<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://huntrule.com/</loc>
    <changefreq>daily</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules</loc>
    <changefreq>hourly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://huntrule.com/pricing</loc>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>
  <url>
    <loc>https://huntrule.com/about</loc>
    <changefreq>monthly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://huntrule.com/contact</loc>
    <changefreq>monthly</changefreq>
    <priority>0.2</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-full-data-export-triggered-via-audit</loc>
    <lastmod>2026-07-28T23:34:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-global-permission-changed-via-audit</loc>
    <lastmod>2026-07-28T23:34:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-bitbucket-global-secret-scanning-rule-via-audit</loc>
    <lastmod>2026-07-28T23:34:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-global-ssh-settings-changed-via-audit</loc>
    <lastmod>2026-07-28T23:34:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-audit-log-configuration-updated-via-audit</loc>
    <lastmod>2026-07-28T23:34:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-bitbucket-project-secret-scanning-allowlist-added-via-audit</loc>
    <lastmod>2026-07-28T23:34:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-secret-scanning-exempt-repository-added-via-audit</loc>
    <lastmod>2026-07-28T23:34:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-removal-of-bitbucket-secret-scanning-rule-via-audit</loc>
    <lastmod>2026-07-28T23:34:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-unauthorized-access-to-a-resource-via-audit</loc>
    <lastmod>2026-07-28T23:34:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-unauthorized-full-data-export-triggered-via-audit</loc>
    <lastmod>2026-07-28T23:34:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-user-details-export-attempt-detected-via-audit</loc>
    <lastmod>2026-07-28T23:34:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-user-login-failure-via-audit</loc>
    <lastmod>2026-07-28T23:34:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-user-login-failure-through-ssh-via-audit</loc>
    <lastmod>2026-07-28T23:34:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-user-permissions-export-attempt-via-audit</loc>
    <lastmod>2026-07-28T23:34:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-django-framework-exceptions-via-application</loc>
    <lastmod>2026-07-28T23:34:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-github-delete-action-invoked-via-audit</loc>
    <lastmod>2026-07-28T23:34:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-github-high-risk-configuration-via-audit</loc>
    <lastmod>2026-07-28T23:34:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-outdated-dependency-or-vulnerability-alert-via-audit</loc>
    <lastmod>2026-07-28T23:34:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-github-fork-private-repositories-setting-enabled-cleared-via-audit</loc>
    <lastmod>2026-07-28T23:33:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-github-organization-member-added-via-audit</loc>
    <lastmod>2026-07-28T23:33:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-github-new-secret-via-audit</loc>
    <lastmod>2026-07-28T23:33:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-github-outside-collaborator-detected-via-audit</loc>
    <lastmod>2026-07-28T23:33:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-github-repository-pages-site-changed-to-public-via-audit</loc>
    <lastmod>2026-07-28T23:33:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-github-push-protection-bypass-detected-via-audit</loc>
    <lastmod>2026-07-28T23:33:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-github-push-protection-via-audit</loc>
    <lastmod>2026-07-28T23:33:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-github-repository-organization-transferred-via-audit</loc>
    <lastmod>2026-07-28T23:33:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-github-repository-archive-status-changed-via-audit</loc>
    <lastmod>2026-07-28T23:33:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-github-secret-scanning-feature-via-audit</loc>
    <lastmod>2026-07-28T23:33:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-github-self-hosted-runner-changes-detected-via-audit</loc>
    <lastmod>2026-07-28T23:33:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-github-ssh-certificate-configuration-changed-via-audit</loc>
    <lastmod>2026-07-28T23:33:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-jndi-injection-exploitation-in-jvm-based-application-via-application</loc>
    <lastmod>2026-07-28T23:33:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-file-read-vulnerability-in-jvm-based-application-via-application</loc>
    <lastmod>2026-07-28T23:33:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ognl-injection-exploitation-in-jvm-based-application-via-application</loc>
    <lastmod>2026-07-28T23:33:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-execution-error-in-jvm-based-application-via-application</loc>
    <lastmod>2026-07-28T23:33:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-xxe-exploitation-attempt-in-jvm-based-application-via-application</loc>
    <lastmod>2026-07-28T23:33:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-admission-controller-change-via-audit</loc>
    <lastmod>2026-07-28T23:33:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-cronjob-job-change-via-audit</loc>
    <lastmod>2026-07-28T23:33:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-deployment-deleted-from-kubernetes-cluster-via-application</loc>
    <lastmod>2026-07-28T23:33:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-kubernetes-events-via-application</loc>
    <lastmod>2026-07-28T23:33:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-command-execution-in-pod-container-via-application</loc>
    <lastmod>2026-07-28T23:33:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-container-with-a-hostpath-mount-via-application</loc>
    <lastmod>2026-07-28T23:33:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-pod-in-system-namespace-via-application</loc>
    <lastmod>2026-07-28T23:33:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-possible-enumeration-behavior-via-audit</loc>
    <lastmod>2026-07-28T23:33:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privileged-container-deployed-via-application</loc>
    <lastmod>2026-07-28T23:33:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rbac-permission-enumeration-attempt-via-application</loc>
    <lastmod>2026-07-28T23:33:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-rolebinding-change-via-audit</loc>
    <lastmod>2026-07-28T23:33:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-kubernetes-secrets-enumeration-via-application</loc>
    <lastmod>2026-07-28T23:33:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-secrets-modified-or-deleted-via-audit</loc>
    <lastmod>2026-07-28T23:33:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-new-kubernetes-service-account-via-application</loc>
    <lastmod>2026-07-28T23:33:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sidecar-injection-into-running-deployment-via-application</loc>
    <lastmod>2026-07-28T23:33:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-kubernetes-unauthorized-or-unauthenticated-access-via-audit</loc>
    <lastmod>2026-07-28T23:33:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rce-exploitation-attempt-in-nodejs-via-application</loc>
    <lastmod>2026-07-28T23:33:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-ftp-login-attempt-via-application</loc>
    <lastmod>2026-07-28T23:33:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-git-clone-request-via-application</loc>
    <lastmod>2026-07-28T23:33:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-http-get-request-via-application</loc>
    <lastmod>2026-07-28T23:33:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-http-post-login-attempt-via-application</loc>
    <lastmod>2026-07-28T23:33:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-httpproxy-login-attempt-via-application</loc>
    <lastmod>2026-07-28T23:33:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-mssql-login-attempt-via-sqlauth-via-application</loc>
    <lastmod>2026-07-28T23:33:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-mssql-login-attempt-via-windows-authentication-via-application</loc>
    <lastmod>2026-07-28T23:33:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-mysql-login-attempt-via-application</loc>
    <lastmod>2026-07-28T23:33:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-ntp-monlist-request-via-application</loc>
    <lastmod>2026-07-28T23:33:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-nmap-fin-scan-via-application</loc>
    <lastmod>2026-07-28T23:33:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-nmap-null-scan-via-application</loc>
    <lastmod>2026-07-28T23:33:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-nmap-os-scan-via-application</loc>
    <lastmod>2026-07-28T23:33:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-nmap-xmas-scan-via-application</loc>
    <lastmod>2026-07-28T23:33:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-host-port-scan-syn-scan-via-application</loc>
    <lastmod>2026-07-28T23:33:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-rdp-new-connection-attempt-via-application</loc>
    <lastmod>2026-07-28T23:33:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-redis-action-command-attempt-via-application</loc>
    <lastmod>2026-07-28T23:33:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-sip-request-via-application</loc>
    <lastmod>2026-07-28T23:33:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-smb-file-open-request-via-application</loc>
    <lastmod>2026-07-28T23:33:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-snmp-oid-request-via-application</loc>
    <lastmod>2026-07-28T23:33:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-ssh-login-attempt-via-application</loc>
    <lastmod>2026-07-28T23:33:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-ssh-new-connection-attempt-via-application</loc>
    <lastmod>2026-07-28T23:33:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-telnet-login-attempt-via-application</loc>
    <lastmod>2026-07-28T23:33:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-tftp-request-via-application</loc>
    <lastmod>2026-07-28T23:33:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-vnc-connection-attempt-via-application</loc>
    <lastmod>2026-07-28T23:33:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-sql-exceptions-via-application</loc>
    <lastmod>2026-07-28T23:33:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-schedule-task-lateral-movement-through-atsvc-via-application</loc>
    <lastmod>2026-07-28T23:33:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-schedule-task-recon-through-atscv-via-application</loc>
    <lastmod>2026-07-28T23:32:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dcsync-attack-via-application</loc>
    <lastmod>2026-07-28T23:32:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-encrypting-file-system-misuse-via-application</loc>
    <lastmod>2026-07-28T23:32:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-event-log-recon-via-application</loc>
    <lastmod>2026-07-28T23:32:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-schedule-task-lateral-movement-through-itaskschedulerservice-via-application</loc>
    <lastmod>2026-07-28T23:32:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-schedule-task-recon-through-itaskschedulerservice-via-application</loc>
    <lastmod>2026-07-28T23:32:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-printing-misuse-for-lateral-movement-via-application</loc>
    <lastmod>2026-07-28T23:32:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-dcom-wmi-lateral-movement-via-application</loc>
    <lastmod>2026-07-28T23:32:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-registry-lateral-movement-via-application</loc>
    <lastmod>2026-07-28T23:32:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-registry-recon-via-application</loc>
    <lastmod>2026-07-28T23:32:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-server-service-misuse-via-application</loc>
    <lastmod>2026-07-28T23:32:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-server-service-misuse-for-lateral-movement-via-application</loc>
    <lastmod>2026-07-28T23:32:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-schedule-task-lateral-movement-through-sasec-via-application</loc>
    <lastmod>2026-07-28T23:32:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-behavior-through-sasec-via-application</loc>
    <lastmod>2026-07-28T23:32:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sharphound-recon-account-enumeration-via-application</loc>
    <lastmod>2026-07-28T23:32:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sharphound-recon-sessions-via-application</loc>
    <lastmod>2026-07-28T23:32:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ruby-on-rails-framework-exceptions-via-application</loc>
    <lastmod>2026-07-28T23:32:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-spring-framework-exceptions-via-application</loc>
    <lastmod>2026-07-28T23:32:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-spel-injection-in-spring-framework-via-application</loc>
    <lastmod>2026-07-28T23:32:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-error-messages-via-application</loc>
    <lastmod>2026-07-28T23:32:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-server-side-template-injection-in-velocity-via-application</loc>
    <lastmod>2026-07-28T23:32:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-antivirus-apt-malware-signature-via-antivirus</loc>
    <lastmod>2026-07-28T23:32:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-antivirus-exploitation-framework-signature-via-antivirus</loc>
    <lastmod>2026-07-28T23:32:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-antivirus-hacktool-signature-via-antivirus</loc>
    <lastmod>2026-07-28T23:32:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-antivirus-password-dumper-signature-via-antivirus</loc>
    <lastmod>2026-07-28T23:32:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-antivirus-ransomware-signature-via-antivirus</loc>
    <lastmod>2026-07-28T23:32:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-antivirus-relevant-file-paths-alerts-signature-via-antivirus</loc>
    <lastmod>2026-07-28T23:32:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-antivirus-remote-access-tools-signature-via-antivirus</loc>
    <lastmod>2026-07-28T23:32:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-antivirus-web-shell-detection-signature-via-antivirus</loc>
    <lastmod>2026-07-28T23:32:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-query-via-database</loc>
    <lastmod>2026-07-28T23:32:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-aws-bedrock-guardrail-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-bedrock-guardrail-updated-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-aws-bucket-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-consolelogin-failed-authentication-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-successful-console-login-without-mfa-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-cloudtrail-important-change-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-guardduty-detector-deleted-or-updated-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-use-of-imds-credentials-outside-of-aws-infrastructure-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-network-acl-entry-added-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-network-route-added-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-aws-trufflehog-execution-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-enableregion-command-monitoring-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ingress-egress-security-group-change-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-loadbalancer-security-group-change-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rds-database-security-group-change-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-malicious-use-of-cloudtrail-system-manager-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-aws-vpc-flow-logs-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-config-disabling-channel-recorder-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-console-getsignintoken-possible-misuse-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-ses-identity-has-been-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-saml-provider-removal-behavior-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-s3-bucket-versioning-disable-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-aws-ec2-disable-ebs-encryption-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-key-pair-import-behavior-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-aws-ec2-startup-shell-script-change-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-aws-ec2-vm-export-failure-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-ecs-task-definition-that-queries-the-credential-endpoint-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-efs-fileshare-modified-or-deleted-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-efs-fileshare-mount-modified-or-deleted-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-eks-cluster-created-or-deleted-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:32:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-aws-elasticache-security-group-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-elasticache-security-group-modified-or-deleted-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-bucket-enumeration-on-aws-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-guardduty-important-change-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-aws-iam-backdoor-users-keys-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-iam-s3browser-loginprofile-creation-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-iam-s3browser-templated-s3-bucket-policy-creation-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-iam-s3browser-user-or-accesskey-creation-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-kms-imported-key-material-use-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-new-aws-lambda-function-url-configuration-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-new-lambda-layer-attached-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-glue-development-endpoint-behavior-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-rds-master-password-change-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-or-removal-of-an-aws-rds-cluster-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-restore-public-aws-rds-instance-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-root-credentials-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-disabling-of-aws-route-53-domain-transfer-lock-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-route-53-domain-transferred-to-another-account-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-s3-data-management-manipulation-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-securityhub-findings-evasion-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-snapshot-backup-exfiltration-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-identity-center-identity-provider-change-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-sts-assumerole-misuse-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-sts-getcalleridentity-enumeration-through-trufflehog-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-sts-getsessiontoken-misuse-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-suspicious-saml-behavior-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-aws-user-login-profile-was-via-cloudtrail</loc>
    <lastmod>2026-07-28T23:31:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-active-directory-hybrid-health-ad-fs-new-server-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-active-directory-hybrid-health-ad-fs-service-delete-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-application-gateway-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-application-security-group-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-azure-container-registry-created-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-number-of-resource-creation-or-deployment-activities-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-device-or-configuration-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-dns-zone-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-firewall-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-firewall-rule-collection-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-granting-of-permissions-to-an-account-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-keyvault-key-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-key-vault-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-keyvault-secrets-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-admission-controller-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-azure-kubernetes-cluster-created-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-cronjob-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-azure-kubernetes-events-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-network-policy-change-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-azure-kubernetes-pods-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-sensitive-role-access-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-rolebinding-clusterrolebinding-modified-and-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-secret-or-config-object-access-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-service-account-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-network-firewall-policy-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-firewall-rule-configuration-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-point-to-site-vpn-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-network-security-configuration-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-virtual-network-device-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-azure-new-cloudshell-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rare-subscription-level-operations-in-azure-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-subscription-permission-elevation-through-activitylogs-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-azure-suppression-rule-via-activitylogs</loc>
    <lastmod>2026-07-28T23:31:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-virtual-network-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:30:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-vpn-connection-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-28T23:30:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ca-policy-removed-by-non-approved-actor-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ca-policy-updated-by-non-approved-actor-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-ca-policy-by-non-approved-actor-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-account-created-and-deleted-within-a-close-time-frame-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitlocker-key-retrieval-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-based-authentication-enabled-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-changes-to-device-registration-policy-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-root-certificate-authority-added-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-an-administrator-s-azure-ad-role-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-users-added-to-global-or-device-admin-roles-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-appid-uri-configuration-changes-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-added-credentials-to-existing-application-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-delegated-permissions-granted-for-all-users-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-end-user-consent-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-end-user-consent-blocked-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-added-owner-to-application-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-app-granted-microsoft-permissions-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-app-granted-privileged-delegated-or-app-permissions-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-app-assigned-to-azure-rbac-microsoft-entra-role-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-uri-configuration-changes-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-azure-application-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-laps-credential-dump-from-entra-id-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-to-authentication-method-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-device-no-longer-managed-or-compliant-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-azure-domain-federation-settings-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-group-with-ca-policy-change-access-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-removed-from-group-with-ca-policy-change-access-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-guest-user-invited-by-non-approved-inviters-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-state-changed-from-guest-to-member-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabled-mfa-to-bypass-authentication-mechanisms-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-owner-removed-from-application-or-service-principal-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pim-approvals-and-deny-elevation-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-pim-alert-setting-changes-to-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-changes-to-pim-settings-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-privilege-role-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bulk-removal-changes-to-privileged-account-permissions-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-privileged-account-creation-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-azure-service-principal-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-azure-service-principal-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-subscription-permission-elevation-through-auditlogs-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-temporary-access-pass-added-to-an-account-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-risk-and-mfa-registration-policy-updated-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-multi-factor-authentication-disabled-for-user-account-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-reset-by-user-account-via-auditlogs</loc>
    <lastmod>2026-07-28T23:30:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/anomalous-token-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/anomalous-user-behavior-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-behavior-from-anonymous-ip-address-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-anonymous-ip-address-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-atypical-travel-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-impossible-travel-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-inbox-forwarding-identity-protection-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-inbox-manipulation-rules-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-ad-account-credential-leaked-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ip-address-sign-in-failure-rate-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ip-address-sign-in-suspicious-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sign-in-from-malware-infected-ip-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-country-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-spray-behavior-via-riskdetection</loc>
    <lastmod>2026-07-28T23:30:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-primary-refresh-token-access-attempt-via-riskdetection</loc>
    <lastmod>2026-07-28T23:29:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-behavior-via-riskdetection</loc>
    <lastmod>2026-07-28T23:29:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-ad-threat-intelligence-via-riskdetection</loc>
    <lastmod>2026-07-28T23:29:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-saml-token-issuer-anomaly-via-riskdetection</loc>
    <lastmod>2026-07-28T23:29:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unfamiliar-sign-in-properties-via-riskdetection</loc>
    <lastmod>2026-07-28T23:29:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-stale-accounts-in-a-privileged-role-via-pim</loc>
    <lastmod>2026-07-28T23:29:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invalid-pim-license-via-pim</loc>
    <lastmod>2026-07-28T23:29:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-roles-assigned-outside-pim-via-pim</loc>
    <lastmod>2026-07-28T23:29:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-roles-activated-too-frequently-via-pim</loc>
    <lastmod>2026-07-28T23:29:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-roles-activation-doesn-t-require-mfa-via-pim</loc>
    <lastmod>2026-07-28T23:29:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-roles-are-not-being-used-via-pim</loc>
    <lastmod>2026-07-28T23:29:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-too-many-global-admins-via-pim</loc>
    <lastmod>2026-07-28T23:29:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-account-lockout-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-via-azurehound-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-device-registration-or-join-without-mfa-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-azure-ad-only-single-factor-authentication-required-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-signins-from-a-non-registered-device-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sign-ins-from-non-compliant-devices-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sign-ins-by-unknown-devices-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mfa-bypass-via-legacy-client-authentication-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-via-device-code-authentication-flow-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-applications-that-are-via-ropc-authentication-flow-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-account-disabled-or-blocked-for-sign-in-attempts-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sign-in-failure-due-to-conditional-access-requirements-not-met-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-legacy-authentication-protocols-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-login-to-disabled-account-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-multifactor-authentication-denied-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-multifactor-authentication-interrupted-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-unusual-authentication-interruption-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-access-blocked-by-azure-conditional-access-via-signinlogs</loc>
    <lastmod>2026-07-28T23:29:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-gcp-access-policy-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gcp-break-glass-container-workload-deployed-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-google-cloud-storage-buckets-enumeration-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-storage-buckets-modified-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-re-identifies-sensitive-information-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-dns-zone-modified-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-firewall-modified-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-full-network-traffic-packet-capture-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-kubernetes-admission-controller-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-kubernetes-cronjob-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-kubernetes-rolebinding-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-kubernetes-secrets-modified-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-service-account-disabled-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-google-cloud-service-account-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-sql-database-modified-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-vpn-tunnel-modified-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-07-28T23:29:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-google-workspace-application-access-level-via-google-workspace-admin</loc>
    <lastmod>2026-07-28T23:29:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-google-workspace-application-via-google-workspace-admin</loc>
    <lastmod>2026-07-28T23:29:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-workspace-granted-domain-api-access-via-google-workspace-admin</loc>
    <lastmod>2026-07-28T23:29:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-google-workspace-mfa-via-google-workspace-admin</loc>
    <lastmod>2026-07-28T23:29:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-workspace-role-modified-or-deleted-via-google-workspace-admin</loc>
    <lastmod>2026-07-28T23:29:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-google-workspace-role-privilege-via-google-workspace-admin</loc>
    <lastmod>2026-07-28T23:29:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-workspace-user-granted-admin-privileges-via-google-workspace-admin</loc>
    <lastmod>2026-07-28T23:29:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-workspace-government-attack-warning-via-google-workspace-login</loc>
    <lastmod>2026-07-28T23:29:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-workspace-out-of-domain-email-forwarding-via-google-workspace-login</loc>
    <lastmod>2026-07-28T23:29:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-login-behavior-classified-by-google-via-google-workspace-login</loc>
    <lastmod>2026-07-28T23:29:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-login-bypassing-conditional-access-policies-via-audit</loc>
    <lastmod>2026-07-28T23:29:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-multi-factor-authentication-via-audit</loc>
    <lastmod>2026-07-28T23:29:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-federated-domain-added-via-audit</loc>
    <lastmod>2026-07-28T23:29:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-email-delivered-in-microsoft-365-via-audit</loc>
    <lastmod>2026-07-28T23:29:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-federated-domain-added-exchange-via-exchange</loc>
    <lastmod>2026-07-28T23:28:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/behavior-from-suspicious-ip-addresses-via-threat-detection</loc>
    <lastmod>2026-07-28T23:28:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-behavior-performed-by-terminated-user-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-behavior-from-anonymous-ip-addresses-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-behavior-from-infrequent-country-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-to-unsanctioned-apps-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-365-impossible-travel-activity-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-logon-from-a-risky-ip-address-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-potential-ransomware-activity-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-pst-export-alert-via-ediscovery-alert-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pst-export-alert-via-new-compliancesearchaction-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-inbox-forwarding-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-oauth-app-file-download-activities-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-unusual-volume-of-file-deletion-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-365-user-restricted-from-sending-email-via-threat-management</loc>
    <lastmod>2026-07-28T23:28:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-duo-successful-mfa-authentication-through-bypass-code-via-duo</loc>
    <lastmod>2026-07-28T23:28:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-admin-functions-access-through-proxy-via-okta</loc>
    <lastmod>2026-07-28T23:28:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-admin-role-assigned-to-an-user-or-group-via-okta</loc>
    <lastmod>2026-07-28T23:28:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-okta-admin-role-assignment-via-okta</loc>
    <lastmod>2026-07-28T23:28:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-okta-api-token-via-okta</loc>
    <lastmod>2026-07-28T23:28:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-api-token-revoked-via-okta</loc>
    <lastmod>2026-07-28T23:28:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-application-modified-or-deleted-via-okta</loc>
    <lastmod>2026-07-28T23:28:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-application-sign-on-policy-modified-or-deleted-via-okta</loc>
    <lastmod>2026-07-28T23:28:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-fastpass-phishing-via-okta</loc>
    <lastmod>2026-07-28T23:28:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-okta-identity-provider-via-okta</loc>
    <lastmod>2026-07-28T23:28:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-mfa-reset-or-deactivated-via-okta</loc>
    <lastmod>2026-07-28T23:28:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-network-zone-deactivated-or-deleted-via-okta</loc>
    <lastmod>2026-07-28T23:28:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-new-admin-console-behaviours-via-okta</loc>
    <lastmod>2026-07-28T23:28:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-okta-password-in-alternateid-field-via-okta</loc>
    <lastmod>2026-07-28T23:28:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-okta-policy-modified-or-deleted-via-okta</loc>
    <lastmod>2026-07-28T23:28:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-policy-rule-modified-or-deleted-via-okta</loc>
    <lastmod>2026-07-28T23:28:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-security-threat-detected-via-okta</loc>
    <lastmod>2026-07-28T23:28:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-suspicious-behavior-reported-by-end-user-via-okta</loc>
    <lastmod>2026-07-28T23:28:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-unauthorized-access-to-app-via-okta</loc>
    <lastmod>2026-07-28T23:28:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-user-account-locked-out-via-okta</loc>
    <lastmod>2026-07-28T23:28:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-new-okta-user-via-okta</loc>
    <lastmod>2026-07-28T23:28:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-user-session-start-through-an-anonymising-proxy-service-via-okta</loc>
    <lastmod>2026-07-28T23:28:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-onelogin-user-assumed-another-user-via-onelogin-events</loc>
    <lastmod>2026-07-28T23:28:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-onelogin-user-account-locked-via-onelogin-events</loc>
    <lastmod>2026-07-28T23:28:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-binary-padding-linux-via-auditd</loc>
    <lastmod>2026-07-28T23:28:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bpfdoor-tcp-ports-redirect-via-auditd</loc>
    <lastmod>2026-07-28T23:28:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-capabilities-enumeration-via-auditd</loc>
    <lastmod>2026-07-28T23:28:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-time-attribute-change-linux-via-auditd</loc>
    <lastmod>2026-07-28T23:28:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remove-immutable-file-attribute-auditd-via-auditd</loc>
    <lastmod>2026-07-28T23:28:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-clipboard-collection-with-xclip-utility-auditd-via-auditd</loc>
    <lastmod>2026-07-28T23:28:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-clipboard-collection-of-image-data-with-xclip-utility-via-auditd</loc>
    <lastmod>2026-07-28T23:28:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-coin-miner-cpu-priority-param-via-auditd</loc>
    <lastmod>2026-07-28T23:28:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-data-compressed-via-auditd</loc>
    <lastmod>2026-07-28T23:28:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-with-wget-via-auditd</loc>
