exe-file-events-68578b43</loc>
    <lastmod>2026-07-31T13:08:26.865Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-consent-exe-and-comctl32-dll-file-target-path-62ed5b55</loc>
    <lastmod>2026-07-31T13:08:03.302Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-by-microsoft-office-with-executable-or-script-extensions-c7a74c80</loc>
    <lastmod>2026-07-31T13:05:13.427Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/exchange-certificate-export-writes-csr-to-web-server-paths-or-aspx-suffixes-b7bc7038</loc>
    <lastmod>2026-07-31T12:50:08.206Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-suspicious-oauth-app-file-downloads-from-sharepoint-onedrive-ee111937</loc>
    <lastmod>2026-07-31T12:34:08.352Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/m365-securitycompliancecenter-successful-logon-from-risky-ip-address-in-sanction-c191e2fa</loc>
    <lastmod>2026-07-31T12:33:57.584Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-cloud-app-security-successful-data-exfiltration-to-unsanctioned-ap-2b669496</loc>
    <lastmod>2026-07-31T12:33:49.736Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-cloud-app-security-success-events-from-infrequent-countries-0f2468a2</loc>
    <lastmod>2026-07-31T12:33:47.115Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-threat-management-activity-from-anonymous-proxy-ip-addresses-d8b0a4fe</loc>
    <lastmod>2026-07-31T12:33:44.805Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-cloud-app-security-activity-by-terminated-user-across-platforms-2e669ed8</loc>
    <lastmod>2026-07-31T12:33:42.876Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-cloud-app-security-successful-logins-from-microsoft-threat-intel-risky-a3501e8e</loc>
    <lastmod>2026-07-31T12:33:41.119Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-google-workspace-admin-role-granted-to-user-2d1b83e4</loc>
    <lastmod>2026-07-31T12:33:21.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-google-workspace-admin-api-client-access-authorized-at-domain-level-04e2a23a</loc>
    <lastmod>2026-07-31T12:33:12.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-razerinstaller-explorer-subprocess-with-system-integrity-level-a4eaf250</loc>
    <lastmod>2026-07-31T12:06:34.977Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dce-rpc-remote-printer-driver-and-print-processor-installation-activity-pri-7b33baef</loc>
    <lastmod>2026-07-31T12:04:38.791Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-threat-management-alert-on-suspicious-inbox-forwarding-6c220477</loc>
    <lastmod>2026-07-31T12:34:06.026Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-powerup-write-hijack-dll-abuse-creating-bat-on-windows-602a1f13</loc>
    <lastmod>2026-07-31T13:03:35.258Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-reg-exe-changing-screen-saver-registry-settings-for-scr-payloads-0fc35fc3</loc>
    <lastmod>2026-07-30T05:00:04.381Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-wmi-event-subscription-persistence-via-new-ciminstance-in-scriptblock-9e07f6e7</loc>
    <lastmod>2026-07-31T13:23:02.300Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dns-lookups-for-known-cryptocurrency-mining-pool-domains-bf74135c</loc>
    <lastmod>2026-07-31T12:45:17.104Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-securitycompliancecenter-user-restricted-from-sending-email-succes-ff246f56</loc>
    <lastmod>2026-07-31T12:34:12.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-threat-management-high-volume-file-deletion-by-a-user-78a34b67</loc>
    <lastmod>2026-07-31T12:34:10.406Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-cloud-app-security-reports-potential-ransomware-uploads-bd132164</loc>
    <lastmod>2026-07-31T12:33:59.523Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-rule-fortinet-waf-cve-2021-22123-exploitation-attempt-via-post-to-saml-f425637f</loc>
    <lastmod>2026-07-31T12:04:51.197Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-persistence-add-content-to-modify-profile-for-startup-executi-05b3e303</loc>
    <lastmod>2026-07-31T13:22:41.178Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dce-rpc-encrypting-file-system-efs-rpc-operations-starting-with-efs-4096842a</loc>
    <lastmod>2026-07-31T12:45:09.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-procdump-process-execution-2e65275c</loc>
    <lastmod>2026-07-30T05:10:21.502Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-cloud-vpn-tunnel-insert-or-delete-via-audit-logs-99980a85</loc>
    <lastmod>2026-07-31T12:33:07.128Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-alert-suppression-rule-created-92cc3e5d</loc>
    <lastmod>2026-07-31T12:29:40.390Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-key-vault-secrets-modified-or-deleted-via-activity-logs-b831353c</loc>
    <lastmod>2026-07-31T12:29:08.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-key-vault-write-delete-deployment-and-access-policy-changes-459a2970</loc>
    <lastmod>2026-07-31T12:29:06.123Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-key-vault-key-modified-or-deleted-via-activity-log-80eeab92</loc>
