<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://huntrule.com/</loc>
    <changefreq>daily</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules</loc>
    <changefreq>hourly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://huntrule.com/pricing</loc>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>
  <url>
    <loc>https://huntrule.com/about</loc>
    <changefreq>monthly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://huntrule.com/contact</loc>
    <changefreq>monthly</changefreq>
    <priority>0.2</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/reported-bindcloak-encrypted-payload-file-event-9179a5b3</loc>
    <lastmod>2026-07-30T07:13:59.270Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-wscript-activity-in-wmi-event-consumer-commands-fe21810c</loc>
    <lastmod>2026-07-30T05:23:41.710Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-event-consumer-with-encoded-payload-containing-suspicious-strings-83844185</loc>
    <lastmod>2026-07-30T05:23:39.876Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-event-subscription-creation-sysmon-event-19-20-21-0f06a3a5</loc>
    <lastmod>2026-07-30T05:23:38.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-fileexecutabledetected-event-id-29-alerts-on-new-executable-files-693a44e9</loc>
    <lastmod>2026-07-30T05:23:35.772Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sysmon-fileblockshredding-policy-violations-event-id-28-on-windows-c3e5c1b1</loc>
    <lastmod>2026-07-30T05:23:34.300Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sysmon-fileblockexecutable-event-blocked-executable-execution-attempts-on-window-23b71bc5</loc>
    <lastmod>2026-07-30T05:23:32.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-configuration-event-where-sysmon-stops-1f2b5353</loc>
    <lastmod>2026-07-30T05:23:31.219Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-error-events-indicating-service-configuration-update-failures-815cd91b</loc>
    <lastmod>2026-07-30T05:23:29.678Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-configuration-change-event-id-16-8ac03a65</loc>
    <lastmod>2026-07-30T05:23:26.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winlogon-notify-registry-key-dll-persistence-logon-bbf59793</loc>
    <lastmod>2026-07-30T05:23:25.102Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-winlogon-allowmultipletssessions-enabled-f7997770</loc>
    <lastmod>2026-07-30T05:23:23.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-winget-enablelocalmanifestfiles-set-to-dword-1-fa277e82</loc>
    <lastmod>2026-07-30T05:23:21.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winget-appinstaller-admin-settings-registry-modification-via-winget-exe-6db5eaf9</loc>
    <lastmod>2026-07-30T05:23:20.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-to-disable-windows-defender-components-0eb46774</loc>
    <lastmod>2026-07-30T05:23:18.282Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-enable-wdigest-uselogoncredential-use-clear-text-logon-credenti-d6a9b252</loc>
    <lastmod>2026-07-30T05:23:16.734Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-based-dll-hijack-via-wab-exe-using-wab-registry-dllpath-fc014922</loc>
    <lastmod>2026-07-30T05:23:14.795Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vulnerable-driver-blocklist-disabled-via-registry-dword-setting-d526c60a</loc>
    <lastmod>2026-07-30T05:23:13.154Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-vbscript-htmlapplication-payload-stored-under-run-keys-46490193</loc>
    <lastmod>2026-07-30T05:23:11.397Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uac-promptonsecuredesktop-disabled-0d7ceeef</loc>
    <lastmod>2026-07-30T05:23:09.773Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uac-notification-disabled-via-uacdisablenotify-set-to-dword-0x0-c5f6a85d</loc>
    <lastmod>2026-07-30T05:23:08.244Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-user-account-control-by-setting-enablelua-to-0-48437c39</loc>
    <lastmod>2026-07-30T05:23:06.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uac-bypass-attempt-via-windows-media-player-osk-exe-appcompatfl-5f9db380</loc>
    <lastmod>2026-07-30T05:23:04.755Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uac-bypass-via-winsat-exe-lowercaselongpath-and-uacme-path-pars-6597be7b</loc>
    <lastmod>2026-07-30T05:23:02.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-indicator-via-sdclt-registry-key-manipulation-5b872a46</loc>
    <lastmod>2026-07-30T05:23:00.711Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uac-bypass-via-event-viewer-command-key-mscfile-shell-open-comm-7c81fec3</loc>
    <lastmod>2026-07-30T05:22:59.262Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-enabling-developer-features-for-sideloading-and-untruste-b110ebaf</loc>
    <lastmod>2026-07-30T05:22:57.643Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-detection-com-treatas-default-hijacking-dc5c24af</loc>
    <lastmod>2026-07-30T05:22:56.164Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-enabled-tls-1-0-or-tls-1-1-via-schannel-protocols-enabled-1-439957a7</loc>
    <lastmod>2026-07-30T05:22:54.229Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-w32time-timeprovider-dllname-values-set-under-services-w32t-e88a6ddc</loc>
    <lastmod>2026-07-30T05:22:51.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-rdp-terminal-services-sensitive-settings-tampering-3f6b7b62</loc>
    <lastmod>2026-07-30T05:22:49.942Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-registry-settings-modified-to-zero-a2863fbc</loc>
    <lastmod>2026-07-30T05:22:48.245Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-windows-registry-persistence-via-appcompatflags-telemetrycontroller-co-73a883d0</loc>
    <lastmod>2026-07-30T05:22:46.729Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-taskcache-entry-created-by-unusual-process-image-4720b7df</loc>
    <lastmod>2026-07-30T05:22:44.844Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-lsa-nolmhash-to-0-to-enable-lm-hash-storage-c420410f</loc>
    <lastmod>2026-07-30T05:22:43.210Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-detection-of-suspicious-environment-variable-commands-966315ef</loc>
    <lastmod>2026-07-30T05:22:41.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-add-wfp-filter-rules-via-bfe-parameters-path-1f1d8209</loc>
    <lastmod>2026-07-30T05:22:39.559Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modify-user-shell-folders-startup-values-for-persistence-9c226817</loc>
    <lastmod>2026-07-30T05:22:37.709Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-suspicious-space-padded-typedpaths-details-string-8f2a5c3d</loc>
    <lastmod>2026-07-30T05:22:36.031Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-alert-on-changes-to-shell-open-command-targeting-common-malware-9e8894c0</loc>
    <lastmod>2026-07-30T05:22:34.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-service-installation-via-registry-imagepath-outside-system32-f2485272</loc>
    <lastmod>2026-07-30T05:22:32.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-runmru-path-with-suspicious-space-characters-and-delimiter-7a1b4c5e</loc>
    <lastmod>2026-07-30T05:22:30.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-run-key-set-to-executable-in-suspicious-folder-02ee49e2</loc>
    <lastmod>2026-07-30T05:22:29.004Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-explorer-run-key-persistence-pointing-to-suspicious-paths-b7916c2a</loc>
    <lastmod>2026-07-30T05:22:27.315Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-printer-driver-installations-with-empty-manufacturer-field-e0813366</loc>
    <lastmod>2026-07-30T05:22:25.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-monitor-pendingfilerenameoperations-changes-from-suspicious-ima-4eec988f</loc>
    <lastmod>2026-07-30T05:22:24.106Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-suspicious-keyboard-layout-preload-in-user-session-34aa0252</loc>
    <lastmod>2026-07-30T05:22:22.593Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modification-suppress-windows-security-center-notifications-0c93308a</loc>
    <lastmod>2026-07-30T05:22:20.784Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-hidden-user-via-winlogon-specialaccounts-userlist-value-0-f8aebc67</loc>
    <lastmod>2026-07-30T05:22:19.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-tampering-targeting-sophos-av-tamper-protection-enabled-flags-9f4662ac</loc>
    <lastmod>2026-07-30T05:22:17.458Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-sip-persistence-via-new-cryptography-provider-registration-5a2b21ee</loc>
    <lastmod>2026-07-30T05:22:15.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-policy-modification-for-explorer-ui-function-disabling-1c3121ed</loc>
    <lastmod>2026-07-30T05:22:14.240Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-etw-logging-disabled-via-scm-registry-tracingdisabled-key-4f281b83</loc>
    <lastmod>2026-07-30T05:22:12.293Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-servicedll-hijack-via-service-parameters-servicedll-612e47e9</loc>
    <lastmod>2026-07-30T05:22:10.760Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-sentinelone-scan-context-menu-command-tampering-by-non-sentinel-6c304b02</loc>
    <lastmod>2026-07-30T05:22:09.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-by-rundll32-for-screen-saver-execution-via-scrnsave-exe-40b6e656</loc>
    <lastmod>2026-07-30T05:22:07.665Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-runmru-powershell-or-wmic-execution-command-indicators-a7df0e9e</loc>
    <lastmod>2026-07-30T05:22:05.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-disables-etw-for-rpcrt4-dll-via-exterrorinformation-90f342e1</loc>
    <lastmod>2026-07-30T05:22:04.335Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registryset-eulaaccepted-set-for-renamed-sysinternals-tools-8023f872</loc>
    <lastmod>2026-07-30T05:22:02.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-sysinternals-eula-accepted-key-for-pua-tool-execution-c7da8edc</loc>
    <lastmod>2026-07-30T05:22:00.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-sysinternals-renamed-tool-execution-indicator-via-eulaaccepted--f50f3c09</loc>
    <lastmod>2026-07-30T05:21:59.244Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-key-created-sysinternals-eula-acceptance-25ffa65d</loc>
    <lastmod>2026-07-30T05:21:57.705Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-key-abuse-via-provisioning-commands-for-proxy-binary-execution-7021255e</loc>
    <lastmod>2026-07-30T05:21:56.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-key-changes-disabling-powershell-logging-for-current-user-fecfd1a1</loc>
    <lastmod>2026-07-30T05:21:54.683Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-run-key-entries-containing-powershell-execution-strings-8d85cf08</loc>
    <lastmod>2026-07-30T05:21:53.043Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-powershell-executionpolicy-tampering-bypass-unrestricted-fad91067</loc>
    <lastmod>2026-07-30T05:21:51.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-enablescripts-policy-enabled-via-registry-dword-8218c875</loc>
    <lastmod>2026-07-30T05:21:49.849Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-service-persistence-via-registry-imagepath-on-windows-4a5f5a5e</loc>
    <lastmod>2026-07-30T05:21:48.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modification-oracleocilib-oracleocilibpath-under-msdtc-for-oci--c0e0bdec</loc>
    <lastmod>2026-07-30T05:21:46.640Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-runmru-tampering-with-http-https-and-script-execution-indicator-f5fe36cf</loc>
    <lastmod>2026-07-30T05:21:44.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-attachment-manager-policy-tampering-via-attachments-settings-va-ee77a5db</loc>
    <lastmod>2026-07-30T05:21:42.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-tampering-attachment-manager-associations-default-file-type-ris-a9b6c011</loc>
    <lastmod>2026-07-30T05:21:41.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-excel-options-run-entry-point-for-xll-add-in-persistence-961e33d1</loc>
    <lastmod>2026-07-30T05:21:39.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-risk-typedpaths-key-modified-by-non-explorer-proces-086ae989</loc>
    <lastmod>2026-07-30T05:21:37.793Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appcompatflags-installedsdb-new-shim-database-in-non-default-path-6b6976a3</loc>
    <lastmod>2026-07-30T05:21:36.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-appcompatflags-custom-shim-databases-targeting-system-proce-bf344fea</loc>
    <lastmod>2026-07-30T05:21:34.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modification-of-application-shim-database-installedsdb-custom-f-dfb5b4e8</loc>
    <lastmod>2026-07-30T05:21:32.522Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-com-hijacking-via-scrobj-dll-inprocserver32-default-persistence-fe20dda1</loc>
    <lastmod>2026-07-30T05:21:30.869Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-werfault-reflectdebugger-registry-key-value-targeting-0cf2e1c6</loc>
    <lastmod>2026-07-30T05:21:29.218Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-custom-outlook-today-page-for-persistence-487bb375</loc>
    <lastmod>2026-07-30T05:21:27.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-changes-for-outlook-webview-home-page-url-persistence-ddd171b5</loc>
    <lastmod>2026-07-30T05:21:25.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-vsto-add-ins-in-microsoft-office-9d15044a</loc>
    <lastmod>2026-07-30T05:21:24.319Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-detect-dllpathoverride-persistence-in-contentindex-natural-lang-a1b1fd53</loc>
    <lastmod>2026-07-30T05:21:22.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-mycomputer-default-value-modification-8fbe98a8</loc>
    <lastmod>2026-07-30T05:21:20.859Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-mpnotify-sip-provider-persistence-via-winlogon-92772523</loc>
    <lastmod>2026-07-30T05:21:19.298Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-lsa-extensions-multi-sz-dll-persistence-reg-multi-sz-41f6531d</loc>
    <lastmod>2026-07-30T05:21:17.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-userinitmprlogonscript-value-9ace0707</loc>
    <lastmod>2026-07-30T05:21:16.353Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-ifilter-registration-via-persistenthandler-clsid-keys-b23818c7</loc>
    <lastmod>2026-07-30T05:21:14.523Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-internet-settings-zone-and-cache-related-key-modifications-d88d0ab2</loc>
    <lastmod>2026-07-30T05:21:12.784Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-image-file-execution-options-globalflag-and-sil-36803969</loc>
    <lastmod>2026-07-30T05:21:10.943Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-indicators-in-event-viewer-events-asp-links-a1e11042</loc>
    <lastmod>2026-07-30T05:21:09.197Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-custom-url-protocol-handler-persistence-via-hkcr-protocol-regis-fdbf0b9d</loc>
    <lastmod>2026-07-30T05:21:07.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-com-inprocserver32-hijack-via-psfactory-clsid-default-value-243380fa</loc>
    <lastmod>2026-07-30T05:21:05.552Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-com-hijacking-via-treatas-subkey-in-clsid-9b0f8a61</loc>
    <lastmod>2026-07-30T05:21:03.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-com-clsid-hijacking-via-registry-default-inprocserver32-localserver32-mo-790317c0</loc>
    <lastmod>2026-07-30T05:21:01.972Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-htmlhelp-author-location-modification-976dd1f2</loc>
    <lastmod>2026-07-30T05:20:59.884Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-to-services-winsock2-parameters-autodialdll-for-dll-pers-e6fe26ee</loc>
    <lastmod>2026-07-30T05:20:58.215Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-appx-debugpath-key-for-potential-persistence-df4dc653</loc>
    <lastmod>2026-07-30T05:20:56.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-app-paths-default-property-change-using-suspicious-values-707e097c</loc>
    <lastmod>2026-07-30T05:20:54.881Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-appcompatflags-layers-registerapprestart-b86852fb</loc>
    <lastmod>2026-07-30T05:20:52.800Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-amsi-provider-persistence-via-providers-key-33efc23c</loc>
    <lastmod>2026-07-30T05:20:51.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-maxmpxct-value-changed-lanmanserver-parameters-0e6a9e62</loc>
    <lastmod>2026-07-30T05:20:49.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-office-vbawarning-disabled-vbawarnings-set-to-1-91239011</loc>
    <lastmod>2026-07-30T05:20:47.742Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uncommon-microsoft-office-trusted-location-path-added-f742bde7</loc>
    <lastmod>2026-07-30T05:20:45.989Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-trustrecords-change-for-macro-enabled-documents-in-suspicious-p-a166f74e</loc>
    <lastmod>2026-07-30T05:20:44.356Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-changes-to-outlook-security-settings-c3cefdf4</loc>
    <lastmod>2026-07-30T05:20:42.569Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-outlook-enableunsafeclientmailrules-set-to-1-6763c6c8</loc>
    <lastmod>2026-07-30T05:20:40.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-outlook-macro-security-level-set-to-enable-all-macros-e3b50fa5</loc>
    <lastmod>2026-07-30T05:20:38.810Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-persistence-outlook-loadmacroprovideronboot-registry-setting-modificatio-396ae3eb</loc>
    <lastmod>2026-07-30T05:20:37.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-enable-microsoft-dde-in-word-or-excel-security-settings-63647769</loc>
    <lastmod>2026-07-30T05:20:35.320Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-python-function-execution-warnings-in-excel-17e53739</loc>
    <lastmod>2026-07-30T05:20:33.706Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-microsoft-office-protected-view-disabled-via-security-policy-ke-a5c7a43f</loc>
    <lastmod>2026-07-30T05:20:26.691Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-accessvbom-dword-1-disables-access-security-for-access-vba-1a5c46e9</loc>
    <lastmod>2026-07-30T05:20:25.119Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-odbc-driver-registration-in-suspicious-path-e4d22291</loc>
    <lastmod>2026-07-30T05:20:23.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-odbc-driver-registration-via-odbcinst-ini-3390fbef</loc>
    <lastmod>2026-07-30T05:20:21.613Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-networkprovider-service-keys-indicative-of-credential-dumpi-0442defa</loc>
    <lastmod>2026-07-30T05:20:19.949Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appcompatflags-store-new-application-registry-entries-60936b49</loc>
    <lastmod>2026-07-30T05:20:18.133Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-netsh-helper-dll-value-added-under-software-microsoft-netsh-c90362e0</loc>
    <lastmod>2026-07-30T05:20:16.530Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-helper-dll-registration-via-suspicious-registry-paths-e7b18879</loc>
    <lastmod>2026-07-30T05:20:15.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-ngenassemblyusagelog-key-tampering-via-net-usage-log-configurat-28036918</loc>
    <lastmod>2026-07-30T05:20:13.114Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-lsass-full-dump-via-wer-localdumps-dumptype-2-33efc23c</loc>
    <lastmod>2026-07-30T05:20:11.562Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disablerestrictedadmin-value-tampering-to-change-restricted-adm-d6ce7ebd</loc>
    <lastmod>2026-07-30T05:20:09.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-onedrivestandaloneupdater-exe-url-from-updateofficeconfig-for-p-3aff0be0</loc>
    <lastmod>2026-07-30T05:20:08.362Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-ransom-note-keyword-changes-in-legalnoticecaption-text-8b9606c9</loc>
    <lastmod>2026-07-30T05:20:06.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-internet-explorer-disablefirstruncustomize-set-via-explorer-or--ab567429</loc>
    <lastmod>2026-07-30T05:20:04.860Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-root-ca-or-authroot-certificates-added-to-certificate-store-d223b46b</loc>
    <lastmod>2026-07-30T05:20:03.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-ime-file-value-used-from-suspicious-paths-9d8f9bb8</loc>
    <lastmod>2026-07-30T05:20:01.537Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-uncommon-ime-file-value-in-keyboard-layouts-path-b888e3f2</loc>
    <lastmod>2026-07-30T05:19:59.765Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-zonemap-protocoldefaults-downgraded-to-my-computer-for-http-htt-3fd4c8d7</loc>
    <lastmod>2026-07-30T05:19:57.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-hvci-disallowed-image-list-modified-hvcidisallowedimages-555155a2</loc>
    <lastmod>2026-07-30T05:19:56.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-index-registry-tampering-hiding-tasks-from-query-tools-5b16df71</loc>
    <lastmod>2026-07-30T05:19:54.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-defense-impairment-via-explorer-hide-policy-values-5a93eb65</loc>
    <lastmod>2026-07-30T05:19:53.001Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-disabling-hidden-and-system-file-display-5a5152f1</loc>
    <lastmod>2026-07-30T05:19:51.493Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-to-hide-file-extensions-via-explorer-advanced-keys-5df86130</loc>
    <lastmod>2026-07-30T05:19:49.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-hhctrl-clsid-inprocserver32-default-modificatio-f10ed525</loc>
    <lastmod>2026-07-30T05:19:48.353Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-add-debugger-value-under-windows-error-reporting-hangs-key-833ef470</loc>
    <lastmod>2026-07-30T05:19:46.690Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-filefix-style-command-evidence-in-typedpaths-url1-4fee3d51</loc>
    <lastmod>2026-07-30T05:19:45.040Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-file-association-via-exefile-handler-classes-exefile-44a22d59</loc>
    <lastmod>2026-07-30T05:19:43.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-fax-device-provider-imagename-changed-to-load-external-dll-9e3357ba</loc>
    <lastmod>2026-07-30T05:19:41.480Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-user-account-changed-for-fax-service-e3fdf743</loc>
    <lastmod>2026-07-30T05:19:39.804Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-exploit-guard-controlled-folder-access-added-allowed-application-for-blo-42205c73</loc>
    <lastmod>2026-07-30T05:19:38.204Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-eventlog-service-file-location-tampering-0cb8d736</loc>
    <lastmod>2026-07-30T05:19:36.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-enable-scripteddiagnostics-turnoffcheck-dword-via-policies-7d995e63</loc>
    <lastmod>2026-07-30T05:19:35.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-net-cor-coreclr-profiling-environment-variables-enabled-ad89044a</loc>
    <lastmod>2026-07-30T05:19:33.584Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-recall-enabled-by-registry-disableaidataanalysis-set-to-0-windows-75180c5f</loc>
    <lastmod>2026-07-30T05:19:31.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-enableperiodicbackup-value-set-for-periodic-system-hive-backups-973ef012</loc>
    <lastmod>2026-07-30T05:19:30.293Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-tampering-dsrmadminlogonbehavior-value-changes-dsrm-b61e87c0</loc>
    <lastmod>2026-07-30T05:19:28.520Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sysmon-registry-net-etwenabled-disabled-via-complus-etw-flags-bf4fc428</loc>
    <lastmod>2026-07-30T05:19:26.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-serverlevelplugindll-registry-installation-e61e8a88</loc>
    <lastmod>2026-07-30T05:19:24.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-changes-enabling-dns-over-https-via-edge-chrome-or-firefox-poli-04b45a8a</loc>
    <lastmod>2026-07-30T05:19:23.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-disk-cleanup-handler-autorun-keys-d4e2745c</loc>
    <lastmod>2026-07-30T05:19:21.549Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-disallowrun-dword-to-0x1-to-block-user-program-execution-275641a5</loc>
    <lastmod>2026-07-30T05:19:19.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-tamper-protection-disabled-in-microsoft-defender-features-93d298a1</loc>
    <lastmod>2026-07-30T05:19:18.066Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disabling-windows-defender-pua-protection-via-puaprotection-dwo-8ffc5407</loc>
    <lastmod>2026-07-30T05:19:16.257Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-changes-disabling-windows-defender-event-log-channel-fcddca7c</loc>
    <lastmod>2026-07-30T05:19:14.669Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-windows-defender-exploit-guard-network-protection-via-p-bf9e1387</loc>
    <lastmod>2026-07-30T05:19:13.097Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-event-log-tampering-by-disabling-winevt-channel-enabled-key-2f78da12</loc>
    <lastmod>2026-07-30T05:19:11.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-firewall-via-enablefirewall-dword-policies-e78c408a</loc>
    <lastmod>2026-07-30T05:19:09.465Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-eventlog-channelaccess-sddl-tampering-detection-ba226dcf</loc>
    <lastmod>2026-07-30T05:19:07.791Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-disabling-windefend-service-windefend-start-4-e1aa95de</loc>
    <lastmod>2026-07-30T05:19:06.004Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-key-change-disabling-system-restore-5de03871</loc>
    <lastmod>2026-07-30T05:19:04.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-windows-security-center-notifications-via-useactioncent-3ae1a046</loc>
    <lastmod>2026-07-30T05:19:02.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-privacy-settings-experience-via-disableprivacyexperienc-0372e1f9</loc>
    <lastmod>2026-07-30T05:19:00.801Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-disabling-macroruntimescanscope-runtime-macro-scanning-ab871450</loc>
    <lastmod>2026-07-30T05:18:59.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-policy-change-to-disable-impair-internal-tools-and-ui-features-e2482f8d</loc>
    <lastmod>2026-07-30T05:18:57.544Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-microsoft-defender-firewall-by-setting-enablefirewall-t-974515da</loc>
    <lastmod>2026-07-30T05:18:55.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-autologger-session-disable-start-tampering-via-event-log-target-f37b4bce</loc>
    <lastmod>2026-07-30T05:18:53.687Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-administrative-share-creation-via-lanmanserver-paramete-c7dcacd0</loc>
    <lastmod>2026-07-30T05:18:51.494Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-dhcp-server-callout-dll-and-enable-parameters-installation-9d3436ef</loc>
    <lastmod>2026-07-30T05:18:50.066Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disablehypervisorenforcedpagingtranslation-set-to-1-7f2954d2</loc>
    <lastmod>2026-07-30T05:18:48.526Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-hypervisor-enforced-code-integrity-enabled-dword-set-to-0-8b7273a4</loc>
    <lastmod>2026-07-30T05:18:46.818Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disabling-antivirus-filter-driver-on-dev-drive-via-fltmgrdevdri-31e124fb</loc>
    <lastmod>2026-07-30T05:18:45.189Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-to-desktop-wallpaper-policy-or-settings-85b88e05</loc>
    <lastmod>2026-07-30T05:18:42.543Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-defender-exclusions-path-set-microsoft-windows-defender-exclusi-a982fc9c</loc>
    <lastmod>2026-07-30T05:18:40.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-dbgmanageddebugger-debugger-value-added-9827ae57</loc>
    <lastmod>2026-07-30T05:18:39.345Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-custom-file-open-handler-executes-powershell-7530b96f</loc>
    <lastmod>2026-07-30T05:18:37.511Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-disable-windows-credential-guard-by-zeroing-enablevirtualiz-73921b9c</loc>
    <lastmod>2026-07-30T05:18:35.852Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-service-configured-with-image-path-in-suspicious-public-temp-fo-a07f0359</loc>
    <lastmod>2026-07-30T05:18:34.217Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-minint-key-added-to-disable-security-event-logging-on-reboot-8839e550</loc>
    <lastmod>2026-07-30T05:18:31.669Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disable-crashdump-via-crashcontrol-dword-value-2ff692c2</loc>
    <lastmod>2026-07-30T05:18:29.739Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-com-hijack-by-registry-delegateexecute-modification-hkcu-classes-folder--07743f65</loc>
    <lastmod>2026-07-30T05:18:28.211Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-service-install-indicators-for-cobalt-strike-staging-61a7697c</loc>
    <lastmod>2026-07-30T05:18:26.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-clickonce-trust-promptinglevel-set-to-enabled-for-multiple-loca-ac9159cc</loc>
    <lastmod>2026-07-30T05:18:24.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-startup-chrome-vpn-extensions-installed-via-extension-registry--b64a026b</loc>
    <lastmod>2026-07-30T05:18:22.753Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-tampering-channelaccess-permissions-for-winevt-event-channels-7d9263bd</loc>