    <lastmod>2026-07-28T23:28:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-overwriting-the-file-with-dev-zero-or-null-via-auditd</loc>
    <lastmod>2026-07-28T23:28:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-or-folder-permissions-change-via-auditd</loc>
    <lastmod>2026-07-28T23:28:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credentials-in-files-linux-via-auditd</loc>
    <lastmod>2026-07-28T23:28:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-hidden-files-and-directories-via-auditd</loc>
    <lastmod>2026-07-28T23:28:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-steganography-hide-zip-information-in-picture-file-via-auditd</loc>
    <lastmod>2026-07-28T23:28:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-masquerading-as-linux-crond-process-via-auditd</loc>
    <lastmod>2026-07-28T23:28:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modify-system-firewall-via-auditd</loc>
    <lastmod>2026-07-28T23:28:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-network-sniffing-linux-via-auditd</loc>
    <lastmod>2026-07-28T23:28:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-screen-capture-with-import-utility-via-auditd</loc>
    <lastmod>2026-07-28T23:28:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-screen-capture-with-xwd-via-auditd</loc>
    <lastmod>2026-07-28T23:28:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-steganography-hide-files-with-steghide-via-auditd</loc>
    <lastmod>2026-07-28T23:28:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-steganography-extract-files-with-steghide-via-auditd</loc>
    <lastmod>2026-07-28T23:27:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-commands-linux-via-auditd</loc>
    <lastmod>2026-07-28T23:27:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-history-file-operations-linux-via-auditd</loc>
    <lastmod>2026-07-28T23:27:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-service-reload-or-start-linux-via-auditd</loc>
    <lastmod>2026-07-28T23:27:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-shutdown-reboot-linux-via-auditd</loc>
    <lastmod>2026-07-28T23:27:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-steganography-unzip-hidden-information-from-picture-file-via-auditd</loc>
    <lastmod>2026-07-28T23:27:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-owner-or-user-enumeration-linux-via-auditd</loc>
    <lastmod>2026-07-28T23:27:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-audio-capture-via-auditd</loc>
    <lastmod>2026-07-28T23:27:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aslr-disabled-through-sysctl-or-direct-syscall-linux-via-auditd</loc>
    <lastmod>2026-07-28T23:27:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-keylogging-with-pam-d-via-auditd</loc>
    <lastmod>2026-07-28T23:27:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-password-policy-enumeration-linux-via-auditd</loc>
    <lastmod>2026-07-28T23:27:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-c2-activities-via-auditd</loc>
    <lastmod>2026-07-28T23:27:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-auditd-via-auditd</loc>
    <lastmod>2026-07-28T23:27:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-auditing-configuration-changes-on-linux-host-via-auditd</loc>
    <lastmod>2026-07-28T23:27:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bpfdoor-abnormal-process-id-or-lock-file-accessed-via-auditd</loc>
    <lastmod>2026-07-28T23:27:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-use-of-hidden-paths-or-files-via-auditd</loc>
    <lastmod>2026-07-28T23:27:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-ld-so-preload-via-auditd</loc>
    <lastmod>2026-07-28T23:27:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-logging-configuration-changes-on-linux-host-via-auditd</loc>
    <lastmod>2026-07-28T23:27:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-misuse-of-linux-magic-system-request-key-via-auditd</loc>
    <lastmod>2026-07-28T23:27:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-and-hardware-information-enumeration-via-auditd</loc>
    <lastmod>2026-07-28T23:27:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-systemd-service-creation-via-auditd</loc>
    <lastmod>2026-07-28T23:27:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unix-shell-configuration-change-via-auditd</loc>
    <lastmod>2026-07-28T23:27:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-system-firewall-via-auditd</loc>
    <lastmod>2026-07-28T23:27:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clear-or-disable-kernel-ring-buffer-logs-through-syslog-syscall-via-auditd</loc>
    <lastmod>2026-07-28T23:27:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-an-user-account-via-auditd</loc>
    <lastmod>2026-07-28T23:27:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-loading-of-kernel-module-through-insmod-via-auditd</loc>
    <lastmod>2026-07-28T23:27:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-network-service-scanning-auditd-via-auditd</loc>
    <lastmod>2026-07-28T23:27:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-split-a-file-into-pieces-linux-via-auditd</loc>
    <lastmod>2026-07-28T23:27:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-info-enumeration-through-sysinfo-syscall-via-auditd</loc>
    <lastmod>2026-07-28T23:27:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/program-executions-in-suspicious-folders-via-auditd</loc>
    <lastmod>2026-07-28T23:27:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-special-file-creation-through-mknod-syscall-via-auditd</loc>
    <lastmod>2026-07-28T23:27:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-webshell-remote-command-via-auditd</loc>
    <lastmod>2026-07-28T23:27:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-relevant-clamav-message-via-clamav</loc>
    <lastmod>2026-07-28T23:27:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modifying-crontab-via-cron</loc>
    <lastmod>2026-07-28T23:27:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-guacamole-two-users-sharing-session-anomaly-via-guacamole</loc>
    <lastmod>2026-07-28T23:27:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-equation-group-indicators-via-linux</loc>
    <lastmod>2026-07-28T23:27:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-buffer-overflow-attempts-via-linux</loc>
    <lastmod>2026-07-28T23:27:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-commands-to-clear-or-remove-the-syslog-builtin-via-linux</loc>
    <lastmod>2026-07-28T23:27:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-file-copy-via-linux</loc>
    <lastmod>2026-07-28T23:27:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-code-injection-by-ld-so-preload-via-linux</loc>
    <lastmod>2026-07-28T23:27:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-bpf-behavior-linux-via-linux</loc>
    <lastmod>2026-07-28T23:27:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-privileged-user-has-been-via-linux</loc>
    <lastmod>2026-07-28T23:27:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-command-history-manipulation-via-linux</loc>
    <lastmod>2026-07-28T23:27:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-behavior-in-shell-commands-via-linux</loc>
    <lastmod>2026-07-28T23:27:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-log-entries-via-linux</loc>
    <lastmod>2026-07-28T23:27:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-reverse-shell-command-line-via-linux</loc>
    <lastmod>2026-07-28T23:27:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shellshock-expression-via-linux</loc>
    <lastmod>2026-07-28T23:27:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-dev-tcp-via-linux</loc>
    <lastmod>2026-07-28T23:27:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-jexboss-command-sequence-via-linux</loc>
    <lastmod>2026-07-28T23:27:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-symlink-etc-passwd-via-linux</loc>
    <lastmod>2026-07-28T23:27:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-openssh-daemon-error-via-sshd</loc>
    <lastmod>2026-07-28T23:27:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-security-utilities-builtin-via-syslog</loc>
    <lastmod>2026-07-28T23:27:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-named-error-via-syslog</loc>
    <lastmod>2026-07-28T23:27:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vsftpd-error-messages-via-vsftpd</loc>
    <lastmod>2026-07-28T23:27:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-doas-conf-file-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:27:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-through-sudoers-d-files-via-file-event</loc>
    <lastmod>2026-07-28T23:27:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-new-cron-file-via-file-event</loc>
    <lastmod>2026-07-28T23:27:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-filename-with-embedded-base64-commands-via-file-event</loc>
    <lastmod>2026-07-28T23:27:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-shell-script-creation-in-profile-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:27:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-triple-cross-ebpf-rootkit-default-lockfile-via-file-event</loc>
    <lastmod>2026-07-28T23:27:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-triple-cross-ebpf-rootkit-default-persistence-via-file-event</loc>
    <lastmod>2026-07-28T23:26:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wget-creating-files-in-tmp-directory-via-file-event</loc>
    <lastmod>2026-07-28T23:26:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-reverse-shell-indicator-via-network-connection</loc>
    <lastmod>2026-07-28T23:26:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-crypto-mining-pool-connections-via-network-connection</loc>
    <lastmod>2026-07-28T23:26:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-traffic-to-localtonet-tunneling-service-initiated-linux-via-network-connection</loc>
    <lastmod>2026-07-28T23:26:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-traffic-to-ngrok-tunneling-service-linux-via-network-connection</loc>
    <lastmod>2026-07-28T23:26:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-malware-callback-traffic-linux-via-network-connection</loc>
    <lastmod>2026-07-28T23:26:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-invocation-through-apt-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-scheduled-task-job-at-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-audit-rules-deleted-through-auditctl-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kaspersky-endpoint-security-stopped-through-commandline-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invocation-of-shell-through-awk-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-decode-base64-encoded-text-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-base64-encoded-pipe-to-shell-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-base64-encoded-shebang-in-cli-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-bash-interactive-shell-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-bpf-kprobes-tracing-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bpftrace-unsafe-option-use-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-setgid-capability-set-on-a-binary-through-setcap-utility-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-setuid-capability-set-on-a-binary-through-setcap-utility-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-capabilities-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-capsh-shell-invocation-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remove-immutable-file-attribute-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chmod-targeting-sensitive-directories-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-linux-sudo-chroot-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-logs-clearing-attempts-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-syslog-clearing-or-removal-through-system-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-clipboard-collection-with-xclip-utility-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copy-passwd-or-shadow-from-tmp-path-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-crontab-enumeration-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remove-scheduled-cron-task-job-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-crypto-mining-indicators-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-curl-use-on-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-and-execute-pattern-through-curl-wget-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dd-file-overwrite-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-process-code-injection-through-dd-utility-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ufw-disable-attempt-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-linux-doas-utility-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-invocation-through-env-command-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-esxi-network-configuration-enumeration-through-esxcli-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esxi-admin-permission-assigned-to-account-through-esxcli-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-esxi-storage-information-enumeration-through-esxcli-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esxi-syslog-configuration-change-through-esxcli-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-esxi-system-information-enumeration-through-esxcli-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esxi-account-creation-through-esxcli-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-esxi-vm-list-enumeration-through-esxcli-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esxi-vm-kill-through-esxcli-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-esxi-vsan-information-enumeration-through-esxcli-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-and-directory-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-removal-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-through-find-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-through-flock-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-gcc-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-through-git-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-os-architecture-enumeration-through-grep-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-group-has-been-deleted-through-groupdel-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-install-root-certificate-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-package-installed-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-flush-iptables-ufw-chain-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-system-accounts-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:26:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-groups-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-gobrat-file-enumeration-through-grep-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-named-pipe-created-through-mkfifo-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-named-pipe-created-through-mkfifo-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mount-execution-with-hidepid-parameter-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-netcat-reverse-shell-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-through-nice-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-nohup-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-nohup-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-omigod-scx-runasprovider-executescript-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-omigod-scx-runasprovider-executeshellcommand-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-perl-reverse-shell-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-php-reverse-shell-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pnscan-binary-data-transmission-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-connection-proxy-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pua-trufflehog-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-one-liners-with-base64-decoding-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-python-webserver-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-spawning-pretty-tty-through-pty-module-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-reverse-shell-execution-through-pty-and-socket-modules-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-inline-python-spawn-shell-via-os-system-library-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-team-viewer-session-started-on-linux-host-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-remote-system-enumeration-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-package-uninstall-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-through-rsync-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invocation-of-shell-through-rsync-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ruby-reverse-shell-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-cron-task-job-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-security-software-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-security-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-or-stop-services-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-setuid-and-setgid-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-invocation-through-ssh-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-amazon-ssm-agent-hijacking-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-container-residence-enumeration-through-proc-virtual-fs-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-file-upload-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-change-user-agents-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-docker-container-enumeration-through-dockerenv-listing-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-execution-from-shared-memory-directory-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-execution-from-tmp-folder-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-behavior-via-find-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-git-clone-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-history-file-removal-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-print-history-file-contents-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-linux-hacktool-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-container-enumeration-through-inodes-listing-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/interactive-bash-suspicious-children-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-java-children-processes-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-linux-network-service-scanning-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-shell-pipe-to-shell-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-of-sudoers-file-content-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-recon-indicators-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-interpreter-spawning-credential-scanner-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-change-to-sensitive-critical-files-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-of-process-located-in-tmp-directory-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-script-located-in-potentially-suspicious-directory-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-network-connections-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-network-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mask-system-power-settings-through-systemctl-via-process-creation</loc>
    <lastmod>2026-07-28T23:25:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/touch-suspicious-service-file-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-triple-cross-ebpf-rootkit-execve-hijack-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-triple-cross-ebpf-rootkit-install-commands-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-has-been-deleted-through-userdel-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-root-sudoers-group-via-usermod-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vim-gtfobin-misuse-linux-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-linux-webshell-indicators-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/download-file-to-potentially-suspicious-directory-through-wget-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-xterm-reverse-shell-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-emond-launch-daemon-via-file-event</loc>
    <lastmod>2026-07-28T23:24:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-startup-item-file-macos-via-file-event</loc>
    <lastmod>2026-07-28T23:24:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-scripting-interpreter-applescript-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-decode-base64-encoded-text-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-binary-padding-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-time-attribute-change-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-flag-set-on-file-directory-through-chflags-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-indicator-removal-on-host-clear-mac-system-logs-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clipboard-access-through-osascript-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-a-local-user-account-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-user-creation-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credentials-from-password-stores-keychain-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-system-integrity-protection-sip-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-integrity-protection-sip-enumeration-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-security-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-admin-group-through-dscl-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-admin-group-through-dseditgroup-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-root-account-enable-through-dsenableroot-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-and-directory-enumeration-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credentials-in-files-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-gui-input-capture-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disk-image-creation-through-hdiutil-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disk-image-mounting-through-hdiutil-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-installer-package-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-via-ioreg-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/jamf-mdm-possible-suspicious-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-jamf-mdm-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-jxa-in-memory-execution-through-osascript-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-launch-agent-daemon-execution-through-launchctl-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-system-accounts-enumeration-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-groups-enumeration-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-macos-network-service-scanning-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-network-sniffing-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-through-nscurl-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-office-child-process-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-osacompile-run-only-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-payload-decoded-and-decrypted-through-built-in-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-plistbuddy-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-remote-access-utility-possible-meshagent-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-remote-access-utility-renamed-meshagent-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-team-viewer-session-started-on-macos-host-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-macos-remote-system-enumeration-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-cron-task-job-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-screen-capture-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-security-software-enumeration-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-space-after-filename-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-split-a-file-into-pieces-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-child-process-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-through-macos-script-editor-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-behavior-via-find-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-history-file-operations-via-process-creation</loc>
    <lastmod>2026-07-28T23:24:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-in-memory-download-and-compile-of-payloads-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-firmware-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-network-enumeration-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/osacompile-execution-by-potentially-suspicious-applet-osascript-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-via-sw-vers-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-admin-group-through-sysadminctl-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-guest-account-enabled-through-sysadminctl-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-through-sysctl-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-network-connections-enumeration-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-via-system-profiler-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-shutdown-reboot-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-base64-decoded-from-images-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-time-machine-backup-removal-attempt-through-tmutil-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-time-machine-backup-disabled-through-tmutil-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-file-exclusion-added-to-time-machine-through-tmutil-macos-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-wizardupdate-malware-infection-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-gatekeeper-bypass-through-xattr-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-xcsset-malware-infection-via-process-creation</loc>
    <lastmod>2026-07-28T23:23:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-clear-logs-via-aaa</loc>
    <lastmod>2026-07-28T23:23:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cisco-collect-data-via-aaa</loc>
    <lastmod>2026-07-28T23:23:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-crypto-commands-via-aaa</loc>
    <lastmod>2026-07-28T23:23:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-disabling-logging-via-aaa</loc>
    <lastmod>2026-07-28T23:23:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cisco-enumeration-via-aaa</loc>
    <lastmod>2026-07-28T23:23:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-denial-of-service-via-aaa</loc>
    <lastmod>2026-07-28T23:23:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-cisco-dot1x-via-aaa</loc>
    <lastmod>2026-07-28T23:23:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-file-removal-via-aaa</loc>
    <lastmod>2026-07-28T23:23:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-show-commands-input-via-aaa</loc>
    <lastmod>2026-07-28T23:23:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-local-accounts-via-aaa</loc>
    <lastmod>2026-07-28T23:23:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-modify-configuration-via-aaa</loc>
    <lastmod>2026-07-28T23:23:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cisco-stage-data-via-aaa</loc>
    <lastmod>2026-07-28T23:23:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-sniffing-via-aaa</loc>
    <lastmod>2026-07-28T23:23:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cisco-bgp-authentication-failures-via-bgp</loc>
    <lastmod>2026-07-28T23:23:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cisco-ldp-authentication-failures-via-ldp</loc>
    <lastmod>2026-07-28T23:23:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-external-service-interaction-domains-via-dns</loc>
    <lastmod>2026-07-28T23:23:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cobalt-strike-dns-beaconing-via-dns</loc>
    <lastmod>2026-07-28T23:23:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-monero-crypto-coin-mining-pool-lookup-via-dns</loc>
    <lastmod>2026-07-28T23:23:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-query-with-b64-encoded-string-via-dns</loc>
    <lastmod>2026-07-28T23:23:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-telegram-bot-api-request-via-dns</loc>
    <lastmod>2026-07-28T23:23:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dns-txt-answer-with-possible-execution-strings-via-dns</loc>
    <lastmod>2026-07-28T23:23:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wannacry-killswitch-domain-via-dns</loc>
    <lastmod>2026-07-28T23:23:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cleartext-protocol-use-via-firewall</loc>
    <lastmod>2026-07-28T23:23:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-new-administrator-account-created-via-event</loc>
    <lastmod>2026-07-28T23:23:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-firewall-address-object-added-via-event</loc>
    <lastmod>2026-07-28T23:23:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-new-firewall-policy-added-via-event</loc>
    <lastmod>2026-07-28T23:23:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-new-local-user-created-via-event</loc>
    <lastmod>2026-07-28T23:23:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-new-vpn-ssl-web-portal-added-via-event</loc>
    <lastmod>2026-07-28T23:23:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-user-group-modified-via-event</loc>
    <lastmod>2026-07-28T23:23:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-vpn-ssl-settings-modified-via-event</loc>
    <lastmod>2026-07-28T23:23:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-huawei-bgp-authentication-failures-via-bgp</loc>
    <lastmod>2026-07-28T23:23:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-juniper-bgp-missing-md5-via-bgp</loc>
    <lastmod>2026-07-28T23:23:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-mitre-bzar-indicators-for-via-dce-rpc</loc>
    <lastmod>2026-07-28T23:23:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mitre-bzar-indicators-for-persistence-via-dce-rpc</loc>
    <lastmod>2026-07-28T23:23:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-petitpotam-attack-through-efs-rpc-calls-via-dce-rpc</loc>
    <lastmod>2026-07-28T23:23:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-smb-spoolss-name-piped-use-via-smb-files</loc>
    <lastmod>2026-07-28T23:23:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-default-cobalt-strike-certificate-via-x509</loc>
    <lastmod>2026-07-28T23:23:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-query-indicating-kerberos-coercion-through-dns-object-spn-spoofing-network-via-dns</loc>
    <lastmod>2026-07-28T23:23:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-events-related-to-mining-pools-via-dns</loc>
    <lastmod>2026-07-28T23:23:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-kind-of-network-nkn-via-dns</loc>
    <lastmod>2026-07-28T23:23:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-z-flag-bit-set-via-dns</loc>
    <lastmod>2026-07-28T23:23:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-tor-proxies-via-dns</loc>
    <lastmod>2026-07-28T23:23:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-from-webdav-via-http</loc>
    <lastmod>2026-07-28T23:22:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/http-request-to-low-reputation-tld-or-suspicious-file-extension-via-http</loc>
    <lastmod>2026-07-28T23:22:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-webdav-put-request-via-http</loc>
    <lastmod>2026-07-28T23:22:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-publicly-accessible-rdp-service-via-rdp</loc>
    <lastmod>2026-07-28T23:22:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-task-creation-through-atsvc-named-pipe-zeek-via-smb-files</loc>
    <lastmod>2026-07-28T23:22:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-impacket-secretdump-remote-behavior-zeek-via-smb-files</loc>
    <lastmod>2026-07-28T23:22:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-first-time-seen-remote-named-pipe-zeek-via-smb-files</loc>
    <lastmod>2026-07-28T23:22:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-psexec-zeek-via-smb-files</loc>
    <lastmod>2026-07-28T23:22:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-to-sensitive-file-extensions-zeek-via-smb-files</loc>
    <lastmod>2026-07-28T23:22:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-transferring-files-with-credential-data-through-network-shares-zeek-via-smb-files</loc>
    <lastmod>2026-07-28T23:22:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kerberos-network-traffic-rc4-ticket-encryption-via-kerberos</loc>
    <lastmod>2026-07-28T23:22:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-apache-segmentation-fault-via-apache</loc>
    <lastmod>2026-07-28T23:22:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-apache-threading-error-via-apache</loc>
    <lastmod>2026-07-28T23:22:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-nginx-core-dump-via-nginx</loc>
    <lastmod>2026-07-28T23:22:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/download-from-suspicious-dyndns-hosts-via-proxy</loc>
    <lastmod>2026-07-28T23:22:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/download-from-suspicious-tld-blacklist-via-proxy</loc>
    <lastmod>2026-07-28T23:22:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/download-from-suspicious-tld-whitelist-via-proxy</loc>
    <lastmod>2026-07-28T23:22:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-webdav-user-agent-via-proxy</loc>
    <lastmod>2026-07-28T23:22:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-f5-big-ip-icontrol-rest-api-command-proxy-via-proxy</loc>
    <lastmod>2026-07-28T23:22:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-hello-world-scraper-botnet-behavior-via-proxy</loc>
    <lastmod>2026-07-28T23:22:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-babyshark-agent-default-url-pattern-via-proxy</loc>
    <lastmod>2026-07-28T23:22:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-cobaltstrike-malleable-profile-patterns-proxy-via-proxy</loc>
    <lastmod>2026-07-28T23:22:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-empire-useragent-uri-combo-via-proxy</loc>
    <lastmod>2026-07-28T23:22:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-advanced-ip-port-scanner-update-check-via-proxy</loc>
    <lastmod>2026-07-28T23:22:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pwndrp-access-via-proxy</loc>
    <lastmod>2026-07-28T23:22:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-raw-paste-service-access-via-proxy</loc>
    <lastmod>2026-07-28T23:22:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/flash-player-update-from-suspicious-location-via-proxy</loc>
    <lastmod>2026-07-28T23:22:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-traffic-with-ipfs-via-proxy</loc>
    <lastmod>2026-07-28T23:22:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-telegram-api-access-via-proxy</loc>
    <lastmod>2026-07-28T23:22:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-apt-user-agent-via-proxy</loc>
    <lastmod>2026-07-28T23:22:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-base64-encoded-user-agent-via-proxy</loc>
    <lastmod>2026-07-28T23:22:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitsadmin-to-unusual-ip-server-address-via-proxy</loc>
    <lastmod>2026-07-28T23:22:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitsadmin-to-unusual-tld-via-proxy</loc>
    <lastmod>2026-07-28T23:22:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-crypto-miner-user-agent-via-proxy</loc>
    <lastmod>2026-07-28T23:22:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-http-request-with-empty-user-agent-via-proxy</loc>
    <lastmod>2026-07-28T23:22:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-exploit-framework-user-agent-via-proxy</loc>
    <lastmod>2026-07-28T23:22:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hack-utility-user-agent-via-proxy</loc>
    <lastmod>2026-07-28T23:22:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-malware-user-agent-via-proxy</loc>
    <lastmod>2026-07-28T23:22:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-powershell-user-agent-via-proxy</loc>
    <lastmod>2026-07-28T23:22:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rclone-behavior-through-proxy-via-proxy</loc>
    <lastmod>2026-07-28T23:22:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-agent-via-proxy</loc>
    <lastmod>2026-07-28T23:22:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-base64-encoded-user-agent-via-proxy</loc>
    <lastmod>2026-07-28T23:22:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-external-webdav-via-proxy</loc>
    <lastmod>2026-07-28T23:22:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-f5-big-ip-icontrol-rest-api-command-webserver-via-webserver</loc>
    <lastmod>2026-07-28T23:22:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-successful-iis-shortname-fuzzing-scan-via-webserver</loc>
    <lastmod>2026-07-28T23:22:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-java-payload-strings-via-webserver</loc>
    <lastmod>2026-07-28T23:22:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-jndiexploit-pattern-via-webserver</loc>
    <lastmod>2026-07-28T23:22:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-path-traversal-exploitation-attempts-via-webserver</loc>
    <lastmod>2026-07-28T23:22:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-source-code-enumeration-detection-by-keyword-via-webserver</loc>
    <lastmod>2026-07-28T23:22:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-injection-strings-in-uri-via-webserver</loc>
    <lastmod>2026-07-28T23:22:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-server-side-template-injection-strings-via-webserver</loc>
    <lastmod>2026-07-28T23:22:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-agents-related-to-recon-utilities-via-webserver</loc>
    <lastmod>2026-07-28T23:22:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-strings-in-uri-via-webserver</loc>
    <lastmod>2026-07-28T23:22:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webshell-regeorg-detection-through-web-logs-via-webserver</loc>
    <lastmod>2026-07-28T23:22:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-webshell-strings-via-webserver</loc>
    <lastmod>2026-07-28T23:22:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cross-site-scripting-strings-via-webserver</loc>
    <lastmod>2026-07-28T23:22:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-relevant-anti-virus-signature-keywords-in-application-log-via-application</loc>
    <lastmod>2026-07-28T23:22:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-process-crashed-application-via-application</loc>
    <lastmod>2026-07-28T23:22:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-malware-protection-engine-crash-via-application</loc>
    <lastmod>2026-07-28T23:22:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntdsutil-misuse-via-application</loc>
    <lastmod>2026-07-28T23:22:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dump-ntds-dit-to-suspicious-location-via-application</loc>
    <lastmod>2026-07-28T23:21:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-audit-cve-event-via-application</loc>
    <lastmod>2026-07-28T23:21:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-backup-catalog-via-application</loc>
    <lastmod>2026-07-28T23:21:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-restricted-software-access-by-srp-via-application</loc>
    <lastmod>2026-07-28T23:21:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-application-uninstalled-via-application</loc>
    <lastmod>2026-07-28T23:21:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/msi-deployment-from-suspicious-locations-via-application</loc>
    <lastmod>2026-07-28T23:21:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msi-deployment-from-web-via-application</loc>
    <lastmod>2026-07-28T23:21:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-atera-agent-deployment-via-application</loc>
    <lastmod>2026-07-28T23:21:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mssql-add-account-to-sysadmin-role-via-application</loc>
    <lastmod>2026-07-28T23:21:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mssql-destructive-query-via-application</loc>