    <lastmod>2026-07-31T12:29:04.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-application-security-group-modified-or-deleted-via-activity-logs-835747f1</loc>
    <lastmod>2026-07-31T12:28:51.460Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-application-gateway-modified-or-deleted-via-activity-logs-ad87d14e</loc>
    <lastmod>2026-07-31T12:28:49.744Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-eks-cluster-createcluster-or-deletecluster-via-cloudtrail-33d50d03</loc>
    <lastmod>2026-07-31T12:27:55.852Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-detect-hacktool-and-attack-tool-signatures-by-name-and-prefix-fa0c05b6</loc>
    <lastmod>2026-07-31T12:26:51.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sqlcmd-database-dumping-commands-indicative-of-ransomware-activity-2f47f1fd</loc>
    <lastmod>2026-07-31T12:06:50.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-xss-payload-strings-in-get-request-urls-access-logs-65354b83</loc>
    <lastmod>2026-07-31T12:47:20.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dns-queries-to-tor-proxy-and-onion-domain-indicators-a8322756</loc>
    <lastmod>2026-07-31T12:45:22.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-cloud-dns-managed-zone-updated-patched-or-deleted-audit-logs-28268a8f</loc>
    <lastmod>2026-07-31T12:32:48.661Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-sensitive-data-re-identified-via-projects-content-reidentify-234f9f48</loc>
    <lastmod>2026-07-31T12:32:47.086Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-efs-mount-target-deleted-or-modified-6a7ba45c</loc>
    <lastmod>2026-07-31T12:27:53.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-efs-deletefilesystem-events-for-fileshare-modification-or-deletion-25cb1ba1</loc>
    <lastmod>2026-07-31T12:27:51.916Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-service-account-modified-via-service-accounts-api-methods-6b67c12e</loc>
    <lastmod>2026-07-31T12:33:03.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-cloud-audit-service-account-disabled-or-deleted-13f81a90</loc>
    <lastmod>2026-07-31T12:33:01.250Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-cloud-storage-buckets-modified-or-deleted-via-audit-api-4d9f2ee2</loc>
    <lastmod>2026-07-31T12:32:45.364Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-detects-google-cloud-storage-bucket-enumeration-via-list-apis-e2feb918</loc>
    <lastmod>2026-07-31T12:32:43.754Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-full-network-packet-mirroring-api-activity-980a7598</loc>
    <lastmod>2026-07-31T12:32:52.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-logs-firewall-rule-modified-or-deleted-fe513c69</loc>
    <lastmod>2026-07-31T12:32:50.614Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-whoami-exe-execution-from-suspicious-parent-processes-8de1cbe8</loc>
    <lastmod>2026-07-30T05:13:48.445Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-whoami-exe-renamed-execution-via-mismatched-originalfilename-f1086bf7</loc>
    <lastmod>2026-07-30T05:02:58.132Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-systemnightmare-exploitation-attempt-via-printnightmare-cli-indicators-c01f7bd6</loc>
    <lastmod>2026-07-31T12:06:37.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/iis-webserver-ssrf-proxylogon-reset-virtual-directory-via-ecp-setobject-post-effee1f6</loc>
    <lastmod>2026-07-31T12:05:21.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-injection-triggered-by-winword-exe-from-littlecorporal-maldoc-7bdde3bf</loc>
    <lastmod>2026-07-31T13:23:26.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-shellintel-commandlet-abuse-via-script-block-logging-402e1e1d</loc>
    <lastmod>2026-07-31T13:20:44.449Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-exchange-powershell-mailbox-export-to-unc-path-with-aspx-or-role-assig-516376b4</loc>
    <lastmod>2026-07-31T12:50:09.983Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msexchange-management-post-proxylogon-set-oabvirtualdirectory-with-suspi-550d3350</loc>
    <lastmod>2026-07-31T12:50:06.116Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-kubernetes-audit-secrets-modified-or-deleted-via-kubernetes-api-methods-2f0bae2d</loc>
    <lastmod>2026-07-31T12:32:59.622Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-logs-kubernetes-rolebinding-and-clusterrolebinding-create-patch-update-0322d9f2</loc>
    <lastmod>2026-07-31T12:32:57.977Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-updateloginprofile-password-changes-for-other-users-055fb148</loc>
    <lastmod>2026-07-31T12:28:44.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detects-vss-shadow-copy-listing-via-vssadmin-7b30e0a7</loc>
    <lastmod>2026-07-31T12:06:44.950Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-activity-indicating-successful-proxyshell-exploit-targeting-exchange-992be1eb</loc>
    <lastmod>2026-07-31T12:06:32.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-vpn-gateway-connection-modified-or-deleted-61171ffc</loc>