    <lastmod>2026-07-30T05:18:20.967Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-driver-altitude-registry-changes-4916a35e</loc>
    <lastmod>2026-07-30T05:18:19.359Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-ie-zonemap-domain-zone-change-via-zonemap-domains-45e112d0</loc>
    <lastmod>2026-07-30T05:18:17.760Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-rdp-portnumber-changed-from-default-3389-509e84b9</loc>
    <lastmod>2026-07-30T05:18:16.064Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-detect-windir-environment-key-changes-for-silentcleanup-uac-byp-724ea201</loc>
    <lastmod>2026-07-30T05:18:14.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/registry-modification-for-uac-bypass-via-event-viewer-command-handler-windows-674202d0</loc>
    <lastmod>2026-07-30T05:18:12.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-detect-delegateexecute-uac-bypass-via-targetobject-path-46dd5308</loc>
    <lastmod>2026-07-30T05:18:11.001Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-bginfo-userfields-value-enabling-custom-wmi-query-execution-cd277474</loc>
    <lastmod>2026-07-30T05:18:09.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-bginfo-userfields-value-enabling-custom-vbscript-execution-992dd79f</loc>
    <lastmod>2026-07-30T05:18:06.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-new-bginfo-database-path-value-53330955</loc>
    <lastmod>2026-07-30T05:18:04.166Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-wow6432node-nt-currentversion-autorun-keys-modification-480421f9</loc>
    <lastmod>2026-07-30T05:18:02.571Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-wow6432node-classes-autorun-asep-key-modification-via-shellex-c-18f2065c</loc>
    <lastmod>2026-07-30T05:18:00.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-wow6432node-currentversion-autorun-key-modification-b29aed60</loc>
    <lastmod>2026-07-30T05:17:58.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-winsock2-autostart-extensibility-point-modification-d6c2ce7e</loc>
    <lastmod>2026-07-30T05:17:56.837Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-autostart-script-keys-modification-via-system-scripts-policies-e7a2fd40</loc>
    <lastmod>2026-07-30T05:17:54.834Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-session-manager-asep-modification-via-auto-start-extensibility--046218bd</loc>
    <lastmod>2026-07-30T05:17:52.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modification-of-internet-explorer-autostart-extension-keys-asep-a80f662f</loc>
    <lastmod>2026-07-30T05:17:49.456Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modification-of-windows-nt-currentversion-autostart-extensibili-cbf93e5d</loc>
    <lastmod>2026-07-30T05:17:47.709Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-currentversion-autostart-run-key-modification-monitoring-20f0ee37</loc>
    <lastmod>2026-07-30T05:17:45.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-currentcontrolset-control-autorun-asep-key-modification-f674e36a</loc>
    <lastmod>2026-07-30T05:17:43.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-autorun-asep-key-modification-for-persistence-f59c3faf</loc>
    <lastmod>2026-07-30T05:17:42.073Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-classes-autorun-key-modification-for-persistence-9df5f547</loc>
    <lastmod>2026-07-30T05:17:40.261Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-amsi-disabled-by-registry-value-modification-amsienable-aa37cbb0</loc>
    <lastmod>2026-07-30T05:17:38.684Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-amsi-com-server-hijacking-via-inprocserver32-clsid-modification-160d2780</loc>
    <lastmod>2026-07-30T05:17:37.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-enable-rdp-remote-assistance-via-fallowtogethelp-37b437cf</loc>
    <lastmod>2026-07-30T05:17:35.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-add-debugger-value-under-aedebug-for-crash-time-execution-persi-092af964</loc>
    <lastmod>2026-07-30T05:17:33.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-add-print-port-monitor-dll-persistence-944e8941</loc>
    <lastmod>2026-07-30T05:17:31.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-service-persistence-via-safeboot-control-keys-1547e27c</loc>
    <lastmod>2026-07-30T05:17:29.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-allowanonymouscallback-enabled-for-anonymous-remote-connection-4d431012</loc>
    <lastmod>2026-07-30T05:17:27.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-changes-indicating-suspicious-camera-microphone-capability-acce-62120148</loc>
    <lastmod>2026-07-30T05:17:24.780Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-run-key-created-from-downloads-or-outlook-ie-temporary-folder-9c5037d1</loc>
    <lastmod>2026-07-30T05:17:21.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-image-file-execution-options-debugger-backdoor-sethc-exe-utilma-baca5663</loc>
    <lastmod>2026-07-30T05:17:17.865Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-new-security-support-provider-ssp-added-to-lsa-configuration-eeb30123</loc>
    <lastmod>2026-07-30T05:17:16.186Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-silentprocessexit-lsass-exe-monitor-registration-for-credential-55e29995</loc>
    <lastmod>2026-07-30T05:17:14.392Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-run-key-modification-via-winekey-or-team9-backdoor-b98968aa</loc>
    <lastmod>2026-07-30T05:17:07.761Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-event-triggered-by-redmimicry-winnti-playbook-htmlhelp-data-5b175490</loc>
    <lastmod>2026-07-30T05:17:06.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-portproxy-registry-key-modified-for-port-forwarding-a54f842a</loc>
    <lastmod>2026-07-30T05:17:04.425Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-trustrecords-key-modification-indicating-macro-based-initial-ac-295a59c1</loc>
    <lastmod>2026-07-30T05:17:01.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-via-office-test-startup-key-3d27f6dd</loc>
    <lastmod>2026-07-30T05:16:59.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-appcertdlls-newname-targetobject-creation-for-dll-load-persiste-6aa1d992</loc>
    <lastmod>2026-07-30T05:16:56.560Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-add-on-delegateexecute-persistence-via-narrator-feedback-hub-ap-f663a6d9</loc>
    <lastmod>2026-07-30T05:16:53.140Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-screensaver-path-value-modified-scrnsave-exe-67a6c006</loc>
    <lastmod>2026-07-30T05:16:51.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-event-for-potential-qakbot-iceid-persistence-key-1c8e96cd</loc>
    <lastmod>2026-07-30T05:16:49.711Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-access-to-wceservice-start-key-a6b33c02</loc>
    <lastmod>2026-07-30T05:16:45.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-detect-esentutl-exe-activity-under-vss-service-keys-5aad0995</loc>
    <lastmod>2026-07-30T05:16:42.373Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modification-of-wdigest-iscredguardenabled-to-disable-credentia-1a2d6c47</loc>
    <lastmod>2026-07-30T05:16:40.663Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-createkey-rename-of-hklm-system-currentcontrolset-control-minin-919f2ef0</loc>
    <lastmod>2026-07-30T05:16:37.722Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-events-cmstp-execution-via-cmmgr32-exe-targetobject-b6d235fc</loc>
    <lastmod>2026-07-30T05:16:33.783Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uac-bypass-using-wsreset-exe-registry-command-path-windows-6ea3bf32</loc>
    <lastmod>2026-07-30T05:16:31.909Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-lsass-exe-creating-local-hidden-user-account-entries-460479f3</loc>
    <lastmod>2026-07-30T05:16:30.321Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-delete-sd-value-under-schedule-taskcache-tree-to-impair-schedul-acd74772</loc>
    <lastmod>2026-07-30T05:16:28.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-scheduled-task-index-value-removal-to-hide-task-taskcache-526cc8bc</loc>
    <lastmod>2026-07-30T05:16:26.793Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-runmru-key-deletion-3a9b8c1e</loc>
    <lastmod>2026-07-30T05:16:25.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-deletion-of-shell-open-command-com-hijacking-key-paths-96f697b0</loc>
    <lastmod>2026-07-30T05:16:23.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-amsi-provider-registry-key-deletion-hklm-software-microsoft-amsi-41d1058a</loc>
    <lastmod>2026-07-30T05:16:21.722Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-clearing-rdp-client-connection-history-via-mru-and-server-keys--07bdd2f5</loc>
    <lastmod>2026-07-30T05:16:19.852Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-exploit-guard-protectedfolders-value-deleted-272e55a4</loc>
    <lastmod>2026-07-30T05:16:18.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-recall-enabled-by-deleting-disableaidataanalysis-registry-value-5dfc1465</loc>
    <lastmod>2026-07-30T05:16:16.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-delete-of-credential-guard-enablevirtualizationbasedsecurity-or-d645ef86</loc>
    <lastmod>2026-07-30T05:16:14.374Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-delete-remove-shellex-contextmenuhandlers-epp-key-for-scan-with-72a0369a</loc>
    <lastmod>2026-07-30T05:16:12.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-disk-cleanup-handler-persistence-via-volumecaches-key-creation-d4f4e0be</loc>
    <lastmod>2026-07-30T05:16:09.995Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-raw-disk-access-by-uncommon-process-paths-db809f10</loc>
    <lastmod>2026-07-30T05:16:07.834Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-hollowing-suspected-via-replaced-in-memory-image-c4b890e5</loc>
    <lastmod>2026-07-30T05:16:00.671Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/xwizard-exe-com-execution-with-runwizard-and-guid-argument-windows-53d4bb30</loc>
    <lastmod>2026-07-30T05:15:58.820Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-xwizard-exe-execution-from-non-default-directory-193d5ccd</loc>
    <lastmod>2026-07-30T05:15:57.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wusa-exe-execution-with-parent-in-suspicious-windows-paths-ef64fc9c</loc>
    <lastmod>2026-07-30T05:15:55.402Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wusa-exe-cab-extraction-from-suspicious-directory-paths-c74c0390</loc>
    <lastmod>2026-07-30T05:15:53.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wuauclt-exe-process-creation-on-windows-with-empty-command-line-flags-52d097e2</loc>
    <lastmod>2026-07-30T05:15:51.326Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-proxy-execution-via-wuauclt-exe-updatedeploymentprovider-runhandlercomse-af77cf95</loc>
    <lastmod>2026-07-30T05:15:49.702Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wsl-process-execution-of-kali-linux-on-windows-6f1a11aa</loc>
    <lastmod>2026-07-30T05:15:46.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wsl-kali-linux-installation-via-wsl-exe-install-i-eca8ae39</loc>
    <lastmod>2026-07-30T05:15:44.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wsl-process-spawning-uncommon-child-executables-2267fe65</loc>
    <lastmod>2026-07-30T05:15:42.010Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wscript-cscript-executes-files-with-uncommon-non-script-extensions-99b7460d</loc>
    <lastmod>2026-07-30T05:15:40.195Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-regsvr32-msiexec-child-process-from-windows-script-hosts-csc-b6676963</loc>
    <lastmod>2026-07-30T05:15:37.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-script-execution-from-user-accessible-paths-via-wscript-cscript-or-mshta-cea72823</loc>
    <lastmod>2026-07-30T05:15:36.153Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uefi-persistence-detect-wpbbin-exe-execution-4abc0ec4</loc>
    <lastmod>2026-07-30T05:15:31.798Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmiprvse-exe-spawning-suspicious-script-and-lolbin-child-processes-8a582fe2</loc>
    <lastmod>2026-07-30T05:15:30.132Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wmiprvse-exe-spawned-powershell-child-process-on-windows-692f0bec</loc>
    <lastmod>2026-07-30T05:15:28.329Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmiprvse-exe-spawning-a-child-process-d21374ff</loc>
    <lastmod>2026-07-30T05:15:26.780Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-uninstall-terminate-actions-targeting-security-products-847d5ff3</loc>
    <lastmod>2026-07-30T05:15:23.336Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-application-uninstall-via-wmic-exe-wmic-call-uninstall-b53317a0</loc>
    <lastmod>2026-07-30T05:15:21.479Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wmic-exe-call-terminate-attempt-49d9671b</loc>
    <lastmod>2026-07-30T05:15:19.686Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-process-creation-with-suspicious-command-execution-3c89a1e8</loc>
    <lastmod>2026-07-30T05:15:18.070Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-office-launched-wmic-with-lolbin-style-command-argument-e1693bc8</loc>
    <lastmod>2026-07-30T05:15:16.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-registry-changes-via-wmi-stdregprov-write-methods-c453ab7a</loc>
    <lastmod>2026-07-30T05:15:14.212Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-stdregprov-registry-enumeration-via-wmic-exe-a0e417e2</loc>
    <lastmod>2026-07-30T05:15:12.331Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-service-changestartmode-sets-manual-or-disabled-startup-type-c0514f28</loc>
    <lastmod>2026-07-30T05:15:08.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-exe-used-to-start-or-stop-services-0b7163dc</loc>
    <lastmod>2026-07-30T05:15:06.214Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-remote-query-execution-via-node-7773b877</loc>
    <lastmod>2026-07-30T05:15:04.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-disk-and-volume-discovery-via-wmic-exe-c79da740</loc>
    <lastmod>2026-07-30T05:15:03.035Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-process-creation-recon-for-unquoted-service-paths-68bcd73b</loc>
    <lastmod>2026-07-30T05:15:01.253Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-system-information-discovery-via-wmic-exe-recon-9d5a1274</loc>
    <lastmod>2026-07-30T05:14:59.395Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-exe-service-reconnaissance-via-remote-service-queries-76f55eaa</loc>
    <lastmod>2026-07-30T05:14:57.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-exe-product-class-reconnaissance-via-security-product-queries-e568650b</loc>
    <lastmod>2026-07-30T05:14:56.252Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-product-reconnaissance-via-firewall-av-enumeration-15434e33</loc>
    <lastmod>2026-07-30T05:14:54.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-process-flag-execution-indicating-process-reconnaissance-221b251a</loc>
    <lastmod>2026-07-30T05:14:52.663Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hotfix-inventory-recon-via-wmic-exe-qfe-dfd2fcb7</loc>
    <lastmod>2026-07-30T05:14:51.135Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-discovery-via-wmic-exe-group-flag-164eda96</loc>
    <lastmod>2026-07-30T05:14:49.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-exe-hardware-model-reconnaissance-using-csproduct-3e3ceccd</loc>
    <lastmod>2026-07-30T05:14:47.330Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-system-reconnaissance-using-computersystem-flag-9d7ca793</loc>
    <lastmod>2026-07-30T05:14:45.622Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-attempt-using-wmic-exe-process-call-create-526be59f</loc>
    <lastmod>2026-07-30T05:14:43.758Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wmic-exe-activescripteventconsumer-creation-attempt-ebef4391</loc>
    <lastmod>2026-07-30T05:14:40.196Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-script-event-consumer-execution-via-scrcons-exe-ec1d5e28</loc>
    <lastmod>2026-07-30T05:14:38.442Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-wmic-exe-sets-user-password-to-never-expire-7864a175</loc>
    <lastmod>2026-07-30T05:14:36.676Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-backdoor-in-exchange-transport-agent-via-wmi-event-filter-execution-797011dc</loc>
    <lastmod>2026-07-30T05:14:35.147Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wlrmdr-exe-with-u-flag-or-uncommon-child-process-execut-9cfc00b6</loc>
    <lastmod>2026-07-30T05:14:33.553Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winzip-executed-with-password-flag-and-archive-parameters-indicative-of--e2e80da2</loc>
    <lastmod>2026-07-30T05:14:31.936Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-child-process-spawned-by-winrshost-exe-79df3f68</loc>
    <lastmod>2026-07-30T05:14:30.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrs-exe-local-command-execution-via-localhost-loopback-bcfece3d</loc>
    <lastmod>2026-07-30T05:14:28.684Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrm-service-process-spawning-command-line-and-scripting-utilities-5cc2cda8</loc>
    <lastmod>2026-07-30T05:14:27.029Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-powershell-session-activity-via-wsmprovhost-exe-process-relations-734f8d9b</loc>
    <lastmod>2026-07-30T05:14:25.005Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-code-execution-via-winrm-vbs-using-cscript-and-wmicimv2-win32-cre-9df0dd3a</loc>
    <lastmod>2026-07-30T05:14:23.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrm-vbs-awl-bypass-using-attacker-wsmpty-xsl-wsmtxt-xsl-074e0ded</loc>
    <lastmod>2026-07-30T05:14:21.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrar-or-rar-utility-execution-from-non-default-installation-paths-4ede543c</loc>
    <lastmod>2026-07-30T05:14:19.830Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-spawned-by-winrar-exe-on-windows-146aace8</loc>
    <lastmod>2026-07-30T05:14:18.288Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrar-compression-of-dmp-dump-files-via-command-line-1ac14d38</loc>
    <lastmod>2026-07-30T05:14:16.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winget-installs-applications-using-local-manifest-file-313d6012</loc>
    <lastmod>2026-07-30T05:14:14.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-winget-adds-new-download-source-via-source-add-with-ip-endpoint-c15a46a0</loc>
    <lastmod>2026-07-30T05:14:12.750Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winget-adds-http-package-source-81a0ecb5</loc>
    <lastmod>2026-07-30T05:14:10.937Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winget-exe-adds-new-download-sources-via-source-add-05ebafc8</loc>
    <lastmod>2026-07-30T05:14:09.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-whoami-exe-privilege-enumeration-using-priv-flag-97a80ec7</loc>
    <lastmod>2026-07-30T05:13:49.978Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-whoami-exe-execution-from-suspicious-parent-processes-8de1cbe8</loc>
    <lastmod>2026-07-30T05:13:48.445Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-whoami-exe-execution-with-fo-csv-or-output-redirection-c30fb093</loc>
    <lastmod>2026-07-30T05:13:46.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-whoami-exe-group-membership-reconnaissance-via-groups-flag-bd8b828d</loc>
    <lastmod>2026-07-30T05:13:42.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-whoami-exe-executed-by-privileged-accounts-79ce34ca</loc>
    <lastmod>2026-07-30T05:13:41.144Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-whoami-exe-executed-with-all-for-full-identity-enumerat-c248c896</loc>
    <lastmod>2026-07-30T05:13:39.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-where-exe-with-browser-bookmark-database-or-history-725a9768</loc>
    <lastmod>2026-07-30T05:13:37.988Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-wget-exe-downloads-from-ip-to-common-staging-paths-40aa399c</loc>
    <lastmod>2026-07-30T05:13:36.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wget-exe-downloads-from-file-sharing-domains-matching-suspicious-output--a0d7e4d2</loc>
    <lastmod>2026-07-30T05:13:34.260Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-wget-exe-downloading-files-from-an-ip-with-output-flags-17f0c0a8</loc>
    <lastmod>2026-07-30T05:13:32.475Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-wermgr-exe-running-outside-standard-system-directories-5394fcc7</loc>
    <lastmod>2026-07-30T05:13:30.343Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-child-process-spawned-by-wermgr-exe-396f6630</loc>
    <lastmod>2026-07-30T05:13:28.455Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-werfaultsecure-exe-ppl-tampering-with-dump-impair-param-1f0b4cac</loc>
    <lastmod>2026-07-30T05:13:26.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-werfault-exe-executed-with-pr-flag-fabfb3a7</loc>
    <lastmod>2026-07-30T05:13:24.634Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-webserver-spawned-recon-commands-probing-scripting-tool-help-perl-python-f64e5c19</loc>
    <lastmod>2026-07-30T05:13:06.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-web-server-executables-8202070f</loc>
    <lastmod>2026-07-30T05:13:04.286Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-webshell-recon-command-line-keywords-via-web-server-processes-bed2a484</loc>
    <lastmod>2026-07-30T05:13:02.199Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-webserver-parent-process-launching-credential-dumping-and-exfiltration-c-4ebc877f</loc>
    <lastmod>2026-07-30T05:13:00.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-china-chopper-webshell-command-pattern-via-w3wp-fa3c117a</loc>
    <lastmod>2026-07-30T05:12:58.115Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-triggered-from-webdav-lnk-paths-1412aa78</loc>
    <lastmod>2026-07-30T05:12:55.858Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wbadmin-exe-used-to-recover-dump-sensitive-registry-hives-and-ntds-dit-84972c80</loc>
    <lastmod>2026-07-30T05:12:54.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-file-recovery-from-backup-via-wbadmin-exe-6fe4aa1e</loc>
    <lastmod>2026-07-30T05:12:52.482Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wbadmin-exe-triggered-for-backup-of-sensitive-registry--8b93a509</loc>
    <lastmod>2026-07-30T05:12:50.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-delete-backup-or-system-state-backups-via-wbadmin-exe-89f75308</loc>
    <lastmod>2026-07-30T05:12:49.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wbadmin-exe-deletes-all-backup-copies-keepversions-0-639c9081</loc>
    <lastmod>2026-07-30T05:12:47.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-unusual-process-tree-for-wab-exe-and-wabmig-exe-63d1ccc0</loc>
    <lastmod>2026-07-30T05:12:46.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wab-exe-or-wabmig-exe-run-from-non-default-paths-395907ee</loc>
    <lastmod>2026-07-30T05:12:44.354Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-w32tm-exe-timer-delay-usage-via-stripchart-parameters-6da2c9f5</loc>
    <lastmod>2026-07-30T05:12:42.792Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vulnerable-driver-blocklist-registry-tampering-via-powershell-or-reg-exe-22154f0e</loc>
    <lastmod>2026-07-30T05:12:41.260Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vsls-agent-exe-executed-with-agentextensionpath-suspicious-library-load-43103702</loc>
    <lastmod>2026-07-30T05:12:39.697Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vshadow-exe-proxy-execution-via-exec-script-command-d7c75059</loc>
    <lastmod>2026-07-30T05:12:37.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vsdiagnostics-exe-started-with-launch-parameters-to-proxy-arbitrary-bina-ac1c92b4</loc>
    <lastmod>2026-07-30T05:12:34.634Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-vs-code-tunnel-code-tunnel-installed-as-a-service-30bf1789</loc>
    <lastmod>2026-07-30T05:12:32.503Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-visual-studio-code-tunnel-execution-with-renamed-binary-2cf29f11</loc>
    <lastmod>2026-07-30T05:12:29.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vs-code-tunnel-launching-powershell-or-wsl-bash-shell-f4a623c2</loc>
    <lastmod>2026-07-30T05:12:28.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-visual-studio-code-tunnel-exe-tunnel-execution-90d6bd71</loc>
    <lastmod>2026-07-30T05:12:26.471Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-process-spawned-by-vscode-code-exe-5a3164f2</loc>
    <lastmod>2026-07-30T05:12:24.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vmtoolsd-exe-child-process-spawn-via-scripting-utility-binaries-5687f942</loc>
    <lastmod>2026-07-30T05:12:23.010Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vmwaretoolboxcmd-exe-script-set-execution-used-for-vm-state-persistence-236d8e89</loc>
    <lastmod>2026-07-30T05:12:20.992Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vmwaretoolboxcmd-exe-script-set-used-to-configure-vm-state-persistence-7aa4e81a</loc>
    <lastmod>2026-07-30T05:12:19.338Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vboxdrvinst-exe-invoked-with-driver-executeinf-parameters-b7b19cb6</loc>
    <lastmod>2026-07-30T05:12:17.681Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-virtualbox-driver-registration-or-vm-startup-via-process-command-line-bab049ca</loc>
    <lastmod>2026-07-30T05:12:16.146Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-verclsid-exe-executes-com-object-via-guid-parameters-d06be4b9</loc>
    <lastmod>2026-07-30T05:12:14.618Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vbscript-registry-write-attempt-via-wscript-shell-regwrite-on-windows-921aa10f</loc>
    <lastmod>2026-07-30T05:12:13.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-credential-manager-enumeration-via-vaultcmd-exe-listcreds-58f50261</loc>
    <lastmod>2026-07-30T05:12:11.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-userinit-exe-spawns-uncommon-child-processes-0a98a10c</loc>
    <lastmod>2026-07-30T05:12:10.080Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-user-shell-folders-value-modification-via-reg-exe-or-powershell-8f3ab69a</loc>
    <lastmod>2026-07-30T05:12:08.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uninstall-crowdstrike-falcon-sensor-via-windowssensor-exe-uninstall-quie-f0f7be61</loc>
    <lastmod>2026-07-30T05:12:06.702Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-ultravnc-command-line-with-auto-reconnect-flags-871b9555</loc>
    <lastmod>2026-07-30T05:12:05.044Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-of-ultravnc-vncviewer-vncviewer-exe-145322e4</loc>
    <lastmod>2026-07-30T05:12:03.046Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-using-wsreset-exe-with-high-system-integrity-89a9a0e0</loc>
    <lastmod>2026-07-30T05:12:01.275Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wsreset-exe-used-with-non-conhost-child-process-d797268e</loc>
    <lastmod>2026-07-30T05:11:59.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-uac-bypass-via-windows-media-player-osksupport-dll-osk-exe-cmd-e-0058b9e5</loc>
    <lastmod>2026-07-30T05:11:58.065Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-uac-bypass-via-winsat-exe-path-parsing-7a01183d</loc>
    <lastmod>2026-07-30T05:11:56.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-matching-trustedpath-uac-bypass-directory-mocking-strin-4ac47ed3</loc>
    <lastmod>2026-07-30T05:11:54.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sdclt-exe-spawned-with-high-integrity-possible-uac-bypass-40f9af16</loc>
    <lastmod>2026-07-30T05:11:52.940Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-pkgmgr-exe-launching-dism-exe-high-system-integrity-a743ceba</loc>
    <lastmod>2026-07-30T05:11:51.335Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-ntfs-reparse-point-wusa-exe-dll-hijacking-process-behavio-39ed3c80</loc>
    <lastmod>2026-07-30T05:11:49.368Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-msconfig-token-modification-msconfig-exe-5-process-creati-ad92e3f9</loc>
    <lastmod>2026-07-30T05:11:47.791Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-ieinstal-exe-launching-consent-exe-from-temp-with-elevate-80fc36aa</loc>
    <lastmod>2026-07-30T05:11:45.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-idiagnosticprofileuac-triggered-from-dllhost-exe-4cbef972</loc>
    <lastmod>2026-07-30T05:11:43.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-elevated-com-interface-using-icmluautil-49f2f17b</loc>
    <lastmod>2026-07-30T05:11:41.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-uac-bypass-attempt-via-mmc-windows-firewall-snap-in-hij-e52cb31c</loc>
    <lastmod>2026-07-30T05:11:38.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-fodhelper-exe-spawned-processes-indicative-of-uac-bypass-7f741dcf</loc>
    <lastmod>2026-07-30T05:11:35.734Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-event-viewer-recentviews-path-in-process-command-line-30fc8de7</loc>
    <lastmod>2026-07-30T05:11:34.189Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-dismhost-exe-dll-hijacking-853e74f9</loc>
    <lastmod>2026-07-30T05:11:32.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-consent-exe-and-werfault-exe-with-comctl32-dll-related-be-1ca6bd18</loc>
    <lastmod>2026-07-30T05:11:29.887Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-computerdefaults-exe-with-elevated-integrity-parent-proce-3c05e90d</loc>
    <lastmod>2026-07-30T05:11:28.055Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmstp-uac-bypass-attempt-via-autoelevate-com-object-dllhost-execution-4b60e6f2</loc>