    <lastmod>2026-07-28T23:21:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mssql-disable-audit-settings-via-application</loc>
    <lastmod>2026-07-28T23:21:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mssql-server-failed-logon-via-application</loc>
    <lastmod>2026-07-28T23:21:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mssql-server-failed-logon-from-external-network-via-application</loc>
    <lastmod>2026-07-28T23:21:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mssql-spprocoption-set-via-application</loc>
    <lastmod>2026-07-28T23:21:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-mssql-xpcmdshell-suspicious-via-application</loc>
    <lastmod>2026-07-28T23:21:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mssql-xpcmdshell-option-change-via-application</loc>
    <lastmod>2026-07-28T23:21:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-screenconnect-command-execution-via-application</loc>
    <lastmod>2026-07-28T23:21:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-screenconnect-file-transfer-via-application</loc>
    <lastmod>2026-07-28T23:21:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-malware-protection-engine-crash-wer-via-application</loc>
    <lastmod>2026-07-28T23:21:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-applocker-prevented-application-or-script-from-running-via-applocker</loc>
    <lastmod>2026-07-28T23:21:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-applocker-application-would-have-been-blocked-via-applocker</loc>
    <lastmod>2026-07-28T23:21:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-sysinternals-utilities-appx-versions-via-appmodel-runtime</loc>
    <lastmod>2026-07-28T23:21:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deployment-appx-package-was-blocked-by-applocker-via-appxdeployment-server</loc>
    <lastmod>2026-07-28T23:21:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-appx-package-downloaded-from-file-sharing-or-cdn-domain-via-appxdeployment-server</loc>
    <lastmod>2026-07-28T23:21:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-appx-package-deployment-failed-due-to-signing-requirements-via-appxdeployment-server</loc>
    <lastmod>2026-07-28T23:21:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-appx-located-in-known-staging-directory-added-to-deployment-pipeline-via-appxdeployment-server</loc>
    <lastmod>2026-07-28T23:21:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-malicious-appx-package-deployment-attempts-via-appxdeployment-server</loc>
    <lastmod>2026-07-28T23:21:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deployment-of-the-appx-package-was-blocked-by-the-policy-via-appxdeployment-server</loc>
    <lastmod>2026-07-28T23:21:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/appx-located-in-unusual-directory-added-to-deployment-pipeline-via-appxdeployment-server</loc>
    <lastmod>2026-07-28T23:21:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-appx-deployment-full-trust-package-deployment-via-appxdeployment-server</loc>
    <lastmod>2026-07-28T23:21:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-appx-deployment-unsigned-package-deployment-via-appxdeployment-server</loc>
    <lastmod>2026-07-28T23:21:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-digital-signature-of-appx-package-via-appxpackaging-om</loc>
    <lastmod>2026-07-28T23:21:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-bits-job-created-through-bitsadmin-via-bits-client</loc>
    <lastmod>2026-07-28T23:21:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-bits-job-created-through-powershell-via-bits-client</loc>
    <lastmod>2026-07-28T23:21:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bits-transfer-job-downloading-file-possible-suspicious-extension-via-bits-client</loc>
    <lastmod>2026-07-28T23:21:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bits-transfer-job-download-from-file-sharing-domains-via-bits-client</loc>
    <lastmod>2026-07-28T23:21:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bits-transfer-job-download-from-direct-ip-via-bits-client</loc>
    <lastmod>2026-07-28T23:21:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bits-transfer-job-with-unusual-or-suspicious-remote-tld-via-bits-client</loc>
    <lastmod>2026-07-28T23:21:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bits-transfer-job-download-to-possible-suspicious-folder-via-bits-client</loc>
    <lastmod>2026-07-28T23:21:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-private-key-acquired-via-capi2</loc>
    <lastmod>2026-07-28T23:21:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-exported-from-local-certificate-store-via-certificateservicesclient-lifecycle-system</loc>
    <lastmod>2026-07-28T23:21:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-codeintegrity-unmet-signing-level-requirements-by-file-under-validation-via-codeintegrity-operational</loc>
    <lastmod>2026-07-28T23:21:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-disallowed-file-for-protected-processes-has-been-blocked-via-codeintegrity-operational</loc>
    <lastmod>2026-07-28T23:21:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-blocked-image-driver-load-for-policy-violation-via-codeintegrity-operational</loc>
    <lastmod>2026-07-28T23:21:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-blocked-driver-load-with-revoked-certificate-via-codeintegrity-operational</loc>
    <lastmod>2026-07-28T23:21:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-revoked-kernel-driver-loaded-via-codeintegrity-operational</loc>
    <lastmod>2026-07-28T23:21:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-blocked-image-load-with-revoked-certificate-via-codeintegrity-operational</loc>
    <lastmod>2026-07-28T23:21:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-revoked-image-loaded-via-codeintegrity-operational</loc>
    <lastmod>2026-07-28T23:21:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-unsigned-kernel-module-loaded-via-codeintegrity-operational</loc>
    <lastmod>2026-07-28T23:21:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-unsigned-image-loaded-via-codeintegrity-operational</loc>
    <lastmod>2026-07-28T23:21:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-unmet-whql-requirements-for-loaded-kernel-module-via-codeintegrity-operational</loc>
    <lastmod>2026-07-28T23:21:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-loading-diagcab-package-from-remote-path-via-diagnosis-scripted</loc>
    <lastmod>2026-07-28T23:21:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-for-anonfiles-com-domain-dns-client-via-dns-client</loc>
    <lastmod>2026-07-28T23:21:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cobalt-strike-dns-beaconing-dns-client-via-dns-client</loc>
    <lastmod>2026-07-28T23:21:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-mega-hosting-website-dns-client-via-dns-client</loc>
    <lastmod>2026-07-28T23:21:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-put-io-dns-client-via-dns-client</loc>
    <lastmod>2026-07-28T23:21:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-query-tor-onion-address-dns-client-via-dns-client</loc>
    <lastmod>2026-07-28T23:21:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-ufile-io-dns-client-via-dns-client</loc>
    <lastmod>2026-07-28T23:21:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-failed-dns-zone-transfer-via-dns-server</loc>
    <lastmod>2026-07-28T23:21:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-server-error-failed-loading-the-serverlevelplugindll-via-dns-server</loc>
    <lastmod>2026-07-28T23:21:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-usb-device-plugged-via-driver-framework</loc>
    <lastmod>2026-07-28T23:20:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-new-firewall-rule-added-in-windows-firewall-exception-list-via-firewall-as</loc>
    <lastmod>2026-07-28T23:20:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/new-firewall-rule-added-in-windows-firewall-exception-list-for-possible-suspicious-application-via-firewall-as</loc>
    <lastmod>2026-07-28T23:20:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-firewall-rule-added-in-windows-firewall-exception-list-through-wmiprvse-exe-via-firewall-as</loc>
    <lastmod>2026-07-28T23:20:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-all-rules-have-been-deleted-from-the-windows-firewall-configuration-via-firewall-as</loc>
    <lastmod>2026-07-28T23:20:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-a-rule-has-been-deleted-from-the-windows-firewall-exception-list-via-firewall-as</loc>
    <lastmod>2026-07-28T23:20:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-the-windows-defender-firewall-service-failed-to-load-group-policy-via-firewall-as</loc>
    <lastmod>2026-07-28T23:20:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-defender-firewall-has-been-reset-to-its-default-configuration-via-firewall-as</loc>
    <lastmod>2026-07-28T23:20:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-firewall-settings-have-been-changed-via-firewall-as</loc>
    <lastmod>2026-07-28T23:20:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-etw-logging-processing-option-disabled-on-iis-server-via-iis-configuration</loc>
    <lastmod>2026-07-28T23:20:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-http-logging-disabled-on-iis-server-via-iis-configuration</loc>
    <lastmod>2026-07-28T23:20:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-module-module-added-to-iis-server-via-iis-configuration</loc>
    <lastmod>2026-07-28T23:20:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-removal-of-previously-installed-iis-module-was-via-iis-configuration</loc>
    <lastmod>2026-07-28T23:20:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-reconnaissance-enumeration-through-ldap-via-ldap</loc>
    <lastmod>2026-07-28T23:20:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-standard-user-in-high-privileged-group-via-lsa-server</loc>
    <lastmod>2026-07-28T23:20:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-proxylogon-msexchange-oabvirtualdirectory-via-msexchange-management</loc>
    <lastmod>2026-07-28T23:20:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-request-export-to-exchange-webserver-via-msexchange-management</loc>
    <lastmod>2026-07-28T23:20:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mailbox-export-to-exchange-webserver-via-msexchange-management</loc>
    <lastmod>2026-07-28T23:20:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remove-exported-mailbox-from-exchange-webserver-via-msexchange-management</loc>
    <lastmod>2026-07-28T23:20:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-exchange-set-oabvirtualdirectory-externalurl-property-via-msexchange-management</loc>
    <lastmod>2026-07-28T23:20:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msexchange-transport-agent-deployment-builtin-via-msexchange-management</loc>
    <lastmod>2026-07-28T23:20:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-failed-msexchange-transport-agent-deployment-via-msexchange-management</loc>
    <lastmod>2026-07-28T23:20:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ntlm-logon-via-ntlm</loc>
    <lastmod>2026-07-28T23:20:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntlm-brute-force-via-ntlm</loc>
    <lastmod>2026-07-28T23:20:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-desktop-connection-to-non-domain-host-via-ntlm</loc>
    <lastmod>2026-07-28T23:20:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-openssh-server-listening-on-socket-via-openssh</loc>
    <lastmod>2026-07-28T23:20:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-access-token-misuse-via-security</loc>
    <lastmod>2026-07-28T23:20:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-admin-user-remote-logon-via-security</loc>
    <lastmod>2026-07-28T23:20:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-diagtrackeop-default-login-username-via-security</loc>
    <lastmod>2026-07-28T23:20:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-a-member-was-added-to-a-security-enabled-global-group-via-security</loc>
    <lastmod>2026-07-28T23:20:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-a-member-was-removed-from-a-security-enabled-global-group-via-security</loc>
    <lastmod>2026-07-28T23:20:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-successful-overpass-the-hash-attempt-via-security</loc>
    <lastmod>2026-07-28T23:20:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pass-the-hash-behavior-2-via-security</loc>
    <lastmod>2026-07-28T23:20:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-login-from-localhost-via-security</loc>
    <lastmod>2026-07-28T23:20:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-removal-of-a-security-enabled-global-group-was-via-security</loc>
    <lastmod>2026-07-28T23:20:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-external-remote-rdp-logon-from-public-ip-via-security</loc>
    <lastmod>2026-07-28T23:20:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-external-remote-smb-logon-from-public-ip-via-security</loc>
    <lastmod>2026-07-28T23:20:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-failed-logon-from-public-ip-via-security</loc>
    <lastmod>2026-07-28T23:20:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-outgoing-logon-with-new-credentials-via-security</loc>
    <lastmod>2026-07-28T23:20:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privilege-escalation-through-local-kerberos-relay-over-ldap-via-security</loc>
    <lastmod>2026-07-28T23:20:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rottenpotato-like-attack-pattern-via-security</loc>
    <lastmod>2026-07-28T23:20:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-successful-account-login-through-wmi-via-security</loc>
    <lastmod>2026-07-28T23:20:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-filtering-platform-blocked-connection-from-edr-agent-binary-via-security</loc>
    <lastmod>2026-07-28T23:20:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-ad-health-monitoring-agent-registry-keys-access-via-security</loc>
    <lastmod>2026-07-28T23:20:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-ad-health-service-agents-registry-keys-access-via-security</loc>
    <lastmod>2026-07-28T23:20:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powerview-add-domainobjectacl-dcsync-ad-extend-right-via-security</loc>
    <lastmod>2026-07-28T23:20:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ad-privileged-users-or-groups-recon-via-security</loc>
    <lastmod>2026-07-28T23:20:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ad-object-writedac-access-via-security</loc>
    <lastmod>2026-07-28T23:20:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-replication-from-non-machine-account-via-security</loc>
    <lastmod>2026-07-28T23:20:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ad-user-enumeration-from-non-machine-account-via-security</loc>
    <lastmod>2026-07-28T23:20:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-adcs-certificate-template-configuration-vulnerability-via-security</loc>
    <lastmod>2026-07-28T23:20:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-adcs-certificate-template-configuration-vulnerability-with-risky-eku-via-security</loc>
    <lastmod>2026-07-28T23:20:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-add-or-remove-computer-from-dc-via-security</loc>
    <lastmod>2026-07-28T23:20:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-access-to-admin-network-share-via-security</loc>
    <lastmod>2026-07-28T23:20:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enabled-user-right-in-ad-to-control-user-objects-via-security</loc>
    <lastmod>2026-07-28T23:20:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-active-directory-user-backdoors-via-security</loc>
    <lastmod>2026-07-28T23:20:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-weak-encryption-enabled-and-kerberoast-via-security</loc>
    <lastmod>2026-07-28T23:20:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-ruler-via-security</loc>
    <lastmod>2026-07-28T23:20:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-task-creation-through-atsvc-named-pipe-via-security</loc>
    <lastmod>2026-07-28T23:20:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-of-security-eventlog-via-security</loc>
    <lastmod>2026-07-28T23:20:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-processes-accessing-the-microphone-and-webcam-via-security</loc>
    <lastmod>2026-07-28T23:19:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobaltstrike-service-installations-security-via-security</loc>
    <lastmod>2026-07-28T23:19:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-failed-code-integrity-checks-via-security</loc>
    <lastmod>2026-07-28T23:19:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dcerpc-smb-spoolss-named-pipe-via-security</loc>
    <lastmod>2026-07-28T23:19:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dcom-internetexplorer-application-iertutil-dll-hijack-security-via-security</loc>
    <lastmod>2026-07-28T23:19:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mimikatz-dc-sync-via-security</loc>
    <lastmod>2026-07-28T23:19:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-default-domain-gpo-change-via-security</loc>
    <lastmod>2026-07-28T23:19:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-device-deployment-blocked-via-security</loc>
    <lastmod>2026-07-28T23:19:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-disabling-of-windows-event-auditing-via-security</loc>
    <lastmod>2026-07-28T23:19:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-important-windows-event-auditing-via-security</loc>
    <lastmod>2026-07-28T23:19:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-etw-logging-disabled-in-net-processes-registry-via-security</loc>
    <lastmod>2026-07-28T23:19:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dpapi-domain-backup-key-extraction-via-security</loc>
    <lastmod>2026-07-28T23:19:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dpapi-domain-master-key-backup-attempt-via-security</loc>
    <lastmod>2026-07-28T23:19:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-external-disk-drive-or-usb-storage-device-was-recognized-by-the-system-via-security</loc>
    <lastmod>2026-07-28T23:19:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-and-execution-at-scale-through-gpo-scheduled-task-via-security</loc>
    <lastmod>2026-07-28T23:19:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-local-user-creation-via-security</loc>
    <lastmod>2026-07-28T23:19:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-edrsilencer-filter-added-via-security</loc>
    <lastmod>2026-07-28T23:19:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-nofilter-execution-via-security</loc>
    <lastmod>2026-07-28T23:19:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hybridconnectionmanager-service-deployment-via-security</loc>
    <lastmod>2026-07-28T23:19:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-impacket-psexec-via-security</loc>
    <lastmod>2026-07-28T23:19:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-impacket-secretdump-remote-behavior-via-security</loc>
    <lastmod>2026-07-28T23:19:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-clip-launcher-security-via-security</loc>
    <lastmod>2026-07-28T23:19:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-obfuscated-iex-invocation-security-via-security</loc>
    <lastmod>2026-07-28T23:19:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-stdin-launcher-security-via-security</loc>
    <lastmod>2026-07-28T23:19:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-security-via-security</loc>
    <lastmod>2026-07-28T23:19:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-compress-obfuscation-security-via-security</loc>
    <lastmod>2026-07-28T23:19:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-rundll-launcher-security-via-security</loc>
    <lastmod>2026-07-28T23:19:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-stdin-security-via-security</loc>
    <lastmod>2026-07-28T23:19:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-clip-security-via-security</loc>
    <lastmod>2026-07-28T23:19:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-mshta-security-via-security</loc>
    <lastmod>2026-07-28T23:19:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-rundll32-security-via-security</loc>
    <lastmod>2026-07-28T23:19:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-obfuscation-security-via-security</loc>
    <lastmod>2026-07-28T23:19:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iso-image-mounted-via-security</loc>
    <lastmod>2026-07-28T23:19:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-kerberoasting-behavior-initial-query-via-security</loc>
    <lastmod>2026-07-28T23:19:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-as-rep-roasting-through-kerberos-tgt-requests-via-security</loc>
    <lastmod>2026-07-28T23:19:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-kerberos-coercion-by-spoofing-spns-through-dns-manipulation-via-security</loc>
    <lastmod>2026-07-28T23:19:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-first-time-seen-remote-named-pipe-via-security</loc>
    <lastmod>2026-07-28T23:19:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-access-from-non-system-account-via-security</loc>
    <lastmod>2026-07-28T23:19:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-credential-dumping-utilities-service-security-via-security</loc>
    <lastmod>2026-07-28T23:19:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wce-wceaux-dll-access-via-security</loc>
    <lastmod>2026-07-28T23:19:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-metasploit-smb-authentication-via-security</loc>
    <lastmod>2026-07-28T23:19:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-metasploit-or-impacket-service-deployment-through-smb-psexec-via-security</loc>
    <lastmod>2026-07-28T23:19:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-meterpreter-or-cobalt-strike-getsystem-service-deployment-security-via-security</loc>
    <lastmod>2026-07-28T23:19:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netntlm-downgrade-attack-via-security</loc>
    <lastmod>2026-07-28T23:19:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-access-suspicious-desktop-ini-action-via-security</loc>
    <lastmod>2026-07-28T23:19:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-or-renamed-user-account-with-character-via-security</loc>
    <lastmod>2026-07-28T23:19:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-denied-access-to-remote-desktop-via-security</loc>
    <lastmod>2026-07-28T23:19:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-of-password-policy-via-security</loc>
    <lastmod>2026-07-28T23:19:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-pcap-drivers-via-security</loc>
    <lastmod>2026-07-28T23:19:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-petitpotam-coerce-authentication-attempt-via-security</loc>
    <lastmod>2026-07-28T23:19:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/petitpotam-suspicious-kerberos-tgt-request-via-security</loc>
    <lastmod>2026-07-28T23:19:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dc-shadow-attack-via-security</loc>
    <lastmod>2026-07-28T23:19:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-scripts-installed-as-services-security-via-security</loc>
    <lastmod>2026-07-28T23:19:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-protected-storage-service-access-via-security</loc>
    <lastmod>2026-07-28T23:19:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-over-reverse-ssh-tunnel-wfp-via-security</loc>
    <lastmod>2026-07-28T23:19:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-register-new-logon-process-by-rubeus-via-security</loc>
    <lastmod>2026-07-28T23:19:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-service-registry-key-read-access-request-via-security</loc>
    <lastmod>2026-07-28T23:19:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-powershell-sessions-network-connections-winrm-via-security</loc>
    <lastmod>2026-07-28T23:19:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-replay-attack-detected-via-security</loc>
    <lastmod>2026-07-28T23:19:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sam-registry-hive-handle-request-via-security</loc>
    <lastmod>2026-07-28T23:19:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scm-database-handle-failure-via-security</loc>
    <lastmod>2026-07-28T23:18:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scm-database-privileged-operation-via-security</loc>
    <lastmod>2026-07-28T23:18:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-secure-removal-with-sdelete-via-security</loc>
    <lastmod>2026-07-28T23:18:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-services-have-been-installed-security-via-security</loc>
    <lastmod>2026-07-28T23:18:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/service-installed-by-unusual-client-security-via-security</loc>
    <lastmod>2026-07-28T23:18:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-access-of-signal-desktop-sensitive-data-via-security</loc>
    <lastmod>2026-07-28T23:18:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-smb-create-remote-file-admin-share-via-security</loc>
    <lastmod>2026-07-28T23:18:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-a-new-trust-was-created-to-a-domain-via-security</loc>
    <lastmod>2026-07-28T23:18:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-addition-of-sid-history-to-active-directory-object-via-security</loc>
    <lastmod>2026-07-28T23:18:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-win-susp-computer-name-containing-samtheadmin-via-security</loc>
    <lastmod>2026-07-28T23:18:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-change-on-directory-service-restore-mode-dsrm-account-via-security</loc>
    <lastmod>2026-07-28T23:18:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/account-manipulation-suspicious-failed-logon-reasons-via-security</loc>
    <lastmod>2026-07-28T23:18:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-group-policy-misuse-for-privilege-addition-via-security</loc>
    <lastmod>2026-07-28T23:18:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-startup-logon-script-added-to-group-policy-object-via-security</loc>
    <lastmod>2026-07-28T23:18:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kerberos-manipulation-via-security</loc>
    <lastmod>2026-07-28T23:18:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ldap-attributes-used-via-security</loc>
    <lastmod>2026-07-28T23:18:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-suspicious-windows-anonymous-logon-local-account-via-security</loc>
    <lastmod>2026-07-28T23:18:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-logon-with-explicit-credentials-via-security</loc>
    <lastmod>2026-07-28T23:18:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-dumper-behavior-on-lsass-via-security</loc>
    <lastmod>2026-07-28T23:18:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-accessmask-requested-from-lsass-via-security</loc>
    <lastmod>2026-07-28T23:18:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-behavior-via-security</loc>
    <lastmod>2026-07-28T23:18:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-protected-zip-file-opened-via-security</loc>
    <lastmod>2026-07-28T23:18:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/password-protected-zip-file-opened-suspicious-filenames-via-security</loc>
    <lastmod>2026-07-28T23:18:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-protected-zip-file-opened-email-attachment-via-security</loc>
    <lastmod>2026-07-28T23:18:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-outbound-kerberos-connection-security-via-security</loc>
    <lastmod>2026-07-28T23:18:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-shadow-credentials-added-via-security</loc>
    <lastmod>2026-07-28T23:18:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-psexec-via-security</loc>
    <lastmod>2026-07-28T23:18:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-to-sensitive-file-extensions-via-security</loc>
    <lastmod>2026-07-28T23:18:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kerberos-rc4-ticket-encryption-via-security</loc>
    <lastmod>2026-07-28T23:18:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-via-security</loc>
    <lastmod>2026-07-28T23:18:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-important-scheduled-task-deleted-disabled-via-security</loc>
    <lastmod>2026-07-28T23:18:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-update-via-security</loc>
    <lastmod>2026-07-28T23:18:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-unauthorized-system-time-change-via-security</loc>
    <lastmod>2026-07-28T23:18:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-service-behavior-through-svcctl-named-pipe-via-security</loc>
    <lastmod>2026-07-28T23:18:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-syskey-registry-keys-access-via-security</loc>
    <lastmod>2026-07-28T23:18:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-channel-reference-removal-via-security</loc>
    <lastmod>2026-07-28T23:18:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-tap-driver-deployment-security-via-security</loc>
    <lastmod>2026-07-28T23:18:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-teams-application-related-objectacess-event-via-security</loc>
    <lastmod>2026-07-28T23:18:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-transferring-files-with-credential-data-through-network-shares-via-security</loc>
    <lastmod>2026-07-28T23:18:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-local-administrator-group-via-security</loc>
    <lastmod>2026-07-28T23:18:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-couldn-t-call-a-privileged-service-lsaregisterlogonprocess-via-security</loc>
    <lastmod>2026-07-28T23:18:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-user-creation-via-security</loc>
    <lastmod>2026-07-28T23:18:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privileged-system-service-operation-seloaddriverprivilege-via-security</loc>
    <lastmod>2026-07-28T23:18:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-user-logoff-event-via-security</loc>
    <lastmod>2026-07-28T23:18:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-vssaudit-security-event-source-registration-via-security</loc>
    <lastmod>2026-07-28T23:18:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-windows-defender-exclusion-list-via-security</loc>
    <lastmod>2026-07-28T23:18:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-defender-exclusion-registry-key-write-access-requested-via-security</loc>
    <lastmod>2026-07-28T23:18:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-persistence-security-via-security</loc>
    <lastmod>2026-07-28T23:18:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-t1047-wmiprvse-wbemcomn-dll-hijack-via-security</loc>
    <lastmod>2026-07-28T23:18:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-locked-workstation-via-security</loc>
    <lastmod>2026-07-28T23:18:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-defender-blocked-from-loading-unsigned-dll-via-security-mitigations</loc>
    <lastmod>2026-07-28T23:18:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unsigned-binary-loaded-from-suspicious-location-via-security-mitigations</loc>
    <lastmod>2026-07-28T23:18:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hybridconnectionmanager-service-running-via-microsoft-servicebus-client</loc>
    <lastmod>2026-07-28T23:18:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-installed-via-shell-core</loc>
    <lastmod>2026-07-28T23:18:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rejected-smb-guest-logon-from-ip-via-smbclient-security</loc>
    <lastmod>2026-07-28T23:18:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-or-unencrypted-smb-connection-to-share-established-via-smbserver-connectivity</loc>
    <lastmod>2026-07-28T23:18:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-application-crashed-via-system</loc>
    <lastmod>2026-07-28T23:18:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntlmv1-logon-between-client-and-server-via-system</loc>
    <lastmod>2026-07-28T23:18:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-isatap-router-address-was-set-via-system</loc>
    <lastmod>2026-07-28T23:18:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-certificate-services-denied-certificate-enrollment-request-via-system</loc>
    <lastmod>2026-07-28T23:18:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dhcp-server-loaded-the-callout-dll-via-system</loc>
    <lastmod>2026-07-28T23:17:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dhcp-server-error-failed-loading-the-callout-dll-via-system</loc>
    <lastmod>2026-07-28T23:17:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-local-privilege-escalation-indicator-tabtip-via-system</loc>
    <lastmod>2026-07-28T23:17:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-of-eventlog-via-system</loc>
    <lastmod>2026-07-28T23:17:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-of-important-windows-eventlog-via-system</loc>
    <lastmod>2026-07-28T23:17:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-use-with-no-strong-mapping-via-system</loc>
    <lastmod>2026-07-28T23:17:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-no-suitable-encryption-key-found-for-generating-kerberos-ticket-via-system</loc>
    <lastmod>2026-07-28T23:17:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/clearing-of-critical-hive-in-suspicious-location-access-bits-via-system</loc>
    <lastmod>2026-07-28T23:17:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-volume-shadow-copy-mount-via-system</loc>
    <lastmod>2026-07-28T23:17:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-crash-dump-created-by-operating-system-via-system</loc>
    <lastmod>2026-07-28T23:17:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-update-error-via-system</loc>
    <lastmod>2026-07-28T23:17:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-zerologon-exploitation-via-well-known-utilities-via-system</loc>
    <lastmod>2026-07-28T23:17:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vulnerable-netlogon-secure-channel-connection-allowed-via-system</loc>
    <lastmod>2026-07-28T23:17:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntfs-vulnerability-exploitation-via-system</loc>
    <lastmod>2026-07-28T23:17:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobaltstrike-service-installations-system-via-system</loc>
    <lastmod>2026-07-28T23:17:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-defender-threat-detection-service-via-system</loc>
    <lastmod>2026-07-28T23:17:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-smbexec-py-service-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-clip-launcher-system-via-system</loc>
    <lastmod>2026-07-28T23:17:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-obfuscated-iex-invocation-system-via-system</loc>
    <lastmod>2026-07-28T23:17:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-stdin-launcher-system-via-system</loc>
    <lastmod>2026-07-28T23:17:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-system-via-system</loc>
    <lastmod>2026-07-28T23:17:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-compress-obfuscation-system-via-system</loc>
    <lastmod>2026-07-28T23:17:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-rundll-launcher-system-via-system</loc>
    <lastmod>2026-07-28T23:17:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-stdin-system-via-system</loc>
    <lastmod>2026-07-28T23:17:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-clip-system-via-system</loc>
    <lastmod>2026-07-28T23:17:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-mshta-system-via-system</loc>
    <lastmod>2026-07-28T23:17:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-rundll32-system-via-system</loc>
    <lastmod>2026-07-28T23:17:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-obfuscation-system-via-system</loc>
    <lastmod>2026-07-28T23:17:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-krbrelayup-service-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-credential-dumping-utilities-service-system-via-system</loc>
    <lastmod>2026-07-28T23:17:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-meterpreter-or-cobalt-strike-getsystem-service-deployment-system-via-system</loc>
    <lastmod>2026-07-28T23:17:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-moriya-rootkit-system-via-system</loc>
    <lastmod>2026-07-28T23:17:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-scripts-installed-as-services-via-system</loc>
    <lastmod>2026-07-28T23:17:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-anydesk-remote-access-software-service-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-csexec-service-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-service-registration-or-execution-via-system</loc>
    <lastmod>2026-07-28T23:17:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mesh-agent-service-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netsupport-manager-service-install-via-system</loc>
    <lastmod>2026-07-28T23:17:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-paexec-service-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-pdqdeploy-service-server-side-via-system</loc>
    <lastmod>2026-07-28T23:17:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-pdqdeploy-service-client-side-via-system</loc>
    <lastmod>2026-07-28T23:17:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-processhacker-privilege-elevation-via-system</loc>
    <lastmod>2026-07-28T23:17:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remcom-service-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-services-have-been-installed-system-via-system</loc>
    <lastmod>2026-07-28T23:17:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-utilities-host-service-install-via-system</loc>
    <lastmod>2026-07-28T23:17:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sliver-c2-default-service-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/service-installed-by-unusual-client-system-via-system</loc>
    <lastmod>2026-07-28T23:17:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-service-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tacticalrmm-service-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tap-driver-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-service-deployment-image-path-via-system</loc>
    <lastmod>2026-07-28T23:17:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-service-terminated-with-error-via-system</loc>
    <lastmod>2026-07-28T23:17:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-important-windows-service-terminated-with-error-via-system</loc>
    <lastmod>2026-07-28T23:17:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-important-windows-service-terminated-unexpectedly-via-system</loc>
    <lastmod>2026-07-28T23:17:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rtcore-suspicious-service-deployment-via-system</loc>
    <lastmod>2026-07-28T23:17:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/service-deployment-in-suspicious-folder-via-system</loc>
    <lastmod>2026-07-28T23:17:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/service-deployment-with-suspicious-folder-pattern-via-system</loc>
    <lastmod>2026-07-28T23:17:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-deployment-script-via-system</loc>
    <lastmod>2026-07-28T23:17:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/scheduled-task-executed-from-a-suspicious-location-via-taskscheduler</loc>
    <lastmod>2026-07-28T23:17:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/scheduled-task-executed-unusual-lolbin-via-taskscheduler</loc>
    <lastmod>2026-07-28T23:16:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-important-scheduled-task-deleted-or-disabled-via-taskscheduler</loc>
    <lastmod>2026-07-28T23:16:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ngrok-use-with-remote-desktop-service-via-terminalservices-localsessionmanager</loc>
    <lastmod>2026-07-28T23:16:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mimikatz-use-via-windows</loc>