    <lastmod>2026-07-31T12:29:43.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-log-virtual-network-modified-or-deleted-bcfcc962</loc>
    <lastmod>2026-07-31T12:29:42.052Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-virtual-network-device-modified-or-deleted-15ef3fac</loc>
    <lastmod>2026-07-31T12:29:33.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-network-security-group-security-rules-modified-or-deleted-d22b4df4</loc>
    <lastmod>2026-07-31T12:29:31.876Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-point-to-site-vpn-gateway-modified-or-deleted-d9557b75</loc>
    <lastmod>2026-07-31T12:29:30.243Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-firewall-rule-collections-and-groups-modified-or-deleted-via-activity-logs-2a7d64cf</loc>
    <lastmod>2026-07-31T12:29:28.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-firewall-rule-collections-modified-or-deleted-activity-logs-025c9fe7</loc>
    <lastmod>2026-07-31T12:29:01.252Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-firewall-created-modified-or-deleted-via-azure-activity-logs-512cf937</loc>
    <lastmod>2026-07-31T12:28:59.519Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-dns-zone-modified-or-deleted-via-activity-logs-af6925b0</loc>
    <lastmod>2026-07-31T12:28:57.882Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-kubernetes-service-account-write-delete-or-impersonate-12d027c3</loc>
    <lastmod>2026-07-31T12:29:25.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-kubernetes-service-activity-logs-secret-configmap-write-or-delete-7ee0b4aa</loc>
    <lastmod>2026-07-31T12:29:23.604Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-rolebinding-clusterrolebinding-created-patched-or-deleted-ku-25cb259b</loc>
    <lastmod>2026-07-31T12:29:21.814Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-kubernetes-rbac-roles-clusterroles-modified-or-deleted-818fee0c</loc>
    <lastmod>2026-07-31T12:29:20.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-kubernetes-network-policy-write-delete-operations-08d6ac24</loc>
    <lastmod>2026-07-31T12:29:16.730Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-kubernetes-connected-cluster-created-or-deleted-via-activity-logs-9541f321</loc>
    <lastmod>2026-07-31T12:29:11.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-container-registry-created-or-deleted-93e0ef48</loc>
    <lastmod>2026-07-31T12:28:52.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/exchange-proxyshell-url-probing-via-autodiscover-json-and-powershell-related-pat-23eee45e</loc>
    <lastmod>2026-07-31T12:06:30.585Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/how-to-write-a-sigma-rule-a-step-by-step-guide-for-beginners</loc>
    <lastmod>2026-08-01T17:59:52.359Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-baseline-in-detection-engineering</loc>
    <lastmod>2026-08-01T10:00:12.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-playbook-in-threat-hunting-and-incident-response</loc>
    <lastmod>2026-08-01T03:00:11.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-att-ck-mitre-att-ck-framework-explained</loc>
    <lastmod>2026-08-01T00:43:27.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/how-to-choose-which-sigma-rules-to-deploy-first</loc>
    <lastmod>2026-07-28T09:02:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-managed-sigma-rule-service</loc>
    <lastmod>2026-07-24T10:20:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-rule-validation-in-huntrule</loc>
    <lastmod>2026-07-12T15:57:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-rule-lifecycle-in-huntrule</loc>
    <lastmod>2026-07-08T08:42:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-huntrule</loc>
    <lastmod>2026-06-25T10:11:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-build-pipeline-compromise</loc>
    <lastmod>2026-06-14T14:48:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-cicd-security</loc>
    <lastmod>2026-05-27T11:33:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-typosquatting</loc>
    <lastmod>2026-05-21T12:48:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-dependency-confusion</loc>
    <lastmod>2026-05-11T15:06:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-supply-chain-security</loc>
    <lastmod>2026-04-26T10:35:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-malware-analysis</loc>
    <lastmod>2026-04-17T08:20:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-event-correlation</loc>
    <lastmod>2026-04-06T15:31:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-data-source</loc>
    <lastmod>2026-03-18T08:07:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-detection-signal-vs-noise</loc>
    <lastmod>2026-03-07T14:33:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-log-normalization</loc>
    <lastmod>2026-02-26T11:32:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-security-telemetry</loc>
    <lastmod>2026-02-16T10:33:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-an-sbom</loc>
    <lastmod>2026-01-31T10:59:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-supply-chain-attack</loc>