    <lastmod>2026-07-30T05:11:25.975Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-execution-of-cmstp-exe-with-inf-install-silent-autobind-fla-e66779cc</loc>
    <lastmod>2026-07-30T05:11:24.219Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-disk-cleanup-cleanmgr-exe-run-from-scheduled-task-b697e69c</loc>
    <lastmod>2026-07-30T05:11:22.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-changepk-exe-launched-from-slui-exe-with-elevated-integri-503d581c</loc>
    <lastmod>2026-07-30T05:11:20.326Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-session-hijacking-via-tscon-exe-from-system-integrity-224f140f</loc>
    <lastmod>2026-07-30T05:11:18.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-rdp-session-redirect-via-tscon-exe-dest-rdp-tcp-f72aa3e8</loc>
    <lastmod>2026-07-30T05:11:17.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-tscon-exe-launched-under-system-context-9847f263</loc>
    <lastmod>2026-07-30T05:11:14.810Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-virtual-smart-card-created-using-tpmvscmgr-exe-c633622e</loc>
    <lastmod>2026-07-30T05:11:13.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-targets-microsoft-teams-cookies-or-leveldb-d2eb17db</loc>
    <lastmod>2026-07-30T05:11:11.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-with-taskmgr-exe-as-parent-process-3d7679bd</loc>
    <lastmod>2026-07-30T05:11:09.858Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-taskmgr-exe-launched-in-local-system-context-9fff585c</loc>
    <lastmod>2026-07-30T05:11:08.289Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-module-usage-enumeration-via-tasklist-exe-m-rdpcorets-dll-34275eb8</loc>
    <lastmod>2026-07-30T05:11:05.786Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-taskkill-used-to-terminate-ccsvchst-exe-symantec-endpoint-protection-ser-4a6713f6</loc>
    <lastmod>2026-07-30T05:11:04.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-tar-exe-archive-extraction-using-x-flag-bf361876</loc>
    <lastmod>2026-07-30T05:11:02.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-tar-exe-used-to-create-compressed-archives-418a3163</loc>
    <lastmod>2026-07-30T05:11:00.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-tapinstall-exe-execution-99793437</loc>
    <lastmod>2026-07-30T05:10:59.152Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-takeown-exe-recursive-ownership-change-554601fb</loc>
    <lastmod>2026-07-30T05:10:57.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-activity-enabling-developer-mode-or-sideloading-via-systemsettin-a383dec4</loc>
    <lastmod>2026-07-30T05:10:55.774Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-systemsettingsadminflows-exe-used-to-disable-windows-defender-da92713f</loc>
    <lastmod>2026-07-30T05:10:54.146Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-systeminfo-exe-execution-0ef56343</loc>
    <lastmod>2026-07-30T05:10:51.739Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysprep-execution-targeting-appdata-directory-d5b9ae7a</loc>
    <lastmod>2026-07-30T05:10:49.673Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-sysinternals-tool-name-impersonation-by-executab-7cce6fc8</loc>
    <lastmod>2026-07-30T05:10:48.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-event-for-sysmon-uninstall-using-sysmon-u-6a5f68d1</loc>
    <lastmod>2026-07-30T05:10:46.345Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-configuration-update-via-sysmon64-command-line-87911521</loc>
    <lastmod>2026-07-30T05:10:44.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-psexec-paexec-flags-indicating-system-execution-207b0396</loc>
    <lastmod>2026-07-30T05:10:43.178Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sdelete-used-for-file-overwrite-a4824fca</loc>
    <lastmod>2026-07-30T05:10:40.995Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sysinternals-pssuspend-targeting-msmpeng-exe-4beb6ae0</loc>
    <lastmod>2026-07-30T05:10:39.520Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysinternals-pssuspend-process-execution-48bbc537</loc>
    <lastmod>2026-07-30T05:10:37.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sysinternals-psservice-psservice-exe-execution-3371f518</loc>
    <lastmod>2026-07-30T05:10:36.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-psloglist-with-event-log-dump-export-flags-aae1243f</loc>
    <lastmod>2026-07-30T05:10:34.471Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexesvc-launched-child-process-running-as-local-system-7c0dcd3d</loc>
    <lastmod>2026-07-30T05:10:32.748Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexec-service-execution-via-psexesvc-exe-fdfcbd78</loc>
    <lastmod>2026-07-30T05:10:31.048Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexec-paexec-command-line-flags-escalating-to-local-system-8834e2f7</loc>
    <lastmod>2026-07-30T05:10:28.262Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexec-execution-triggered-by-psexec-exe-process-creation-730fc21b</loc>
    <lastmod>2026-07-30T05:10:26.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-procdump-command-lines-targeting-lsass-memory-dumps-5afee48e</loc>
    <lastmod>2026-07-30T05:10:24.995Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-procdump-renamed-copied-or-moved-for-stealth-evasion-79b06761</loc>
    <lastmod>2026-07-30T05:10:23.119Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-procdump-process-execution-2e65275c</loc>
    <lastmod>2026-07-30T05:10:21.502Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-livekd-kernel-memory-dump-attempt-via-m-flag-c7746f1c</loc>
    <lastmod>2026-07-30T05:10:19.687Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-livekd-execution-suggesting-potential-memory-dumping-a85f7765</loc>
    <lastmod>2026-07-30T05:10:17.974Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-execution-using-sysinternals-accepteula-flag-7cccd811</loc>
    <lastmod>2026-07-30T05:10:16.065Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sysinternals-adexplorer-snapshot-exports-active-directo-ef61af62</loc>
    <lastmod>2026-07-30T05:10:14.430Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysinternals-adexplorer-invoked-with-snapshot-flag-to-create-ad-database-9212f354</loc>
    <lastmod>2026-07-30T05:10:12.691Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-accesschk-exe-permission-audit-execution-c625d754</loc>
    <lastmod>2026-07-30T05:10:11.145Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-svchost-exe-spawned-by-uncommon-parent-process-01d2e2a1</loc>
    <lastmod>2026-07-30T05:10:09.188Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-svchost-exe-uncommon-command-line-parameter-process-creation-f17211f1</loc>
    <lastmod>2026-07-30T05:10:07.542Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-terminal-service-parent-process-spawn-svchost-exe-termsvcs-1012f107</loc>
    <lastmod>2026-07-30T05:10:05.931Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-masquerading-as-svchost-exe-via-binary-name-and-location-be58d2e2</loc>
    <lastmod>2026-07-30T05:10:04.239Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-svchost-exe-spawned-without-command-line-arguments-16c37b52</loc>
    <lastmod>2026-07-30T05:10:01.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-via-workfolders-exe-launching-control-exe-0bbc6369</loc>
    <lastmod>2026-07-30T05:09:59.082Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-containing-whoami-as-first-parameter-e9142d84</loc>
    <lastmod>2026-07-30T05:09:56.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-web-request-cmdlets-and-cli-tools-usage-9fc51a3c</loc>
    <lastmod>2026-07-30T05:09:54.857Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cli-processes-using-common-weak-or-abused-passwords-91edcfb1</loc>
    <lastmod>2026-07-30T05:09:53.308Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-velociraptor-child-process-execution-indicators-4bc90587</loc>
    <lastmod>2026-07-30T05:09:51.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-userinit-exe-child-process-creation-b655a06a</loc>
    <lastmod>2026-07-30T05:09:49.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-malicious-child-process-execution-via-vsjitdebugger-exe-just-in-time-deb-15c7904e</loc>
    <lastmod>2026-07-30T05:09:47.589Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-te-exe-execution-of-test-components-taef-via-process-creation-634b00d5</loc>
    <lastmod>2026-07-30T05:09:45.946Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-lines-using-system32-syswow64-tasks-folder-cc4e02ba</loc>
    <lastmod>2026-07-30T05:09:19.522Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-access-to-domain-group-policy-in-sysvol-05f3c945</loc>
    <lastmod>2026-07-30T05:09:16.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-process-creation-as-system-user-with-likely-credential-defens-2617e7ed</loc>
    <lastmod>2026-07-30T05:09:14.884Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-binary-execution-from-unusual-location-process-creation-e4a6b256</loc>
    <lastmod>2026-07-30T05:09:13.004Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-using-the-sysnative-directory-path-3c1b5fb0</loc>
    <lastmod>2026-07-30T05:09:11.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-child-programs-spawned-by-mshta-powershell-w-3a6586ad</loc>
    <lastmod>2026-07-30T05:09:09.638Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-shadow-copy-deletion-via-powershell-wmic-vssadmin-diskshadow-or-wbadmin-c947b146</loc>
    <lastmod>2026-07-30T05:09:07.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-shadow-copy-creation-via-powershell-pwsh-wmic-vssadmin-commands-b17ea6f7</loc>
    <lastmod>2026-07-30T05:09:05.858Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-service-stop-pause-delete-disable-via-net-sc-ce72ef99</loc>
    <lastmod>2026-07-30T05:09:04.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-service-binary-executed-from-public-system-directories-883faa95</loc>
    <lastmod>2026-07-30T05:09:01.809Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-service-creation-via-sc-exe-or-powershell-new-service-with-ab-17a1be64</loc>
    <lastmod>2026-07-30T05:08:59.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-script-interpreter-launching-trufflehog-or-gitleaks-credential-scanner-0f60b28c</loc>
    <lastmod>2026-07-30T05:08:56.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-script-interpreter-execution-from-suspicious-folders-via-command-line-fl-1228c958</loc>
    <lastmod>2026-07-30T05:08:54.299Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-containing-unicode-right-to-left-override-u-202e-ad691d92</loc>
    <lastmod>2026-07-30T05:08:51.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-ssh-port-forwarding-commands-targeting-rdp-3389-8a3038e8</loc>
    <lastmod>2026-07-30T05:08:49.996Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-and-powershell-modification-of-ms-settings-protocol-handler-dd3ee8cc</loc>
    <lastmod>2026-07-30T05:08:48.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-from-fake-recycle-bin-directories-5ce0f04e</loc>
    <lastmod>2026-07-30T05:08:37.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-recon-data-export-via-command-prompt-redirection-aa2efee7</loc>
    <lastmod>2026-07-30T05:08:35.894Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-flag-suspicious-program-names-and-powershell-script-ind-efdd8dd5</loc>
    <lastmod>2026-07-30T05:08:34.222Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-alert-on-suspicious-parent-of-core-system-executables-96036718</loc>
    <lastmod>2026-07-30T05:08:32.341Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-runas-like-command-line-flag-combination-50d66fb0</loc>
    <lastmod>2026-07-30T05:08:30.338Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-private-key-file-recon-via-cmd-exe-powershell-or-findstr-exe-213d6a77</loc>
    <lastmod>2026-07-30T05:08:28.222Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-command-execution-hidden-in-dll-invocation-6812a10b</loc>
    <lastmod>2026-07-30T05:08:25.071Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-parent-processes-unusual-child-creation-by-system-utilities-cbec226f</loc>
    <lastmod>2026-07-30T05:08:23.108Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cli-usage-of-obfuscated-ip-address-patterns-in-ping-arp-commands-56d19cb4</loc>
    <lastmod>2026-07-30T05:08:21.166Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-obfuscated-ip-address-in-download-command-urls-cb5a2333</loc>
    <lastmod>2026-07-30T05:08:19.238Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-image-contains-ntfs-8-3-short-filename-patterns-3ef5605c</loc>
    <lastmod>2026-07-30T05:08:17.531Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-contains-ntfs-8-3-short-filename-patterns-1-2-dd6b39d9</loc>
    <lastmod>2026-07-30T05:08:15.691Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-use-of-8-3-short-name-in-image-path-1-2-a96970af</loc>
    <lastmod>2026-07-30T05:08:13.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-wmi-win32-nteventlogfile-calls-with-event-log-tampering-metho-caf201a9</loc>
    <lastmod>2026-07-30T05:08:11.631Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-ntds-dit-and-registry-hive-exfiltration-tooling-8bc64091</loc>
    <lastmod>2026-07-30T05:08:10.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/non-privileged-reg-exe-or-powershell-registry-service-configuration-changes-on-w-8f02c935</loc>
    <lastmod>2026-07-30T05:08:07.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-executable-image-extension-c09dad97</loc>
    <lastmod>2026-07-30T05:08:06.009Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-ending-in-exe-with-no-image-name-f208d6d8</loc>
    <lastmod>2026-07-30T05:08:04.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-tool-use-for-possible-packet-sniffing-tshark-windump-ba1f7802</loc>
    <lastmod>2026-07-30T05:08:02.763Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-for-foreach-scan-loop-with-nslookup-or-ping-f8ad2e2c</loc>
    <lastmod>2026-07-30T05:08:01.068Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-network-configuration-and-discovery-commands-a29c1813</loc>
    <lastmod>2026-07-30T05:07:59.525Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-use-of-ms-appinstaller-protocol-handler-for-file-downloads-180c7c5c</loc>
    <lastmod>2026-07-30T05:07:57.837Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-lsass-dmp-related-dump-keywords-in-command-line-ffa6861c</loc>
    <lastmod>2026-07-30T05:07:56.169Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lolbin-execution-from-abnormal-drive-calc-certutil-mshta-regsvr32-rundll-d4ca7c59</loc>
    <lastmod>2026-07-30T05:07:54.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-local-account-discovery-via-system-utilities-process-execution-502b42de</loc>
    <lastmod>2026-07-30T05:07:52.578Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-lnk-command-line-whitespace-padding-beyond-u-dd8756e7</loc>
    <lastmod>2026-07-30T05:07:50.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cli-searching-for-jwt-strings-eyj0ex-eyjhbgci-in-command-line-6d3a3952</loc>
    <lastmod>2026-07-30T05:07:49.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-winapi-function-names-in-command-line-ba3f5c1b</loc>
    <lastmod>2026-07-30T05:07:46.788Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-inline-javascript-execution-by-node-js-node-exe-on-windows-8537c866</loc>
    <lastmod>2026-07-30T05:07:45.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-base64-encoded-pe-mz-header-present-in-command-line-22e58743</loc>
    <lastmod>2026-07-30T05:07:43.402Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-executable-image-missing-absolute-path-possible-process-71158e3f</loc>
    <lastmod>2026-07-30T05:07:41.822Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-matches-perfect-homoglyph-unicode-characters-32e280f1</loc>
    <lastmod>2026-07-30T05:07:40.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-lines-writing-malicious-files-to-c-windows-fonts-ae9b0bd7</loc>
    <lastmod>2026-07-30T05:07:38.489Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-cli-commandline-references-ntfs-index-allocation-stream-0900463c</loc>
    <lastmod>2026-07-30T05:07:36.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-process-execution-of-gathernetworkinfo-vbs-via-cscript-wscrip-07aa184a</loc>
    <lastmod>2026-07-30T05:07:34.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-file-upload-clickfix-lure-via-browser-to-command-execut-b5b29e4e</loc>
    <lastmod>2026-07-30T05:07:33.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-executable-downloads-missing-file-metadata-fields-9637e8a5</loc>
    <lastmod>2026-07-30T05:07:30.975Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-from-uncommon-or-sensitive-directories-3dfd06d2</loc>
    <lastmod>2026-07-30T05:07:29.262Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-parent-process-execution-from-users-public-spawning-scripting-69bd9b97</loc>
    <lastmod>2026-07-30T05:07:27.434Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-recon-via-event-log-query-tools-and-event-id-searches-beaa66d6</loc>
    <lastmod>2026-07-30T05:07:25.781Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-activity-clearing-or-modifying-event-logs-via-wevtutil-powershel-cc36992a</loc>
    <lastmod>2026-07-30T05:07:23.096Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-etw-trace-evasion-via-clearing-disabling-logs-or-providers-a238b5d0</loc>
    <lastmod>2026-07-30T05:07:21.226Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-net-etw-logging-environment-variables-set-via-command-l-41421f44</loc>
    <lastmod>2026-07-30T05:07:19.622Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-contains-emoji-characters-225274c4</loc>
    <lastmod>2026-07-30T05:07:17.799Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-contains-emoji-characters-f9578658</loc>
    <lastmod>2026-07-30T05:07:16.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-contains-specific-emoji-characters-c98f2a0d</loc>
    <lastmod>2026-07-30T05:07:14.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-contains-emoji-characters-4a30ac0c</loc>
    <lastmod>2026-07-30T05:07:12.513Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-cmd-exe-launching-with-powershell-in-lnk-link-command-30e92f50</loc>
    <lastmod>2026-07-30T05:07:10.885Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-elevated-powershell-or-cmd-spawned-from-uncommon-parent-location-178e615d</loc>
    <lastmod>2026-07-30T05:07:09.119Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-commandline-parameters-for-electron-apps-on-windows-378a05d8</loc>
    <lastmod>2026-07-30T05:07:07.234Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-electron-apps-f26eb764</loc>
    <lastmod>2026-07-30T05:07:05.675Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msiexec-exe-installer-process-spawning-cmd-exe-or-powershell-1e53dd56</loc>
    <lastmod>2026-07-30T05:07:03.730Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-dumpstack-log-used-to-evade-microsoft-defender-4f647cfa</loc>
    <lastmod>2026-07-30T05:07:02.043Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-downloads-from-outlook-onenote-attachment-domains-via-co-00d49ed5</loc>
    <lastmod>2026-07-30T05:07:00.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-double-extension-execution-via-parent-command-line-5e6a80c8</loc>
    <lastmod>2026-07-30T05:06:59.077Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-executable-extension-masquerading-with-exe-after-decoy--1cdd9a09</loc>
    <lastmod>2026-07-30T05:06:57.173Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-raccine-removal-via-taskkill-registry-and-scheduled-tas-a31eeaed</loc>
    <lastmod>2026-07-30T05:06:55.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-tools-performing-web-post-exfiltration-via-iwr-curl-wget-7d1aaf3d</loc>
    <lastmod>2026-07-30T05:06:53.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-indicators-of-crypto-mining-66c3b204</loc>
    <lastmod>2026-07-30T05:06:51.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lolbin-copy-from-windows-system-directories-using-windows-copy-tools-f5d19838</loc>
    <lastmod>2026-07-30T05:06:49.905Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-copy-from-system-directories-to-other-locations-fff9d2b7</loc>
    <lastmod>2026-07-30T05:06:47.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-copy-move-of-browser-credential-stores-47147b5b</loc>
    <lastmod>2026-07-30T05:06:43.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-command-line-path-traversal-evasion-strings-1327381e</loc>
    <lastmod>2026-07-30T05:06:41.383Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-for-f-tokens-with-recursive-dir-listing-2782fbd8</loc>
    <lastmod>2026-07-30T05:06:37.987Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-explorer-command-lines-with-unicode-whitespace-padding--3ae9974a</loc>
    <lastmod>2026-07-30T05:06:36.403Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-clickfix-filefix-clipboard-phishing-leading-to-suspicious-mshta-powershe-d487ed4a</loc>
    <lastmod>2026-07-30T05:06:34.616Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-obfuscation-via-escape-characters-f0cdd048</loc>
    <lastmod>2026-07-30T05:06:30.915Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-child-process-spawned-with-system-integrity-by-local-network-service-par-590a5f4c</loc>
    <lastmod>2026-07-30T05:06:29.317Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-web-browser-launch-from-pdf-office-reader-on-windows-over-http-s-1193d960</loc>
    <lastmod>2026-07-30T05:06:27.442Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-default-argument-invocation-of-rundll32-werfault-regsvc-a7c3d773</loc>
    <lastmod>2026-07-30T05:06:25.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-automated-document-and-directory-discovery-via-dir-and--f576a613</loc>
    <lastmod>2026-07-30T05:06:23.542Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iso-image-opened-by-archiver-utilities-winrar-7-zip-peazip-fcdf69e5</loc>
    <lastmod>2026-07-30T05:06:21.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-settingcontent-ms-command-line-24de4f3b</loc>
    <lastmod>2026-07-30T05:06:19.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-child-processes-from-windowsapps-directory-f91ed517</loc>
    <lastmod>2026-07-30T05:06:18.025Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detect-elevated-windows-installer-msiexec-running-as-system-cd951fdc</loc>
    <lastmod>2026-07-30T05:06:16.156Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-execution-commandlines-involving-ntfs-alternate-data-st-7f43c430</loc>
    <lastmod>2026-07-30T05:06:14.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-user-added-to-local-remote-desktop-users-group-via-net-or-powershell-ffa28e60</loc>
    <lastmod>2026-07-30T05:06:12.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-user-added-to-highly-privileged-local-directory-groups-via-net-exe-or-ad-10fb649c</loc>
    <lastmod>2026-07-30T05:06:10.765Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-user-added-to-local-administrators-group-via-net-or-add-localgroupmember-ad720b90</loc>
    <lastmod>2026-07-30T05:06:09.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-abused-debug-privilege-via-command-line-route-add-spawned-by-system-pare-d522eca2</loc>
    <lastmod>2026-07-30T05:06:07.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-ntvdm-ntvdm-exe-csrstub-exe-start-for-16-bit-app-compat-16905e21</loc>
    <lastmod>2026-07-30T05:06:05.627Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-via-stordiag-exe-launching-schtasks-exe-systeminfo-exe-961e0abb</loc>
    <lastmod>2026-07-30T05:06:03.707Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-amazon-ssm-agent-process-creation-with-registration-and-code-parameters-d20ee2f4</loc>
    <lastmod>2026-07-30T05:06:01.768Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ssh-exe-rdp-tunneling-to-3389-via-ssh-f7d7ebd5</loc>
    <lastmod>2026-07-30T05:05:59.972Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ssh-exe-used-as-proxy-local-command-launcher-via-proxycommand-and-localc-7d6d30b8</loc>
    <lastmod>2026-07-30T05:05:58.244Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/port-forwarding-via-ssh-exe-on-windows-327f48c1</loc>
    <lastmod>2026-07-30T05:05:56.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-via-squirrel-exe-proxy-arguments-45239e6a</loc>
    <lastmod>2026-07-30T05:05:54.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-squirrel-exe-using-download-update-flags-to-fetch-files-1e75c1cc</loc>
    <lastmod>2026-07-30T05:05:53.147Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sqlite-access-to-firefox-profile-databases-4833155a</loc>
    <lastmod>2026-07-30T05:05:51.439Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sqlite-cli-querying-chromium-browser-profile-databases-24c77512</loc>
    <lastmod>2026-07-30T05:05:49.695Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sqlcmd-exe-credential-dump-query-against-veeambackup-dbo-b57ba453</loc>
    <lastmod>2026-07-30T05:05:47.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-sqlcmd-exe-querying-veeam-backup-databases-696bfb54</loc>
    <lastmod>2026-07-30T05:05:46.171Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-spoolsv-exe-child-process-execution-indicators-dcdbc940</loc>
    <lastmod>2026-07-30T05:05:44.664Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-splwow64-exe-missing-command-line-parameters-1f1a8509</loc>
    <lastmod>2026-07-30T05:05:37.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-speechruntime-exe-child-process-creation-78f10490</loc>
    <lastmod>2026-07-30T05:05:35.707Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-soundrecorder-audio-capture-using-file-83865853</loc>
    <lastmod>2026-07-30T05:05:34.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-child-processes-spawned-by-sndvol-exe-ba42babc</loc>
    <lastmod>2026-07-30T05:05:32.597Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-child-processes-spawned-by-sigverif-exe-7d4aaec2</loc>
    <lastmod>2026-07-30T05:05:30.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-use-of-shutdown-exe-to-log-off-a-user-ec290c06</loc>
    <lastmod>2026-07-30T05:05:29.174Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-shutdown-or-reboot-via-shutdown-exe-command-line-34ebb878</loc>
    <lastmod>2026-07-30T05:05:27.460Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sftp-exe-indirect-command-execution-via-proxycommand-762bb580</loc>
    <lastmod>2026-07-30T05:05:25.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-setup16-exe-execution-triggered-by-custom-lst-file-99c8be4f</loc>
    <lastmod>2026-07-30T05:05:24.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-kerberoasting-spn-enumeration-via-setspn-exe-1eeed653</loc>
    <lastmod>2026-07-30T05:05:22.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-unusual-child-process-of-setres-exe-spawning-choice-executables-835e75bf</loc>
    <lastmod>2026-07-30T05:05:20.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-parent-serv-u-exe-command-line-process-spawning-58f4ea09</loc>
    <lastmod>2026-07-30T05:05:19.174Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-javascript-via-node-exe-ba3874b9</loc>
    <lastmod>2026-07-30T05:05:17.500Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-secedit-exe-security-policy-export-or-config-c2c76b77</loc>
    <lastmod>2026-07-30T05:05:15.819Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sdiagnhost-exe-spawns-suspicious-child-process-powershell-cmd-mshta-etc-f3d39c45</loc>
    <lastmod>2026-07-30T05:05:14.164Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sdclt-exe-child-process-creation-da2738f2</loc>
    <lastmod>2026-07-30T05:05:11.476Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sdbinst-exe-installing-shim-database-with-uncommon-extension-18ee686c</loc>
    <lastmod>2026-07-30T05:05:10.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-shim-database-persistence-via-sdbinst-exe-with-sdb-payload-517490a7</loc>
    <lastmod>2026-07-30T05:05:06.980Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-process-spawned-by-scrcons-exe-script-event-consumer-f6d1dd2f</loc>
    <lastmod>2026-07-30T05:05:05.113Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-using-system-process-names-9f8573c9</loc>
    <lastmod>2026-07-30T05:05:03.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-scheduled-task-create-modify-running-as-system-89ca78fd</loc>
    <lastmod>2026-07-30T05:05:01.867Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-via-schtasks-with-suspicious-command-line-patter-f2c64357</loc>
    <lastmod>2026-07-30T05:05:00.159Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-with-schtasks-xml-using-non-xml-file-dd2a821e</loc>
    <lastmod>2026-07-30T05:04:58.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-scheduled-task-creation-or-modification-with-high-privilege-7a02e22e</loc>
    <lastmod>2026-07-30T05:04:56.774Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-scheduled-task-creation-or-modification-with-suspicious-sch-24c8392b</loc>
    <lastmod>2026-07-30T05:04:54.887Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-creates-registry-backed-base64-powershell-payload-via-encoded-c-c4eeeeae</loc>
    <lastmod>2026-07-30T05:04:53.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-schtasks-exe-creating-scheduled-task-launching-registry-86588b36</loc>
    <lastmod>2026-07-30T05:04:51.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-task-scheduler-persistence-using-svchost-launched-powershell-with-hidden-b66474aa</loc>
    <lastmod>2026-07-30T05:04:49.521Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-manual-persistence-attempt-using-schtasks-to-run-microsoft-compatibility-f548a603</loc>