    <lastmod>2026-07-28T23:16:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-grace-period-expired-via-windefend</loc>
    <lastmod>2026-07-28T23:16:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-access-detected-through-attack-surface-reduction-via-windefend</loc>
    <lastmod>2026-07-28T23:16:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-and-wmi-process-creations-block-via-windefend</loc>
    <lastmod>2026-07-28T23:16:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-exclusions-added-via-windefend</loc>
    <lastmod>2026-07-28T23:16:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-exploit-guard-tamper-via-windefend</loc>
    <lastmod>2026-07-28T23:16:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-disabling-of-windows-defender-submit-sample-feature-via-windefend</loc>
    <lastmod>2026-07-28T23:16:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-malware-detection-history-removal-via-windefend</loc>
    <lastmod>2026-07-28T23:16:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-disabling-of-windows-defender-malware-and-pua-scanning-via-windefend</loc>
    <lastmod>2026-07-28T23:16:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-amsi-trigger-detected-via-windefend</loc>
    <lastmod>2026-07-28T23:16:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-defender-real-time-protection-via-windefend</loc>
    <lastmod>2026-07-28T23:16:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-real-time-protection-failure-restart-via-windefend</loc>
    <lastmod>2026-07-28T23:16:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-win-defender-restored-quarantine-file-via-windefend</loc>
    <lastmod>2026-07-28T23:16:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-configuration-changes-via-windefend</loc>
    <lastmod>2026-07-28T23:16:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-defender-tamper-protection-trigger-via-windefend</loc>
    <lastmod>2026-07-28T23:16:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-threat-detected-via-windefend</loc>
    <lastmod>2026-07-28T23:16:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-defender-virus-scanning-feature-via-windefend</loc>
    <lastmod>2026-07-28T23:16:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-failed-event-log-clear-through-wmi-nteventlogfile-cleareventlog-via-wmi</loc>
    <lastmod>2026-07-28T23:16:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-persistence-via-wmi</loc>
    <lastmod>2026-07-28T23:16:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-cactustorch-remote-thread-creation-via-create-remote-thread</loc>
    <lastmod>2026-07-28T23:16:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/hacktool-potential-cobaltstrike-process-injection-via-create-remote-thread</loc>
    <lastmod>2026-07-28T23:16:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-thread-created-in-keepass-exe-via-create-remote-thread</loc>
    <lastmod>2026-07-28T23:16:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-thread-creation-in-mstsc-exe-from-suspicious-location-via-create-remote-thread</loc>
    <lastmod>2026-07-28T23:16:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-attempt-through-powershell-remote-thread-via-create-remote-thread</loc>
    <lastmod>2026-07-28T23:16:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-thread-creation-through-powershell-in-unusual-target-via-create-remote-thread</loc>
    <lastmod>2026-07-28T23:16:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-dumper-remote-thread-in-lsass-via-create-remote-thread</loc>
    <lastmod>2026-07-28T23:16:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rare-remote-thread-creation-by-unusual-source-image-via-create-remote-thread</loc>
    <lastmod>2026-07-28T23:16:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-thread-creation-by-unusual-source-image-via-create-remote-thread</loc>
    <lastmod>2026-07-28T23:16:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-thread-creation-in-unusual-target-image-via-create-remote-thread</loc>
    <lastmod>2026-07-28T23:16:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-thread-creation-ttdinject-exe-proxy-via-create-remote-thread</loc>
    <lastmod>2026-07-28T23:16:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-executable-in-ntfs-alternate-data-stream-via-create-stream-hash</loc>
    <lastmod>2026-07-28T23:16:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-a-suspicious-ads-file-outside-a-browser-download-via-create-stream-hash</loc>
    <lastmod>2026-07-28T23:16:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-file-sharing-websites-file-stream-via-create-stream-hash</loc>
    <lastmod>2026-07-28T23:16:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-download-from-file-sharing-websites-file-stream-via-create-stream-hash</loc>
    <lastmod>2026-07-28T23:16:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-creation-of-hacktool-named-file-stream-via-create-stream-hash</loc>
    <lastmod>2026-07-28T23:16:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-exports-registry-key-to-an-alternate-data-stream-via-create-stream-hash</loc>
    <lastmod>2026-07-28T23:16:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-download-from-direct-ip-address-via-create-stream-hash</loc>
    <lastmod>2026-07-28T23:16:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-winget-package-deployment-via-create-stream-hash</loc>
    <lastmod>2026-07-28T23:16:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-file-download-from-zip-tld-via-create-stream-hash</loc>
    <lastmod>2026-07-28T23:16:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-for-anonfiles-com-domain-sysmon-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-appx-package-deployment-attempts-through-appinstaller-exe-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cloudflared-tunnels-related-dns-requests-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dns-query-to-common-malware-hosting-and-shortener-services-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-devtunnels-domain-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-server-enumeration-through-ldap-query-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-azurewebsites-net-by-non-browser-process-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-by-finger-utility-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/notepad-updater-dns-query-to-unusual-domains-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-hybridconnectionmanager-service-bus-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-query-indicating-kerberos-coercion-through-dns-object-spn-spoofing-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cobalt-strike-dns-beaconing-sysmon-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-mega-hosting-website-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-request-to-onelaunch-update-service-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-request-by-quickassist-exe-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-request-by-regsvr32-exe-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-remote-access-software-domain-from-non-browser-app-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-query-for-ip-lookup-service-apis-via-dns-query</loc>
    <lastmod>2026-07-28T23:16:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-teamviewer-domain-query-by-non-teamviewer-application-via-dns-query</loc>
    <lastmod>2026-07-28T23:15:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-tor-onion-address-sysmon-via-dns-query</loc>
    <lastmod>2026-07-28T23:15:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-ufile-io-via-dns-query</loc>
    <lastmod>2026-07-28T23:15:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-visual-studio-code-tunnels-domain-via-dns-query</loc>
    <lastmod>2026-07-28T23:15:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-driver-load-via-driver-load</loc>
    <lastmod>2026-07-28T23:15:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-driver-load-by-name-via-driver-load</loc>
    <lastmod>2026-07-28T23:15:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-process-hacker-driver-load-via-driver-load</loc>
    <lastmod>2026-07-28T23:15:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-system-informer-driver-load-via-driver-load</loc>
    <lastmod>2026-07-28T23:15:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-driver-load-from-a-temporary-directory-via-driver-load</loc>
    <lastmod>2026-07-28T23:15:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-vulnerable-driver-load-by-name-via-driver-load</loc>
    <lastmod>2026-07-28T23:15:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vulnerable-hacksys-extreme-vulnerable-driver-load-via-driver-load</loc>
    <lastmod>2026-07-28T23:15:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vulnerable-winring0-driver-load-via-driver-load</loc>
    <lastmod>2026-07-28T23:15:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windivert-driver-load-via-driver-load</loc>
    <lastmod>2026-07-28T23:15:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/credential-manager-access-by-unusual-applications-via-file-access</loc>
    <lastmod>2026-07-28T23:15:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/access-to-windows-credential-history-file-by-unusual-applications-via-file-access</loc>
    <lastmod>2026-07-28T23:15:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/access-to-crypto-currency-wallets-by-unusual-applications-via-file-access</loc>
    <lastmod>2026-07-28T23:15:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/access-to-windows-dpapi-master-keys-by-unusual-applications-via-file-access</loc>
    <lastmod>2026-07-28T23:15:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/access-to-potentially-sensitive-sysvol-files-by-unusual-applications-via-file-access</loc>
    <lastmod>2026-07-28T23:15:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-access-to-browser-credential-storage-via-file-access</loc>
    <lastmod>2026-07-28T23:15:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-teams-sensitive-file-access-by-unusual-applications-via-file-access</loc>
    <lastmod>2026-07-28T23:15:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-change-by-dns-exe-via-file-change</loc>
    <lastmod>2026-07-28T23:15:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-backup-files-via-file-delete</loc>
    <lastmod>2026-07-28T23:15:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-eventlog-evtx-file-via-file-delete</loc>
    <lastmod>2026-07-28T23:15:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-exchange-powershell-cmdlet-history-via-file-delete</loc>
    <lastmod>2026-07-28T23:15:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-iis-webserver-access-logs-via-file-delete</loc>
    <lastmod>2026-07-28T23:15:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-removal-of-its-own-executable-via-file-delete</loc>
    <lastmod>2026-07-28T23:15:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-powershell-console-history-logs-via-file-delete</loc>
    <lastmod>2026-07-28T23:15:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-prefetch-file-via-file-delete</loc>
    <lastmod>2026-07-28T23:15:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-removal-of-teamviewer-log-file-via-file-delete</loc>
    <lastmod>2026-07-28T23:15:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-tomcat-webserver-logs-via-file-delete</loc>
    <lastmod>2026-07-28T23:15:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-deleted-through-sysinternals-sdelete-via-file-delete</loc>
    <lastmod>2026-07-28T23:15:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-removal-by-dns-exe-via-file-delete</loc>
    <lastmod>2026-07-28T23:15:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ads-zone-identifier-deleted-by-unusual-application-via-file-delete</loc>
    <lastmod>2026-07-28T23:15:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/adsi-cache-file-creation-by-unusual-utility-via-file-event</loc>
    <lastmod>2026-07-28T23:15:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-advanced-ip-scanner-file-event-via-file-event</loc>
    <lastmod>2026-07-28T23:15:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-anydesk-temporary-artefact-via-file-event</loc>
    <lastmod>2026-07-28T23:15:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-binary-writes-through-anydesk-via-file-event</loc>
    <lastmod>2026-07-28T23:15:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-created-by-arcsoc-exe-via-file-event</loc>
    <lastmod>2026-07-28T23:15:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-assembly-dll-creation-through-aspnetcompiler-via-file-event</loc>
    <lastmod>2026-07-28T23:15:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bloodhound-collection-files-via-file-event</loc>
    <lastmod>2026-07-28T23:15:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-file-creation-by-openedr-s-itsmservice-via-file-event</loc>
    <lastmod>2026-07-28T23:15:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/evtx-created-in-unusual-location-via-file-event</loc>
    <lastmod>2026-07-28T23:15:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-non-existent-system-dll-via-file-event</loc>
    <lastmod>2026-07-28T23:15:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deno-file-written-from-remote-source-via-file-event</loc>
    <lastmod>2026-07-28T23:15:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-new-custom-shim-database-via-file-event</loc>
    <lastmod>2026-07-28T23:15:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-screensaver-binary-file-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:15:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-files-with-system-dll-name-in-unsuspected-locations-via-file-event</loc>
    <lastmod>2026-07-28T23:15:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-files-with-system-process-name-in-unsuspected-locations-via-file-event</loc>
    <lastmod>2026-07-28T23:15:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-exe-for-service-with-unquoted-path-via-file-event</loc>
    <lastmod>2026-07-28T23:15:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cred-dump-utilities-dropped-files-via-file-event</loc>
    <lastmod>2026-07-28T23:15:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-or-cscript-dropper-file-via-file-event</loc>
    <lastmod>2026-07-28T23:15:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-csexec-service-file-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:15:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dynamic-csharp-compile-artefact-via-file-event</loc>
    <lastmod>2026-07-28T23:15:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dcom-internetexplorer-application-dll-hijack-via-file-event</loc>
    <lastmod>2026-07-28T23:15:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/desktop-ini-created-by-unusual-process-via-file-event</loc>
    <lastmod>2026-07-28T23:15:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-search-order-hijackig-through-additional-space-in-path-via-file-event</loc>
    <lastmod>2026-07-28T23:15:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-dmp-hdmp-file-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:15:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-attempt-through-errorhandler-cmd-via-file-event</loc>
    <lastmod>2026-07-28T23:15:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aspx-file-drop-by-exchange-via-file-event</loc>
    <lastmod>2026-07-28T23:15:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-drop-by-exchange-via-file-event</loc>
    <lastmod>2026-07-28T23:14:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gotoassist-temporary-deployment-artefact-via-file-event</loc>
    <lastmod>2026-07-28T23:14:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-created-by-notepad-updater-gup-exe-via-file-event</loc>
    <lastmod>2026-07-28T23:14:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-crackmapexec-file-indicators-via-file-event</loc>
    <lastmod>2026-07-28T23:14:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-dumpert-process-dumper-default-file-via-file-event</loc>
    <lastmod>2026-07-28T23:14:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-typical-hivenightmare-sam-file-export-via-file-event</loc>
    <lastmod>2026-07-28T23:14:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-inveigh-execution-artefacts-via-file-event</loc>
    <lastmod>2026-07-28T23:14:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-remotekrbrelay-smb-relay-secrets-dump-module-indicators-via-file-event</loc>
    <lastmod>2026-07-28T23:14:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-mimikatz-kirbi-file-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:14:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-netexec-file-indicators-via-file-event</loc>
    <lastmod>2026-07-28T23:14:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-nppspy-hacktool-usage-via-file-event</loc>
    <lastmod>2026-07-28T23:14:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-powerup-write-hijack-dll-via-file-event</loc>
    <lastmod>2026-07-28T23:14:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-quarkspwdump-dump-file-via-file-event</loc>
    <lastmod>2026-07-28T23:14:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/hacktool-possible-remote-credential-dumping-behavior-through-crackmapexec-or-impacket-secretsdump-via-file-event</loc>
    <lastmod>2026-07-28T23:14:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-safetykatz-dump-indicator-via-file-event</loc>
    <lastmod>2026-07-28T23:14:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-impacket-file-indicators-via-file-event</loc>
    <lastmod>2026-07-28T23:14:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-initial-access-through-dll-search-order-hijacking-via-file-event</loc>
    <lastmod>2026-07-28T23:14:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deployment-of-teamviewer-desktop-via-file-event</loc>
    <lastmod>2026-07-28T23:14:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-file-dropped-in-the-teams-or-onedrive-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:14:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iso-file-created-within-temp-folders-via-file-event</loc>
    <lastmod>2026-07-28T23:14:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iso-or-image-mount-indicator-in-recent-files-via-file-event</loc>
    <lastmod>2026-07-28T23:14:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-gathernetworkinfo-vbs-recon-script-output-via-file-event</loc>
    <lastmod>2026-07-28T23:14:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-process-memory-dump-files-via-file-event</loc>
    <lastmod>2026-07-28T23:14:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-process-dump-artefact-in-crashdumps-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:14:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-werfault-lsass-process-memory-dump-via-file-event</loc>
    <lastmod>2026-07-28T23:14:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-adwind-rat-jrat-file-artifact-via-file-event</loc>
    <lastmod>2026-07-28T23:14:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-octopus-scanner-malware-via-file-event</loc>
    <lastmod>2026-07-28T23:14:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-creation-in-suspicious-directory-by-msdt-exe-via-file-event</loc>
    <lastmod>2026-07-28T23:14:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-creation-by-mysql-daemon-process-via-file-event</loc>
    <lastmod>2026-07-28T23:14:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dotnet-clr-use-log-artifact-via-file-event</loc>
    <lastmod>2026-07-28T23:14:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-creation-in-unusual-appdata-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:14:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scr-file-write-event-via-file-event</loc>
    <lastmod>2026-07-28T23:14:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-notepad-plugins-via-file-event</loc>
    <lastmod>2026-07-28T23:14:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-ntds-dit-via-file-event</loc>
    <lastmod>2026-07-28T23:14:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ntds-dit-creation-by-unusual-parent-process-via-file-event</loc>
    <lastmod>2026-07-28T23:14:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ntds-dit-creation-by-unusual-process-via-file-event</loc>
    <lastmod>2026-07-28T23:14:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntds-exfiltration-filename-patterns-via-file-event</loc>
    <lastmod>2026-07-28T23:14:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-microsoft-office-add-in-via-file-event</loc>
    <lastmod>2026-07-28T23:14:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-office-macro-file-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:14:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-office-macro-file-download-via-file-event</loc>
    <lastmod>2026-07-28T23:14:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/office-macro-file-creation-from-suspicious-process-via-file-event</loc>
    <lastmod>2026-07-28T23:14:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/onenote-attachment-file-dropped-in-suspicious-location-via-file-event</loc>
    <lastmod>2026-07-28T23:14:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-created-through-onenote-application-via-file-event</loc>
    <lastmod>2026-07-28T23:14:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-new-outlook-macro-via-file-event</loc>
    <lastmod>2026-07-28T23:14:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-outlook-form-via-file-event</loc>
    <lastmod>2026-07-28T23:14:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-created-in-outlook-temporary-directory-via-file-event</loc>
    <lastmod>2026-07-28T23:14:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-suspicious-outlook-macro-via-file-event</loc>
    <lastmod>2026-07-28T23:14:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/publisher-attachment-file-dropped-in-suspicious-location-via-file-event</loc>
    <lastmod>2026-07-28T23:14:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-microsoft-office-startup-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:14:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-with-unusual-extension-created-by-an-office-application-via-file-event</loc>
    <lastmod>2026-07-28T23:14:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-created-in-office-startup-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:14:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pcre-net-package-temp-files-via-file-event</loc>
    <lastmod>2026-07-28T23:14:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-created-in-perflogs-via-file-event</loc>
    <lastmod>2026-07-28T23:14:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-binary-or-script-dropper-through-powershell-via-file-event</loc>
    <lastmod>2026-07-28T23:14:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-script-dropped-through-powershell-exe-via-file-event</loc>
    <lastmod>2026-07-28T23:14:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-scripts-filecreation-via-file-event</loc>
    <lastmod>2026-07-28T23:14:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-powershell-module-file-via-file-event</loc>
    <lastmod>2026-07-28T23:14:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-possible-suspicious-powershell-module-file-via-file-event</loc>
    <lastmod>2026-07-28T23:14:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-module-file-created-by-non-powershell-process-via-file-event</loc>
    <lastmod>2026-07-28T23:14:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-startup-shortcut-persistence-through-powershell-exe-via-file-event</loc>
    <lastmod>2026-07-28T23:14:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/psscriptpolicytest-creation-by-unusual-process-via-file-event</loc>
    <lastmod>2026-07-28T23:13:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rclone-config-file-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:13:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rdp-file-created-by-unusual-application-via-file-event</loc>
    <lastmod>2026-07-28T23:13:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-winnti-dropper-behavior-via-file-event</loc>
    <lastmod>2026-07-28T23:13:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pdf-file-created-by-regedit-exe-via-file-event</loc>
    <lastmod>2026-07-28T23:13:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remcom-service-file-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:13:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-screenconnect-temporary-deployment-artefact-via-file-event</loc>
    <lastmod>2026-07-28T23:13:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-screenconnect-temporary-file-via-file-event</loc>
    <lastmod>2026-07-28T23:13:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ripzip-attack-on-startup-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:13:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sam-database-dump-via-file-event</loc>
    <lastmod>2026-07-28T23:13:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/self-extraction-directive-file-created-in-potentially-suspicious-location-via-file-event</loc>
    <lastmod>2026-07-28T23:13:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-shell-scripting-application-file-write-to-suspicious-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:13:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-binaries-write-suspicious-extensions-via-file-event</loc>
    <lastmod>2026-07-28T23:13:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-startup-folder-file-write-via-file-event</loc>
    <lastmod>2026-07-28T23:13:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-with-colorcpl-via-file-event</loc>
    <lastmod>2026-07-28T23:13:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-created-files-by-microsoft-sync-center-via-file-event</loc>
    <lastmod>2026-07-28T23:13:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-files-in-default-gpo-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:13:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-desktopimgdownldr-target-file-via-file-event</loc>
    <lastmod>2026-07-28T23:13:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-a-diagcab-via-file-event</loc>
    <lastmod>2026-07-28T23:13:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-double-extension-files-via-file-event</loc>
    <lastmod>2026-07-28T23:13:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dpapi-backup-keys-and-certificate-export-behavior-ioc-via-file-event</loc>
    <lastmod>2026-07-28T23:13:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msexchangemailboxreplication-aspx-write-via-file-event</loc>
    <lastmod>2026-07-28T23:13:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-file-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:13:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-write-to-webapps-root-directory-via-file-event</loc>
    <lastmod>2026-07-28T23:13:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-write-to-sharepoint-layouts-directory-via-file-event</loc>
    <lastmod>2026-07-28T23:13:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-variable-exe-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:13:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-hidden-directory-creation-through-ntfs-index-allocation-stream-via-file-event</loc>
    <lastmod>2026-07-28T23:13:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-homoglyph-attack-via-lookalike-characters-in-filename-via-file-event</loc>
    <lastmod>2026-07-28T23:13:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-legitimate-application-dropped-archive-via-file-event</loc>
    <lastmod>2026-07-28T23:13:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-legitimate-application-dropped-executable-via-file-event</loc>
    <lastmod>2026-07-28T23:13:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/legitimate-application-writing-files-in-unusual-location-via-file-event</loc>
    <lastmod>2026-07-28T23:13:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-legitimate-application-dropped-script-via-file-event</loc>
    <lastmod>2026-07-28T23:13:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-suspicious-lnk-double-extension-file-via-file-event</loc>
    <lastmod>2026-07-28T23:13:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-profile-change-via-file-event</loc>
    <lastmod>2026-07-28T23:13:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-procexp152-sys-file-created-in-tmp-via-file-event</loc>
    <lastmod>2026-07-28T23:13:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-binaries-and-scripts-in-public-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:13:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-creation-behavior-from-fake-recycle-bin-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:13:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-extension-spoofing-via-right-to-left-override-via-file-event</loc>
    <lastmod>2026-07-28T23:13:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-drop-binaries-into-spool-drivers-color-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:13:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-startup-folder-persistence-via-file-event</loc>
    <lastmod>2026-07-28T23:13:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-interactive-powershell-as-system-via-file-event</loc>
    <lastmod>2026-07-28T23:13:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-write-to-system32-tasks-via-file-event</loc>
    <lastmod>2026-07-28T23:13:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-teamviewer-remote-session-via-file-event</loc>
    <lastmod>2026-07-28T23:13:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vscode-powershell-profile-change-via-file-event</loc>
    <lastmod>2026-07-28T23:13:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-wdac-policy-file-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:13:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-terminal-profile-settings-change-by-unusual-process-via-file-event</loc>
    <lastmod>2026-07-28T23:13:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winsxs-executable-file-creation-by-non-system-process-via-file-event</loc>
    <lastmod>2026-07-28T23:13:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-adexplorer-writing-complete-ad-snapshot-into-dat-file-via-file-event</loc>
    <lastmod>2026-07-28T23:13:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-livekd-kernel-memory-dump-file-via-file-event</loc>
    <lastmod>2026-07-28T23:13:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-livekd-driver-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:13:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/livekd-driver-creation-by-unusual-process-via-file-event</loc>
    <lastmod>2026-07-28T23:13:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-explorer-driver-creation-by-non-sysinternals-binary-via-file-event</loc>
    <lastmod>2026-07-28T23:13:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-monitor-driver-creation-by-non-sysinternals-binary-via-file-event</loc>
    <lastmod>2026-07-28T23:13:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-psexec-service-file-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:13:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-remote-execution-file-artefact-via-file-event</loc>
    <lastmod>2026-07-28T23:13:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privilege-escalation-attempt-through-exe-local-technique-via-file-event</loc>
    <lastmod>2026-07-28T23:13:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-process-memory-dump-creation-through-taskmgr-exe-via-file-event</loc>
    <lastmod>2026-07-28T23:13:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hijack-legit-rdp-session-to-move-laterally-via-file-event</loc>
    <lastmod>2026-07-28T23:13:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-consent-and-comctl32-file-via-file-event</loc>
    <lastmod>2026-07-28T23:13:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-net-code-profiler-on-mmc-via-file-event</loc>
    <lastmod>2026-07-28T23:13:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-eventvwr-via-file-event</loc>
    <lastmod>2026-07-28T23:12:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-idiagnostic-profile-file-via-file-event</loc>
    <lastmod>2026-07-28T23:12:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-ieinstal-file-via-file-event</loc>
    <lastmod>2026-07-28T23:12:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-msconfig-token-change-file-via-file-event</loc>
    <lastmod>2026-07-28T23:12:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-ntfs-reparse-point-file-via-file-event</loc>
    <lastmod>2026-07-28T23:12:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-abusing-winsat-path-parsing-file-via-file-event</loc>
    <lastmod>2026-07-28T23:12:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-windows-media-player-file-via-file-event</loc>
    <lastmod>2026-07-28T23:12:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vhd-image-download-through-browser-via-file-event</loc>
    <lastmod>2026-07-28T23:12:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-visual-studio-code-tunnel-remote-file-creation-via-file-event</loc>
    <lastmod>2026-07-28T23:12:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-vscode-code-tunnel-file-indicator-via-file-event</loc>
    <lastmod>2026-07-28T23:12:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-webshell-creation-on-static-website-via-file-event</loc>
    <lastmod>2026-07-28T23:12:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-werfault-exe-wer-dll-in-unusual-folder-via-file-event</loc>
    <lastmod>2026-07-28T23:12:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winrar-creating-files-in-startup-locations-via-file-event</loc>
    <lastmod>2026-07-28T23:12:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/awl-bypass-with-winrm-vbs-and-malicious-wsmpty-xsl-wsmtxt-xsl-file-via-file-event</loc>
    <lastmod>2026-07-28T23:12:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-persistence-script-event-consumer-file-write-via-file-event</loc>
    <lastmod>2026-07-28T23:12:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmiexec-default-output-file-via-file-event</loc>
    <lastmod>2026-07-28T23:12:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmiprvse-wbemcomn-dll-hijack-file-via-file-event</loc>
    <lastmod>2026-07-28T23:12:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uefi-persistence-through-wpbbin-filecreation-via-file-event</loc>
    <lastmod>2026-07-28T23:12:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-writing-local-admin-share-via-file-event</loc>
    <lastmod>2026-07-28T23:12:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-potentially-suspicious-self-extraction-directive-file-via-file-executable-detected</loc>
    <lastmod>2026-07-28T23:12:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-appended-extension-via-file-rename</loc>
    <lastmod>2026-07-28T23:12:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/clfs-sys-loaded-by-process-located-in-a-possible-suspicious-location-via-image-load</loc>
    <lastmod>2026-07-28T23:12:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dll-loaded-from-suspicious-location-through-cmspt-exe-via-image-load</loc>
    <lastmod>2026-07-28T23:12:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-amsi-dll-loaded-through-lolbin-process-via-image-load</loc>
    <lastmod>2026-07-28T23:12:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-azure-browser-sso-misuse-via-image-load</loc>
    <lastmod>2026-07-28T23:12:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-renamed-comsvcs-dll-loaded-by-rundll32-via-image-load</loc>
    <lastmod>2026-07-28T23:12:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/credui-dll-loaded-by-unusual-process-via-image-load</loc>
    <lastmod>2026-07-28T23:12:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-dbghelp-dbgcore-dll-loaded-via-image-load</loc>
    <lastmod>2026-07-28T23:12:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pcre-net-package-image-load-via-image-load</loc>
    <lastmod>2026-07-28T23:12:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/load-of-rstrtmgr-dll-by-a-suspicious-process-via-image-load</loc>
    <lastmod>2026-07-28T23:12:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/load-of-rstrtmgr-dll-by-an-unusual-process-via-image-load</loc>
    <lastmod>2026-07-28T23:12:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-diagnostic-library-sdiageng-dll-loaded-by-msdt-exe-via-image-load</loc>
    <lastmod>2026-07-28T23:12:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-core-dll-loaded-by-non-powershell-process-via-image-load</loc>
    <lastmod>2026-07-28T23:12:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-time-travel-debugging-utility-use-image-via-image-load</loc>
    <lastmod>2026-07-28T23:12:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-node-file-loaded-via-image-load</loc>
    <lastmod>2026-07-28T23:12:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-volume-shadow-copy-vss-ps-dll-load-via-image-load</loc>
    <lastmod>2026-07-28T23:12:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-volume-shadow-copy-vssapi-dll-load-via-image-load</loc>
    <lastmod>2026-07-28T23:12:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-volume-shadow-copy-vsstrace-dll-load-via-image-load</loc>
    <lastmod>2026-07-28T23:12:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpevtmute-dll-load-via-image-load</loc>
    <lastmod>2026-07-28T23:12:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-silenttrinity-stager-dll-load-via-image-load</loc>
    <lastmod>2026-07-28T23:12:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dcom-internetexplorer-application-dll-hijack-image-load-via-image-load</loc>
    <lastmod>2026-07-28T23:12:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-image-loaded-into-lsass-process-via-image-load</loc>
    <lastmod>2026-07-28T23:12:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dotnet-assembly-dll-loaded-through-office-application-via-image-load</loc>
    <lastmod>2026-07-28T23:12:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clr-dll-loaded-through-office-applications-via-image-load</loc>
    <lastmod>2026-07-28T23:12:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gac-dll-loaded-through-office-applications-via-image-load</loc>
    <lastmod>2026-07-28T23:12:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-excel-add-in-loaded-from-unusual-location-via-image-load</loc>
    <lastmod>2026-07-28T23:12:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-vba-for-outlook-addin-loaded-through-outlook-via-image-load</loc>
    <lastmod>2026-07-28T23:12:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-core-dll-loaded-through-office-application-via-image-load</loc>
    <lastmod>2026-07-28T23:12:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vba-dll-loaded-through-office-application-via-image-load</loc>
    <lastmod>2026-07-28T23:12:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-dll-load-through-rundll32-exe-via-image-load</loc>
    <lastmod>2026-07-28T23:12:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-activescripteventconsumers-behavior-through-scrcons-exe-dll-load-via-image-load</loc>
    <lastmod>2026-07-28T23:12:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-7za-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:12:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/abusable-dll-possible-sideloading-from-suspicious-location-via-image-load</loc>
    <lastmod>2026-07-28T23:12:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-antivirus-software-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:12:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-appverifui-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:12:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aruba-network-service-possible-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:12:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-avkkid-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:12:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ccleanerdu-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:12:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ccleanerreactivator-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:12:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-chrome-frame-helper-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:12:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-through-classicexplorer32-dll-via-image-load</loc>