    <lastmod>2026-01-19T15:09:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-living-off-the-land</loc>
    <lastmod>2026-01-16T08:53:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-fileless-malware</loc>
    <lastmod>2025-12-30T13:17:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-webshell</loc>
    <lastmod>2025-12-20T08:07:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-ransomware</loc>
    <lastmod>2025-12-11T12:22:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-command-and-control-server</loc>
    <lastmod>2025-11-26T16:37:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-remote-access-trojan</loc>
    <lastmod>2025-11-19T12:47:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-lessons-learned-session</loc>
    <lastmod>2025-11-07T11:46:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-post-incident-review</loc>
    <lastmod>2025-10-23T08:09:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-root-cause-analysis</loc>
    <lastmod>2025-10-16T08:58:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-an-incident-timeline</loc>
    <lastmod>2025-09-26T09:30:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-an-incident-response-plan</loc>
    <lastmod>2025-09-23T14:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-incident-response</loc>
    <lastmod>2025-09-11T08:24:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-soc-runbook</loc>
    <lastmod>2025-08-28T10:26:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-soar</loc>
    <lastmod>2025-08-18T16:48:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-ueba</loc>
    <lastmod>2025-08-06T08:53:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-an-ndr</loc>
    <lastmod>2025-07-18T08:20:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-an-xdr</loc>
    <lastmod>2025-07-13T09:16:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-an-edr</loc>
    <lastmod>2025-06-25T12:10:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-siem</loc>
    <lastmod>2025-06-16T11:32:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-soc</loc>
    <lastmod>2025-06-06T12:19:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-alert-fatigue</loc>
    <lastmod>2025-05-28T16:01:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-patch-management</loc>
    <lastmod>2025-05-15T08:11:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-vulnerability-management</loc>
    <lastmod>2025-04-28T12:39:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-zero-day-vulnerability</loc>
    <lastmod>2025-04-15T11:42:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-exploit-chaining</loc>
    <lastmod>2025-04-08T10:08:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-cvss</loc>
    <lastmod>2025-03-30T14:36:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-cve</loc>
    <lastmod>2025-03-20T16:05:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-threat-modeling</loc>
    <lastmod>2025-03-02T11:33:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-operational-threat-intelligence</loc>
    <lastmod>2025-02-21T08:43:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-an-indicator-of-attack</loc>
    <lastmod>2025-02-06T15:54:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-an-indicator-of-compromise</loc>
    <lastmod>2025-01-27T08:10:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-an-advanced-persistent-threat</loc>
    <lastmod>2025-01-21T09:51:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-cyber-threat-intelligence</loc>
    <lastmod>2025-01-01T15:10:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-an-apt-campaign</loc>
    <lastmod>2024-12-24T12:35:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-ttp-in-cybersecurity</loc>
    <lastmod>2024-12-13T16:14:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-strategic-threat-intelligence</loc>
    <lastmod>2024-12-05T08:40:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-tactical-threat-intelligence</loc>
    <lastmod>2024-11-19T16:17:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-are-hunting-rules</loc>
    <lastmod>2024-11-07T08:42:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-threat-hunting</loc>
    <lastmod>2024-10-27T13:41:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-use-case-library</loc>
    <lastmod>2024-10-20T14:51:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-hypothesis-driven-hunt</loc>
    <lastmod>2024-10-02T08:41:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-detection-playbook</loc>
    <lastmod>2024-09-23T13:18:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-detection-rule</loc>
    <lastmod>2024-09-13T16:19:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-a-sigma-rule-catalog</loc>
    <lastmod>2024-08-29T12:38:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-is-detection-engineering</loc>
    <lastmod>2024-08-17T16:50:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://huntrule.com/blog/what-are-sigma-rules</loc>
    <lastmod>2024-08-12T14:33:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
</urlset>