    <lastmod>2026-07-30T05:04:47.725Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-via-schtasks-exe-using-sshd-ssh-exe-for-tunnel-s-2daa93a0</loc>
    <lastmod>2026-07-30T05:04:45.987Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-triggered-once-at-00-00-using-scripted-commands-970823b7</loc>
    <lastmod>2026-07-30T05:04:43.846Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-with-guid-like-task-name-ff2fff64</loc>
    <lastmod>2026-07-30T05:04:41.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-scheduled-task-creation-from-suspicious-folders-8a8379b8</loc>
    <lastmod>2026-07-30T05:04:39.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-task-creation-targeting-suspicious-paths-or-env-variables-81325ce1</loc>
    <lastmod>2026-07-30T05:04:37.978Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-disable-used-to-disable-security-critical-scheduled-tasks-9ac94dc8</loc>
    <lastmod>2026-07-30T05:04:36.285Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-delete-all-scheduled-tasks-via-tn-delete-f-220457c1</loc>
    <lastmod>2026-07-30T05:04:34.613Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-used-to-delete-scheduled-tasks-for-system-and-security-comp-dbc1f800</loc>
    <lastmod>2026-07-30T05:04:32.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-via-schtasks-exe-with-curl-and-powershell-comman-1d174d38</loc>
    <lastmod>2026-07-30T05:04:30.980Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-creating-one-time-scheduled-tasks-using-temp-folder-39019a4e</loc>
    <lastmod>2026-07-30T05:04:29.098Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-scheduled-task-creation-by-non-microsoft-office-integration-92626ddd</loc>
    <lastmod>2026-07-30T05:04:27.301Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-scheduled-task-modification-via-schtasks-change-tn-1c0e41cd</loc>
    <lastmod>2026-07-30T05:04:25.621Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-create-executes-file-from-appdata-local-c5c00f49</loc>
    <lastmod>2026-07-30T05:04:23.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-stop-a-service-with-sc-exe-via-process-creation-sc-exe-stop-81bcb81b</loc>
    <lastmod>2026-07-30T05:04:21.171Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-configuration-tampering-via-sc-reg-with-payload-execution-paths-38879043</loc>
    <lastmod>2026-07-30T05:04:19.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-sc-exe-service-config-binpath-changes-to-suspicious-commands-path-138d3531</loc>
    <lastmod>2026-07-30T05:04:17.783Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sc-exe-service-security-descriptor-tampering-sdset-98c5aeef</loc>
    <lastmod>2026-07-30T05:04:16.087Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-sc-exe-service-creation-with-dacl-modification-sdset-dclcwpdtsd-a537cfc3</loc>
    <lastmod>2026-07-30T05:04:14.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sc-exe-security-descriptor-tampering-to-deny-service-access-via-sdset-99cf1e02</loc>
    <lastmod>2026-07-30T05:04:12.477Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sc-exe-service-security-descriptor-changes-via-sdset-6c8fbee5</loc>
    <lastmod>2026-07-30T05:04:10.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sc-exe-service-query-for-termservice-enumeration-e83e8899</loc>
    <lastmod>2026-07-30T05:04:09.089Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-sc-exe-creating-kernel-driver-services-431a1fdb</loc>
    <lastmod>2026-07-30T05:04:07.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sc-exe-service-startuptype-change-to-disabled-or-demand-85c312b7</loc>
    <lastmod>2026-07-30T05:04:05.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-new-service-creation-via-sc-exe-85ff530b</loc>
    <lastmod>2026-07-30T05:04:04.292Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sc-exe-service-configuration-changed-by-medium-integrity-users-d937b75f</loc>
    <lastmod>2026-07-30T05:04:02.569Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-runonce-execution-via-runonce-exe-with-alternateshellstartup-and-r-198effb6</loc>
    <lastmod>2026-07-30T05:04:00.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-execution-with-no-parameters-or-arguments-5bb68627</loc>
    <lastmod>2026-07-30T05:03:58.336Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-svchost-exe-spawning-rundll32-exe-with-webdav-davclnt-dll-davsetcookie-982e9f2d</loc>
    <lastmod>2026-07-30T05:03:56.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-webdav-client-execution-davclnt-dll-davsetcookie-2dbd9d3d</loc>
    <lastmod>2026-07-30T05:03:54.886Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-locks-workstation-via-user32-dll-lockworkstation-3b5b0213</loc>
    <lastmod>2026-07-30T05:03:53.144Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-execution-with-uncommon-dll-cpl-inf-extension-in-command-line-c3a99af4</loc>
    <lastmod>2026-07-30T05:03:51.252Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-rundll32-exe-command-line-invoking-sys-files-731231b9</loc>
    <lastmod>2026-07-30T05:03:45.522Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-shimcache-flush-via-rundll32-apphelp-dll-kernel3-b0524451</loc>
    <lastmod>2026-07-30T05:03:42.944Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-shellexec-rundll-via-shell32-dll-ordinal-in-parent-command-li-8823e85d</loc>
    <lastmod>2026-07-30T05:03:41.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-shellexec-rundll-command-line-usage-d87bd452</loc>
    <lastmod>2026-07-30T05:03:39.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-execution-masquerading-as-image-files-via-image-extensions-4aa6040b</loc>
    <lastmod>2026-07-30T05:03:37.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-dll-load-via-control-exe-spawning-d7eb979b</loc>
    <lastmod>2026-07-30T05:03:35.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-rundll32-command-line-invocations-of-common--e593cf51</loc>
    <lastmod>2026-07-30T05:03:34.135Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-spawning-explorer-exe-child-process-shell32-control-rundll-caa06de8</loc>
    <lastmod>2026-07-30T05:03:32.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-using-shellexecute-via-shelldispatch-dll-functionality-82343930</loc>
    <lastmod>2026-07-30T05:03:30.651Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-loading-shell32-dll-via-control-rundll-from-user-temp-paths-32b96012</loc>
    <lastmod>2026-07-30T05:03:28.412Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rundll32-executes-setupapi-dll-installhinfsection-via-runonce-exe-285b85b1</loc>
    <lastmod>2026-07-30T05:03:26.342Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-from-unusual-system-locations-15b75071</loc>
    <lastmod>2026-07-30T05:03:24.131Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-executing-registered-com-local-servers-via-command-line-f1edd233</loc>
    <lastmod>2026-07-30T05:03:22.099Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-memory-dump-via-comsvcs-dll-using-rundll32-646ea171</loc>
    <lastmod>2026-07-30T05:03:20.103Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-launched-by-explorer-exe-parent-process-1723e720</loc>
    <lastmod>2026-07-30T05:03:18.480Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-executions-using-obfuscated-ordinal-call-arguments-43fa5350</loc>
    <lastmod>2026-07-30T05:03:16.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-calls-davsetcookie-for-ntlm-coercion-via-spoolss-srvsvc-bb76d96b</loc>
    <lastmod>2026-07-30T05:03:15.186Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-started-without-command-line-parameters-1775e15e</loc>
    <lastmod>2026-07-30T05:03:13.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-mshtml-dll-runhtmlapplication-execution-via-protocol-ha-4782eb5a</loc>
    <lastmod>2026-07-30T05:03:11.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-key-manager-launch-keymgr-krshowkeymgr-credential-access-a4694263</loc>
    <lastmod>2026-07-30T05:03:09.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-executing-installscreensaver-via-desk-cpl-scr-file-15bd98ea</loc>
    <lastmod>2026-07-30T05:03:07.661Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-executing-inline-vbscript-via-regread-1cc50f3f</loc>
    <lastmod>2026-07-30T05:03:06.026Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-rundll32-execution-of-advpack-dll-with-ordinal-registerocx-ca-a1473adb</loc>
    <lastmod>2026-07-30T05:03:04.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-launching-dll-from-alternate-data-stream-ads-paths-9248c7e1</loc>
    <lastmod>2026-07-30T05:03:02.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ruby-inline-code-execution-via-ruby-exe-e-flag-20a5ffa1</loc>
    <lastmod>2026-07-30T05:03:01.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-identify-rpcping-exe-s-rpc-test-that-requests-ntlm-authentication-93671f99</loc>
    <lastmod>2026-07-30T05:02:59.633Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-whoami-exe-renamed-execution-via-mismatched-originalfilename-f1086bf7</loc>
    <lastmod>2026-07-30T05:02:58.132Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vmnat-exe-renamed-execution-for-possible-dll-side-loading-7b4f794b</loc>
    <lastmod>2026-07-30T05:02:55.864Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-sysinternals-sdelete-execution-c1d867fe</loc>
    <lastmod>2026-07-30T05:02:54.341Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexec-service-binary-renamed-execution-via-psexesvc-exe-51ae86a2</loc>
    <lastmod>2026-07-30T05:02:52.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-procdump-execution-via-renamed-binary-4a0b2c7e</loc>
    <lastmod>2026-07-30T05:02:51.099Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-renamed-sysinternals-debugview-process-execution-cd764533</loc>
    <lastmod>2026-07-30T05:02:49.496Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-execution-with-renamed-schtasks-exe-binary-f91e51c9</loc>
    <lastmod>2026-07-30T05:02:48.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-remote-utilities-renamed-to-rutserv-exe-or-rfusclient-e-9ef27c24</loc>
    <lastmod>2026-07-30T05:02:46.349Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-masquerading-dllregisterserver-commandline-not-using-rundll32-e-2569ed8c</loc>
    <lastmod>2026-07-30T05:02:44.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-renamed-visual-studio-nodejstools-pressanykey-exe-execution-65c3ca2c</loc>
    <lastmod>2026-07-30T05:02:43.123Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-plink-plink-exe-with-ssh-port-forwarding-flags-1c12727d</loc>
    <lastmod>2026-07-30T05:02:41.546Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-renamed-pingcastle-binary-execution-via-pe-metadata-and-scanner-c-2433a154</loc>
    <lastmod>2026-07-30T05:02:39.825Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-paexec-application-execution-c4e49831</loc>
    <lastmod>2026-07-30T05:02:38.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-binary-execution-with-renamed-image-path-0b0cd537</loc>
    <lastmod>2026-07-30T05:02:36.635Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-renamed-nircmd-exe-nircmd-exe-nircmdc-exe-via-pe-originalfi-264982dc</loc>
    <lastmod>2026-07-30T05:02:34.685Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detects-netsupport-rat-client32-exe-execution-using-imphash-and-filename-0afbd410</loc>
    <lastmod>2026-07-30T05:02:32.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-microsoft-teams-executable-launch-88f46b67</loc>
    <lastmod>2026-07-30T05:02:30.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-msdt-exe-execution-bd1c6866</loc>
    <lastmod>2026-07-30T05:02:29.098Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-execution-of-renamed-megasync-exe-original-megasync-via-process-c-643bdcac</loc>
    <lastmod>2026-07-30T05:02:27.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-mavinject32-64-exe-execution-e6474a1b</loc>
    <lastmod>2026-07-30T05:02:25.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-jusched-exe-execution-via-java-scheduler-names-edd8a48c</loc>
    <lastmod>2026-07-30T05:02:23.589Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-execution-of-renamed-gpg-exe-or-gpg2-exe-ec0722a3</loc>
    <lastmod>2026-07-30T05:02:21.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-renamed-ftp-exe-execution-via-originalfilename-pe-metadata-277a4393</loc>
    <lastmod>2026-07-30T05:02:19.893Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-renamed-dctask64-exe-execution-via-known-imphash-values-340a090b</loc>
    <lastmod>2026-07-30T05:02:17.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-execution-of-renamed-curl-exe-via-pe-metadata-7530cd3d</loc>
    <lastmod>2026-07-30T05:02:16.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-createdump-exe-used-for-dmp-memory-dumps-1a1ed54a</loc>
    <lastmod>2026-07-30T05:02:14.350Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-renamed-cloudflared-exe-with-tunnel-run-command-arg-e0c69ebd</loc>
    <lastmod>2026-07-30T05:02:12.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-browsercore-exe-renamed-execution-for-azure-token-theft-8a4519e8</loc>
    <lastmod>2026-07-30T05:02:10.229Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-execution-of-renamed-boinc-exe-binary-30d07da2</loc>
    <lastmod>2026-07-30T05:02:08.611Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-flag-renamed-execution-of-common-lolbins-based-on-origi-0ba1da6d</loc>
    <lastmod>2026-07-30T05:02:07.005Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-renamed-binary-masquerading-as-common-tools-36480ae1</loc>
    <lastmod>2026-07-30T05:02:05.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-autoit2-autoit3-execution-via-autoit3executescr-f4264e47</loc>
    <lastmod>2026-07-30T05:02:03.326Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-autohotkey-executable-via-pe-metadata-0f16d9cf</loc>
    <lastmod>2026-07-30T05:02:01.325Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-renamed-adfind-exe-executions-df55196f</loc>
    <lastmod>2026-07-30T05:01:59.657Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-time-discovery-via-net-exe-or-w32tm-exe-b243b280</loc>
    <lastmod>2026-07-30T05:01:57.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ultraviewer-desktop-app-execution-88656cec</loc>
    <lastmod>2026-07-30T05:01:56.159Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-teamviewer-remote-session-process-command-line-start-ab70c354</loc>
    <lastmod>2026-07-30T05:01:54.398Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-tacticalrmm-agent-installed-with-api-auth-flags-pointing-to-remote-rmm-s-2db93a3f</loc>
    <lastmod>2026-07-30T05:01:52.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-simpleservice-execution-via-remote-access-tool-wrapper-paths-95e60a2b</loc>
    <lastmod>2026-07-30T05:01:49.806Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-service-web-shell-execution-via-cmd-exe-or-csc-exe-b19146a3</loc>
    <lastmod>2026-07-30T05:01:48.250Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-client-service-spawning-suspicious-utility-commands-7b582f1a</loc>
    <lastmod>2026-07-30T05:01:46.623Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-rmm-system-command-execution-via-cmd-exe-b1f73849</loc>
    <lastmod>2026-07-30T05:01:44.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-installation-execution-via-remote-access-parameters-75bfe6e6</loc>
    <lastmod>2026-07-30T05:01:39.553Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-screenconnect-service-execution-57bff678</loc>
    <lastmod>2026-07-30T05:01:37.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rurat-remote-utilities-executed-from-unusual-path-e01fa958</loc>
    <lastmod>2026-07-30T05:01:36.355Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rmm-tool-meshagent-execution-with-renamed-meshservicename-b471f462</loc>
    <lastmod>2026-07-30T05:01:34.727Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsupport-client32-exe-executed-from-non-standard-directory-37e8d358</loc>
    <lastmod>2026-07-30T05:01:33.065Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-netsupport-client-configurator-pcicfgui-exe-758ff488</loc>
    <lastmod>2026-07-30T05:01:31.178Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-meshagent-remote-command-execution-via-cmd-exe-or-powershell-child-proce-74a2b202</loc>
    <lastmod>2026-07-30T05:01:29.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-meshagent-remote-access-tool-command-line-execution-indicators-2fbbe9ff</loc>
    <lastmod>2026-07-30T05:01:27.784Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-logmein-lmiguardiansvc-execution-associated-with-remote-access-tools-d85873ef</loc>
    <lastmod>2026-07-30T05:01:26.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-matching-goto-opener-logmein-for-remote-access-tooling-b6d98a4f</loc>
    <lastmod>2026-07-30T05:01:24.603Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-anydesk-executed-from-suspicious-directory-065b00ca</loc>
    <lastmod>2026-07-30T05:01:22.692Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-anydesk-silent-installation-via-command-line-flags-114e7f1c</loc>
    <lastmod>2026-07-30T05:01:21.154Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-anydesk-execution-using-revoked-certificate-versions-41f407b5</loc>
    <lastmod>2026-07-30T05:01:19.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-anydesk-password-piped-via-cmd-using-set-password-b1377339</loc>
    <lastmod>2026-07-30T05:01:17.747Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/anydesk-executable-execution-on-windows-b52e84a3</loc>
    <lastmod>2026-07-30T05:01:16.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-executes-dll-with-uncommon-extension-in-command-line-50919691</loc>
    <lastmod>2026-07-30T05:01:14.874Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scripting-engines-spawning-regsvr32-exe-via-parent-process-execution-ab37a6ec</loc>
    <lastmod>2026-07-30T05:01:13.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-exe-executed-with-suspicious-file-extension-masquerading-as-dll-089fc3d2</loc>
    <lastmod>2026-07-30T05:01:10.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-execution-from-suspicious-dll-paths-327ff235</loc>
    <lastmod>2026-07-30T05:01:09.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-execution-with-dll-path-in-common-temporary-public-directories-9525dc73</loc>
    <lastmod>2026-07-30T05:01:07.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-child-processes-spawned-by-regsvr32-exe-6f0947a4</loc>
    <lastmod>2026-07-30T05:01:05.031Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-regsvr32-command-line-uses-ftp-http-to-register-remote-compon-867356ee</loc>
    <lastmod>2026-07-30T05:01:01.739Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-downloads-remote-dlls-via-http-https-ip-in-i-parameter-2dd2c217</loc>
    <lastmod>2026-07-30T05:01:00.026Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-usage-of-i-without-n-flag-b236190c</loc>
    <lastmod>2026-07-30T05:00:58.084Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-persistence-via-typedpaths-registry-modification-ec88289a</loc>
    <lastmod>2026-07-30T05:00:56.394Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-reg-exe-adds-winlogon-specialaccounts-userlist-value-0-9ec9fb1b</loc>
    <lastmod>2026-07-30T05:00:54.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-execution-policy-registry-tampering-via-comm-cf2e938e</loc>
    <lastmod>2026-07-30T05:00:53.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-provisioning-registry-key-abuse-leading-to-indirect-execution-via-provla-2a4b3e61</loc>
    <lastmod>2026-07-30T05:00:51.464Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-configuration-tampering-by-medium-integrity-processes-0f9c21f1</loc>
    <lastmod>2026-07-30T05:00:49.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-watch-pythonfunctionwarnings-disabled-via-excel-security-registr-023c654f</loc>
    <lastmod>2026-07-30T05:00:47.941Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-cli-networkprovider-addition-for-credential--baef1ec6</loc>
    <lastmod>2026-07-30T05:00:46.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-logon-script-persistence-via-userinitmprlogonscript-21d856f9</loc>
    <lastmod>2026-07-30T05:00:44.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-debugger-registration-via-image-file-execution-options-ae215552</loc>
    <lastmod>2026-07-30T05:00:43.265Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-ie-zonemap-protocoldefaults-downgraded-to-my-computer-f-10344bb3</loc>
    <lastmod>2026-07-30T05:00:41.475Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-registry-save-export-of-third-party-credential-paths-cc1abf27</loc>
    <lastmod>2026-07-30T05:00:39.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cli-enumeration-of-3rd-party-credential-registry-keys-87a476dc</loc>
    <lastmod>2026-07-30T05:00:38.019Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-execution-via-register-cimprovider-exe-with-path-dll-a2910908</loc>
    <lastmod>2026-07-30T05:00:36.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regini-exe-execution-leading-to-registry-key-changes-5f60740a</loc>
    <lastmod>2026-07-30T05:00:34.885Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regini-exe-used-to-modify-registry-via-alternate-data-streams-ads-77946e79</loc>
    <lastmod>2026-07-30T05:00:33.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regedit-exe-launched-with-trustedinstaller-or-process-hacker-parent-883835a7</loc>
    <lastmod>2026-07-30T05:00:31.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regedit-exe-imports-reg-via-an-alternate-data-stream-ads-0b80ade5</loc>
    <lastmod>2026-07-30T05:00:30.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regedit-exe-imports-registry-keys-from-reg-file-73bba97f</loc>
    <lastmod>2026-07-30T05:00:27.801Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-key-export-via-regedit-exe-e-to-file-f0e53e89</loc>
    <lastmod>2026-07-30T05:00:26.148Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regedit-exports-registry-hives-to-files-82880171</loc>
    <lastmod>2026-07-30T05:00:24.411Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-regasm-regsvcs-from-uncommon-directories-cc368ed0</loc>
    <lastmod>2026-07-30T05:00:22.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-execution-of-regasm-regsvcs-with-uncommon-command-line-extens-e9f8f8cc</loc>
    <lastmod>2026-07-30T05:00:21.063Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/regasm-exe-process-execution-missing-command-line-and-assembly-path-windows-651f87f7</loc>
    <lastmod>2026-07-30T05:00:19.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-writes-registry-to-disable-storage-write-protection-75f7a0e2</loc>
    <lastmod>2026-07-30T05:00:17.934Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-registry-tampering-of-windows-defender-policy-keys-452bce90</loc>
    <lastmod>2026-07-30T05:00:16.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-disables-volume-shadow-copy-vss-snapshots-dee4af55</loc>
    <lastmod>2026-07-30T05:00:14.698Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-restore-registry-modification-via-powershell-or-reg-exe-command-l-7c06ab9b</loc>
    <lastmod>2026-07-30T05:00:12.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-query-for-system-language-using-reg-exe-c43a5405</loc>
    <lastmod>2026-07-30T05:00:10.914Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-adds-or-modifies-suspicious-registry-locations-via-command-line-b7e2a8d4</loc>
    <lastmod>2026-07-30T05:00:09.392Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-reg-exe-software-version-discovery-via-svcversion-query-e13f668e</loc>
    <lastmod>2026-07-30T05:00:07.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-modifies-service-imagepath-in-hklm-system-currentcontrolset-serv-9b0b7ac3</loc>
    <lastmod>2026-07-30T05:00:05.966Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-reg-exe-changing-screen-saver-registry-settings-for-scr-payloads-0fc35fc3</loc>
    <lastmod>2026-07-30T05:00:04.381Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-used-to-modify-rdp-terminal-server-registry-values-0d5675be</loc>
    <lastmod>2026-07-30T05:00:02.675Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-registry-query-reconnaissance-process-creation-970007b7</loc>
    <lastmod>2026-07-30T05:00:00.739Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-enable-lm-hash-storage-via-lsa-nolmhash-0-in-command-li-98dedfdd</loc>
    <lastmod>2026-07-30T04:59:59.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-reg-exe-modifying-group-policy-registry-settings-ada4b0c4</loc>
    <lastmod>2026-07-30T04:59:57.430Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-reg-exe-query-for-machineguid-f5240972</loc>
    <lastmod>2026-07-30T04:59:55.786Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-registry-tampering-of-disablerestrictedadmin-in-lsa-key-28ac00d6</loc>
    <lastmod>2026-07-30T04:59:54.320Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-importing-reg-files-from-common-user-and-temp-directories-62e0298b</loc>
    <lastmod>2026-07-30T04:59:52.793Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-credential-enumeration-via-registry-query-hklm-hkcu-e0b0c2ab</loc>
    <lastmod>2026-07-30T04:59:50.945Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-recall-enabled-via-reg-exe-registry-changes-windows-817f252c</loc>
    <lastmod>2026-07-30T04:59:49.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-registry-hive-dumping-for-sam-system-and-security-fd877b94</loc>
    <lastmod>2026-07-30T04:59:47.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-used-to-modify-security-service-start-parameters-5e95028c</loc>
    <lastmod>2026-07-30T04:59:45.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-disables-defender-wmi-autologger-sessions-by-setting-start-to-0-a1b2c3d4</loc>
    <lastmod>2026-07-30T04:59:38.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-direct-modification-of-registry-autostart-extensibility-keys-ase-24357373</loc>
    <lastmod>2026-07-30T04:59:36.735Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-changes-desktop-background-policy-values-8cbc9475</loc>
    <lastmod>2026-07-30T04:59:34.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-deletes-service-registry-keys-using-the-delete-flag-05b2aa93</loc>
    <lastmod>2026-07-30T04:59:33.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-safeboot-registry-key-deletion-via-reg-exe-command-line-fc0e89b5</loc>
    <lastmod>2026-07-30T04:59:31.773Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-reg-exe-deletion-of-runmru-registry-key-c11aecef</loc>
    <lastmod>2026-07-30T04:59:30.110Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-adds-windows-defender-exclusion-paths-via-registry-value-update-48917adc</loc>
    <lastmod>2026-07-30T04:59:28.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-credential-access-via-reg-add-in-lsa-registry-paths-b7966f4a</loc>
    <lastmod>2026-07-30T04:59:26.234Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-adds-bitlocker-policy-registry-values-0e0255bf</loc>
    <lastmod>2026-07-30T04:59:19.245Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-reg-exe-adds-or-copies-safeboot-registry-keys-d7662ff6</loc>
    <lastmod>2026-07-30T04:59:17.709Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reg-exe-run-key-modification-for-persistence-via-process-creation-de587dce</loc>
    <lastmod>2026-07-30T04:59:16.051Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-reagentc-exe-winre-disabled-via-disable-command-line-switch-db1c21e4</loc>
    <lastmod>2026-07-30T04:59:14.574Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-memory-dump-using-rdrleakdiag-exe-memdmp-fullmemdmp-edadb1e5</loc>
    <lastmod>2026-07-30T04:59:12.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-enable-disable-via-win32-terminalservicesetting-wmi-tool-commands-4b8f6d3a</loc>
    <lastmod>2026-07-30T04:59:11.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-rasdial-exe-process-execution-6bba49bf</loc>
    <lastmod>2026-07-30T04:59:09.421Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-rar-exe-archive-creation-using-password-or-compression-options-faa48cae</loc>
    <lastmod>2026-07-30T04:59:06.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rar-exe-files-added-to-archive-activity-6f3e2987</loc>
    <lastmod>2026-07-30T04:59:04.406Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-microsoft-quickassist-exe-execution-e20b5b14</loc>
    <lastmod>2026-07-30T04:59:02.741Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-query-exe-used-to-enumerate-sessions-and-processes-possible-data-exfil-s-53ef0cef</loc>
    <lastmod>2026-07-30T04:59:01.098Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-qemu-execution-with-low-memory-and-network-tunneling-flags-5fc297ae</loc>
    <lastmod>2026-07-30T04:58:59.679Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/python-process-spawning-a-pretty-tty-via-pty-spawn-on-windows-480e7e51</loc>
    <lastmod>2026-07-30T04:58:58.059Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-python-executed-with-the-c-inline-code-flag-899133d5</loc>
    <lastmod>2026-07-30T04:58:56.096Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-python-one-liners-decoding-base64-via-command-line-50a0aa3d</loc>
    <lastmod>2026-07-30T04:58:54.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-adidnsdump-execution-via-python-exe-26d3f0a2</loc>
    <lastmod>2026-07-30T04:58:52.940Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-wsudo-with-system-or-trustedinstaller-bdeeabc9</loc>