    <lastmod>2026-07-28T23:11:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-through-comctl32-dll-via-image-load</loc>
    <lastmod>2026-07-28T23:11:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-via-coregen-exe-via-image-load</loc>
    <lastmod>2026-07-28T23:11:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/system-control-panel-item-loaded-from-unusual-location-via-image-load</loc>
    <lastmod>2026-07-28T23:11:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-dbgcore-dll-via-image-load</loc>
    <lastmod>2026-07-28T23:11:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-dbghelp-dll-via-image-load</loc>
    <lastmod>2026-07-28T23:11:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-dbgmodel-dll-via-image-load</loc>
    <lastmod>2026-07-28T23:11:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-eacore-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-edputil-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-dll-sideloading-from-non-system-locations-via-image-load</loc>
    <lastmod>2026-07-28T23:11:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-goopdate-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-libcurl-dll-through-gup-exe-via-image-load</loc>
    <lastmod>2026-07-28T23:11:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-iviewers-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-jli-dll-side-loading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-through-jsschhlp-via-image-load</loc>
    <lastmod>2026-07-28T23:11:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-keyscramblerie-dll-through-keyscrambler-exe-via-image-load</loc>
    <lastmod>2026-07-28T23:11:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-libvlc-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mfdetours-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-mfdetours-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-mpsvc-dll-via-image-load</loc>
    <lastmod>2026-07-28T23:11:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-mscorsvc-dll-via-image-load</loc>
    <lastmod>2026-07-28T23:11:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-non-existent-dlls-from-system-folders-via-image-load</loc>
    <lastmod>2026-07-28T23:11:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-office-dll-sideload-via-image-load</loc>
    <lastmod>2026-07-28T23:11:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-python-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rcdll-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rjvplatform-dll-sideloading-from-default-location-via-image-load</loc>
    <lastmod>2026-07-28T23:11:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rjvplatform-dll-sideloading-from-non-default-location-via-image-load</loc>
    <lastmod>2026-07-28T23:11:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-roboform-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-sideloading-of-shellchromeapi-dll-via-image-load</loc>
    <lastmod>2026-07-28T23:11:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-shelldispatch-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-smadhook-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-solidpdfcreator-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-third-party-software-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fax-service-dll-search-order-hijack-via-image-load</loc>
    <lastmod>2026-07-28T23:11:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-vcruntime140-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-vivaldi-elf-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vmguestlib-dll-sideload-via-image-load</loc>
    <lastmod>2026-07-28T23:11:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vmmap-signed-dbghelp-dll-possible-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vmmap-unsigned-dbghelp-dll-possible-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-through-vmware-xfer-via-image-load</loc>
    <lastmod>2026-07-28T23:11:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-waveedit-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-wazuh-security-platform-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mpclient-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-wwlib-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-28T23:11:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/baaupdate-exe-suspicious-dll-load-via-image-load</loc>
    <lastmod>2026-07-28T23:11:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-module-loaded-by-clickonce-application-via-image-load</loc>
    <lastmod>2026-07-28T23:11:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dll-load-by-system-process-from-suspicious-locations-via-image-load</loc>
    <lastmod>2026-07-28T23:11:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-python-image-load-by-non-python-process-via-image-load</loc>
    <lastmod>2026-07-28T23:11:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dotnet-clr-dll-loaded-by-scripting-applications-via-image-load</loc>
    <lastmod>2026-07-28T23:11:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-dll-loaded-by-windows-utility-via-image-load</loc>
    <lastmod>2026-07-28T23:11:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-unsigned-thor-scanner-via-image-load</loc>
    <lastmod>2026-07-28T23:11:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-iscsicpl-imageload-via-image-load</loc>
    <lastmod>2026-07-28T23:11:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-with-fake-dll-via-image-load</loc>
    <lastmod>2026-07-28T23:11:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mmc-loading-script-engines-dlls-via-image-load</loc>
    <lastmod>2026-07-28T23:11:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-loading-of-dbgcore-dbghelp-dlls-from-unusual-location-via-image-load</loc>
    <lastmod>2026-07-28T23:11:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-trusted-path-bypass-through-windows-directory-spoofing-via-image-load</loc>
    <lastmod>2026-07-28T23:11:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-persistence-command-line-event-consumer-via-image-load</loc>
    <lastmod>2026-07-28T23:11:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmic-loading-scripting-libraries-via-image-load</loc>
    <lastmod>2026-07-28T23:11:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmiprvse-wbemcomn-dll-hijack-via-image-load</loc>
    <lastmod>2026-07-28T23:11:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wsman-provider-image-loads-via-image-load</loc>
    <lastmod>2026-07-28T23:11:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-by-addinutil-exe-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-connection-to-active-directory-web-services-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-network-connection-initiated-by-certutil-exe-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-network-connection-initiated-by-cmstp-exe-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-network-connection-initiated-by-microsoft-dialer-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-to-azurewebsites-net-by-non-browser-process-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-to-btunnels-domains-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-to-cloudflared-tunnels-domains-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-traffic-with-crypto-mining-pool-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/new-connection-initiated-to-possible-dead-drop-resolver-domain-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-to-devtunnels-domain-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dropbox-api-use-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-to-ip-lookup-service-apis-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-non-browser-network-traffic-with-google-api-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-traffic-to-localtonet-tunneling-service-initiated-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-network-connection-initiated-to-mega-nz-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-initiated-network-connection-to-ngrok-domain-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-traffic-to-ngrok-tunneling-service-initiated-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-network-connection-to-notion-api-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-traffic-initiated-to-portmap-io-domain-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-non-browser-network-traffic-with-telegram-api-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-to-visual-studio-code-tunnels-domain-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-by-eqnedt32-exe-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-through-finger-exe-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-by-imewdbld-exe-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-through-notepad-exe-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-office-application-initiated-network-connection-to-non-local-ip-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/office-application-initiated-network-connection-over-unusual-ports-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-initiated-connection-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-rdp-connections-over-non-standard-utilities-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-over-reverse-ssh-tunnel-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-to-http-or-https-target-ports-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regasm-exe-initiating-network-connection-to-public-ip-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-by-regsvr32-exe-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-anydesk-incoming-connection-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-internet-connection-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-silenttrinity-stager-msbuild-behavior-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-binary-no-commandline-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/network-traffic-initiated-to-file-sharing-domains-from-process-located-in-suspicious-folder-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/network-connection-initiated-from-process-located-in-potentially-suspicious-or-unusual-location-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-malware-callback-traffic-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/traffic-to-unusual-destination-ports-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-outbound-kerberos-connection-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-sync-center-suspicious-network-connections-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-smtp-connections-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-powershell-session-initiated-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-network-connection-to-public-ip-through-winlogon-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wordpad-outbound-connections-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-local-network-connection-initiated-by-script-interpreter-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-network-connection-initiated-by-script-interpreter-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-wuauclt-network-connection-via-network-connection</loc>
    <lastmod>2026-07-28T23:10:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/adfs-database-named-pipe-connection-by-unusual-utility-via-pipe-created</loc>
    <lastmod>2026-07-28T23:10:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobaltstrike-named-pipe-via-pipe-created</loc>
    <lastmod>2026-07-28T23:10:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobaltstrike-named-pipe-pattern-regex-via-pipe-created</loc>
    <lastmod>2026-07-28T23:10:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobaltstrike-named-pipe-patterns-via-pipe-created</loc>
    <lastmod>2026-07-28T23:10:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-coercedpotato-named-pipe-creation-via-pipe-created</loc>
    <lastmod>2026-07-28T23:10:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-diagtrackeop-default-named-pipe-via-pipe-created</loc>
    <lastmod>2026-07-28T23:10:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-efspotato-named-pipe-creation-via-pipe-created</loc>
    <lastmod>2026-07-28T23:10:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-credential-dumping-tools-named-pipe-created-via-pipe-created</loc>
    <lastmod>2026-07-28T23:10:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-koh-default-named-pipe-via-pipe-created</loc>
    <lastmod>2026-07-28T23:10:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-alternate-powershell-hosts-pipe-via-pipe-created</loc>
    <lastmod>2026-07-28T23:09:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-new-powershell-instance-via-pipe-created</loc>
    <lastmod>2026-07-28T23:09:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-csexec-default-named-pipe-via-pipe-created</loc>
    <lastmod>2026-07-28T23:09:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-paexec-default-named-pipe-via-pipe-created</loc>
    <lastmod>2026-07-28T23:09:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-remcom-default-named-pipe-via-pipe-created</loc>
    <lastmod>2026-07-28T23:09:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-event-consumer-created-named-pipe-via-pipe-created</loc>
    <lastmod>2026-07-28T23:09:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-malicious-named-pipe-via-pipe-created</loc>
    <lastmod>2026-07-28T23:09:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/psexec-utility-execution-from-suspicious-locations-pipename-via-pipe-created</loc>
    <lastmod>2026-07-28T23:09:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-nslookup-powershell-download-cradle-via-ps-classic-start</loc>
    <lastmod>2026-07-28T23:09:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-delete-volume-shadow-copies-through-wmi-with-powershell-via-ps-classic-start</loc>
    <lastmod>2026-07-28T23:09:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-downgrade-attack-powershell-via-ps-classic-start</loc>
    <lastmod>2026-07-28T23:09:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-download-through-net-webclient-powershell-classic-via-ps-classic-start</loc>
    <lastmod>2026-07-28T23:09:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-called-from-an-executable-version-mismatch-via-ps-classic-start</loc>
    <lastmod>2026-07-28T23:09:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netcat-the-powershell-version-via-ps-classic-start</loc>
    <lastmod>2026-07-28T23:09:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-powershell-session-ps-classic-via-ps-classic-start</loc>
    <lastmod>2026-07-28T23:09:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remotefxvgpudisablement-exe-misuse-via-powershell-classic</loc>
    <lastmod>2026-07-28T23:09:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-renamed-powershell-under-powershell-channel-via-ps-classic-start</loc>
    <lastmod>2026-07-28T23:09:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-use-get-nettcpconnection-via-ps-classic-start</loc>
    <lastmod>2026-07-28T23:09:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-zip-a-folder-with-powershell-for-staging-in-temp-powershell-via-powershell-classic</loc>
    <lastmod>2026-07-28T23:09:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tamper-windows-defender-psclassic-via-ps-classic-provider-start</loc>
    <lastmod>2026-07-28T23:09:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-non-powershell-wsman-com-provider-via-powershell-classic</loc>
    <lastmod>2026-07-28T23:09:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-enumeration-via-ad-module-psmodule-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-alternate-powershell-hosts-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bad-opsec-powershell-code-artifacts-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clear-powershell-history-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-decompress-commands-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-scripts-poshmodule-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-addbaccount-use-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-get-clipboard-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-evil-winrm-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-clip-launcher-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-obfuscated-iex-invocation-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-stdin-launcher-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-compress-obfuscation-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-rundll-launcher-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-stdin-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-clip-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-mshta-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-rundll32-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-obfuscation-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-commandlets-poshmodule-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-powershell-session-ps-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remotefxvgpudisablement-exe-misuse-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ad-groups-or-users-enumeration-via-powershell-poshmodule-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-poshmodule-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-use-get-nettcpconnection-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invocations-generic-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invocations-specific-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-local-groups-information-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-computer-machine-password-by-powershell-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-information-for-smb-share-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-zip-a-folder-with-powershell-for-staging-in-temp-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-syncappvpublishingserver-bypass-powershell-restriction-ps-module-via-ps-module</loc>
    <lastmod>2026-07-28T23:09:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-aadinternals-powershell-cmdlets-psscript-via-ps-script</loc>
    <lastmod>2026-07-28T23:09:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-to-browser-login-data-via-ps-script</loc>
    <lastmod>2026-07-28T23:09:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-enumeration-via-ad-module-psscript-via-ps-script</loc>
    <lastmod>2026-07-28T23:09:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-add-name-resolution-policy-table-rule-via-ps-script</loc>
    <lastmod>2026-07-28T23:09:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-windows-capability-through-powershell-script-via-ps-script</loc>
    <lastmod>2026-07-28T23:09:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-powershell-adrecon-via-ps-script</loc>
    <lastmod>2026-07-28T23:09:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-amsi-bypass-pattern-assembly-gettype-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-amsi-bypass-script-via-null-bits-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-silence-eda-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-get-aduser-enumeration-via-useraccountcontrol-flags-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-data-exfiltration-through-audio-file-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-automated-collection-command-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-screen-capture-with-copyfromscreen-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clear-powershell-history-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-windows-console-history-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-create-scheduled-task-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-computer-enumeration-and-export-through-get-adcomputer-cmdlet-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-install-a-dll-in-system-directory-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-free-process-scope-cor-profiler-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-create-local-user-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dmsa-service-account-created-in-specific-ous-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-create-volume-shadow-copy-with-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-detect-virtualization-environment-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-directorysearcher-powershell-exploitation-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-manipulation-of-user-computer-or-group-security-principals-across-ad-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-powershell-command-history-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windowsoptionalfeature-command-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-in-memory-execution-via-reflection-assembly-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-com-objects-download-cradles-use-ps-script-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dsinternals-suspicious-powershell-cmdlets-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dump-credentials-from-windows-credential-manager-with-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-windows-remote-management-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-windows-feature-enabled-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enumerate-credentials-from-windows-credential-manager-with-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-of-etw-trace-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-exported-through-powershell-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-frombase64string-use-on-gzip-archive-ps-script-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-registry-permissions-weakness-check-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-computers-enumeration-with-get-adcomputer-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-group-enumeration-with-get-adgroup-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-adreplaccount-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-automated-collection-bookmarks-via-get-childitem-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-security-software-enumeration-through-powershell-script-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-rubeus-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-winpwn-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-hotfix-enumeration-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-icmp-exfiltration-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/import-powershell-modules-from-suspicious-directories-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-appx-deployment-attempt-via-add-appxpackage-psscript-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execute-invoke-command-on-remote-host-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-dnsexfiltration-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-clip-launcher-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-obfuscated-iex-invocation-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-stdin-launcher-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-compress-obfuscation-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-rundll-launcher-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-stdin-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-clip-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-mshta-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-rundll32-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-obfuscation-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-keylogging-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-localaccount-manipulation-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-mailbox-export-to-share-ps-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-commandlets-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:08:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-keywords-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-live-memory-dump-via-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-change-of-dmsa-link-attributes-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modify-group-policy-settings-scriptblocklogging-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-msxml-com-object-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-nishang-powershell-commandlets-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntfs-alternate-data-stream-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-code-executed-through-office-add-in-xll-file-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-packet-capture-behavior-through-start-neteventsession-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-invoke-mimikatz-powershell-script-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-unconstrained-delegation-enumeration-through-get-adcomputer-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-web-access-deployment-psscript-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powerview-powershell-cmdlets-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-credential-prompt-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psasyncshell-asynchronous-tcp-reverse-shell-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-psattack-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-remote-session-creation-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remotefxvgpudisablement-exe-misuse-powershell-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kerberos-ticket-request-through-powershell-script-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-script-with-file-hostname-resolving-capabilities-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-root-certificate-installed-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-item-from-mount-diskimage-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-script-with-file-upload-capabilities-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-sensitive-file-enumeration-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-script-change-permission-through-set-acl-psscript-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-set-acl-on-windows-folder-psscript-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-powershell-policies-to-an-insecure-level-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-shellcode-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shellintel-powershell-commandlets-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-detected-windows-software-enumeration-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-store-file-in-alternate-data-stream-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-security-descriptors-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ad-groups-or-users-enumeration-via-powershell-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-obfuscation-via-character-join-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-eventlog-clear-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-directory-enumeration-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-powershell-script-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-execute-batch-script-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-extracting-information-with-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-troubleshooting-pack-cmdlet-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-password-policy-enumeration-with-get-addefaultdomainpasswordpolicy-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-get-current-user-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gpo-enumeration-with-get-gpo-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-enumeration-with-get-process-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-get-process-lsass-in-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gettypefromclsid-shellexecute-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hyper-v-cmdlets-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invocations-generic-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invocations-specific-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-user-agents-with-webrequest-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-io-filestream-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-keylogger-behavior-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-powershell-keywords-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-local-groups-information-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-local-email-collection-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mount-diskimage-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-deleted-mounted-share-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-connection-to-remote-account-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-psdrive-to-admin-share-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tcp-tunnel-through-powershell-script-via-ps-script</loc>
    <lastmod>2026-07-28T23:07:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-information-for-export-with-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remove-account-from-domain-admin-group-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-dacl-change-through-set-service-cmdlet-ps-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-obfuscation-via-alias-cmdlets-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-information-for-smb-share-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ssl-connection-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-start-process-passthru-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unblock-file-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-replace-desktop-wallpaper-by-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-suspicious-win32-pnpentity-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-volume-shadow-copies-through-wmi-with-powershell-ps-script-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-windowstyle-option-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-write-eventlog-use-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-zip-a-folder-with-powershell-for-staging-in-temp-powershell-script-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-syncappvpublishingserver-execution-to-bypass-powershell-restriction-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tamper-windows-defender-remove-mppreference-scriptblocklogging-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tamper-windows-defender-scriptblocklogging-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-testing-use-of-uncommonly-used-port-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-timestomp-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-user-enumeration-and-export-through-get-aduser-cmdlet-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-powershell-user-profile-via-add-content-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-misuse-of-service-permissions-to-hide-services-through-set-service-ps-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-change-attempt-through-vbscript-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-veeam-backup-servers-credential-dumping-script-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-web-request-commands-and-cmdlets-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-call-to-win32-nteventlogfile-class-psscript-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-wmi-win32-product-install-msi-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-winapi-calls-through-powershell-scripts-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-exclusions-added-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-firewall-profile-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winlogon-helper-dll-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-wmi-persistence-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmic-unquoted-services-path-lookup-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmimplant-hack-utility-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-x509enrollment-ps-script-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-xml-execute-command-via-ps-script</loc>
    <lastmod>2026-07-28T23:06:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmstp-execution-process-access-via-process-access</loc>
    <lastmod>2026-07-28T23:06:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-cobaltstrike-bof-injection-pattern-via-process-access</loc>
    <lastmod>2026-07-28T23:06:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-generic-process-access-via-process-access</loc>
    <lastmod>2026-07-28T23:06:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-handlekatz-duplicating-lsass-handle-via-process-access</loc>
    <lastmod>2026-07-28T23:06:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-littlecorporal-generated-maldoc-injection-via-process-access</loc>
    <lastmod>2026-07-28T23:06:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sysmonente-execution-via-process-access</loc>
    <lastmod>2026-07-28T23:06:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-memory-dump-through-comsvcs-dll-via-process-access</loc>
    <lastmod>2026-07-28T23:06:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-memory-access-by-utility-with-dump-keyword-in-name-via-process-access</loc>
    <lastmod>2026-07-28T23:06:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-behavior-through-lsass-via-process-access</loc>
    <lastmod>2026-07-28T23:06:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-dumping-behavior-by-python-based-utility-via-process-access</loc>
    <lastmod>2026-07-28T23:06:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-lsass-process-access-through-windows-remote-management-via-process-access</loc>
    <lastmod>2026-07-28T23:06:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-access-through-malseclogon-via-process-access</loc>
    <lastmod>2026-07-28T23:06:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-grantedaccess-flags-on-lsass-via-process-access</loc>
    <lastmod>2026-07-28T23:06:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-dumping-attempt-through-werfault-via-process-access</loc>
    <lastmod>2026-07-28T23:06:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-access-from-potentially-white-listed-processes-via-process-access</loc>
    <lastmod>2026-07-28T23:06:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-process-access-rights-for-target-image-via-process-access</loc>
    <lastmod>2026-07-28T23:06:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-access-to-lsass-with-dbgcore-dbghelp-dlls-via-process-access</loc>
    <lastmod>2026-07-28T23:06:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-direct-syscall-of-ntopenprocess-via-process-access</loc>
    <lastmod>2026-07-28T23:06:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-dumping-attempt-through-svchost-via-process-access</loc>
    <lastmod>2026-07-28T23:06:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-svchost-process-access-via-process-access</loc>
    <lastmod>2026-07-28T23:06:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-function-call-from-undocumented-com-interface-editionupgrademanager-via-process-access</loc>
    <lastmod>2026-07-28T23:06:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-wow64-logger-dll-hijack-via-process-access</loc>
    <lastmod>2026-07-28T23:06:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-access-of-msmpeng-by-werfaultsecure-edr-freeze-via-process-access</loc>
    <lastmod>2026-07-28T23:06:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-7zip-compressing-dump-files-via-process-creation</loc>
    <lastmod>2026-07-28T23:06:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-compress-data-and-lock-with-password-for-exfiltration-with-7-zip-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-injection-through-acccheckconsole-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-addinutil-exe-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-addinutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-unusual-addinutil-exe-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/addinutil-exe-execution-from-unusual-directory-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-adplus-exe-misuse-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-agentexecutor-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-agentexecutor-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-amsi-related-registry-manipulation-through-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-appvlp-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arcsoc-exe-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-aspnetcompiler-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-aspnetcompiler-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-asp-net-compilation-through-aspnetcompiler-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-interactive-at-job-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-assistive-technology-applications-execution-through-atbroker-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hiding-files-with-attrib-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/set-suspicious-files-as-system-files-via-attrib-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-audit-policy-manipulation-through-nt-resource-kit-auditpol-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-audit-policy-manipulation-through-auditpol-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-eventlog-autologger-session-registry-change-through-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-autorun-registry-modified-through-wmi-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-bitlocker-access-agent-update-utility-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-indirect-inline-command-execution-through-bash-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-indirect-command-execution-from-script-file-through-bash-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-boot-configuration-manipulation-through-bcdedit-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ransomware-or-unauthorized-mbr-manipulation-through-bcdedit-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-export-from-mssql-table-through-bcp-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-bginfo-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-bginfo-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-bitlockertogo-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-through-bitsadmin-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-from-direct-ip-through-bitsadmin-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-from-file-sharing-website-through-bitsadmin-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-with-suspicious-extension-downloaded-through-bitsadmin-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-download-through-bitsadmin-to-a-suspicious-target-folder-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-monitoring-for-persistence-through-bits-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-data-stealing-through-chromium-headless-debugging-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-browser-execution-in-headless-mode-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-with-headless-browser-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chromium-browser-instance-executed-with-custom-extension-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chromium-browser-headless-execution-to-mockbin-like-site-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chromium-browser-instance-executed-with-custom-extension-suspicious-parent-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-browser-process-through-inline-url-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-started-with-remote-debugging-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-tor-client-browser-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-calculator-use-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-binary-proxy-execution-through-cdb-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-root-certificate-installed-through-certmgr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-through-certoc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-ip-based-url-through-certoc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-loaded-through-certoc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-loaded-through-certoc-exe-uncommon-location-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certreq-command-to-download-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-root-certificate-installed-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-decoded-from-base64-hex-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-downloaded-from-direct-ip-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-downloaded-from-file-sharing-website-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:05:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-encoded-to-base64-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-encoded-to-base64-through-certutil-exe-uncommon-extension-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-in-suspicious-location-encoded-to-base64-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-exported-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ntlm-coercion-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-console-codepage-lookup-through-chcp-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codepage-switch-through-chcp-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deleted-data-overwritten-through-cipher-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-access-through-trolleyexpress-exclusion-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-data-copied-to-clipboard-through-clip-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-cloudflared-portable-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-cloudflared-quick-tunnel-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cloudflared-tunnel-connections-cleanup-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-cloudflared-tunnel-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-change-default-file-association-through-assoc-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-default-file-association-to-executable-through-assoc-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copy-dmp-dump-files-from-remote-share-through-cmd-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-download-and-execute-combination-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-removal-through-del-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-greedy-file-removal-via-del-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-and-subfolder-enumeration-through-dir-command-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dosfuscation-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/command-line-execution-with-suspicious-url-and-appdata-strings-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cmd-launched-with-hidden-start-flags-to-suspicious-targets-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privilege-escalation-via-symlink-between-osk-and-cmd-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-volumeshadowcopy-symlink-creation-through-mklink-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-execution-from-internet-hosted-webdav-share-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmd-exe-missing-space-characters-execution-anomaly-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-ntdllpipe-like-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-commandline-path-traversal-through-cmd-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-ping-copy-command-combination-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ping-del-command-combination-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-cmd-shell-output-redirect-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-directory-removal-through-rmdir-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copy-from-volumeshadowcopy-through-cmd-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-read-contents-from-stdin-through-cmd-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-sticky-key-like-backdoor-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-persistence-through-sticky-key-backdoor-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-download-upload-behavior-via-type-command-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-parent-process-for-cmd-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-generic-credentials-added-through-cmdkey-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-for-cached-credentials-through-cmdkey-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-arbitrary-file-download-through-cmdl32-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmstp-execution-process-creation-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-openedr-spawning-command-shell-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-configsecuritypolicy-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-executed-from-headless-conhost-process-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-high-integritylevel-conhost-legacy-option-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-conhost-exe-commandline-path-traversal-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-conhost-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-processes-spawned-by-conhost-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/conhost-spawned-by-unusual-parent-process-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-control-panel-items-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-dmsa-service-account-created-in-specific-ous-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-createdump-process-dump-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-credential-guard-registry-manipulation-through-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dynamic-net-compilation-through-csc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/csc-exe-execution-form-potentially-suspicious-parent-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-csi-exe-use-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-csharp-interactive-console-via-process-creation</loc>
    <lastmod>2026-07-28T23:04:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-structure-export-through-csvde-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cookies-session-hijacking-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/curl-web-request-with-possible-custom-user-agent-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-ip-url-through-curl-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-ip-through-curl-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-file-sharing-domain-through-curl-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-insecure-transfer-through-curl-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-insecure-proxy-doh-transfer-through-curl-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-local-file-read-via-curl-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntlm-hash-leak-through-curl-ntlm-authentication-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-exe-download-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-file-upload-to-file-sharing-websites-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-customshellhost-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/manageengine-endpoint-central-dctask64-exe-possible-misuse-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-defaultpack-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-defender-threat-severity-default-action-set-to-allow-or-noaction-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-windows-defender-context-menu-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-file-download-through-desktopimgdownldr-utility-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-desktopimgdownldr-command-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-devcon-execution-disabling-vmware-vmci-device-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-devicecredentialdeployment-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-through-deviceenroller-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-msi-download-through-devinit-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-process-of-clickonce-application-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-dirlister-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-through-registry-queries-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-process-of-diskshadow-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-diskshadow-script-mode-uncommon-script-extension-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/diskshadow-script-mode-execution-from-potential-suspicious-location-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-web-access-feature-enabled-through-dism-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dism-remove-online-package-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-sideloading-by-vmware-xfer-utility-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dllhost-exe-execution-anomaly-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-exfiltration-and-tunneling-utilities-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-dns-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-behavior-through-dnscmd-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-dns-serverlevelplugindll-installed-through-dnscmd-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-application-whitelisting-bypass-through-dnx-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-dll-or-csproj-code-execution-through-dotnet-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-binary-proxy-execution-through-dotnet-trace-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-memory-dump-through-dotnet-dump-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-behavior-via-driverquery-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-driverquery-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-potentially-over-permissive-permissions-granted-via-dsacls-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-password-spraying-attempt-via-dsacls-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-domain-trust-enumeration-through-dsquery-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kernel-dump-via-dtrace-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-defender-av-bypass-through-dump64-exe-rename-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-dumpminitool-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-dumpminitool-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-capture-session-launched-through-dxcap-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esentutl-gather-credentials-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copying-sensitive-files-with-credential-data-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esentutl-steals-browser-information-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-event-logging-disabled-through-minint-registry-key-process-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-event-viewer-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-cabinet-file-expansion-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-explorer-process-tree-break-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-explorer-folder-opened-via-explorer-folder-shortcut-through-shell-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-explorer-nouaccheck-flag-via-process-creation</loc>
    <lastmod>2026-07-28T23:03:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-file-download-through-findstr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-findstr-gpp-passwords-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-findstr-launching-lnk-file-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-lsass-process-recon-through-findstr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-permission-misconfiguration-recon-through-findstr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-command-output-piped-to-findstr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-utilities-keyword-lookup-through-findstr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-insensitive-subfolder-search-through-findstr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sysmon-enumeration-through-default-driver-altitude-via-findstr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-finger-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-filter-driver-unloaded-through-fltmc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-driver-unloaded-through-fltmc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-forfiles-exe-child-process-masquerading-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-forfiles-command-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-filesystem-load-attempt-by-format-com-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-fsharp-interpreters-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-fsutil-drive-enumeration-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-ntfs-symlink-behavior-change-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fsutil-suspicious-invocation-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-arbitrary-command-execution-through-ftp-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-gfxdownloadwrapper-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-git-clone-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-github-self-hosted-runner-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-googleupdate-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-decryption-via-gpg4win-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-encryption-via-gpg4win-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-portable-gpg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-encryption-decryption-through-gpg4win-from-suspicious-locations-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gpresult-display-group-policy-information-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-binary-execution-via-gup-utility-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-via-notepad-gup-utility-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-notepad-updater-gup-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gup-use-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-hh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-chm-file-download-execution-through-hh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/html-help-hh-exe-suspicious-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-hh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-adcspwn-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-bloodhound-sharphound-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-f-secure-c3-load-by-rundll32-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-certify-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-certipy-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-operator-bloopers-cobalt-strike-commands-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-operator-bloopers-cobalt-strike-modules-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobaltstrike-load-by-rundll32-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cobaltstrike-process-patterns-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-coercedpotato-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-covenant-powershell-launcher-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-crackmapexec-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-crackmapexec-execution-patterns-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-crackmapexec-process-patterns-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-crackmapexec-powershell-obfuscation-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-createminidump-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-dinjector-powershell-cradle-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-doppelanger-lsass-dumper-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-dumpert-process-dumper-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-edr-freeze-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-edrsilencer-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-empire-powershell-launch-parameters-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-empire-powershell-uac-bypass-via-process-creation</loc>
    <lastmod>2026-07-28T23:02:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-winrm-access-through-evil-winrm-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-imphash-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-pe-metadata-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-gmer-rootkit-detector-and-remover-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-handlekatz-lsass-dumper-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-hashcat-password-cracker-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-hollowreaper-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-htran-natbypass-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-hydra-password-bruteforce-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/hacktool-potential-impacket-lateral-movement-activity-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-impacket-tools-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-impersonate-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-inveigh-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-clip-launcher-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-obfuscated-iex-invocation-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-stdin-launcher-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-compress-obfuscation-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-stdin-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-clip-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-mshta-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-obfuscation-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-jlaive-in-memory-assembly-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-koadic-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-krbrelay-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-remotekrbrelay-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-krbrelayup-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-lazagne-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-localpotato-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-meterpreter-cobaltstrike-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-mimikatz-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-netexec-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-pchunter-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-default-powersploit-empire-scheduled-task-creation-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-powertool-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-purplesharp-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-pypykatz-credentials-dumping-activity-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-quarks-pwdump-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-redmimicry-winnti-playbook-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-smb-relay-attack-utility-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-rubeus-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-safetykatz-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-securityxploded-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-ppid-spoofing-selectmyparent-tool-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpchisel-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpdpapi-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpimpersonation-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpldapmonitor-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpersist-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpevtmute-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpldapwhoami-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpmove-tool-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hktl-sharpsuccessor-privilege-escalation-tool-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpup-privesc-tool-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpview-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpwsus-wsuspendu-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-silenttrinity-stager-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sliver-c2-implant-activity-pattern-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-soaphound-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-stracciatella-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:01:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sysmoneop-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-trufflesnout-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-uacme-akagi-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-windows-credential-editor-wce-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-winpeas-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-winpwn-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-wmiexec-default-powershell-command-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-wsass-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-xordump-execution-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-zipexec-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-hostname-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hypervisor-protected-code-integrity-hvci-related-registry-manipulation-through-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hwp-sub-processes-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-fake-instance-of-hxtsr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-icacls-to-hide-file-to-everyone-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-and-execution-through-ieexec-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/self-extracting-package-creation-through-iexpress-exe-from-potentially-suspicious-location-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windows-iis-http-logging-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-iis-service-account-password-dumped-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-native-code-module-command-line-deployment-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-url-globalrules-rewrite-through-appcmd-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-iis-connection-strings-decryption-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-webserver-log-removal-through-commandline-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-module-registration-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-c-il-code-compilation-through-ilasm-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/imagingdevices-unusual-parent-child-processes-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-imewdbld-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-infdefaultinstall-exe-inf-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-through-installutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-installutil-without-log-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shells-spawn-by-java-utility-keytool-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-manage-engine-servicedesk-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-java-running-with-remote-debugging-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-processes-spawned-by-java-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-process-spawned-by-java-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysaidserver-child-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-jscript-compiler-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kavremover-dropped-binary-lolbin-use-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-windows-kernel-debugger-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-attempts-of-kerberos-coercion-through-dns-spn-spoofing-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-process-of-keyscrambler-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-computer-password-change-through-ksetup-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-logged-on-user-password-change-through-ksetup-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-structure-export-through-ldifde-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-import-ldap-data-interchange-format-file-through-ldifde-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-link-exe-parent-process-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rebuild-performance-counter-values-through-lodctr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-trace-etw-session-tamper-through-logman-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lolbas-data-exfiltration-by-datasvcutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-devtoolslauncher-exe-executes-specified-binary-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-diantz-alternate-data-stream-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-diantz-download-and-compress-into-a-cab-file-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-extrac32-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-extrac32-alternate-data-stream-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-behavior-through-gathernetworkinfo-vbs-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-gpscript-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ie4uinit-lolbin-use-from-invalid-path-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-launch-vsdevshell-ps1-proxy-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-manage-bde-wsf-misuse-to-proxy-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mavinject-inject-dll-into-running-process-via-process-creation</loc>
    <lastmod>2026-07-28T23:00:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mpiexec-lolbin-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execute-files-with-msdeploy-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-openconsole-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-openwith-exe-executes-specified-binary-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-use-of-pcalua-for-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-indirect-command-execution-by-program-compatibility-wizard-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execute-pcwrun-exe-to-leverage-follina-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-code-execution-through-pcwutl-dll-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execute-code-with-pester-bat-as-parent-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execute-code-with-pester-bat-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-printbrm-zip-creation-of-extraction-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pubprn-vbs-proxy-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-execution-through-rasautou-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-register-app-vbs-proxy-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-remote-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-replace-exe-use-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lolbin-runexehelper-use-as-proxy-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-runscripthelper-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-scriptrunner-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-via-settingsynchost-exe-as-lolbin-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-the-sftp-exe-binary-as-a-lolbin-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-driver-install-by-pnputil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-grpconv-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dumping-process-through-sqldumper-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-syncappvpublishingserver-execute-arbitrary-powershell-code-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-syncappvpublishingserver-vbs-execute-arbitrary-powershell-code-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-injection-or-execution-via-tracker-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-ttdinject-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-time-travel-debugging-utility-use-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lolbin-unregmp2-exe-use-as-proxy-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-utilityfunctions-ps1-proxy-dll-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-visual-basic-command-line-compiler-use-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-visualuiaverifynative-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-vsiisexelauncher-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-wfc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-register-app-vbs-lolscript-misuse-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsa-ppl-protection-setting-change-through-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-through-lsass-process-clone-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mftrace-exe-misuse-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-default-domain-gpo-change-through-gpme-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mmc20-lateral-movement-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mmc-executing-files-with-reversed-extensions-via-rtlo-misuse-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mmc-spawning-windows-shell-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codepage-change-through-mode-com-to-russian-language-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-suspicious-mofcomp-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mpclient-dll-sideloading-through-defender-binaries-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-through-windows-defender-mpcmprun-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-windows-defender-definition-files-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msbuild-execution-by-unusual-parent-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msdt-execution-through-answer-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-arbitrary-command-execution-via-msdt-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cabinet-file-execution-through-msdt-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msdt-parent-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-msedge-proxy-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remotely-hosted-hta-file-executed-through-mshta-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-shell-run-in-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-javascript-execution-through-mshta-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-lethalhta-technique-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mshta-execution-with-suspicious-file-extensions-via-process-creation</loc>
    <lastmod>2026-07-28T22:59:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-exe-execution-patterns-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dllunregisterserver-function-call-through-msiexec-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-embedding-parent-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-execute-arbitrary-dll-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-quiet-deployment-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-quiet-install-from-remote-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-msiexec-masquerading-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-web-install-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-windows-msix-package-support-framework-ai-stubs-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-msohtmed-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-mspub-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-process-injection-through-msra-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-detection-of-powershell-execution-through-sqlps-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-client-utilities-powershell-session-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-sql-server-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-veeam-dabatase-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mstsc-shadowing-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-remote-desktop-connection-initiated-through-mstsc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mstsc-exe-execution-with-local-rdp-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mstsc-exe-execution-with-local-rdp-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mstsc-exe-execution-from-unusual-parent-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-msxsl-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-xsl-execution-through-msxsl-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-group-and-account-recon-behavior-via-net-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-unmount-share-through-net-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-start-windows-service-through-net-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-stop-windows-service-through-net-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-admin-share-mount-through-net-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-internet-hosted-webdav-share-mount-through-net-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-share-mount-through-net-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-network-connections-enumeration-through-net-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-provided-in-command-line-of-net-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-user-created-through-net-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-user-created-through-net-exe-with-never-expire-option-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-manipulation-of-default-accounts-through-net-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-share-and-session-enumeration-via-net-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-firewall-rule-added-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-program-location-whitelisted-in-firewall-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-connection-allowed-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-rule-deleted-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-disabled-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netsh-allow-group-policy-on-microsoft-defender-firewall-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-firewall-configuration-enumeration-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-rule-update-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-netsh-helper-dll-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-network-trace-capture-started-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-port-forwarding-rule-added-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-port-forwarding-rule-added-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-harvesting-of-wifi-credentials-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-nltest-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-behavior-through-nltest-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-arbitrary-code-execution-through-node-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-node-process-executions-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-agent-skills-deployment-attempt-through-node-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-notepad-password-files-enumeration-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-network-recon-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-nslookup-powershell-download-cradle-processcreation-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-active-directory-diagnostic-utility-ntdsutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invocation-of-active-directory-diagnostic-utility-ntdsutil-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-driver-dll-deployment-through-odbcconf-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:58:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-driver-dll-deployment-through-odbcconf-exe-uncommon-extension-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/odbcconf-exe-suspicious-dll-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-dll-registered-through-odbcconf-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-dll-registered-through-odbcconf-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-response-file-execution-through-odbcconf-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-response-file-execution-through-odbcconf-exe-uncommon-extension-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-spawned-by-odbcconf-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-arbitrary-file-download-via-office-application-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-excel-exe-dcom-lateral-movement-through-activatemicrosoftapp-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-office-document-executed-from-trusted-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/onenote-exe-execution-of-malicious-embedded-scripts-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-onenote-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outlook-enableunsafeclientmailrules-setting-enabled-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-from-outlook-temporary-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outlook-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-child-process-from-outlook-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-binary-in-user-directory-spawned-from-office-application-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-office-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-arbitrary-dll-load-via-winword-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-mpclient-dll-sideloading-through-offlinescannershell-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pdq-deploy-remote-adminstartion-utility-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-execution-of-pdqdeployrunner-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-perl-inline-command-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-php-inline-command-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ping-hex-ip-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pktmon-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-plink-port-forwarding-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rdp-tunneling-through-plink-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powercfg-execution-to-change-lock-screen-timeout-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-aadinternals-powershell-cmdlets-proccesscreation-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-enumeration-via-ad-module-proccreation-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-windows-capability-through-powershell-cmdlet-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-amsi-bypass-through-net-reflection-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-amsi-bypass-via-null-bits-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-audio-capture-through-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-encoded-powershell-command-line-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-encoded-command-patterns-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-obfuscated-powershell-code-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-base64-encoded-frombase64string-cmdlet-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-base64-encoded-powershell-keywords-in-command-lines-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-base64-encoded-iex-cmdlet-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-base64-encoded-invoke-keyword-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-base64-encoded-mppreference-cmdlet-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-base64-encoded-reflective-assembly-load-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-encoded-and-obfuscated-reflection-assembly-load-function-call-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-base64-encoded-wmi-classes-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-process-execution-proxy-through-cl-invocation-ps1-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-assembly-loading-through-cl-loadassembly-ps1-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-script-proxy-execution-through-cl-mutexverifiers-ps1-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-convertto-securestring-cmdlet-use-through-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-obfuscation-through-reversed-commands-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-command-line-obfuscation-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-obfuscated-powershell-msi-install-through-windowsinstaller-com-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-msi-install-through-windowsinstaller-com-from-remote-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-computer-enumeration-and-export-through-get-adcomputer-cmdlet-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-console-history-access-attempt-through-history-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-service-creation-via-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gzip-archive-decode-through-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-execution-with-possible-decryption-capabilities-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-defender-disable-scan-feature-via-process-creation</loc>