    <lastmod>2026-07-30T04:58:49.845Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-webbrowserpassview-exe-execution-d0dae994</loc>
    <lastmod>2026-07-30T04:58:48.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-trufflehog-execution-on-windows-via-trufflehog-exe-process-launch-44030449</loc>
    <lastmod>2026-07-30T04:58:46.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/system-informer-execution-on-windows-process-creation-5722dff1</loc>
    <lastmod>2026-07-30T04:58:42.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-seatbelt-exe-pua-discovery-command-line-execution-38646daa</loc>
    <lastmod>2026-07-30T04:58:40.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-runxcmd-command-line-execution-with-system-or-trustedinstaller-accounts-93199800</loc>
    <lastmod>2026-07-30T04:58:38.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-restic-backup-tool-command-line-indicators-6ddff2e8</loc>
    <lastmod>2026-07-30T04:58:36.732Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-rclone-command-execution-with-exfiltration-oriented-flags-e37db05d</loc>
    <lastmod>2026-07-30T04:58:35.238Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-rcedit-editing-pe-version-resource-metadata-via-set-0c92f2e6</loc>
    <lastmod>2026-07-30T04:58:33.562Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/radmin-viewer-utility-execution-on-windows-process-creation-5817e76f</loc>
    <lastmod>2026-07-30T04:58:31.828Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-hacker-execution-identified-by-image-metadata-and-hashes-811e0002</loc>
    <lastmod>2026-07-30T04:58:30.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pingcastle-execution-from-suspicious-parent-processes-b37998de</loc>
    <lastmod>2026-07-30T04:58:28.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-pingcastle-execution-with-full-healthcheck-scanners-b1cb4ab6</loc>
    <lastmod>2026-07-30T04:58:26.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-nsudo-nsudo-exe-nsudolc-nsudolg-771d1eb5</loc>
    <lastmod>2026-07-30T04:58:24.941Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-nps-npc-exe-port-forwarding-proxy-execution-via-command-line-parameters-68d37776</loc>
    <lastmod>2026-07-30T04:58:23.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-nmap-zenmap-nmap-exe-or-zennmap-exe-execution-f6ecd1cf</loc>
    <lastmod>2026-07-30T04:58:21.620Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-nircmd-runassystem-commandline-usage-d9047477</loc>
    <lastmod>2026-07-30T04:58:19.627Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-nircmd-command-execution-4e2ed651</loc>
    <lastmod>2026-07-30T04:58:17.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-nimscan-exe-execution-via-known-file-hashes-4fd6b1c7</loc>
    <lastmod>2026-07-30T04:58:16.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-nimgrab-exe-execution-nim-tool-download-behavior-74a12f18</loc>
    <lastmod>2026-07-30T04:58:14.559Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-lines-indicating-ngrok-exe-tunnel-setup-ee37eb7c</loc>
    <lastmod>2026-07-30T04:58:12.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-softperfect-netscan-exe-network-scanner-execution-ca387a8e</loc>
    <lastmod>2026-07-30T04:58:11.261Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-netcat-ncat-cat-suspicious-execution-e31033fc</loc>
    <lastmod>2026-07-30T04:58:09.742Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-mouse-lock-execution-with-misc314-indicator-c9192ad9</loc>
    <lastmod>2026-07-30T04:58:08.052Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pua-memprocfs-memory-dump-mounting-via-device-8a1b2c3d</loc>
    <lastmod>2026-07-30T04:58:06.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kernel-driver-utility-kdu-and-hamakaze-exe-execution-e76ca062</loc>
    <lastmod>2026-07-30T04:58:04.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-iox-iex-port-forwarding-tunnel-proxy-tool-via-process-creat-d7654f02</loc>
    <lastmod>2026-07-30T04:58:03.242Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-fast-reverse-proxy-frp-frpc-exe-or-frps-exe-32410e29</loc>
    <lastmod>2026-07-30T04:58:01.388Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-dit-snapshot-viewer-ditsnap-exe-d3b70aad</loc>
    <lastmod>2026-07-30T04:57:59.651Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-defendercheck-exe-execution-pua-signature-evasion-f0ca6c24</loc>
    <lastmod>2026-07-30T04:57:58.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pua-csexec-execution-via-process-creation-d08a2711</loc>
    <lastmod>2026-07-30T04:57:56.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-crassus-privilege-escalation-discovery-tool-execution-2c32b543</loc>
    <lastmod>2026-07-30T04:57:54.960Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cleanwipe-like-pua-execution-via-system-tool-uninstall-switches-f44800ac</loc>
    <lastmod>2026-07-30T04:57:53.434Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-chisel-tunneling-tool-chisel-exe-execution-8b0e12da</loc>
    <lastmod>2026-07-30T04:57:51.789Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-advancedrun-executed-with-runas-ids-under-high-privilege-service-account-fa00b701</loc>
    <lastmod>2026-07-30T04:57:49.645Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pua-advancedrun-exe-execution-d2b749ee</loc>
    <lastmod>2026-07-30T04:57:47.970Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-advanced-port-scanner-pua-execution-via-portable-lng-54773c5f</loc>
    <lastmod>2026-07-30T04:57:46.364Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-advanced-ip-scanner-pua-execution-via-process-creation-bef37fa2</loc>
    <lastmod>2026-07-30T04:57:44.498Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-adfind-executed-with-suspicious-recon-flags-9a132afa</loc>
    <lastmod>2026-07-30T04:57:42.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-adfind-exe-execution-for-active-directory-recon-514e7e3e</loc>
    <lastmod>2026-07-30T04:57:41.362Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pua-suspicious-active-directory-enumeration-using-adfind-exe-flags-455b9d50</loc>
    <lastmod>2026-07-30T04:57:39.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-3proxy-proxy-server-execution-f38a82d2</loc>
    <lastmod>2026-07-30T04:57:38.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screen-capture-via-psr-exe-problem-steps-recorder-execution-2158f96f</loc>
    <lastmod>2026-07-30T04:57:35.787Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-suspicious-child-processes-spawned-by-provlaunch-exe-f9999590</loc>
    <lastmod>2026-07-30T04:57:34.243Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-protocolhandler-exe-download-via-embedded-url-schemes-104cdb48</loc>
    <lastmod>2026-07-30T04:57:15.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-print-executable-misuse-via-print-exe-command-line-bafac3d6</loc>
    <lastmod>2026-07-30T04:57:14.196Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-print-exe-sensitive-file-dump-for-credential-access-2fcda7e2</loc>
    <lastmod>2026-07-30T04:57:12.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-microsoft-nodejstools-pressanykey-exe-child-spawns-a20391f8</loc>
    <lastmod>2026-07-30T04:57:10.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-xbap-via-presentationhost-exe-from-uncommon-paths-d22e2925</loc>
    <lastmod>2026-07-30T04:57:09.301Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-presentationhost-exe-downloading-files-via-url-in-command-line-b124ddf4</loc>
    <lastmod>2026-07-30T04:57:07.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-compress-archive-creates-archive-in-temp-or-system-temp-paths-85a8e5ba</loc>
    <lastmod>2026-07-30T04:57:05.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xor-encoded-powershell-command-line-windows-process-creation-bb780e0c</loc>
    <lastmod>2026-07-30T04:57:03.531Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-x509enrollment-cbinaryconverter-execution-114de787</loc>
    <lastmod>2026-07-30T04:57:01.909Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-detects-obfuscated-net-webclient-casing-anomalies-in-command--c86133ad</loc>
    <lastmod>2026-07-30T04:57:00.217Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-user-discovery-and-export-with-get-aduser-1114e048</loc>
    <lastmod>2026-07-30T04:56:52.780Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-uninstall-windowsfeature-remove-windowsfeature-removing-windo-c443012c</loc>
    <lastmod>2026-07-30T04:56:51.128Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-token-obfuscation-via-process-command-line-deb9b646</loc>
    <lastmod>2026-07-30T04:56:49.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-executed-from-appdata-on-windows-command-line-indicators-ac175779</loc>
    <lastmod>2026-07-30T04:56:47.493Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-with-uncommon-suspicious-parent-process-754ed792</loc>
    <lastmod>2026-07-30T04:56:45.786Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-powershell-argument-obfuscation-via-truncate-36210e0d</loc>
    <lastmod>2026-07-30T04:56:42.806Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-commandline-downloads-and-executes-via-webclient-with-iex-or--e6c54d94</loc>
    <lastmod>2026-07-30T04:56:41.040Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-stop-service-used-to-stop-a-service-c49c5062</loc>
    <lastmod>2026-07-30T04:56:39.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-exchange-powershell-snap-in-loading-via-add-pssnapin-25676e10</loc>
    <lastmod>2026-07-30T04:56:37.231Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-wmi-volume-shadow-copy-deletion-21ff4ca9</loc>
    <lastmod>2026-07-30T04:56:35.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-set-service-startuptype-change-to-disabled-or-manual-62b20d44</loc>
    <lastmod>2026-07-30T04:56:32.886Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-executionpolicy-set-to-bypass-unrestricted-87e3c4e8</loc>
    <lastmod>2026-07-30T04:56:31.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-set-acl-targeting-windows-folder-paths-on-windows-0944e002</loc>
    <lastmod>2026-07-30T04:56:29.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-set-acl-script-execution-changes-file-or-folder-permissions-on-window-bdeb2cff</loc>
    <lastmod>2026-07-30T04:56:27.788Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-set-service-securitydescriptorsddl-dacl-modification-for-windows-serv-a95b9b42</loc>
    <lastmod>2026-07-30T04:56:26.386Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-execution-from-windows-temporary-folders-on-windows-a6a39bdb</loc>
    <lastmod>2026-07-30T04:56:24.389Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-spawned-by-wscript-exe-or-cscript-exe-on-windows-95eadcb2</loc>
    <lastmod>2026-07-30T04:56:22.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-sam-hive-copy-via-volume-shadow-copy-paths-on-windows-1af57a4b</loc>
    <lastmod>2026-07-30T04:56:20.604Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-execution-via-redirected-input-stream-c83bf4b5</loc>
    <lastmod>2026-07-30T04:56:19.039Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-execution-from-alternate-data-stream-ads-45a594aa</loc>
    <lastmod>2026-07-30T04:56:17.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-tcpclient-reverse-shell-connection-attempt-via-net-sockets-edc2f8ae</loc>
    <lastmod>2026-07-30T04:56:15.879Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-remove-mppreference-used-to-tamper-windows-defender-set-07e3cb2c</loc>
    <lastmod>2026-07-30T04:56:14.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-atomictestharness-invoke-athremotefxvgpudisablementcommand-ab-a6fc3c46</loc>
    <lastmod>2026-07-30T04:56:11.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-from-c-users-public-fb9d3ff7</loc>
    <lastmod>2026-07-30T04:56:09.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-command-lines-containing-char-0x-or-wchar-0x-obfuscation-synt-e312efd0</loc>
    <lastmod>2026-07-30T04:56:08.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-non-interactive-powershell-powershell-exe-pwsh-exe-spawned-from-gui-or-u-f4bbd493</loc>
    <lastmod>2026-07-30T04:56:06.232Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-exchange-transport-agent-installation-via-install-trans-83809e84</loc>
    <lastmod>2026-07-30T04:56:04.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-powershell-commandlets-used-by-known-exploit-02030f2f</loc>
    <lastmod>2026-07-30T04:56:02.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-kerberos-ticket-requests-from-powershell-using-kerberosreques-caa9a802</loc>
    <lastmod>2026-07-30T04:55:59.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-invoke-webrequest-download-to-suspicious-paths-5e3cc4d8</loc>
    <lastmod>2026-07-30T04:55:57.299Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-invoke-webrequest-execution-via-direct-ip-in-command-line-1edff897</loc>
    <lastmod>2026-07-30T04:55:53.990Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-process-creation-suspicious-base64-encoded-and-iex-webclient--536e2947</loc>
    <lastmod>2026-07-30T04:55:51.122Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-add-appxpackage-attempt-with-allowunsigned-for-appx-installat-37651c2a</loc>
    <lastmod>2026-07-30T04:55:49.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-import-module-from-temp-appdata-public-paths-c31364f7</loc>
    <lastmod>2026-07-30T04:55:47.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-root-certificate-installation-from-suspicious-paths-via-powershell-impor-5f6a601c</loc>
    <lastmod>2026-07-30T04:55:46.003Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-iex-invocation-patterns-in-process-creation-command-lines-09576804</loc>
    <lastmod>2026-07-30T04:55:44.118Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-set-service-sddl-usage-to-hide-services-514e4c3a</loc>
    <lastmod>2026-07-30T04:55:42.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-get-process-or-aliases-targeting-lsass-lsas-b2815d0d</loc>
    <lastmod>2026-07-30T04:55:40.645Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-recon-using-get-localgroupmember-on-local-well-known-groups-c8a180d6</loc>
    <lastmod>2026-07-30T04:55:39.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-get-clipboard-cmdlet-execution-via-cli-on-windows-b9aeac14</loc>
    <lastmod>2026-07-30T04:55:37.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-frombase64string-decoding-of-base64-gzip-content-in-process-creation--d75d6b6b</loc>
    <lastmod>2026-07-30T04:55:35.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-commandline-uses-frombase64string-to-decode-base64-content-windows-e32d4572</loc>
    <lastmod>2026-07-30T04:55:34.170Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-certificate-export-cmdlets-in-windows-process-creation-9e716b33</loc>
    <lastmod>2026-07-30T04:55:32.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-inline-execution-via-file-reads-and-raw-parameters-ee218c12</loc>
    <lastmod>2026-07-30T04:55:31.108Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-command-line-encoded-content-indicators-via-type-conversion-a-cdf05894</loc>
    <lastmod>2026-07-30T04:55:29.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-execution-with-base64-encoded-command-windows-fb843269</loc>
    <lastmod>2026-07-30T04:55:27.696Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-enable-windowsoptionalfeature-enables-suspicious-optional-fea-c740d4cf</loc>
    <lastmod>2026-07-30T04:55:25.569Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-email-address-exfiltration-via-exif-style-recipient-harvesting-on-win-312d0384</loc>
    <lastmod>2026-07-30T04:55:23.680Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-execution-of-dsinternals-cmdlets-on-windows-43d91656</loc>
    <lastmod>2026-07-30T04:55:21.811Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-downloads-via-powershell-exe-from-file-sharing-domains-on-window-b6e04788</loc>
    <lastmod>2026-07-30T04:55:20.071Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-with-download-related-command-line-patterns-3b6ab547</loc>
    <lastmod>2026-07-30T04:55:18.283Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-download-and-execution-cradles-85b0b087</loc>
    <lastmod>2026-07-30T04:55:16.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-downloading-dlls-via-invoke-webrequest-or-invoke-restmethod-0f0450f3</loc>
    <lastmod>2026-07-30T04:55:14.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-of-obfuscated-one-liner-for-in-memory-module-downlo-44e24481</loc>
    <lastmod>2026-07-30T04:55:13.199Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-com-clsid-download-cradles-02b64f1b</loc>
    <lastmod>2026-07-30T04:55:11.435Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-downgrade-attempts-via-version-2-on-windows-process-creation-b3512211</loc>
    <lastmod>2026-07-30T04:55:09.774Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-ie-security-registry-values-disabled-via-command-line-fb50eb7a</loc>
    <lastmod>2026-07-30T04:55:08.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-disables-windows-firewall-profiles-via-set-netfirewallprofile-12f6b752</loc>
    <lastmod>2026-07-30T04:55:06.789Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-or-sc-exe-disabling-windows-defender-behavio-a7ee1722</loc>
    <lastmod>2026-07-30T04:55:05.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-defender-exclusion-via-set-add-mppreference-command-line-flags-window-17769c90</loc>
    <lastmod>2026-07-30T04:55:03.626Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-disable-microsoft-defender-scanning-via-set-mppreference-1ec65a5f</loc>
    <lastmod>2026-07-30T04:55:01.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-decryption-like-activity-involving-lnk-file-processing-434c08ba</loc>
    <lastmod>2026-07-30T04:54:59.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-gzipstream-decompression-attempts-on-windows-98767d61</loc>
    <lastmod>2026-07-30T04:54:57.668Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-creates-windows-service-via-new-service-and-binarypathname-c02e96b7</loc>
    <lastmod>2026-07-30T04:54:56.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-history-file-access-attempt-via-consolehost-history-txt-f4ff7323</loc>
    <lastmod>2026-07-30T04:54:54.555Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-get-adcomputer-export-of-active-directory-computer-data-to-file-windo-435e10e4</loc>
    <lastmod>2026-07-30T04:54:52.937Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-obfuscated-com-msi-installation-via-windowsinstaller-installe-7b6a7418</loc>
    <lastmod>2026-07-30T04:54:49.406Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-command-line-obfuscation-indicators-from-special-character-patterns-w-d7bcd677</loc>
    <lastmod>2026-07-30T04:54:47.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-reversed-powershell-command-tokens-in-commandlin-b6b49cd1</loc>
    <lastmod>2026-07-30T04:54:45.981Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-convertto-securestring-cmdlet-execution-from-command-line-windows-74403157</loc>
    <lastmod>2026-07-30T04:54:44.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-proxy-execution-via-cl-mutexverifiers-ps1-1e0e1a81</loc>
    <lastmod>2026-07-30T04:54:42.672Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-assembly-loading-via-cl-loadassembly-ps1-functions-c57872c7</loc>
    <lastmod>2026-07-30T04:54:41.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-proxy-using-syncinvoke-in-cl-invocation-ps1-a0459f02</loc>
    <lastmod>2026-07-30T04:54:39.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-base64-encoded-wmi-class-invocation-1816994b</loc>
    <lastmod>2026-07-30T04:54:37.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-base64-obfuscated-net-reflection-assembly-load-call-9c0295ce</loc>
    <lastmod>2026-07-30T04:54:35.828Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-base64-encoded-reflective-net-assembly-load-62b7ccc9</loc>
    <lastmod>2026-07-30T04:54:34.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-base64-encoded-mppreference-command-lines-for-windows-defender-modifi-c6fb44c6</loc>
    <lastmod>2026-07-30T04:54:32.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-base64-encoded-commands-containing-invoke-e-6385697e</loc>
    <lastmod>2026-07-30T04:54:30.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-base64-command-line-executing-iex-88f680b8</loc>
    <lastmod>2026-07-30T04:54:29.123Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-command-lines-with-hidden-base64-encoded-key-f26c6093</loc>
    <lastmod>2026-07-30T04:54:27.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-frombase64string-commandline-base64-encoded-usage-windows-fdb62a13</loc>
    <lastmod>2026-07-30T04:54:25.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-detect-command-lines-with-suspicious-utf-16-base64-obfuscatio-8d01b53f</loc>
    <lastmod>2026-07-30T04:54:24.188Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-process-command-lines-with-encoded-command-flags-b9d9cc83</loc>
    <lastmod>2026-07-30T04:54:22.551Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-suspicious-encoded-command-line-execution-ca2092a1</loc>
    <lastmod>2026-07-30T04:54:20.744Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-audio-capture-cmdlets-toggle-get-set-write-audiodevice-932fb0d8</loc>
    <lastmod>2026-07-30T04:54:19.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-net-reflection-attempt-to-disable-amsi-via-amsiinitfailed-30edb182</loc>
    <lastmod>2026-07-30T04:54:16.099Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-on-windows-adding-windows-capabilities-via-add-windowscapability-b36d01a3</loc>
    <lastmod>2026-07-30T04:54:14.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-imports-microsoft-activedirectory-management-dll-via-import-m-70bc5215</loc>
    <lastmod>2026-07-30T04:54:12.905Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-of-aadinternals-cmdlets-process-creation-c86500e9</loc>
    <lastmod>2026-07-30T04:54:11.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-powercfg-execution-changing-lock-video-standby-timeout-f8d6a15e</loc>
    <lastmod>2026-07-30T04:54:09.410Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-tunneling-using-plink-exe-on-local-port-3389-f38ce0b9</loc>
    <lastmod>2026-07-30T04:54:07.836Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-plink-remote-port-forwarding-via-r-command-line-48a61b29</loc>
    <lastmod>2026-07-30T04:54:05.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pktmon-exe-process-execution-pktmon-exe-pktmon-exe-f956c7c1</loc>
    <lastmod>2026-07-30T04:54:04.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ping-hex-ip-usage-via-command-line-1a0d4aba</loc>
    <lastmod>2026-07-30T04:54:02.683Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-inline-php-execution-via-php-exe-r-flag-d81871ef</loc>
    <lastmod>2026-07-30T04:54:00.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-perl-inline-code-execution-via-e-e-f426547a</loc>
    <lastmod>2026-07-30T04:53:59.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pdqdeployrunner-execution-on-windows-with-encoded-download-indicators-12b8e9f5</loc>
    <lastmod>2026-07-30T04:53:57.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pdq-deploy-console-execution-d679950c</loc>
    <lastmod>2026-07-30T04:53:55.891Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-offlinescannershell-exe-mpclient-dll-dll-sideloading-ri-02b18447</loc>
    <lastmod>2026-07-30T04:53:54.350Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winword-exe-dll-loading-via-l-flag-and-dll-path-on-windows-f7375e28</loc>
    <lastmod>2026-07-30T04:53:52.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-process-spawning-from-microsoft-office-applications-438025f9</loc>
    <lastmod>2026-07-30T04:53:50.700Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-exe-in-user-directory-launched-by-microsoft-office-applicatio-aa3a6f94</loc>
    <lastmod>2026-07-30T04:53:48.955Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-process-spawn-by-outlook-parent-208748f7</loc>
    <lastmod>2026-07-30T04:53:45.987Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-program-execution-from-outlook-temporary-internet-files-folde-a018fdc3</loc>
    <lastmod>2026-07-30T04:53:42.653Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-outlook-enableunsafeclientmailrules-security-setting-en-55f0a3a1</loc>
    <lastmod>2026-07-30T04:53:41.149Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-execution-by-microsoft-onenote-on-windows-child-programs-c27515df</loc>
    <lastmod>2026-07-30T04:53:39.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-onenote-exe-launches-cmd-cscript-mshta-powershell-wscript-with-onenote-e-84b1706c</loc>
    <lastmod>2026-07-30T04:53:37.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-executable-running-a-document-from-trusted-template-startup-paths-f99abdf0</loc>
    <lastmod>2026-07-30T04:53:36.107Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-excel-dcom-child-processes-linked-to-activatemicrosofta-551d9c1f</loc>
    <lastmod>2026-07-30T04:53:34.434Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-applications-downloading-files-via-http-https-4ae3e30b</loc>
    <lastmod>2026-07-30T04:53:32.796Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-child-process-spawned-by-odbcconf-exe-8e3c7994</loc>
    <lastmod>2026-07-30T04:53:31.154Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-odbcconf-exe-with-f-response-file-flag-2d32dd6f</loc>
    <lastmod>2026-07-30T04:53:29.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-odbcconf-exe-response-file-execution-via-f-flag-5f03babb</loc>
    <lastmod>2026-07-30T04:53:27.957Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-odbcconf-exe-regsvr-usage-with-non-dll-suffixed-target-ba4cfc11</loc>
    <lastmod>2026-07-30T04:53:25.896Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-odbcconf-exe-used-to-register-a-dll-via-regsvr-9f0a8bf3</loc>
    <lastmod>2026-07-30T04:53:24.041Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-odbcconf-exe-with-dll-in-suspicious-path-6b65c28e</loc>
    <lastmod>2026-07-30T04:53:22.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-odbcconf-exe-installdriver-use-with-missing-dll-target-cb0fe7c5</loc>
    <lastmod>2026-07-30T04:53:19.546Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-odbcconf-exe-installdriver-dll-installation-via-process-command-l-3f5491e2</loc>
    <lastmod>2026-07-30T04:53:18.010Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-ntdsutil-exe-for-ntds-database-operations-2afafd61</loc>
    <lastmod>2026-07-30T04:53:16.317Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntdsutil-exe-use-for-ad-snapshot-mount-or-activation-windows-process--a58353df</loc>
    <lastmod>2026-07-30T04:53:14.493Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-dns-txt-download-cradle-via-nslookup-process-creation-1b3b01c7</loc>
    <lastmod>2026-07-30T04:53:12.518Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-network-recon-via-nslookup-ldap-srv-query-e6313acd</loc>
    <lastmod>2026-07-30T04:53:11.060Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-notepad-password-file-discovery-via-process-creation-3b4e950b</loc>
    <lastmod>2026-07-30T04:53:08.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-node-exe-running-npx-skills-add-new-agent-skills-afa71271</loc>
    <lastmod>2026-07-30T04:53:06.858Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-node-js-executions-from-adobe-creative-cloud-df1f26d3</loc>
    <lastmod>2026-07-30T04:53:05.003Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-node-exe-execution-with-e-eval-and-suspicious-child-process-usage-6640f31c</loc>
    <lastmod>2026-07-30T04:53:03.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-nltest-exe-recon-via-server-query-and-domain-trust-enumeration-5cc90652</loc>
    <lastmod>2026-07-30T04:53:01.689Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-nltest-exe-execution-for-network-information-discovery-903076ff</loc>
    <lastmod>2026-07-30T04:53:00.003Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-exe-wlan-profile-key-clearing-used-for-wifi-credential-harvesting-42b1a5b8</loc>
    <lastmod>2026-07-30T04:52:57.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-exe-used-to-create-rdp-3389-port-forwarding-782d6f3e</loc>
    <lastmod>2026-07-30T04:52:56.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-exe-adds-portproxy-v4-to-v4-forwarding-rule-322ed9ec</loc>
    <lastmod>2026-07-30T04:52:54.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-trace-start-command-execution-d3c3861d</loc>
    <lastmod>2026-07-30T04:52:53.174Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-exe-add-helper-execution-for-custom-helper-dll-loading-56321594</loc>
    <lastmod>2026-07-30T04:52:51.637Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-exe-advanced-firewall-rule-set-modification-a70dcb37</loc>
    <lastmod>2026-07-30T04:52:50.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-exe-firewall-configuration-discovery-show-firewall-rule-state-name-0e4164da</loc>
    <lastmod>2026-07-30T04:52:48.472Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-enables-defender-firewall-group-rules-via-advfirewall-set-rule-gro-347906f3</loc>
    <lastmod>2026-07-30T04:52:46.160Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-netsh-exe-commands-disabling-firewall-57c4bf16</loc>
    <lastmod>2026-07-30T04:52:44.178Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-rule-deleted-via-netsh-exe-command-line-1a5fefe6</loc>