    <lastmod>2026-07-28T22:57:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-defender-exclusion-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windows-defender-av-security-monitoring-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-firewall-disabled-through-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabled-ie-security-features-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-downgrade-attack-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-com-objects-download-cradles-use-process-creation-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-obfuscated-powershell-oneliner-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-file-download-through-powershell-invoke-webrequest-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-and-execution-cradles-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-pattern-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-file-download-from-file-sharing-domain-through-powershell-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dsinternals-suspicious-powershell-cmdlets-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-email-exifiltration-through-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-windows-feature-enabled-proccreation-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-powershell-with-base64-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-encoded-powershell-patterns-in-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-inline-execution-from-a-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-exported-through-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-base64-encoded-powershell-command-detected-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-frombase64string-use-on-gzip-archive-process-creation-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-get-clipboard-cmdlet-through-cli-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-recon-behavior-via-get-localgroupmember-cmdlet-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-get-process-lsass-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-misuse-of-service-permissions-to-hide-services-through-set-service-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-iex-execution-patterns-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-root-certificate-installed-from-susp-locations-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/import-powershell-modules-from-suspicious-directories-proccreation-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-appx-deployment-attempt-via-add-appxpackage-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invocations-specific-processcreation-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-webrequest-execution-with-directip-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-invoke-webrequest-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kerberos-ticket-request-through-cli-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-mailbox-export-to-share-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-commandlets-processcreation-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msexchange-transport-agent-deployment-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-non-interactive-powershell-process-spawned-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-obfuscation-through-wchar-char-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-powershell-script-in-public-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remotefxvgpudisablement-misuse-through-atomictestharnesses-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tamper-windows-defender-remove-mppreference-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-reverseshell-connection-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-powershell-script-from-ads-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-powershell-script-from-redirected-input-stream-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-sam-copy-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invocation-from-script-engines-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-powershell-script-execution-from-temp-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-dacl-change-through-set-service-cmdlet-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-script-change-permission-through-set-acl-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-set-acl-on-windows-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-powershell-policies-to-an-insecure-level-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-startuptype-change-through-powershell-set-service-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-volume-shadow-copies-through-wmi-with-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-exchange-powershell-snap-ins-use-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-stop-windows-service-through-powershell-stop-service-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-and-execute-pattern-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-parameter-substring-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-parent-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-script-run-in-appdata-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-token-obfuscation-process-creation-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uninstall-of-windows-defender-feature-through-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T22:56:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-user-enumeration-and-export-through-get-aduser-cmdlet-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-net-webclient-casing-anomalies-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-x509enrollment-process-creation-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xor-encoded-powershell-command-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/folder-compress-to-potentially-suspicious-output-through-compress-archive-cmdlet-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-presentationhost-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/xbap-execution-from-unusual-locations-through-presentationhost-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-visual-studio-nodejstools-pressanykey-arbitrary-binary-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sensitive-file-dump-through-print-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-abusing-print-executable-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-via-protocolhandler-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-provlaunch-exe-binary-proxy-execution-misuse-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-provlaunch-exe-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-screen-capture-behavior-through-psr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-3proxy-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-suspicious-activedirectory-enumeration-through-adfind-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pua-adfind-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-adfind-suspicious-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-advanced-ip-scanner-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-advanced-port-scanner-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-advancedrun-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-advancedrun-suspicious-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-chisel-tunneling-tool-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-cleanwipe-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-crassus-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-csexec-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-defendercheck-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-dit-snapshot-viewer-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pua-fast-reverse-proxy-frp-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pua-iox-tunneling-utility-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pua-kernel-driver-utility-kdu-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-memory-dump-mount-via-memprocfs-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-mouse-lock-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-netcat-suspicious-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-softperfect-netscan-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-ngrok-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nimgrab-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nimscan-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nircmd-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nircmd-execution-as-local-system-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nmap-zenmap-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nps-tunneling-tool-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nsudo-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-pingcastle-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-pingcastle-execution-from-potentially-suspicious-parent-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-process-hacker-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-radmin-viewer-utility-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-potential-pe-metadata-tamper-using-rcedit-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-rclone-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-restic-backup-tool-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-runxcmd-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-seatbelt-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-system-informer-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-trufflehog-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-webbrowserpassview-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-wsudo-suspicious-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-pua-adidnsdump-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-one-liners-with-base64-decoding-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-python-inline-command-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-spawning-pretty-tty-on-windows-via-process-creation</loc>
    <lastmod>2026-07-28T22:55:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-use-of-qemu-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-query-use-to-exfil-data-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-quickassist-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-files-added-to-an-archive-via-rar-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rar-use-with-password-and-compression-level-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-greedy-compression-via-rar-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rasdial-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-enable-or-disable-through-win32-terminalservicesetting-wmi-class-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-memory-dump-through-rdrleakdiag-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-recovery-environment-disabled-through-reagentc-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-attempt-through-run-keys-via-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-safeboot-keys-through-reg-utility-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-reg-add-bitlocker-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dropping-of-password-filter-dll-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-folder-exclusion-added-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-runmru-registry-key-removal-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-safeboot-registry-key-deleted-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-registry-key-deleted-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-desktop-background-change-via-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-direct-autorun-keys-change-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-windows-defender-wmi-autologger-session-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-service-disabled-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dumping-of-sensitive-hives-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-recall-feature-enabled-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-for-credentials-in-registry-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-registry-file-imported-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-restrictedadminmode-registry-value-manipulation-proccreation-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-query-of-machineguid-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modify-group-policy-settings-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-lm-hash-storage-proccreation-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-configuration-and-service-recon-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-manipulation-with-rdp-related-registry-keys-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-screensave-change-by-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-changing-existing-service-imagepath-value-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-detected-windows-software-enumeration-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/reg-add-suspicious-paths-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-language-enumeration-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-system-restore-registry-change-through-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabled-volume-snapshots-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-registry-key-manipulation-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-write-protect-for-storage-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-regasm-exe-execution-without-commandline-flags-or-files-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-execution-of-regasm-regsvcs-with-unusual-extension-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-execution-of-regasm-regsvcs-from-unusual-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-exports-critical-registry-keys-to-a-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-exports-registry-key-to-a-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-imports-registry-key-from-a-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-imports-registry-key-from-an-ads-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regedit-as-trusted-installer-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-change-from-ads-through-regini-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-registry-change-through-regini-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-execution-through-register-cimprovider-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-for-3rd-party-creds-from-cli-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-export-of-third-party-credentials-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ie-zonemap-setting-downgraded-to-mycomputer-zone-for-http-protocols-through-cli-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-debugger-registration-cmdline-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-logon-scripts-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-attempt-via-new-networkprovider-cli-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-function-execution-security-warning-disabled-in-excel-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privilege-escalation-through-service-permissions-weakness-via-process-creation</loc>
    <lastmod>2026-07-28T22:54:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-provisioning-registry-key-misuse-for-binary-proxy-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-execution-policy-manipulation-proccreation-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hiding-user-account-through-specialaccounts-registry-key-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-through-typedpaths-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-regsvr32-commandline-flag-anomaly-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-regsvr32-http-ip-pattern-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-regsvr32-http-ftp-pattern-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regsvr32-execution-from-remote-share-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-process-of-regsvr32-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/regsvr32-execution-from-possible-suspicious-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/regsvr32-execution-from-highly-suspicious-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/regsvr32-dll-execution-with-suspicious-file-extension-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scripting-commandline-process-spawned-regsvr32-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/regsvr32-dll-execution-with-unusual-extension-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-anydesk-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-anydesk-piped-password-via-cli-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-anydesk-execution-with-known-revoked-signing-certificate-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-anydesk-silent-installation-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-access-utility-anydesk-execution-from-suspicious-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-gotoassist-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-logmein-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-remote-access-utility-possible-meshagent-windows-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-meshagent-command-execution-via-meshcentral-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-netsupport-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-access-utility-netsupport-execution-from-unusual-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-remote-access-utility-renamed-meshagent-windows-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-access-utility-rurat-execution-from-unusual-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-screenconnect-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-screenconnect-installation-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-screenconnect-remote-command-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-access-utility-screenconnect-potential-suspicious-remote-command-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-screenconnect-server-web-shell-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-simple-help-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-tacticalrmm-agent-registration-to-potentially-attacker-controlled-server-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-team-viewer-session-started-on-windows-host-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-ultraviewer-execution-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-of-a-system-time-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-adfind-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-autohotkey-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-autoit-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-through-binary-rename-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-through-rename-of-highly-relevant-binaries-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-boinc-client-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-browsercore-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-cloudflared-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-createdump-utility-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-curl-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-zoho-dctask64-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-ftp-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-gpg-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-jusched-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-mavinject-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-megasync-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-msdt-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-microsoft-teams-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-netsupport-rat-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-nircmd-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-office-binary-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-paexec-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-pingcastle-binary-via-process-creation</loc>
    <lastmod>2026-07-28T22:53:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-plink-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-visual-studio-nodejstools-pressanykey-renamed-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-renamed-rundll32-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-remote-utilities-rat-rurat-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-schtasks-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-sysinternals-debugview-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-procdump-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-psexec-service-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-sysinternals-sdelete-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-vmnat-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-whoami-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-capture-credentials-with-rpcping-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-ruby-inline-command-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rundll32-execution-with-dll-stored-in-ads-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-advpack-call-through-rundll32-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-invoking-inline-vbscript-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-rundll32-installscreensaver-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-key-manager-access-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mshtml-dll-runhtmlapplication-suspicious-use-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-execution-without-commandline-parameters-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntlm-authentication-on-the-printer-spooler-service-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-obfuscated-ordinal-call-through-rundll32-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-spawned-through-explorer-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-memory-dump-through-comsvcs-dll-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-registered-com-objects-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-start-locations-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-setupapi-dll-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/shell32-dll-execution-in-suspicious-directory-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-shelldispatch-dll-functionality-misuse-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-spawning-explorer-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-rundll32-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-control-panel-dll-load-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-execution-with-image-extension-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-shellexec-rundll-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shellexec-rundll-call-through-ordinal-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shimcache-flush-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-behavior-invoking-sys-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-rundll32-exe-execution-of-udl-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-rundll32-unc-path-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rundll32-execution-with-unusual-dll-extension-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-workstation-locking-through-rundll32-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-webdav-client-execution-through-rundll32-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-webdav-client-execution-through-rundll32-exe-high-confidence-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-execution-without-parameters-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-run-once-task-execution-as-configured-in-registry-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privilege-escalation-through-weak-service-permissions-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-service-creation-via-sc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-startuptype-change-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-kernel-driver-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-interesting-service-enumeration-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-allow-service-access-via-security-descriptor-manipulation-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deny-service-access-via-security-descriptor-manipulation-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-dacl-misuse-to-hide-services-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-security-descriptor-manipulation-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-path-change-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-attempt-through-existing-service-manipulation-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-stop-windows-service-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-schtasks-execution-appdata-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-scheduled-tasks-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-scheduled-task-creation-through-schtasks-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:52:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-involving-temp-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-with-curl-and-powershell-execution-combo-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-delete-important-scheduled-task-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-delete-all-scheduled-tasks-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-important-scheduled-task-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/schedule-task-creation-from-env-variable-or-potentially-suspicious-path-through-schtasks-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/schtasks-from-suspicious-folders-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-name-as-guid-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-one-time-only-scheduled-task-at-00-00-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ssh-tunnel-persistence-install-via-a-scheduled-task-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-microsoft-compatibility-appraiser-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-powershell-search-order-hijacking-task-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-executing-payload-from-registry-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-executing-encoded-payload-from-registry-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-schtasks-schedule-types-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-schtasks-schedule-type-with-high-privileges-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-through-masqueraded-xml-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-command-patterns-in-scheduled-task-creation-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-schtasks-creation-or-change-with-system-privileges-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-masquerading-as-system-processes-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-event-consumer-spawning-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-shim-database-persistence-through-sdbinst-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-extension-shim-database-deployment-through-sdbinst-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sdclt-child-processes-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sdiagnhost-calling-suspicious-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-behavior-via-secedit-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-nodejs-execution-of-javascript-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-serv-u-process-pattern-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-setres-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-spn-enumeration-through-setspn-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-setup16-exe-execution-with-custom-lst-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-indirect-command-execution-through-sftp-proxycommand-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-shutdown-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-shutdown-to-log-out-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-sigverif-exe-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-processes-of-sndvol-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-audio-capture-through-soundrecorder-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-speech-runtime-binary-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-splwow64-without-params-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-spool-service-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/veeam-backup-database-suspicious-query-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-veeambackup-database-credentials-dump-through-sqlcmd-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sqlite-chromium-profile-data-db-access-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sqlite-firefox-profile-data-db-access-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-squirrel-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-proxy-execution-through-squirrel-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-port-forwarding-behavior-through-ssh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-program-executed-via-proxy-local-command-through-ssh-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rdp-tunneling-through-ssh-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-amazon-ssm-agent-hijacking-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-through-stordiag-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-start-of-nt-virtual-dos-machine-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-abused-debug-privilege-by-arbitrary-parent-processes-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-local-administrators-group-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-highly-privileged-group-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-remote-desktop-users-group-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execute-from-alternate-data-streams-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-always-install-elevated-windows-installer-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-windows-app-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-shell-command-execution-through-settingcontent-ms-via-process-creation</loc>
    <lastmod>2026-07-28T22:51:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-phishing-pattern-iso-in-archive-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-automated-collection-command-prompt-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bad-opsec-defaults-sacrificial-processes-with-improper-arguments-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-browser-launch-from-document-reader-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-created-as-system-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-commandline-obfuscation-via-escape-characters-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-commandline-obfuscation-via-unicode-characters-from-suspicious-image-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clickfix-filefix-execution-pattern-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-explorer-process-with-whitespace-padding-clickfix-filefix-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-for-loop-with-recursive-directory-search-in-cmd-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-command-line-path-traversal-evasion-attempt-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-browser-data-stealing-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copy-from-or-to-admin-share-or-sysvol-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copy-from-or-to-system-directory-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lol-binary-copied-from-system-directory-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-crypto-mining-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-data-exfiltration-behavior-through-commandline-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-raccine-uninstall-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-double-extension-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-parent-double-extension-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-from-office-domain-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dumpstack-log-defender-evasion-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-always-install-elevated-msi-spawned-cmd-and-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-electron-application-child-processes-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-electron-application-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/elevated-system-shell-spawned-from-unusual-parent-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-powershell-in-link-file-pattern-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-behavior-through-emoji-use-in-commandline-1-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-behavior-through-emoji-use-in-commandline-2-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-behavior-through-emoji-use-in-commandline-3-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-behavior-through-emoji-use-in-commandline-4-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-etw-logging-tamper-in-net-processes-through-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-etw-trace-evasion-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-eventlog-clearing-or-configuration-change-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-eventlog-recon-behavior-via-log-query-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-execution-from-parent-process-in-public-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/process-execution-from-a-potentially-suspicious-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-characteristics-due-to-missing-fields-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-filefix-execution-pattern-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-recon-behavior-through-gathernetworkinfo-vbs-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-hidden-directory-creation-through-ntfs-index-allocation-stream-cli-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/writing-of-malicious-files-to-the-fonts-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-homoglyph-attack-via-lookalike-characters-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-non-existing-file-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-base64-mz-header-in-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-inline-javascript-execution-through-nodejs-binary-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-winapi-calls-through-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-jwt-token-search-through-cli-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lnk-command-line-padding-with-whitespace-characters-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-accounts-enumeration-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/lolbin-execution-from-abnormal-drive-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-dump-keyword-in-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-download-through-ms-appinstaller-protocol-handler-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-command-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scan-loop-network-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-network-sniffing-behavior-via-network-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-launched-without-image-name-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-file-type-extension-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-non-privileged-use-of-reg-or-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-patterns-ntds-dit-exfil-via-process-creation</loc>
    <lastmod>2026-07-28T22:50:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-call-to-win32-nteventlogfile-class-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-short-name-path-in-image-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-ntfs-short-name-in-command-line-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-ntfs-short-name-in-image-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-obfuscated-ip-download-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-obfuscated-ip-through-cli-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-parents-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-execution-through-dll-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-privilege-escalation-through-named-pipe-impersonation-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-private-keys-recon-through-commandline-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-runas-like-flag-combination-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-processes-suspicious-parent-directory-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-program-names-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-information-for-export-with-command-prompt-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-execution-from-fake-recycle-bin-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-redirection-to-local-admin-share-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-change-of-ms-settings-protocol-handler-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-desktop-tunneling-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-through-right-to-left-override-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/script-interpreter-execution-from-suspicious-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-interpreter-spawning-credential-scanner-windows-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sensitive-file-access-through-volume-shadow-copy-backup-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-service-creation-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-binary-directory-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-service-manipulation-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shadow-copies-creation-via-operating-systems-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shadow-copies-removal-via-operating-systems-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-shell-scripting-processes-spawning-suspicious-programs-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-creation-via-sysnative-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-system-file-execution-location-anomaly-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-system-user-process-creation-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysvol-domain-group-policy-access-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tasks-folder-evasion-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-script-components-file-execution-by-taef-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-pe-execution-by-microsoft-visual-studio-debugger-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-userinit-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-velociraptor-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-weak-or-abused-passwords-in-cli-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-web-request-commands-and-cmdlets-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-whoami-as-parameter-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-through-workfolders-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-suspect-svchost-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-masquerading-as-svchost-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-terminal-service-process-spawn-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-svchost-command-line-parameter-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-svchost-parent-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-permission-check-through-accesschk-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-database-snapshot-through-adexplorer-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-database-snapshot-through-adexplorer-high-confidence-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-sysinternals-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-memory-dumping-behavior-through-livekd-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kernel-memory-dump-through-livekd-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-procdump-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sysinternals-procdump-evasion-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-lsass-process-dump-through-procdump-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-psexec-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-paexec-escalation-to-local-system-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-psexec-remote-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-psexec-service-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-service-child-process-execution-as-local-system-via-process-creation</loc>
    <lastmod>2026-07-28T22:49:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-psloglist-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-sysinternals-psservice-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-sysinternals-pssuspend-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-sysinternals-pssuspend-suspicious-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-overwrite-through-sysinternals-sdelete-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privilege-escalation-to-local-system-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-configuration-update-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uninstall-sysinternals-sysmon-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-binary-impersonating-sysinternals-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysprep-on-appdata-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-systeminfo-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-disabled-through-systemsettingsadminflows-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-signing-bypass-through-windows-developer-features-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-recursive-takeown-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-tap-installer-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-compressed-file-creation-through-tar-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-compressed-file-extraction-through-tar-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-taskkill-symantec-endpoint-protection-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-loaded-module-enumeration-through-tasklist-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-taskmgr-as-local-system-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-process-created-through-taskmgr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-command-targeting-teams-sensitive-files-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-virtual-smart-card-created-through-tpmvscmgr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tscon-start-as-system-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-redirect-via-tscon-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rdp-session-hijacking-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-changepk-and-slui-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-disk-cleanup-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bypass-uac-through-cmstp-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmstp-uac-bypass-through-com-object-access-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-utilities-via-computerdefaults-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-consent-and-comctl32-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-dismhost-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-event-viewer-recentviews-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bypass-uac-through-fodhelper-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-through-windows-firewall-snap-in-hijack-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-through-icmluautil-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-idiagnostic-profile-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-ieinstal-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-msconfig-token-change-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-ntfs-reparse-point-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-pkgmgr-and-dism-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-uac-bypass-through-sdclt-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-trustedpath-uac-bypass-pattern-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-abusing-winsat-path-parsing-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-windows-media-player-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bypass-uac-through-wsreset-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-wsreset-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-ultravnc-remote-access-software-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-ultravnc-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uninstall-crowdstrike-falcon-sensor-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-shell-folders-registry-change-through-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-userinit-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-credential-manager-access-through-vaultcmd-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-change-attempt-through-vbscript-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-verclsid-exe-runs-com-object-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-virtualbox-driver-deployment-or-starting-of-vms-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vboxdrvinst-exe-parameters-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-vmwaretoolboxcmd-exe-vm-state-change-script-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-through-vmwaretoolboxcmd-exe-vm-state-change-script-via-process-creation</loc>
    <lastmod>2026-07-28T22:48:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vmtoolsd-suspicious-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-process-of-vscode-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-visual-studio-code-tunnel-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-visual-studio-code-tunnel-shell-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-visual-studio-code-tunnel-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-visual-studio-code-tunnel-service-deployment-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-binary-proxy-execution-through-vsdiagnostics-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-proxy-execution-through-vshadow-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vsls-agent-command-with-agentextensionpath-load-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vulnerable-driver-blocklist-registry-manipulation-through-commandline-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-w32tm-as-timer-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wab-execution-from-non-default-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wab-wabmig-unusual-parent-or-child-processes-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-all-backups-deleted-through-wbadmin-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-backup-deleted-through-wbadmin-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sensitive-file-dump-through-wbadmin-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-recovery-from-backup-through-wbadmin-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sensitive-file-recovery-from-backup-through-wbadmin-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-potentially-suspicious-webdav-lnk-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-chopper-webshell-process-pattern-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webshell-hacking-behavior-patterns-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webshell-detection-with-command-line-keywords-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-by-web-server-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webshell-utility-recon-behavior-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-through-wer-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-reflectdebugger-content-execution-through-werfault-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ppl-manipulation-through-werfaultsecure-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-wermgr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-location-of-wermgr-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-ip-through-wget-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-file-sharing-domain-through-wget-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-ip-through-wget-exe-paths-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-where-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enumerate-all-information-with-whoami-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-whoami-exe-execution-from-privileged-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-group-membership-recon-through-whoami-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-whoami-exe-execution-with-output-option-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-whoami-exe-execution-anomaly-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-security-privileges-enumeration-through-whoami-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windowsterminal-child-processes-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-new-download-source-to-winget-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-insecure-download-source-to-winget-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/add-possible-suspicious-new-download-source-to-winget-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-install-new-package-through-winget-local-manifest-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winrar-compressing-dump-files-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-process-of-winrar-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winrar-execution-in-non-standard-folder-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/awl-bypass-with-winrm-vbs-and-malicious-wsmpty-xsl-wsmtxt-xsl-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-code-execute-through-winrm-vbs-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-powershell-session-host-process-winrm-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-processes-spawned-by-winrm-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-winrs-local-command-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-lateral-movement-through-windows-remote-shell-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-compress-data-and-lock-with-password-for-exfiltration-with-winzip-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wlrmdr-exe-unusual-argument-or-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wmi-backdoor-exchange-transport-agent-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-set-to-never-expire-through-wmi-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-persistence-script-event-consumer-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-newactivescripteventconsumer-creation-attempt-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-defender-manipulation-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:47:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-creation-attempt-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-computer-system-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-hardware-model-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-groups-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-hotfix-updates-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-process-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-product-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-product-class-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-service-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-system-information-enumeration-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-unquoted-service-path-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-disk-and-volume-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-wmic-remote-command-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-started-stopped-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-startup-type-change-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-remote-squiblytwo-technique-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-registry-enumeration-through-wmi-stdregprov-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-manipulation-through-wmi-stdregprov-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmic-execution-through-office-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-created-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-termination-attempt-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-removed-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-manipulation-with-security-products-through-wmic-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xsl-script-execution-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmiprvse-spawned-a-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-wmi-lateral-movement-wmiprvse-spawned-powershell-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmiprvse-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uefi-persistence-through-wpbbin-processcreation-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dropper-script-execution-through-wscript-cscript-mshta-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cscript-wscript-potentially-suspicious-child-process-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-cscript-wscript-unusual-script-extension-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wsl-child-process-anomaly-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deployment-of-wsl-kali-linux-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wsl-kali-linux-use-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-binary-executed-from-wsl-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-proxy-execution-through-wuauclt-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-update-agent-empty-cmdline-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cab-file-extraction-through-wusa-exe-from-potentially-suspicious-paths-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wusa-exe-executed-by-parent-process-located-in-suspicious-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xwizard-exe-execution-from-non-default-location-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-com-object-execution-through-xwizard-exe-via-process-creation</loc>
    <lastmod>2026-07-28T22:46:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-process-hollowing-behavior-via-process-tampering</loc>
    <lastmod>2026-07-28T22:46:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-through-raw-disk-access-by-unusual-utilities-via-raw-access-thread</loc>
    <lastmod>2026-07-28T22:46:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-disk-cleanup-handler-registry-via-registry-add</loc>
    <lastmod>2026-07-28T22:46:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-delete-defender-scan-shellex-context-menu-registry-key-via-registry-delete</loc>
    <lastmod>2026-07-28T22:46:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-windows-credential-guard-related-registry-value-registry-via-registry-delete</loc>
    <lastmod>2026-07-28T22:46:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-recall-feature-enabled-disableaidataanalysis-value-deleted-via-registry-delete</loc>
    <lastmod>2026-07-28T22:46:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-folder-removed-from-exploit-guard-protectedfolders-list-registry-via-registry-delete</loc>
    <lastmod>2026-07-28T22:46:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-of-terminal-server-client-connection-history-registry-via-registry-delete</loc>
    <lastmod>2026-07-28T22:46:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-amsi-provider-registry-keys-via-registry-delete</loc>
    <lastmod>2026-07-28T22:46:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/removal-of-possible-com-hijacking-registry-keys-via-registry-delete</loc>
    <lastmod>2026-07-28T22:46:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-runmru-registry-key-removal-registry-via-registry-delete</loc>
    <lastmod>2026-07-28T22:46:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-index-value-to-hide-schedule-task-registry-via-registry-delete</loc>
    <lastmod>2026-07-28T22:46:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-sd-value-to-hide-schedule-task-registry-via-registry-delete</loc>
    <lastmod>2026-07-28T22:46:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-a-local-hidden-user-account-by-registry-via-registry-event</loc>
    <lastmod>2026-07-28T22:46:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-through-wsreset-via-registry-event</loc>
    <lastmod>2026-07-28T22:46:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmstp-execution-registry-event-via-registry-event</loc>
    <lastmod>2026-07-28T22:46:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-windows-defender-threat-severity-default-action-via-registry-event</loc>
    <lastmod>2026-07-28T22:46:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-security-events-logging-adding-reg-key-minint-via-registry-event</loc>
    <lastmod>2026-07-28T22:46:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wdigest-credguard-registry-change-via-registry-event</loc>
    <lastmod>2026-07-28T22:46:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esentutl-volume-shadow-copy-service-keys-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-credential-editor-registry-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hybridconnectionmanager-service-deployment-registry-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-registry-entries-for-azorult-malware-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-qakbot-registry-behavior-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-path-to-screensaver-binary-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-narrator-s-feedback-hub-persistence-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netntlm-downgrade-attack-registry-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-dll-added-to-appcertdlls-registry-key-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-dll-added-to-appinit-dlls-registry-key-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-office-application-startup-office-test-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-registry-trust-record-change-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-persistence-mechanisms-in-recycle-bin-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-portproxy-registry-entry-added-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-redmimicry-winnti-playbook-registry-manipulation-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winekey-registry-change-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-once-task-configuration-in-registry-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-open-registry-keys-manipulation-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-through-lsass-silentprocessexit-technique-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-support-provider-ssp-added-to-lsa-configuration-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sticky-key-like-backdoor-use-registry-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-atbroker-registry-change-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-from-download-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-load-through-lsass-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-camera-and-microphone-access-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/registry-manipulation-by-potentially-suspicious-processes-via-registry-event</loc>
    <lastmod>2026-07-28T22:45:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-remote-connection-between-anonymous-computer-allowanonymouscallback-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-persistence-through-service-in-safe-mode-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-port-monitor-persistence-in-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-debugger-entry-to-aedebug-for-persistence-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-allow-rdp-remote-assistance-feature-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-amsi-com-server-hijacking-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-amsi-disabled-through-registry-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-classes-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-common-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-currentcontrolset-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-currentversion-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-currentversion-nt-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-internet-explorer-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-office-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-session-manager-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-system-scripts-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winsock2-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wow6432node-currentversion-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wow6432node-classes-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wow6432node-windows-nt-currentversion-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-bginfo-exe-custom-db-path-registry-configuration-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-bginfo-exe-custom-vbscript-registry-configuration-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-bginfo-exe-custom-wmi-query-registry-configuration-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bypass-uac-via-delegateexecute-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bypass-uac-via-event-viewer-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bypass-uac-via-silentcleanup-task-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-default-rdp-port-changed-to-non-standard-port-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ie-change-domain-zone-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-driver-altitude-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-winevt-channel-access-permission-through-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-running-chrome-vpn-extensions-through-the-registry-2-vpn-extension-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clickonce-trust-prompt-manipulation-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cobaltstrike-service-installations-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-com-hijack-through-sdclt-via-registry-set</loc>
    <lastmod>2026-07-28T22:45:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-crashcontrol-crashdump-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-event-logging-disabled-through-minint-registry-key-registry-set-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/service-binary-in-suspicious-folder-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-credential-guard-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-custom-file-open-handler-executes-powershell-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-registry-persistence-attempt-through-dbgmanageddebugger-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-exclusions-added-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-desktop-background-change-through-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-antivirus-filter-driver-disallowed-on-dev-drive-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-hypervisor-enforced-code-integrity-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-hypervisor-enforced-paging-translation-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dhcp-callout-dll-deployment-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-administrative-share-creation-at-startup-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-autologger-sessions-manipulation-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-microsoft-defender-firewall-through-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-internal-utilities-or-feature-in-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-macro-runtime-scan-scope-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-privacy-settings-experience-in-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windows-security-center-notifications-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-disable-system-restore-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-defender-service-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-event-log-access-manipulation-through-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windows-firewall-by-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windows-event-logging-through-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-disable-exploit-guard-network-protection-on-windows-defender-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabled-windows-defender-eventlog-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-pua-protection-on-windows-defender-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-tamper-protection-on-windows-defender-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-disallowrun-execution-to-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-through-disk-cleanup-handler-autorun-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-over-https-enabled-by-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-dns-serverlevelplugindll-installed-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-etw-logging-disabled-in-net-processes-sysmon-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-directory-service-restore-mode-dsrm-registry-value-manipulation-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-periodic-backup-for-system-registry-hives-enabled-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-recall-feature-enabled-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enabling-cor-profiler-environment-variables-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scripted-diagnostics-turn-off-check-enabled-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-eventlog-file-location-manipulation-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-allowed-through-exploit-guard-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-user-account-associated-with-the-fax-service-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-the-fax-dll-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-file-association-via-exefile-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-filefix-command-evidence-in-typedpaths-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-debugger-entry-to-hangs-key-for-persistence-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-through-hhctrl-ocx-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-change-to-hidden-file-extension-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-displaying-hidden-files-feature-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-hide-function-from-user-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hide-schedule-task-through-index-value-tamper-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-driver-added-to-disallowed-images-in-hvci-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ie-zonemap-setting-downgraded-to-mycomputer-zone-for-http-protocols-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-extension-in-keyboard-layout-ime-file-registry-value-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-path-in-keyboard-layout-ime-file-registry-value-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-root-or-ca-or-authroot-certificate-to-store-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-internet-explorer-disablefirstruncustomize-enabled-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ransomware-behavior-via-legalnotice-message-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lolbas-onedrivestandaloneupdater-exe-proxy-download-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-restrictedadminmode-registry-value-manipulation-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-full-dump-request-through-dumptype-registry-settings-via-registry-set</loc>
    <lastmod>2026-07-28T22:44:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-net-ngenassemblyusagelog-registry-key-tamper-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/new-netsh-helper-dll-registered-from-a-suspicious-location-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-netsh-helper-dll-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-application-in-appcompat-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-attempt-via-new-networkprovider-reg-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-odbc-driver-registered-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-odbc-driver-registered-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-trust-access-disable-for-vbapplications-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-microsoft-office-protected-view-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-function-execution-security-warning-disabled-in-excel-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-microsoft-dynamic-data-exchange-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-outlook-loadmacroprovideronboot-setting-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outlook-macro-execution-without-warning-setting-enabled-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outlook-enableunsafeclientmailrules-setting-enabled-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outlook-security-settings-updated-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macro-enabled-in-a-potentially-suspicious-document-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-microsoft-office-trusted-location-added-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-office-macros-warning-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-maxmpxct-registry-value-changed-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-new-amsi-providers-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-appcompat-registerapprestart-layer-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-app-paths-default-property-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-via-debugpath-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-autodialdll-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-chm-helper-dll-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-com-object-hijacking-through-change-of-default-system-clsid-default-value-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-com-object-hijacking-through-treatas-subkey-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-psfactorybuffer-com-hijacking-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-custom-protocol-handler-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-event-viewer-events-asp-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-globalflags-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-change-of-ie-registry-settings-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-register-new-ifiltre-for-persistence-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-logon-scripts-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-lsa-extensions-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-mpnotify-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-mycomputer-registry-keys-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-dllpathoverride-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-visual-studio-utilities-for-office-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-outlook-home-page-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-outlook-today-page-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-werfault-reflectdebugger-registry-value-misuse-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-scrobj-dll-com-hijacking-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-shim-database-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shim-database-patching-behavior-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-shim-database-in-unusual-location-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-typedpaths-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-excel-add-in-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-attachment-manager-settings-associations-tamper-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-attachment-manager-settings-attachments-tamper-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-clickfix-execution-pattern-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-change-for-oci-dll-redirection-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-as-a-service-in-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-script-execution-policy-enabled-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-execution-policy-manipulation-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-in-registry-run-keys-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-logging-disabled-through-registry-key-manipulation-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-provisioning-registry-key-misuse-for-binary-proxy-reg-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-pua-sysinternal-utility-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-sysinternals-utilities-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:43:00.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pua-sysinternals-utilities-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:59.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-renamed-sysinternals-utilities-registryset-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:58.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-etw-logging-disabled-for-rpcrt4-dll-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:57.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-command-executed-through-run-dialog-box-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:56.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-screensaver-registry-key-set-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:55.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sentinelone-shell-context-menu-scan-command-manipulation-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-servicedll-hijack-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:53.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-etw-logging-disabled-for-scm-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:52.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-explorer-policy-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:51.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-through-new-sip-provider-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:50.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tamper-with-sophos-av-registry-keys-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:49.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hiding-user-account-through-specialaccounts-registry-key-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:48.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-activate-suppression-of-windows-security-center-notifications-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-keyboard-layout-load-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:46.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-pendingfilerenameoperations-manipulation-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:45.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-printer-driver-empty-manufacturer-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-persistence-through-explorer-run-key-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:43.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/new-run-key-pointing-to-suspicious-folder-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:42.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-space-characters-in-runmru-registry-path-clickfix-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:41.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-installed-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-open-command-registry-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:39.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-space-characters-in-typedpaths-registry-path-filefix-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:38.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modify-user-shell-folders-startup-value-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:37.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wfp-filter-added-through-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:36.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-environment-variable-has-been-registered-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:35.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-lm-hash-storage-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/scheduled-taskcache-change-by-unusual-program-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:33.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-registry-persistence-attempt-through-windows-telemetry-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-sensitive-settings-changed-to-zero-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-sensitive-settings-changed-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:30.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/new-timeproviders-registered-with-unusual-dll-name-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-old-tls1-0-tls1-1-protocol-version-enabled-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:28.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-com-hijacking-through-treatas-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:27.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-signing-bypass-through-windows-developer-features-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:26.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-through-event-viewer-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:25.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-through-sdclt-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-abusing-winsat-path-parsing-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:23.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-windows-media-player-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:22.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-uac-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:21.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-uac-notification-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-uac-secure-desktop-prompt-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:19.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vbscript-payload-stored-in-registry-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:18.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-vulnerable-driver-blocklist-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:17.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-dll-of-choice-via-wab-exe-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:16.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wdigest-enable-uselogoncredential-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:15.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windows-defender-functionalities-through-registry-keys-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:14.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-winget-admin-settings-change-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:13.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-local-manifest-deployment-with-winget-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:12.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winlogon-allowmultipletssessions-enable-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:11.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winlogon-notify-key-logon-persistence-via-registry-set</loc>
    <lastmod>2026-07-28T22:42:10.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-configuration-change-via-sysmon</loc>
    <lastmod>2026-07-28T22:42:09.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-configuration-error-via-sysmon-error</loc>
    <lastmod>2026-07-28T22:42:08.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-configuration-change-via-sysmon-status</loc>
    <lastmod>2026-07-28T22:42:07.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-blocked-executable-via-sysmon</loc>
    <lastmod>2026-07-28T22:42:06.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-blocked-file-shredding-via-sysmon</loc>
    <lastmod>2026-07-28T22:42:05.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-file-executable-creation-detected-via-sysmon</loc>
    <lastmod>2026-07-28T22:42:04.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-event-subscription-via-wmi-event</loc>
    <lastmod>2026-07-28T22:42:03.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-encoded-scripts-in-a-wmi-consumer-via-wmi-event</loc>
    <lastmod>2026-07-28T22:42:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scripting-in-a-wmi-consumer-via-wmi-event</loc>
    <lastmod>2026-07-28T22:42:01.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-execution-of-denogate-backdoor-via-microsoft-teams-delivery-ed6483b0</loc>
    <lastmod>2026-07-28T21:14:36.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-windows-quick-assist-as-observed-in-unc6692-attacks-37cf84fe</loc>
    <lastmod>2026-07-28T21:13:17.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-unauthorized-use-of-atlas-ai-soc-customizations-655e1514</loc>
    <lastmod>2026-07-28T21:09:23.907Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-quick-assist-unsolicited-launch-d6cd3050</loc>
    <lastmod>2026-07-28T21:07:23.734Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
</urlset>