    <lastmod>2026-07-30T04:52:42.592Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-port-3389-allowed-via-netsh-exe-firewall-rule-creation-01aeb693</loc>
    <lastmod>2026-07-30T04:52:41.076Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsh-exe-whitelists-allowed-program-from-suspicious-path-in-firewall-a35f5a72</loc>
    <lastmod>2026-07-30T04:52:39.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-rule-added-via-netsh-exe-cd5cfd80</loc>
    <lastmod>2026-07-30T04:52:37.363Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-net-exe-commands-manipulating-built-in-default-accounts-administrator-gu-5b768e71</loc>
    <lastmod>2026-07-30T04:52:34.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-local-user-creation-via-net-exe-with-expires-never-b9f0e6f5</loc>
    <lastmod>2026-07-30T04:52:32.002Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-local-user-account-creation-via-net-exe-or-net1-exe-cd219ff3</loc>
    <lastmod>2026-07-30T04:52:30.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-net-exe-network-connections-discovery-via-use-sessions-query-1c67a717</loc>
    <lastmod>2026-07-30T04:52:27.240Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mounting-internet-hosted-webdav-shares-via-net-exe-7e6237fe</loc>
    <lastmod>2026-07-30T04:52:24.130Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-stop-activity-via-net-exe-command-line-88872991</loc>
    <lastmod>2026-07-30T04:52:20.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-net-exe-used-to-start-a-service-with-the-start-flag-2a072a96</loc>
    <lastmod>2026-07-30T04:52:19.195Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-net-exe-unmount-share-delete-execution-cb7c4a03</loc>
    <lastmod>2026-07-30T04:52:17.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-reconnaissance-via-net-exe-group-account-queries-d95de845</loc>
    <lastmod>2026-07-30T04:52:15.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msxsl-exe-execution-with-http-keyword-in-command-line-75d0a94e</loc>
    <lastmod>2026-07-30T04:52:14.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msxsl-exe-execution-9e50a8b3</loc>
    <lastmod>2026-07-30T04:52:12.508Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-client-mstsc-exe-launched-from-uncommon-browser-or-email-parent-proc-ff3b6b39</loc>
    <lastmod>2026-07-30T04:52:10.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mstsc-exe-launched-with-a-local-rdp-file-from-suspicious-paths-6e22722b</loc>
    <lastmod>2026-07-30T04:52:09.197Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mstsc-exe-launched-with-local-rdp-file-argument-5fdce3ac</loc>
    <lastmod>2026-07-30T04:52:07.531Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-mstsc-exe-remote-desktop-connection-via-v-flag-954f0af7</loc>
    <lastmod>2026-07-30T04:52:06.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mstsc-shadowing-commandline-using-shadow-6ba5a05f</loc>
    <lastmod>2026-07-30T04:52:04.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-from-veeam-sql-server-service-d55b793d</loc>
    <lastmod>2026-07-30T04:52:02.748Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-sqlservr-exe-869b9ca7</loc>
    <lastmod>2026-07-30T04:52:00.653Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-via-sqltoolsps-exe-sqltoolsps-exe-child-process-exclusion-a746c9b8</loc>
    <lastmod>2026-07-30T04:51:59.135Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-execution-via-sqlps-exe-windows-process-creation-0152550d</loc>
    <lastmod>2026-07-30T04:51:57.427Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-process-injection-via-msra-exe-spawning-suspicious-child-proce-744a188b</loc>
    <lastmod>2026-07-30T04:51:55.764Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mspub-exe-downloading-arbitrary-files-via-http-ftp-uris-3b3c7f55</loc>
    <lastmod>2026-07-30T04:51:54.305Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msohtmed-exe-arbitrary-file-download-using-http-ftp-urls-459f2f98</loc>
    <lastmod>2026-07-30T04:51:52.825Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-advanced-installer-psf-ai-stubs-executables-with-originalfilename-af5732ed</loc>
    <lastmod>2026-07-30T04:51:51.210Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msiexec-process-creation-with-web-url-parameters-f7b5f842</loc>
    <lastmod>2026-07-30T04:51:49.498Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msiexec-exe-execution-from-uncommon-directory-e22a6eb2</loc>
    <lastmod>2026-07-30T04:51:47.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msiexec-exe-quiet-msi-installation-with-installer-arguments-79a87aa6</loc>
    <lastmod>2026-07-30T04:51:44.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-msiexec-exe-command-line-writes-install-logs-with-y-6f4191bb</loc>
    <lastmod>2026-07-30T04:51:42.160Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-msiexec-exe-embedding-spawned-by-powershell-cmd-pwsh-4a2a2c3e</loc>
    <lastmod>2026-07-30T04:51:40.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msiexec-exe-command-line-loading-a-dll-and-calling-dllunregisterserver-84f52741</loc>
    <lastmod>2026-07-30T04:51:38.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mshta-exe-process-creation-triggered-by-suspicious-command-lines-e32f92d1</loc>
    <lastmod>2026-07-30T04:51:36.145Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mshta-exe-execution-using-non-hta-file-extensions-cc7abbd0</loc>
    <lastmod>2026-07-30T04:51:34.502Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-children-spawned-by-mshta-exe-03cc0c25</loc>
    <lastmod>2026-07-30T04:51:32.664Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-svchost-exe-spawns-mshta-exe-lethalhta-ed5d72a6</loc>
    <lastmod>2026-07-30T04:51:30.949Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mshta-exe-launching-javascript-via-command-line-67f113fa</loc>
    <lastmod>2026-07-30T04:51:29.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wscript-shell-run-keyword-sequence-in-commandline-2c28c248</loc>
    <lastmod>2026-07-30T04:51:27.911Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mshta-exe-launched-with-url-based-arguments-http-https-ftp-b98d0db6</loc>
    <lastmod>2026-07-30T04:51:26.164Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-download-via-msedge-proxy-exe-using-http-https-urls-e84d89c4</loc>
    <lastmod>2026-07-30T04:51:24.446Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msdt-exe-execution-with-suspicious-parent-process-7a74da6b</loc>
    <lastmod>2026-07-30T04:51:22.030Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-msdt-exe-launched-with-cab-flag-dc4576d4</loc>
    <lastmod>2026-07-30T04:51:20.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msdt-exe-ms-msdt-handler-arbitrary-command-execution-attempts-258fc8ce</loc>
    <lastmod>2026-07-30T04:51:18.462Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msdt-exe-execution-using-pcwdiagnostic-xml-answer-file-9c8c7000</loc>
    <lastmod>2026-07-30T04:51:16.689Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-msbuild-exe-execution-from-uncommon-parent-process-33be4333</loc>
    <lastmod>2026-07-30T04:51:14.533Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-mpcmdrun-exe-removing-all-windows-defender-definitions-9719a8aa</loc>
    <lastmod>2026-07-30T04:51:12.839Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-mpcmdrun-exe-used-to-download-files-via-downloadfile-ur-46123129</loc>
    <lastmod>2026-07-30T04:51:10.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-mpclient-dll-side-loading-mpcmdrun-exe-or-nissrv-exe-from-non-d-7002aa10</loc>
    <lastmod>2026-07-30T04:51:09.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-suspicious-mofcomp-exe-execution-from-scripts-or-temp-paths-1dd05363</loc>
    <lastmod>2026-07-30T04:51:07.663Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-page-change-via-mode-com-selecting-russian-code-pages-12fbff88</loc>
    <lastmod>2026-07-30T04:51:05.606Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mmc-spawning-command-line-executables-05a2ab7e</loc>
    <lastmod>2026-07-30T04:51:04.041Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mmc-executes-files-with-rlo-reversed-extensions-in-process-command-line-9cfe4b27</loc>
    <lastmod>2026-07-30T04:51:02.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mmc20-lateral-movement-via-mmc-exe-embedding-spawned-by-svchost-exe-f1f3bf22</loc>
    <lastmod>2026-07-30T04:51:00.605Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-gpme-used-to-modify-default-domain-and-default-domain-controller-dcff7e85</loc>
    <lastmod>2026-07-30T04:50:58.950Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-mftrace-exe-child-process-execution-3d48c9d3</loc>
    <lastmod>2026-07-30T04:50:57.132Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-process-clone-execution-observed-c8da0dfd</loc>
    <lastmod>2026-07-30T04:50:55.276Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsa-ppl-protection-setting-modification-via-reg-exe-or-powershell-comman-8c0eca51</loc>
    <lastmod>2026-07-30T04:50:53.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-cscript-wscript-register-app-vbs-com-registration-28c8f68b</loc>
    <lastmod>2026-07-30T04:50:51.551Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wfc-exe-execution-for-workflow-command-line-compiler-ab-49be8799</loc>
    <lastmod>2026-07-30T04:50:49.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-vsiisexelauncher-exe-used-with-p-and-a-parameters-18749301</loc>
    <lastmod>2026-07-30T04:50:48.023Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/process-creation-of-visualuiaverifynative-exe-on-windows-b30a8bc5</loc>
    <lastmod>2026-07-30T04:50:46.183Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-visual-basic-compiler-using-cvtres-exe-resource-converter-7b10f171</loc>
    <lastmod>2026-07-30T04:50:44.635Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-utilityfunctions-ps1-loading-managed-dll-via-proxy-0403d67d</loc>
    <lastmod>2026-07-30T04:50:43.115Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-unregmp2-exe-used-as-a-proxy-to-launch-wmpnscfg-exe-727454c0</loc>
    <lastmod>2026-07-30T04:50:41.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-time-travel-debugging-utility-tttracer-exe-process-execution-0b4ae027</loc>
    <lastmod>2026-07-30T04:50:39.842Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-ttdinject-exe-ttdinject-exe-b27077d6</loc>
    <lastmod>2026-07-30T04:50:38.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-dll-injection-via-tracker-exe-command-line-on-windows-148431ce</loc>
    <lastmod>2026-07-30T04:50:36.741Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-syncappvpublishingserver-vbs-execution-triggers-powershell-via-semicolon-36475a7d</loc>
    <lastmod>2026-07-30T04:50:34.627Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-syncappvpublishingserver-exe-with-powershell-injection-fbd7c32d</loc>
    <lastmod>2026-07-30T04:50:32.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-dumping-using-sqldumper-exe-with-dump-options-23ceaf5c</loc>
    <lastmod>2026-07-30T04:50:31.042Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-grpconv-utility-execution-for-grp-conversion-or-persistence-f14e169e</loc>
    <lastmod>2026-07-30T04:50:29.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pnputil-exe-driver-installation-via-inf-on-windows-a2ea3ae7</loc>
    <lastmod>2026-07-30T04:50:27.587Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sftp-exe-lolbin-abuse-via-d-flag-a85ffc3a</loc>
    <lastmod>2026-07-30T04:50:26.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-settingsynchost-exe-executing-roamdiag-cmd-via-cmd-exe-c-outputpath-b2ddd389</loc>
    <lastmod>2026-07-30T04:50:24.506Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scriptrunner-exe-process-execution-with-app-v-script-parameters-64760eef</loc>
    <lastmod>2026-07-30T04:50:22.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-runscripthelper-exe-spawning-powershell-script-acti-eca49c87</loc>
    <lastmod>2026-07-30T04:50:20.707Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-runexehelper-exe-used-as-a-proxy-cd71385d</loc>
    <lastmod>2026-07-30T04:50:19.114Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-replace-exe-with-a-argument-9292293b</loc>
    <lastmod>2026-07-30T04:50:17.427Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-remote-exe-windbg-execution-4eddc365</loc>
    <lastmod>2026-07-30T04:50:15.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-register-app-vbs-vss-vds-com-provider-registration-via-register-1c8774a0</loc>
    <lastmod>2026-07-30T04:50:14.343Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rasautou-exe-dll-execution-on-windows-via-d-and-p-parameters-cd3d1298</loc>
    <lastmod>2026-07-30T04:50:12.694Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pubprn-vbs-signed-script-proxy-execution-via-script-command-line-1fb76ab8</loc>
    <lastmod>2026-07-30T04:50:11.110Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-printbrm-exe-zip-creation-extraction-via-command-line-flags-cafeeba3</loc>
    <lastmod>2026-07-30T04:50:09.577Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-execution-via-pester-bat-using-powershell-or-cmd-59e938ff</loc>
    <lastmod>2026-07-30T04:50:07.773Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-execution-via-pester-bat-spawned-by-powershell-18988e1b</loc>
    <lastmod>2026-07-30T04:50:06.005Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-launchapplication-execution-via-pcwutl-dll-9386d78a</loc>
    <lastmod>2026-07-30T04:50:04.186Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pcwrun-exe-indirect-command-execution-via-path-traversal-6004abd0</loc>
    <lastmod>2026-07-30T04:50:02.601Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-indirect-command-execution-via-pcwrun-exe-program-compatibility-assistan-b97cd4b1</loc>
    <lastmod>2026-07-30T04:50:01.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pcalua-exe-flag-a-command-execution-0955e4e1</loc>
    <lastmod>2026-07-30T04:49:59.500Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-openwith-exe-launches-a-binary-via-c-cec8e918</loc>
    <lastmod>2026-07-30T04:49:58.010Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-openconsole-exe-used-as-lolbin-to-launch-other-executab-814c95cc</loc>
    <lastmod>2026-07-30T04:49:56.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msdeploy-exe-executes-with-sync-verb-and-runcommand-source-destination-646bc99f</loc>
    <lastmod>2026-07-30T04:49:55.002Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mpiexec-exe-lolbin-usage-with-n-1-n-1-flag-combination-729ce0ea</loc>
    <lastmod>2026-07-30T04:49:53.361Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-injection-via-mavinject-using-injectrunning-flag-4f73421b</loc>
    <lastmod>2026-07-30T04:49:51.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-manage-bde-wsf-executed-via-wscript-cscript-to-proxy-command-execution-c363385c</loc>
    <lastmod>2026-07-30T04:49:49.579Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-launch-vsdevshell-ps1-proxy-command-execution-45d3a03d</loc>
    <lastmod>2026-07-30T04:49:47.797Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ie4uinit-exe-executed-from-unusual-currentdirectory-invalid-path-d3bf399f</loc>
    <lastmod>2026-07-30T04:49:46.004Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gpscript-exe-execution-with-logon-or-startup-parameters-1e59c230</loc>
    <lastmod>2026-07-30T04:49:44.306Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-execution-of-gathernetworkinfo-vbs-via-cscript-exe-or-wscript-exe-575dce0c</loc>
    <lastmod>2026-07-30T04:49:42.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-extrac32-exe-execution-with-alternate-data-stream-targeting-4b13db67</loc>
    <lastmod>2026-07-30T04:49:40.731Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-diantz-alternate-data-stream-ads-cab-execution-via-command-line-6b369ced</loc>
    <lastmod>2026-07-30T04:49:35.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-devtoolslauncher-exe-launches-specified-binary-via-launchfordeploy-cc268ac1</loc>
    <lastmod>2026-07-30T04:49:34.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-data-exfiltration-via-datasvcutil-exe-with-in-out-uri-arguments-e290b10b</loc>
    <lastmod>2026-07-30T04:49:32.277Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-logman-exe-commands-stopping-or-deleting-trace-etw-sessions-cd1f961e</loc>
    <lastmod>2026-07-30T04:49:30.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lodctr-exe-rebuilds-performance-counter-registry-values-cc9d3712</loc>
    <lastmod>2026-07-30T04:49:29.101Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-uncommon-parent-process-for-link-exe-6e968eb1</loc>
    <lastmod>2026-07-30T04:49:27.449Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ldifde-exe-ldap-import-i-f-execution-6f535e01</loc>
    <lastmod>2026-07-30T04:49:25.948Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-ldifde-exe-export-of-active-directory-via-f-4f7a6757</loc>
    <lastmod>2026-07-30T04:49:24.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-logged-on-user-password-change-via-ksetup-exe-c9783e20</loc>
    <lastmod>2026-07-30T04:49:22.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-password-change-via-ksetup-exe-setcomputerpassword-de16d92c</loc>
    <lastmod>2026-07-30T04:49:21.147Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-processes-spawned-by-keyscrambler-exe-on-windows-ca5583e9</loc>
    <lastmod>2026-07-30T04:49:19.725Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-kerberos-coercion-tooling-via-base64-credential--0ed99dda</loc>
    <lastmod>2026-07-30T04:49:17.985Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-execution-of-kd-exe-windows-kernel-debugger-27ee9438</loc>
    <lastmod>2026-07-30T04:49:16.204Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-kavremover-cleanapi-lolbin-style-command-line-execution-d047726b</loc>
    <lastmod>2026-07-30T04:49:14.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-jscript-compiler-jsc-exe-process-execution-52788a70</loc>
    <lastmod>2026-07-30T04:49:13.270Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysaidserver-spawns-suspicious-java-child-processes-60bfeac3</loc>
    <lastmod>2026-07-30T04:49:11.634Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-java-exe-spawning-command-shell-processes-dff1e1cc</loc>
    <lastmod>2026-07-30T04:49:10.151Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-suspicious-child-processes-spawned-by-java-exe-0d34ed8b</loc>
    <lastmod>2026-07-30T04:49:08.420Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-java-process-launched-with-jdwp-remote-debugging-bound-beyond-localhost-8f88e3f6</loc>
    <lastmod>2026-07-30T04:49:06.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-manageengine-servicedesk-java-serv-cea2b7ea</loc>
    <lastmod>2026-07-30T04:49:05.296Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-keytool-exe-spawns-suspicious-command-line-shell-processes-90fb5e62</loc>
    <lastmod>2026-07-30T04:49:02.571Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-installutil-exe-execution-missing-logfile-parameter-d042284c</loc>
    <lastmod>2026-07-30T04:49:00.621Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-installutil-exe-used-to-download-remote-files-75edd216</loc>
    <lastmod>2026-07-30T04:48:59.128Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-infdefaultinstall-exe-inf-execution-via-process-command-line-ce7cf472</loc>
    <lastmod>2026-07-30T04:48:57.319Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-imewdbld-exe-downloading-files-from-http-https-863218bd</loc>
    <lastmod>2026-07-30T04:48:55.739Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-unusual-parent-child-execution-involving-imagingdevices-exe-f11f2808</loc>
    <lastmod>2026-07-30T04:48:53.711Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-ilasm-exe-compiling-c-il-to-exe-or-dll-850d55f9</loc>
    <lastmod>2026-07-30T04:48:51.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-module-registration-via-appcmd-and-powershell-043c4b8b</loc>
    <lastmod>2026-07-30T04:48:50.348Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-deletion-of-iis-log-files-0649be4a</loc>
    <lastmod>2026-07-30T04:48:44.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-aspnet-regiis-decrypts-connection-strings-via-pdf-97dbf6e2</loc>
    <lastmod>2026-07-30T04:48:42.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-appcmd-creates-global-url-rewrite-rules-via-config-commit-7c8af9b2</loc>
    <lastmod>2026-07-30T04:48:40.531Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-native-code-module-installation-via-appcmd-exe-command-line-9465ddf4</loc>
    <lastmod>2026-07-30T04:48:38.986Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-appcmd-lists-service-account-passwords-via-command-line-2d3cdeec</loc>
    <lastmod>2026-07-30T04:48:37.085Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-http-logging-disabled-via-appcmd-exe-e4ed6030</loc>
    <lastmod>2026-07-30T04:48:35.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-iexpress-exe-self-extraction-directive-sed-package-creation-fro-b2b048b0</loc>
    <lastmod>2026-07-30T04:48:34.149Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ieexec-exe-download-and-execute-execution-via-process-creation-9801abb8</loc>
    <lastmod>2026-07-30T04:48:32.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-executed-hxtsr-exe-from-outside-microsoft-windowscommunicationsapps-wind-4e762605</loc>
    <lastmod>2026-07-30T04:48:29.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hwp-exe-spawned-gbb-exe-subprocess-detection-023394c4</loc>
    <lastmod>2026-07-30T04:48:27.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hvci-registry-tampering-via-reg-exe-or-powershell-command-line-6225c53a</loc>
    <lastmod>2026-07-30T04:48:25.913Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-hostname-exe-run-matching-7be5fb68</loc>
    <lastmod>2026-07-30T04:48:24.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-zipexec-style-password-protected-zip-executi-90dcf730</loc>
    <lastmod>2026-07-30T04:48:22.891Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-xordump-lsass-memory-dump-via-specific-command-line-switches-66e563f9</loc>
    <lastmod>2026-07-30T04:48:20.826Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-execution-of-wsass-exe-leveraging-werfaultsecure-exe-via-wer-589ac73f</loc>
    <lastmod>2026-07-30T04:48:19.277Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-execution-with-wmiexec-default-flag-sequence-022eaba8</loc>
    <lastmod>2026-07-30T04:48:17.465Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-winpwn-keyword-execution-in-command-line-d557dc06</loc>
    <lastmod>2026-07-30T04:48:15.915Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-winpeas-peass-ng-execution-98b53e78</loc>
    <lastmod>2026-07-30T04:48:14.152Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detecting-wce-exe-wce64-exe-credential-editor-execution-7aa7009a</loc>
    <lastmod>2026-07-30T04:48:11.834Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-uacme-akagi-exe-akagi64-exe-via-pe-metadata-indicators-d38d2fa4</loc>
    <lastmod>2026-07-30T04:48:10.064Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-trufflesnout-exe-process-execution-detection-69ca006d</loc>
    <lastmod>2026-07-30T04:48:08.210Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmoneop-hacktool-execution-via-sysmoneop-exe-name-and-imphash-8a7e90c5</loc>
    <lastmod>2026-07-30T04:48:06.647Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-execution-stracciatella-exe-process-identified-via-pe-metadata-7a4d9232</loc>
    <lastmod>2026-07-30T04:48:05.046Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-soaphound-execution-via-ad-data-collection-arguments-e92a4287</loc>
    <lastmod>2026-07-30T04:48:03.415Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-commandline-pattern-for-sliver-c2-implant-activity-42333b2c</loc>
    <lastmod>2026-07-30T04:48:01.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-silenttrinity-st2stager-stager-execution-via-pe-descrip-03552375</loc>
    <lastmod>2026-07-30T04:48:00.140Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sharpwsus-wsuspendu-process-command-line-execution-b0ce780f</loc>
    <lastmod>2026-07-30T04:47:58.350Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sharpview-exe-recon-and-discovery-commands-execution-b2317cfa</loc>
    <lastmod>2026-07-30T04:47:56.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpup-privesc-tool-execution-on-windows-via-process-creation-c484e533</loc>
    <lastmod>2026-07-30T04:47:55.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sharpsuccessor-exe-execution-for-privilege-escalation-38a1ac5f</loc>
    <lastmod>2026-07-30T04:47:53.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpmove-exe-execution-on-windows-dcom-wmi-vbs-and-scheduled-task-actions-055fb54c</loc>
    <lastmod>2026-07-30T04:47:51.750Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpldapwhoami-tool-execution-on-windows-via-process-creation-d9367cbb</loc>
    <lastmod>2026-07-30T04:47:50.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpevtmute-execution-via-process-creation-on-windows-bedfc8ad</loc>
    <lastmod>2026-07-30T04:47:48.483Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sharpersist-hacktool-execution-26488ad0</loc>
    <lastmod>2026-07-30T04:47:46.911Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpldapmonitor-hacktool-execution-on-windows-9f8fc146</loc>
    <lastmod>2026-07-30T04:47:45.551Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpimpersonation-tool-execution-on-windows-via-process-creation-f89b08d0</loc>
    <lastmod>2026-07-30T04:47:43.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharpdpapi-tool-execution-on-windows-via-process-command-line-and-pe-metadata-c7d33b50</loc>
    <lastmod>2026-07-30T04:47:42.211Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sharpchisel-hacktool-execution-via-process-name-or-product-metadata-cf93e05e</loc>
    <lastmod>2026-07-30T04:47:40.575Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-selectmyparent-exe-execution-for-ppid-spoofing-52ff7941</loc>
    <lastmod>2026-07-30T04:47:39.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-securityxploded-passworddump-exe-execution-7679d464</loc>
    <lastmod>2026-07-30T04:47:37.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-safetykatz-hacktool-execution-b1876533</loc>
    <lastmod>2026-07-30T04:47:35.722Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-rubeus-exe-hacktool-execution-via-command-line-kerberos-actions-7ec2c172</loc>
    <lastmod>2026-07-30T04:47:34.211Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-smb-ntlm-relay-and-potato-attack-tools-5589ab4f</loc>
    <lastmod>2026-07-30T04:47:32.432Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-rundll32-cmd-exe-indicators-of-redmimicry-winnti-hackto-95022b85</loc>
    <lastmod>2026-07-30T04:47:30.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-quarkspwdump-exe-credential-dumping-via-command-line-flags-0685b176</loc>
    <lastmod>2026-07-30T04:47:29.308Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-pypykatz-live-registry-credential-dumping-a29808fd</loc>
    <lastmod>2026-07-30T04:47:27.674Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-purplesharp-hacktool-execution-via-process-creation-ff23ffbc</loc>
    <lastmod>2026-07-30T04:47:26.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powertool-execution-via-powertool-exe-or-powertool64-exe-process-creatio-a34f79a3</loc>
    <lastmod>2026-07-30T04:47:24.803Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-and-empire-schtasks-exe-task-creation-via-schtasks-create-with-tn-upd-56c217c3</loc>
    <lastmod>2026-07-30T04:47:23.169Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-pchunter64-pchunter32-execution-fca949cc</loc>
    <lastmod>2026-07-30T04:47:20.940Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netexec-nxc-exe-process-execution-with-network-protocol-commands-7638e5fe</loc>
    <lastmod>2026-07-30T04:47:19.207Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-indicators-for-mimikatz-tool-execution-and-credenti-a642964e</loc>
    <lastmod>2026-07-30T04:47:17.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-service-launched-getsystem-via-cmd-comspec-named-pipes--15619216</loc>
    <lastmod>2026-07-30T04:47:15.891Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-localpotato-exe-execution-for-local-privilege-escalation-6bd75993</loc>
    <lastmod>2026-07-30T04:47:14.119Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-lazagne-password-recovery-tool-execution-c2b86e67</loc>
    <lastmod>2026-07-30T04:47:12.219Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-krbrelayup-exe-process-execution-with-relay-domain-and-scm-spawn--12827a56</loc>
    <lastmod>2026-07-30T04:47:10.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-remotekrbrelay-kerberos-relaying-tool-usage-a7664b14</loc>
    <lastmod>2026-07-30T04:47:09.148Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-krbrelay-relaying-tool-e96253b8</loc>
    <lastmod>2026-07-30T04:47:07.310Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-with-cmd-exe-arguments-matching-koadic-parameters-5cddf373</loc>
    <lastmod>2026-07-30T04:47:05.783Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-jlaive-in-memory-assembly-execution-via-powershell-and--0a99eb3e</loc>
    <lastmod>2026-07-30T04:47:04.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-obfuscated-powershell-via-var-launcher-invoke-obfuscati-e9f55347</loc>
    <lastmod>2026-07-30T04:47:02.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-obfuscated-powershell-command-invoking-mshta-vbscript-from-scrip-ac20ae82</loc>
    <lastmod>2026-07-30T04:47:00.635Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-obfuscation-using-clip-exe-via-clipboard-invoke-e1561947</loc>
    <lastmod>2026-07-30T04:46:59.105Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-stdin-obfuscation-execution-from-command-line-9c14c9fa</loc>
    <lastmod>2026-07-30T04:46:57.569Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-obfuscation-using-compress-and-ascii-encoding-7eedcc9d</loc>
    <lastmod>2026-07-30T04:46:56.061Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-via-obfuscated-cmd-set-environment-variables-27aec9c9</loc>
    <lastmod>2026-07-30T04:46:54.352Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-obfuscated-cmd-launcher-using-powershell-with-stdin-inp-6c96fc76</loc>
    <lastmod>2026-07-30T04:46:52.441Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-obfuscated-iex-invocation-pattern-from-invoke-obfuscation-4bf943c6</loc>
    <lastmod>2026-07-30T04:46:50.891Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-obfuscated-clip-exe-used-to-execute-powershell-b222df08</loc>
    <lastmod>2026-07-30T04:46:49.231Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-inveigh-mitm-tool-execution-via-inveigh-exe-flags-b99a1518</loc>
    <lastmod>2026-07-30T04:46:47.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-impersonate-exe-hacktool-execution-cf0c254b</loc>
    <lastmod>2026-07-30T04:46:46.112Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-impacket-toolset-binary-execution-static-exe-names-4627c6ae</loc>
    <lastmod>2026-07-30T04:46:44.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-indicates-thc-hydra-password-bruteforce-pa-aaafa146</loc>
    <lastmod>2026-07-30T04:46:40.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-matching-htran-natbypass-executable-names-and-cli-flags-f5e3b62f</loc>
    <lastmod>2026-07-30T04:46:39.394Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-hollowreaper-exe-execution-85d23b42</loc>
    <lastmod>2026-07-30T04:46:37.761Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hashcat-exe-password-cracking-execution-via-registry-sourced-sam-39b31e81</loc>
    <lastmod>2026-07-30T04:46:36.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-handlekatz-lsass-dump-execution-via-loader-exe-and-obfuscated-obf-output-ca621ba5</loc>
    <lastmod>2026-07-30T04:46:34.708Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gmer-exe-execution-rootkit-tool-via-image-path-and-known-hashes-9082ff1f</loc>
    <lastmod>2026-07-30T04:46:33.027Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-execution-via-pe-company-metadata-cube0x0-37c1333a</loc>
    <lastmod>2026-07-30T04:46:31.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-execution-via-imphash-matches-renamed-files-24e3e58a</loc>
    <lastmod>2026-07-30T04:46:29.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-evil-winrm-ruby-process-parameters-for-winrm-login-a197e378</loc>
    <lastmod>2026-07-30T04:46:28.400Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-empire-powershell-uac-bypass-command-line-patterns-3268b746</loc>
    <lastmod>2026-07-30T04:46:26.753Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-process-command-lines-with-empire-style-encoded-persistence-l-79f4ede3</loc>
    <lastmod>2026-07-30T04:46:25.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-edrsilencer-hacktool-execution-via-edrsilencer-exe-process-creation-eb2d07d4</loc>
    <lastmod>2026-07-30T04:46:23.587Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-execution-detect-edr-freeze-exe-launch-c598cc0c</loc>
    <lastmod>2026-07-30T04:46:21.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-execution-dumpert-process-dumper-loading-dumpert-dll-2704ab9e</loc>
    <lastmod>2026-07-30T04:46:19.512Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-doppelganger-exe-lsass-memory-dumper-d474c8fe</loc>
    <lastmod>2026-07-30T04:46:17.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-command-line-uses-dinjector-am51-and-password-flags-on-windows-d78b5d61</loc>
    <lastmod>2026-07-30T04:46:16.383Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-createminidump-exe-lsass-minidump-36d88494</loc>
    <lastmod>2026-07-30T04:46:14.873Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detects-crackmapexec-powershell-obfuscation-via-obfuscated-powershell-co-6f8b3439</loc>
    <lastmod>2026-07-30T04:46:13.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-pattern-indicating-crackmapexec-lsass-dumping-via-tasklist-cmd-a-f26307d8</loc>
    <lastmod>2026-07-30T04:46:11.466Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-crackmapexec-execution-via-distinctive-command-line-fla-42a993dd</loc>
    <lastmod>2026-07-30T04:46:07.877Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-command-line-indicators-for-covenant-hacktool-launcher-usage-c260b6db</loc>
    <lastmod>2026-07-30T04:46:06.106Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-coercedpotato-exe-privilege-escalation-execution-e8d34729</loc>
    <lastmod>2026-07-30T04:46:04.560Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-launching-dlls-via-cobalt-strike-startw-ae9c6a7c</loc>
    <lastmod>2026-07-30T04:46:01.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-contains-cobalt-strike-module-commands-entered-in-cmd-exe-4f154fb6</loc>
    <lastmod>2026-07-30T04:45:59.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-cobalt-strike-command-strings-entered-in-cmd-exe-647c7b9e</loc>
    <lastmod>2026-07-30T04:45:58.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-certipy-exe-tool-execution-based-on-pe-and-command-line-6938366d</loc>
    <lastmod>2026-07-30T04:45:56.367Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-certify-exe-for-ad-certificate-abuse-attempts-762f2482</loc>
    <lastmod>2026-07-30T04:45:54.614Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-execution-loading-dlls-exported-with-startnoderelay-b18c9d4c</loc>
    <lastmod>2026-07-30T04:45:52.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-execution-bloodhound-sharphound-command-line-parameter-matching-f376c8a7</loc>
    <lastmod>2026-07-30T04:45:51.169Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-indicative-of-adcspwn-use-via-adcs-options-cd8c163e</loc>
    <lastmod>2026-07-30T04:45:49.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hh-exe-process-execution-with-suspicious-command-line-paths-e8a95b5e</loc>
    <lastmod>2026-07-30T04:45:48.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-hh-exe-via-common-lolbins-52cad028</loc>
    <lastmod>2026-07-30T04:45:46.470Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hh-exe-execution-with-chm-command-line-68c8acb4</loc>
    <lastmod>2026-07-30T04:45:42.625Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-gup-exe-outside-notepad-updater-paths-0a4f6091</loc>
    <lastmod>2026-07-30T04:45:40.985Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-process-execution-by-notepad-updater-gup-exe-bb0e87ce</loc>
    <lastmod>2026-07-30T04:45:39.441Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-notepad-gup-gup-exe-file-downloads-via-http-when-parent-is-not-notepad-e-44143844</loc>
    <lastmod>2026-07-30T04:45:37.622Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gup-utility-used-by-notepad-updater-to-execute-arbitrary-binaries-d65aee4d</loc>
    <lastmod>2026-07-30T04:45:35.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gpresult-exe-used-to-display-group-policy-resultant-set-rsop-e56d3073</loc>
    <lastmod>2026-07-30T04:45:34.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gpg4win-gpg-exe-encrypt-decrypt-using-passphrases-from-suspicious-paths-e1e0b7d7</loc>
    <lastmod>2026-07-30T04:45:32.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-unusual-gpg-exe-or-gpg2-exe-execution-paths-77df53a5</loc>
    <lastmod>2026-07-30T04:45:30.663Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-encryption-via-gpg4win-gpg-exe-gpg2-exe-with-passphrase-550bbb84</loc>
    <lastmod>2026-07-30T04:45:29.084Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-decryption-via-gpg4win-gpg-exe-using-passphrase-flag-037dcd71</loc>
    <lastmod>2026-07-30T04:45:26.204Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-googleupdate-exe-84b1ecf9</loc>
    <lastmod>2026-07-30T04:45:24.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-github-self-hosted-runner-worker-listener-spawn-and-con-5bac7a56</loc>
    <lastmod>2026-07-30T04:45:22.472Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-git-clone-with-vulnerability-payload-keywords-aef9d1f1</loc>
    <lastmod>2026-07-30T04:45:20.764Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gfxdownloadwrapper-exe-used-for-arbitrary-file-download-from-a-url-eee00933</loc>
    <lastmod>2026-07-30T04:45:19.210Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ftp-exe-run-with-s-or-s-flag-leading-to-arbitrary-command-execution-06b401f4</loc>
    <lastmod>2026-07-30T04:45:17.396Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-fsutil-exe-suspicious-usn-journal-and-file-zeroing-commands-add64136</loc>
    <lastmod>2026-07-30T04:45:15.828Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-fsutil-symlinkevaluation-behavior-change-via-cmd-or-powershell-c0b2768a</loc>
    <lastmod>2026-07-30T04:45:14.129Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-fsutil-drive-enumeration-via-drives-argument-63de06b9</loc>
    <lastmod>2026-07-30T04:45:12.208Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-f-interpreters-fsi-exe-and-fsianycpu-exe-b96b2031</loc>
    <lastmod>2026-07-30T04:45:10.833Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-format-com-invoked-with-uncommon-fs-filesystem-parameter-9fb6b26e</loc>
    <lastmod>2026-07-30T04:45:09.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-forfiles-exe-executed-with-c-flag-9aa5106d</loc>
    <lastmod>2026-07-30T04:45:07.466Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-forfiles-exe-child-process-masquerading-via-cmd-exe-execution-f53714ec</loc>
    <lastmod>2026-07-30T04:45:05.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-filter-driver-unloaded-using-fltmc-exe-4d7cda18</loc>
    <lastmod>2026-07-30T04:45:04.054Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-filter-driver-unload-triggered-by-fltmc-exe-process-execution-4931188c</loc>
    <lastmod>2026-07-30T04:45:02.308Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-finger-exe-execution-af491bca</loc>
    <lastmod>2026-07-30T04:45:00.396Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-findstr-exe-used-with-argument-385201-sysmon-default-dr-37db85d1</loc>
    <lastmod>2026-07-30T04:44:58.944Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-findstr-exe-used-for-subfolder-s-and-case-insensitive-i-searches-04936b66</loc>
    <lastmod>2026-07-30T04:44:57.007Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-findstr-exe-security-tool-keyword-lookup-via-command-line-4fe074b4</loc>
    <lastmod>2026-07-30T04:44:55.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-recon-command-output-piped-to-findstr-exe-ccb5742c</loc>
    <lastmod>2026-07-30T04:44:53.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-process-reconnaissance-using-findstr-exe-or-find-exe-fe63010f</loc>
    <lastmod>2026-07-30T04:44:50.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-findstr-used-with-lnk-suffix-to-trigger-shortcut-execut-33339be3</loc>
    <lastmod>2026-07-30T04:44:49.049Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-findstr-searches-for-gpp-cpassword-in-sysvol-xml-91a2c315</loc>
    <lastmod>2026-07-30T04:44:47.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-explorer-spawned-with-nouaccheck-flag-534f2ef7</loc>
    <lastmod>2026-07-30T04:44:43.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-explorer-launched-from-cmd-exe-or-powershell-with-shell-mycomputerfolder-c3d76afc</loc>
    <lastmod>2026-07-30T04:44:42.194Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-explorer-process-tree-break-via-explorer-factory-and-root-flags-949f1ffb</loc>
    <lastmod>2026-07-30T04:44:40.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-expand-exe-cabinet-file-expansion-from-uncommon-paths-9f107a84</loc>
    <lastmod>2026-07-30T04:44:39.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-child-processes-spawned-by-eventvwr-exe-be344333</loc>
    <lastmod>2026-07-30T04:44:35.372Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-disable-security-event-logging-via-registry-minint-key-1a4bd6af</loc>
    <lastmod>2026-07-30T04:44:33.679Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-esentutl-exe-usage-to-collect-browser-cache-data-6a69f62d</loc>
    <lastmod>2026-07-30T04:44:31.912Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-copying-sensitive-credential-files-via-esentutl-vss-command-lines-e7be6119</loc>
    <lastmod>2026-07-30T04:44:30.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-esentutl-access-with-p-for-ntds-credentials-files-7df1713a</loc>
    <lastmod>2026-07-30T04:44:28.462Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-dxcap-exe-with-c-to-launch-arbitrary-payloads-60f16a96</loc>
    <lastmod>2026-07-30T04:44:26.843Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dumpminitool-exe-execution-on-windows-eb1c4225</loc>
    <lastmod>2026-07-30T04:44:25.231Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-dumpminitool-exe-memory-dump-tool-execution-dee0a7a3</loc>
    <lastmod>2026-07-30T04:44:23.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspected-defender-av-bypass-by-renaming-dump64-exe-in--129966c9</loc>
    <lastmod>2026-07-30T04:44:21.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-kernel-dump-via-dtrace-exe-lkd-process-creation-7124aebe</loc>
    <lastmod>2026-07-30T04:44:20.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-dsquery-exe-trusteddomain-discovery-3bad990e</loc>
    <lastmod>2026-07-30T04:44:18.306Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-password-spraying-attempt-via-dsacls-exe-bac9fb54</loc>
    <lastmod>2026-07-30T04:44:16.511Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dsacls-exe-granting-over-permissive-acl-permissions-via-g-01c42d3c</loc>
    <lastmod>2026-07-30T04:44:15.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-driverquery-exe-process-execution-for-installed-driver-discovery-a20def93</loc>
    <lastmod>2026-07-30T04:44:13.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-driverquery-exe-used-for-installed-driver-recon-9fc3072c</loc>
    <lastmod>2026-07-30T04:44:11.413Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-memory-dump-tool-execution-dotnet-dump-exe-collect-53d8d3e1</loc>
    <lastmod>2026-07-30T04:44:09.591Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-using-dotnet-trace-exe-proxy-arguments-9257c05b</loc>
    <lastmod>2026-07-30T04:44:07.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-arbitrary-dll-or-csproj-code-execution-via-dotnet-exe-d80d5c81</loc>
    <lastmod>2026-07-30T04:44:06.229Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-dnx-exe-may-indicate-an-application-whitelisting-bypass-81ebd28b</loc>
    <lastmod>2026-07-30T04:44:04.006Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dnscmd-exe-installs-dns-serverlevelplugindll-via-serverlevelplugindll-f63b56ee</loc>
    <lastmod>2026-07-30T04:44:02.432Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dnscmd-exe-dns-zone-and-record-enumeration-process-creation-b6457d63</loc>
    <lastmod>2026-07-30T04:44:00.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-unusual-child-process-spawned-by-dns-exe-a4e3d776</loc>
    <lastmod>2026-07-30T04:43:58.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-exfiltration-tool-execution-via-iodine-exe-or-dnscat2-98a96a5a</loc>
    <lastmod>2026-07-30T04:43:57.414Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dllhost-exe-spawn-without-command-line-arguments-e7888eb1</loc>
    <lastmod>2026-07-30T04:43:55.774Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vmware-xfer-utility-dll-sideloading-via-vmwarexferlogs-exe-in-non-defaul-ebea773c</loc>
    <lastmod>2026-07-30T04:43:54.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dism-disable-feature-online-execution-dismhost-dism-exe-43e32da2</loc>
    <lastmod>2026-07-30T04:43:52.445Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-web-access-enabled-via-dism-7e8f2d3b</loc>
    <lastmod>2026-07-30T04:43:50.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-diskshadow-script-mode-s-execution-from-potentially-suspicious-paths-fa1a7e52</loc>
    <lastmod>2026-07-30T04:43:49.164Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-diskshadow-script-mode-execution-with-uncommon-script-extension-1dde5376</loc>
    <lastmod>2026-07-30T04:43:47.049Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-child-processes-spawned-by-diskshadow-exe-9f546b25</loc>
    <lastmod>2026-07-30T04:43:45.481Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-discovery-via-registry-queries-reg-exe-and-powershell-0022869c</loc>
    <lastmod>2026-07-30T04:43:43.145Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dirlister-exe-execution-for-directory-and-file-discovery-b4dc61f5</loc>
    <lastmod>2026-07-30T04:43:41.365Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-from-clickonce-appdata-local-apps-2-0-windows-67bc0e75</loc>
    <lastmod>2026-07-30T04:43:39.911Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-devinit-exe-msi-download-flag-abuse-90d50722</loc>
    <lastmod>2026-07-30T04:43:37.889Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-dll-sideloading-via-deviceenroller-exe-phonedeeplink-parameter-windows-e173ad47</loc>
    <lastmod>2026-07-30T04:43:36.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-devicecredentialdeployment-exe-execution-b8b1b304</loc>
    <lastmod>2026-07-30T04:43:34.521Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-devcon-exe-disables-vmware-vmci-device-via-vmci-driver-identifiers-85f520e7</loc>
    <lastmod>2026-07-30T04:43:33.165Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-desktopimgdownldr-suspicious-download-parameters-and-registry-deletion-bb58aa4a</loc>
    <lastmod>2026-07-30T04:43:31.621Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-desktopimgdownldr-exe-remote-file-download-execution-214641c2</loc>
    <lastmod>2026-07-30T04:43:30.053Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-deletion-of-windows-defender-context-menu-registry-hand-b9e8c7d6</loc>
    <lastmod>2026-07-30T04:43:28.581Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-set-mppreference-low-moderate-high-severethreatdefaultaction--1e8a9b4d</loc>
    <lastmod>2026-07-30T04:43:26.742Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-child-process-spawned-by-defaultpack-exe-b2309017</loc>
    <lastmod>2026-07-30T04:43:24.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-dctask64-exe-by-manageengine-endpoint-central-6345b048</loc>
    <lastmod>2026-07-30T04:43:23.539Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-customshellhost-exe-execution-from-non-explorer-parent-84b14121</loc>
    <lastmod>2026-07-30T04:43:21.890Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-file-uploads-to-file-sharing-domains-e328cc73</loc>
    <lastmod>2026-07-30T04:43:19.819Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-download-to-local-file-with-suspicious-paths-and-extensions-e218595b</loc>
    <lastmod>2026-07-30T04:43:18.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-with-ntlm-and-empty-user-credentials-can-leak-current-user-ntlmv2-r-916eb839</loc>
    <lastmod>2026-07-30T04:43:16.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-curl-exe-reading-local-files-via-file-uri-aa6f6ea6</loc>
    <lastmod>2026-07-30T04:43:12.142Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-insecure-proxy-doh-transfer-using-curl-exe-flags-proxy-insecure-doh-inse-2c1486f5</loc>
    <lastmod>2026-07-30T04:43:10.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-curl-exe-executed-with-insecure-insecure-tls-transfer-cb9cc1d1</loc>
    <lastmod>2026-07-30T04:43:09.232Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-curl-exe-file-downloads-from-file-sharing-domains-56454143</loc>
    <lastmod>2026-07-30T04:43:07.577Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-downloads-file-from-direct-ip-via-http-s-with-suspicious-extens-5cb299fc</loc>
    <lastmod>2026-07-30T04:43:05.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-file-download-from-ip-url-via-command-line-9cc85849</loc>
    <lastmod>2026-07-30T04:43:04.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-web-requests-with-custom-user-agent-headers-85de1f22</loc>
    <lastmod>2026-07-30T04:43:02.659Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-curl-exe-cookie-jar-saving-via-c-cookie-jar-5a6e1e16</loc>
    <lastmod>2026-07-30T04:43:01.032Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-active-directory-export-using-csvde-exe-e5d36acd</loc>
    <lastmod>2026-07-30T04:42:59.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-executing-csharp-interactive-console-csi-exe-on-windows-a9e416a8</loc>
    <lastmod>2026-07-30T04:42:57.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-csi-exe-or-rcsi-exe-execution-on-windows-40b95d31</loc>
    <lastmod>2026-07-30T04:42:56.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-csc-exe-launched-from-suspicious-script-or-powershell-parents-b730a276</loc>
    <lastmod>2026-07-30T04:42:54.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detecting-csc-exe-used-to-compile-net-code-dcaa3f04</loc>
    <lastmod>2026-07-30T04:42:51.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-tampering-of-credential-guard-registry-keys-deviceg-c17d47b7</loc>
    <lastmod>2026-07-30T04:42:49.996Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-createdump-exe-used-to-dump-process-memory-515c8be5</loc>
    <lastmod>2026-07-30T04:42:48.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-creates-delegated-service-account-new-adserviceaccount-in-tar-0ea8db81</loc>
    <lastmod>2026-07-30T04:42:46.387Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-reg-exe-adds-control-panel-cpls-under-currentversion-co-0ba863e6</loc>
    <lastmod>2026-07-30T04:42:44.569Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-conhost-exe-spawned-by-uncommon-parent-process-cbb9e3d1</loc>
    <lastmod>2026-07-30T04:42:42.886Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-conhost-exe-child-processes-dfa03a09</loc>
    <lastmod>2026-07-30T04:42:41.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-conhost-exe-path-traversal-in-command-line-ee5e119b</loc>
    <lastmod>2026-07-30T04:42:37.804Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-conhost-exe-forcev1-with-high-integrity-level-3037d961</loc>
    <lastmod>2026-07-30T04:42:35.842Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-via-headless-conhost-conhost-exe-056c7317</loc>
    <lastmod>2026-07-30T04:42:34.208Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-configsecuritypolicy-exe-arbitrary-file-transfer-via-ur-1f0f6176</loc>
    <lastmod>2026-07-30T04:42:32.270Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/openedr-ssh-shellhost-exe-spawning-cmd-exe-or-powershell-with-pty-on-windows-7f3a9c2d</loc>
    <lastmod>2026-07-30T04:42:30.778Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmstp-process-creation-spawning-child-processes-7d4cdc5a</loc>
    <lastmod>2026-07-30T04:42:29.082Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmdl32-exe-executed-with-vpn-and-lan-flags-f37aba28</loc>
    <lastmod>2026-07-30T04:42:27.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-cmdkey-exe-listing-cached-credentials-l-07f8bdc2</loc>
    <lastmod>2026-07-30T04:42:25.901Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmdkey-exe-adds-generic-credentials-via-command-line-flags-b1ec66c6</loc>
    <lastmod>2026-07-30T04:42:24.148Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-parent-process-for-cmd-exe-execution-4b991083</loc>
    <lastmod>2026-07-30T04:42:22.437Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sticky-keys-backdoor-persistence-via-sethc-exe-replaced-with-cmd-exe-1070db9a</loc>
    <lastmod>2026-07-30T04:42:19.300Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sticky-keys-backdoor-winlogon-launched-scripting-tool-execution-targetin-2fdefcb3</loc>
    <lastmod>2026-07-30T04:42:17.226Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-reads-redirected-input-from-stdin-using-operator-241e802a</loc>
    <lastmod>2026-07-30T04:42:15.001Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rmdir-command-execution-for-directory-removal-41ca393d</loc>
    <lastmod>2026-07-30T04:42:11.692Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-command-line-output-redirection-to-suspicious-user-or-system-pat-8e0bb260</loc>
    <lastmod>2026-07-30T04:42:09.166Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-ping-delay-followed-by-del-file-deletion-54786ddc</loc>
    <lastmod>2026-07-30T04:42:07.359Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-one-liner-combining-ping-and-copy-ded2b07a</loc>
    <lastmod>2026-07-30T04:42:05.784Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspected-path-traversal-in-cmd-exe-command-lines-087790e3</loc>
    <lastmod>2026-07-30T04:42:04.199Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-process-creation-missing-space-around-c-k-r-execution-parameters-a16980c2</loc>
    <lastmod>2026-07-30T04:42:00.706Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-cmd-exe-execution-from-internet-hosted-webdav-via-net-use-f0507c0f</loc>
    <lastmod>2026-07-30T04:41:59.082Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-volume-shadow-copy-symlink-creation-using-mklink-40b19fa6</loc>
    <lastmod>2026-07-30T04:41:57.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mklink-symlink-from-osk-exe-to-cmd-exe-for-login-screen-privilege-escala-e9b61244</loc>
    <lastmod>2026-07-30T04:41:55.744Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-launching-start-exe-with-hidden-window-flags-to-script-or-suspic-5a6b7c8d</loc>
    <lastmod>2026-07-30T04:41:53.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-command-line-with-embedded-url-and-appdata-strings-1ac8666b</loc>
    <lastmod>2026-07-30T04:41:52.246Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-dosfuscation-obfuscation-indicators-a77c1610</loc>
    <lastmod>2026-07-30T04:41:50.728Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-dir-enumeration-using-s-subdirectory-flag-7c9340a9</loc>
    <lastmod>2026-07-30T04:41:49.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-deletion-using-cmd-exe-del-erase-commands-379fa130</loc>
    <lastmod>2026-07-30T04:41:45.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-command-line-download-followed-by-execution-via-and-output-redirect-21dd6d38</loc>
    <lastmod>2026-07-30T04:41:42.696Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-assoc-exe-changing-file-associations-to-exefile-ae6f14e6</loc>
    <lastmod>2026-07-30T04:41:39.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-assoc-command-changing-default-file-associations-3d3aa6cd</loc>
    <lastmod>2026-07-30T04:41:37.621Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-cloudflared-tunnel-execution-with-config-and-token-flag-9a019ffc</loc>
    <lastmod>2026-07-30T04:41:36.210Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cloudflared-tunnel-cleanup-command-line-execution-7050bba1</loc>
    <lastmod>2026-07-30T04:41:34.648Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cloudflared-quick-tunnel-execution-via-cloudflared-exe-url-parameters-222129f7</loc>
    <lastmod>2026-07-30T04:41:32.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-cloudflared-exe-from-non-standard-paths-fadb84f0</loc>
    <lastmod>2026-07-30T04:41:30.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-clip-exe-executed-to-copy-data-to-clipboard-ddeff553</loc>
    <lastmod>2026-07-30T04:41:29.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-trolleyexpress-exe-path-used-to-dump-lsass-memory-4c0aaedc</loc>
    <lastmod>2026-07-30T04:41:27.796Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cipher-exe-overwrite-deleted-data-using-w-4b046706</loc>
    <lastmod>2026-07-30T04:41:25.961Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-chcp-code-page-switch-via-chcp-com-in-command-line-bat-c7942406</loc>
    <lastmod>2026-07-30T04:41:24.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-chcp-console-command-used-for-code-page-locale-lookup-discovery-7090adee</loc>
    <lastmod>2026-07-30T04:41:22.841Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-certificate-export-using-exportpfx-3ffd6f51</loc>
    <lastmod>2026-07-30T04:41:19.571Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-certutil-exe-encode-writing-base64-from-suspicious-dire-82a6714f</loc>
    <lastmod>2026-07-30T04:41:17.939Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-encode-base64-of-suspicious-extensions-ea0cdc3e</loc>
    <lastmod>2026-07-30T04:41:16.212Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-file-encode-to-base64-via-encode-flag-e62a9f0c</loc>
    <lastmod>2026-07-30T04:41:14.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-download-from-file-sharing-sites-using-suspicious-url-urlca-42a5f1e7</loc>
    <lastmod>2026-07-30T04:41:12.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-certutil-exe-download-from-direct-ip-using-urlcache-verifyctl-fl-13e6fe51</loc>
    <lastmod>2026-07-30T04:41:10.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-download-execution-with-url-cache-verify-flags-19b08b1c</loc>
    <lastmod>2026-07-30T04:41:09.216Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-base64-hex-decoding-via-decode-or-decodehex-cc9cbe82</loc>
    <lastmod>2026-07-30T04:41:07.428Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-root-certificate-installation-via-addstore-d2125259</loc>
    <lastmod>2026-07-30T04:41:05.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certreq-exe-certreq-post-download-execution-4480827a</loc>
    <lastmod>2026-07-30T04:41:04.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certoc-exe-loading-dll-from-user-writable-paths-84232095</loc>
    <lastmod>2026-07-30T04:41:02.789Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certoc-exe-loads-dll-via-loaddll-argument-242301bc</loc>
    <lastmod>2026-07-30T04:41:01.112Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certoc-exe-download-via-ip-based-url-getcacaps-b86f6dea</loc>
    <lastmod>2026-07-30T04:40:59.562Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/certoc-exe-file-download-via-getcacaps-http-on-windows-70ad0861</loc>
    <lastmod>2026-07-30T04:40:57.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certmgr-exe-root-certificate-added-via-add-root-ff992eac</loc>
    <lastmod>2026-07-30T04:40:56.343Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cdb-exe-launched-with-debugger-script-flags-to-execute-commands-b5c7395f</loc>
    <lastmod>2026-07-30T04:40:54.750Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-calc-exe-command-line-or-non-system-path-737e618a</loc>
    <lastmod>2026-07-30T04:40:53.189Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-tor-or-tor-browser-process-execution-via-tor-and-tor-browser-binaries-62f7c9bf</loc>
    <lastmod>2026-07-30T04:40:51.647Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-browser-started-with-remote-debugging-flags-b3d34dc5</loc>
    <lastmod>2026-07-30T04:40:50.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-browser-process-file-download-via-inline-url-and-suspicious-extension-94771a71</loc>
    <lastmod>2026-07-30T04:40:48.454Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chromium-based-browser-launched-with-custom-extension-via-load-extens-27ba3207</loc>
    <lastmod>2026-07-30T04:40:46.626Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-chromium-headless-browser-execution-targeting-mockbin-u-1c526788</loc>
    <lastmod>2026-07-30T04:40:44.755Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-chromium-based-browser-launched-with-load-extension-custom-flag-88d6e60c</loc>
    <lastmod>2026-07-30T04:40:42.913Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-headless-chromium-file-download-via-dump-dom-in-browser-brave-chrome-edg-0e8cfe08</loc>
    <lastmod>2026-07-30T04:40:41.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-chromium-browsers-in-headless-mode-ef9dcfed</loc>
    <lastmod>2026-07-30T04:40:39.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-chromium-headless-remote-debugging-with-user-profile-directory-3e8207c5</loc>
    <lastmod>2026-07-30T04:40:37.623Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-bitsadmin-exe-persistence-via-setnotifycmdline-or-addfi-b9cbbc17</loc>
    <lastmod>2026-07-30T04:40:36.022Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-bitsadmin-downloading-to-suspicious-target-folders-2ddef153</loc>
    <lastmod>2026-07-30T04:40:34.360Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-bitsadmin-download-of-files-with-suspicious-extensions-5b80a791</loc>
    <lastmod>2026-07-30T04:40:32.767Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bitsadmin-download-from-file-sharing-domains-using-suspicious-transfer-c-8518ed3d</loc>
    <lastmod>2026-07-30T04:40:31.208Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-bitsadmin-download-using-direct-ip-url-99c840f2</loc>
    <lastmod>2026-07-30T04:40:29.421Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-bitsadmin-exe-file-download-activity-d059842b</loc>
    <lastmod>2026-07-30T04:40:27.837Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-bitlockertogo-exe-execution-7f2376f9</loc>
    <lastmod>2026-07-30T04:40:26.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-child-process-spawned-by-bginfo-exe-on-windows-aaf46cdc</loc>
    <lastmod>2026-07-30T04:40:24.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-processes-spawned-by-bginfo-exe-on-windows-811f459f</loc>
    <lastmod>2026-07-30T04:40:22.833Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-bcp-exe-data-export-from-mssql-c615d676</loc>
    <lastmod>2026-07-30T04:40:21.173Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bcdedit-exe-used-to-delete-boot-configuration-or-enable-special-boot-mod-c9fbe8e9</loc>
    <lastmod>2026-07-30T04:40:19.278Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-boot-configuration-tampering-using-bcdedit-exe-set-1444443e</loc>
    <lastmod>2026-07-30T04:40:17.549Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-bash-exe-script-launcher-execution-without-command-line-flags-windows-2d22a514</loc>
    <lastmod>2026-07-30T04:40:15.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-indirect-execution-of-bash-exe-with-c-flag-5edc2273</loc>
    <lastmod>2026-07-30T04:40:14.049Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-baaupdate-exe-spawns-suspicious-utilities-9f38c1db</loc>
    <lastmod>2026-07-30T04:40:12.459Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-persistence-wmic-used-to-add-run-registry-values-via-reg-exe-c80e66d8</loc>
    <lastmod>2026-07-30T04:40:10.881Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-registry-modification-of-wmi-autologger-sessions-via-re-d7b81144</loc>
    <lastmod>2026-07-30T04:40:08.929Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-audit-policy-tampering-via-auditpol-exe-disable-clear-remove-restore-0a13e132</loc>
    <lastmod>2026-07-30T04:40:07.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-audit-policy-tampering-using-auditpol-from-nt-resource-kit-c6c56ada</loc>
    <lastmod>2026-07-30T04:40:05.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-attrib-exe-s-used-to-mark-executables-scripts-in-common-drop-locations-a-efec536f</loc>
    <lastmod>2026-07-30T04:40:03.960Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-assistive-technology-app-via-atbroker-exe-non-built-in-f24bcaea</loc>
    <lastmod>2026-07-30T04:40:00.297Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-interactive-at-exe-job-execution-60fc936d</loc>
    <lastmod>2026-07-30T04:39:58.625Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-aspnet-compiler-exe-from-suspicious-paths-9f50fe98</loc>
    <lastmod>2026-07-30T04:39:57.201Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-aspnet-compiler-exe-9ccba514</loc>
    <lastmod>2026-07-30T04:39:55.681Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-aspnet-compiler-exe-execution-via-net-framework-paths-a01b8329</loc>
    <lastmod>2026-07-30T04:39:53.981Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/arcsoc-exe-spawns-script-and-command-interpreters-windows-process-creation-8e95e73e</loc>
    <lastmod>2026-07-30T04:39:52.202Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detect-uncommon-child-processes-spawned-by-appvlp-exe-on-windows-9c7e131a</loc>
    <lastmod>2026-07-30T04:39:50.593Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-amsi-registry-tampering-via-reg-exe-or-powershell-comma-7dbbcac2</loc>
    <lastmod>2026-07-30T04:39:48.441Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-agentexecutor-exe-powershell-launch-with-executionpolic-c0b40568</loc>
    <lastmod>2026-07-30T04:39:46.197Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-agentexecutor-exe-with-powershell-bypass-7efd2c8d</loc>
    <lastmod>2026-07-30T04:39:44.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-execution-of-adplus-exe-with-memory-dump-and-inline-command-switc-2f869d59</loc>
    <lastmod>2026-07-30T04:39:42.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-addinutil-exe-execution-from-non-standard-directory-6120ac2a</loc>
    <lastmod>2026-07-30T04:39:40.102Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-addinutil-exe-with-uncommon-addinroot-pipelineroot-pat-4f2cd9b6</loc>
    <lastmod>2026-07-30T04:39:38.490Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-child-processes-spawned-by-addinutil-exe-b5746143</loc>
    <lastmod>2026-07-30T04:39:36.752Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-addinutil-exe-with-suspicious-addinroot-pipelineroot-pa-631b22a4</loc>
    <lastmod>2026-07-30T04:39:35.246Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-acccheckconsole-execution-with-injection-capable-command-line-parameters-0f6da907</loc>
    <lastmod>2026-07-30T04:39:33.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-7-zip-used-to-compress-and-password-protect-data-9fbf5927</loc>
    <lastmod>2026-07-30T04:39:31.827Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-7-zip-compressing-dmp-dump-files-ec570e53</loc>
    <lastmod>2026-07-30T04:39:30.055Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-werfaultsecure-to-msmpeng-exe-with-dbgcore-dll-dbghelp-dl-387df17d</loc>
    <lastmod>2026-07-30T04:39:27.868Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-wow64-logger-dll-hijack-uacme-30-pattern-4f6c43e2</loc>
    <lastmod>2026-07-30T04:39:26.201Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-function-calls-involving-editionupgrademanager-com-interf-fb3722e4</loc>
    <lastmod>2026-07-30T04:39:24.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-svchost-exe-process-access-with-unknown-calltrace-166e9c50</loc>
    <lastmod>2026-07-30T04:39:22.934Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-to-svchost-exe-for-credential-dumping-attempts-174afcfa</loc>
    <lastmod>2026-07-30T04:39:21.259Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-to-lsass-with-dbgcore-dll-dbghelp-dll-in-calltrace-9f5c1d59</loc>
    <lastmod>2026-07-30T04:39:18.005Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-process-all-access-granted-to-uncommon-target-image-a24e5861</loc>
    <lastmod>2026-07-30T04:39:10.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-memory-access-from-specific-process-images-4be8b654</loc>
    <lastmod>2026-07-30T04:39:08.389Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-werfault-triggered-lsass-access-for-credential-dumping-e5b33f7d</loc>
    <lastmod>2026-07-30T04:39:06.546Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-to-lsass-with-suspicious-grantedaccess-flags-a18dd26b</loc>
    <lastmod>2026-07-30T04:39:04.773Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-handle-access-from-svchost-exe-via-seclogon-dll-windows-process-472159c5</loc>
    <lastmod>2026-07-30T04:39:02.892Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrm-wsmprovhost-accessing-lsass-process-lsass-exe-remotely-aa35a627</loc>
    <lastmod>2026-07-30T04:39:01.071Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-process-access-by-python-based-tool-f8be3e82</loc>
    <lastmod>2026-07-30T04:38:59.413Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-memory-access-triggered-by-process-name-containing-dump-9bd012ee</loc>
    <lastmod>2026-07-30T04:38:56.239Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-rundll32-comsvcs-dll-minidump-to-dump-lsass-exe-a49fa4d5</loc>
    <lastmod>2026-07-30T04:38:54.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-integrity-attack-tool-execution-sysmonente-via-sysmon-process-acc-d29ada0f</loc>
    <lastmod>2026-07-30T04:38:52.050Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-injection-triggered-by-winword-exe-from-littlecorporal-maldoc-7bdde3bf</loc>
    <lastmod>2026-07-30T04:38:50.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-handlekatz-usage-duplicate-lsass-handle-via-process-dup-handle-b1bd3a59</loc>
    <lastmod>2026-07-30T04:38:48.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-process-access-alerts-via-suspicious-source-image-names-d0d2f720</loc>
    <lastmod>2026-07-30T04:38:46.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-injection-via-cobaltstrike-bof-call-stack-and-high-access-grants-09706624</loc>
    <lastmod>2026-07-30T04:38:44.727Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-involving-cmlua-dll-during-cmstp-execution-3b4b232a</loc>
    <lastmod>2026-07-30T04:38:42.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-abuse-via-system-xml-xmldocument-load-6c6c6282</loc>
    <lastmod>2026-07-30T04:38:41.107Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-powershell-x509enrollment-cbinaryconverter-usage-504d63cb</loc>
    <lastmod>2026-07-30T04:38:39.402Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-parameters-matching-wmimplant-behavior-8028c2c3</loc>
    <lastmod>2026-07-30T04:38:37.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-wmi-service-enumeration-for-unquoted-service-path-recon-09658312</loc>
    <lastmod>2026-07-30T04:38:36.400Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-wmi-event-subscription-persistence-via-new-ciminstance-in-scriptblock-9e07f6e7</loc>
    <lastmod>2026-07-30T04:38:34.678Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-block-monitoring-for-winlogon-registry-helper-modification-on--851c506b</loc>
    <lastmod>2026-07-30T04:38:32.964Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-windows-firewall-profile-disabled-via-set-netfirewallprofile-488b44e7</loc>
    <lastmod>2026-07-30T04:38:30.789Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-exclusions-added-via-powershell-script-block-logging-c1344fa2</loc>
    <lastmod>2026-07-30T04:38:29.227Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-matching-of-suspicious-winapi-call-patterns-03d83090</loc>
    <lastmod>2026-07-30T04:38:27.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-wmi-win32-product-msi-installation-via-invoke-cimmethod-91109523</loc>
    <lastmod>2026-07-30T04:38:26.006Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-suspicious-wmi-win32-nteventlogfile-usage-in-script-e2812b49</loc>
    <lastmod>2026-07-30T04:38:24.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-web-request-commands-and-cmdlets-1139d2e2</loc>
    <lastmod>2026-07-30T04:38:22.519Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-credential-dumping-via-veeam-backup-common-protectedstorage-976d6e6f</loc>
    <lastmod>2026-07-30T04:38:21.029Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-vbscript-registry-modification-attempt-via-wscript-shell-regwrite-2a0a169d</loc>
    <lastmod>2026-07-30T04:38:19.257Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-set-service-sddl-securitydescriptor-to-hide-services-953945c5</loc>
    <lastmod>2026-07-30T04:38:17.524Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-persistence-add-content-to-modify-profile-for-startup-executi-05b3e303</loc>
    <lastmod>2026-07-30T04:38:15.837Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-user-discovery-and-export-via-get-aduser-cmdlet-c2993223</loc>
    <lastmod>2026-07-30T04:38:14.193Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-timestomp-via-file-timestamp-modification-c6438007</loc>
    <lastmod>2026-07-30T04:38:12.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-testing-for-uncommon-network-ports-via-test-netconnection-adf876b3</loc>
    <lastmod>2026-07-30T04:38:10.882Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblocklogging-disable-lower-windows-defender-monitoring-via-set--14c71865</loc>
    <lastmod>2026-07-30T04:38:09.222Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-logging-remove-mppreference-tampering-for-defende-ae2bdd58</loc>
    <lastmod>2026-07-30T04:38:07.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-logging-syncappvpublishingserver-exe-execution-dddfebae</loc>
    <lastmod>2026-07-30T04:38:05.720Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-compress-archive-temp-staging-b7a3c9a3</loc>
    <lastmod>2026-07-30T04:38:04.070Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-write-eventlog-with-rawdata-flag-35f41cd7</loc>
    <lastmod>2026-07-30T04:38:02.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-suspicious-windowstyle-hidden-usage-in-script-block-text-313fbb0a</loc>
    <lastmod>2026-07-30T04:38:01.108Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-wmi-script-deletion-of-windows-volume-shadow-copies-c1337eb8</loc>
    <lastmod>2026-07-30T04:37:59.504Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-suspicious-win32-pnpentity-wmi-query-on-windows-b26647de</loc>
    <lastmod>2026-07-30T04:37:57.665Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-wallpaper-replacement-via-control-panel-desktop-registry-upda-c5ac6a1e</loc>
    <lastmod>2026-07-30T04:37:55.957Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-unblock-file-attempts-to-remove-zone-identifier-ads-5947497f</loc>
    <lastmod>2026-07-30T04:37:54.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-start-process-with-passthru-and-filepath-in-scriptblock-logging-windo-0718cd72</loc>
    <lastmod>2026-07-30T04:37:52.431Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-uses-sslstream-with-client-authentication-and-cert-val-195626f3</loc>
    <lastmod>2026-07-30T04:37:50.580Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-containing-get-smbshare-95f0643a</loc>
    <lastmod>2026-07-30T04:37:48.996Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-alias-cmdlets-set-alias-new-alias-in-script-block-logging-96cd126d</loc>
    <lastmod>2026-07-30T04:37:47.362Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-suspicious-set-service-sddl-to-hide-windows-services-from-enumeration-22d80745</loc>
    <lastmod>2026-07-30T04:37:39.979Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-remove-adgroupmember-removing-account-from-domain-admin-group-48a45d45</loc>
    <lastmod>2026-07-30T04:37:38.217Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-recon-via-script-blocks-service-processes-and-temp-directory-access-a9723fcc</loc>
    <lastmod>2026-07-30T04:37:36.504Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-tcp-tunnel-indicators-on-windows-via-net-socket-apis-bd33d2aa</loc>
    <lastmod>2026-07-30T04:37:34.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-suspicious-ldap-credential-handling-for-remote-access-1883444f</loc>
    <lastmod>2026-07-30T04:37:30.660Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-removal-of-mounted-smb-fileshares-via-remove-smbshare-or-remove-files-66a4d409</loc>
    <lastmod>2026-07-30T04:37:29.049Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-mount-diskimage-using-imagepath-parameter-windows-29e1c216</loc>
    <lastmod>2026-07-30T04:37:27.305Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-local-email-collection-via-outlook-com-automation-on-windows-2837e152</loc>
    <lastmod>2026-07-30T04:37:25.567Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-suspicious-local-group-discovery-via-get-localgroup-and-get-localgrou-fa6a5a45</loc>
    <lastmod>2026-07-30T04:37:24.050Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-keyword-matches-for-suspicious-reflection-and-in-1f49f2ab</loc>
    <lastmod>2026-07-30T04:37:22.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-keylogger-indicators-via-keyboard-state-references-windows-965e2db9</loc>
    <lastmod>2026-07-30T04:37:20.752Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-webrequest-user-agent-modification-d4488827</loc>
    <lastmod>2026-07-30T04:37:17.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-scriptblock-parameters-for-encoded-hidden-and-execution-of-ae7fbf8e</loc>
    <lastmod>2026-07-30T04:37:15.760Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-scriptblock-parameters-enc-hidden-window-and-noninteractiv-ed965133</loc>
    <lastmod>2026-07-30T04:37:14.036Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hyper-v-powershell-cmdlets-usage-on-windows-42d36aa1</loc>
    <lastmod>2026-07-30T04:37:12.298Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-gettypefromclsid-shellexecute-usage-8bc063d5</loc>
    <lastmod>2026-07-30T04:37:10.805Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-get-process-targeting-lsass-84c174ab</loc>
    <lastmod>2026-07-30T04:37:09.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-logs-get-process-process-discovery-af4c87ce</loc>
    <lastmod>2026-07-30T04:37:07.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-suspicious-gpo-enumeration-via-get-gpo-eb2fd349</loc>
    <lastmod>2026-07-30T04:37:06.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-user-discovery-via-getcurrent-user-and-environment-variables-4096a49c</loc>
    <lastmod>2026-07-30T04:37:04.448Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-ad-password-policy-discovery-via-get-addefaultdomainpasswordpolicy-bbb9495b</loc>
    <lastmod>2026-07-30T04:37:02.788Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-of-troubleshootingpack-cmdlet-for-unattended-troubl-03409c93</loc>
    <lastmod>2026-07-30T04:37:01.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-block-information-discovery-via-recursive-listing-and-credenti-bd5971a7</loc>
    <lastmod>2026-07-30T04:36:58.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-starts-processes-using-batch-script-bat-cmd-on-windows-b5522a23</loc>
    <lastmod>2026-07-30T04:36:57.037Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-downloads-via-system-net-webclient-403c2cc0</loc>
    <lastmod>2026-07-30T04:36:55.420Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-directory-enumeration-via-get-childitem-script-block-162e69a7</loc>
    <lastmod>2026-07-30T04:36:53.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-attempts-to-clear-windows-event-logs-via-clear-eventlog-and-related-c-0f017df3</loc>
    <lastmod>2026-07-30T04:36:52.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-alias-obfuscation-via-value-join-in-script-blocks-e8314f79</loc>
    <lastmod>2026-07-30T04:36:50.681Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-enumeration-of-ad-group-membership-and-users-88f0884b</loc>
    <lastmod>2026-07-30T04:36:49.128Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-security-descriptor-manipulation-for-potential-pe-2f77047c</loc>
    <lastmod>2026-07-30T04:36:47.276Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-stores-command-output-in-alternate-data-streams-via-start-pro-a699b30e</loc>
    <lastmod>2026-07-30T04:36:43.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-software-discovery-via-get-itemproperty-and-display-formattin-2650dd1a</loc>
    <lastmod>2026-07-30T04:36:41.372Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-shellintel-commandlet-abuse-via-script-block-logging-402e1e1d</loc>
    <lastmod>2026-07-30T04:36:39.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-base64-encoded-shellcode-in-script-block-text-16b37b70</loc>
    <lastmod>2026-07-30T04:36:37.604Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-set-executionpolicy-changed-to-unrestricted-or-bypass-61d0475c</loc>
    <lastmod>2026-07-30T04:36:36.014Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-sets-file-folder-acl-using-set-acl-cae80281</loc>
    <lastmod>2026-07-30T04:36:32.047Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-sensitive-file-discovery-via-script-block-enumeration-7d416556</loc>
    <lastmod>2026-07-30T04:36:30.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-uses-invoke-webrequest-with-post-or-put-to-upload-data-d2e3f2f6</loc>
    <lastmod>2026-07-30T04:36:29.054Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invoke-item-after-mount-diskimage-from-mounted-drive-lette-902cedee</loc>
    <lastmod>2026-07-30T04:36:27.145Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-root-certificate-installation-via-cert-localmachine-root-42821614</loc>
    <lastmod>2026-07-30T04:36:19.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-reads-files-and-resolves-dns-host-entries-fbc5e92f</loc>
    <lastmod>2026-07-30T04:36:18.376Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-kerberos-ticket-requests-via-system-identitymodel-tokens--a861d835</loc>
    <lastmod>2026-07-30T04:36:16.570Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-module-content-sets-get-vmremotefxphysicalvideoadapter-fu-cacef8fc</loc>
    <lastmod>2026-07-30T04:36:14.900Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-new-pssession-remote-session-creation-a0edd39f</loc>
    <lastmod>2026-07-30T04:36:13.253Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-contains-ps-attack-b7ec41a4</loc>
    <lastmod>2026-07-30T04:36:11.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-psasyncshell-asynchronous-tcp-reverse-shell-afd3df04</loc>
    <lastmod>2026-07-30T04:36:09.706Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-credential-prompt-usage-script-block-logging-ca8b77a9</loc>
    <lastmod>2026-07-30T04:36:08.191Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-logging-powerview-powersploit-cmdlet-enumeration-dcd74b95</loc>
    <lastmod>2026-07-30T04:36:06.595Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-installs-and-configures-powershell-web-access-pswa-5f9c7f1a</loc>
    <lastmod>2026-07-30T04:36:04.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-unconstrained-delegation-discovery-via-get-adcomputer-script-block-cdfa73b6</loc>
    <lastmod>2026-07-30T04:36:03.159Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-matching-mimikatz-credential-certificate-dump-str-189e3b02</loc>
    <lastmod>2026-07-30T04:36:01.440Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-start-neteventsession-packet-event-capture-activity-windo-da34e323</loc>
    <lastmod>2026-07-30T04:35:59.727Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-invokes-office-registerxll-via-com-automation-36fbec91</loc>
    <lastmod>2026-07-30T04:35:58.286Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-writes-to-ntfs-alternate-data-streams-via-stream-with-set-add-content-8c521530</loc>
    <lastmod>2026-07-30T04:35:56.455Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-indicators-for-nishang-commandlets-and-arguments-f772cee9</loc>
    <lastmod>2026-07-30T04:35:54.938Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-msxml2-xmlhttp-via-com-object-creation-78aa1347</loc>
    <lastmod>2026-07-30T04:35:53.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-detect-scriptblock-text-modifying-group-policy-settings-b7216a7d</loc>
    <lastmod>2026-07-30T04:35:51.446Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-modify-dmsa-link-attribute-msds-managedaccountprecededbylink-in-ad-9b111d8e</loc>
    <lastmod>2026-07-30T04:35:49.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-live-memory-dump-via-get-storagediagnosticinfo-with-includelivedump-w-cd185561</loc>
    <lastmod>2026-07-30T04:35:47.483Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-alerts-for-common-credential-theft-and-memory-in-f62176f3</loc>
    <lastmod>2026-07-30T04:35:45.874Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-detection-of-known-malicious-commandlet-names-89819aa4</loc>
    <lastmod>2026-07-30T04:35:44.209Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-local-user-account-manipulation-via-scriptblock-logging-on-windows-4fdc44df</loc>
    <lastmod>2026-07-30T04:35:40.797Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-keylogging-via-get-keystrokes-and-getasynckeystate-on-windows-34f90d3c</loc>
    <lastmod>2026-07-30T04:35:39.271Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-var-launcher-obfuscation-via-scriptblocktext-set-with-encoded-formatt-e54f5149</loc>
    <lastmod>2026-07-30T04:35:37.459Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-obfuscation-using-rundll32-and-shell32-dll-via-script-block-logging-a5a30a6e</loc>
    <lastmod>2026-07-30T04:35:35.768Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-obfuscation-via-mshta-and-vbscript-url-execution-e55a5195</loc>
    <lastmod>2026-07-30T04:35:34.101Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-obfuscation-via-clip-exe-and-clipboard-data-execution-db92dd33</loc>
    <lastmod>2026-07-30T04:35:32.357Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-obfuscation-through-stdin-via-scriptblocktext-86b896ba</loc>
    <lastmod>2026-07-30T04:35:30.743Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/obfuscated-powershell-execution-via-rundll32-launcher-windows-powershell-script-e6cb92b4</loc>
    <lastmod>2026-07-30T04:35:29.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-obfuscation-using-compress-compression-streams-20e5497e</loc>
    <lastmod>2026-07-30T04:35:27.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-var-obfuscation-via-cmd-c-or-r-and-set-with-expansion-0adfbc14</loc>
    <lastmod>2026-07-30T04:35:25.623Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-block-obfuscation-via-stdin-execution-patterns-779c8c12</loc>
    <lastmod>2026-07-30T04:35:24.025Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-iex-obfuscated-invocation-indicators-from-invoke-obfuscation-patterns-1b9dc62e</loc>
    <lastmod>2026-07-30T04:35:22.348Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-obfuscated-clip-exe-launcher-via-command-clipboard-execution-73e67340</loc>
    <lastmod>2026-07-30T04:35:20.711Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-dnsexfiltrator-via-invoke-dnsexfiltrator-with-doh-exfil-parameters-d59d7842</loc>
    <lastmod>2026-07-30T04:35:19.108Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-invoke-command-for-remote-host-execution-via-script-block-log-7b836d7f</loc>
    <lastmod>2026-07-30T04:35:17.195Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-psscript-attempts-to-install-unsigned-appx-via-add-appxpackage-add-ap-975b2262</loc>
    <lastmod>2026-07-30T04:35:15.731Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-imports-modules-from-temp-or-public-paths-21f9162c</loc>
    <lastmod>2026-07-30T04:35:13.120Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-icmp-exfiltration-via-ping-send-4c4af3cd</loc>
    <lastmod>2026-07-30T04:35:11.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-hotfix-enumeration-via-win32-quickfixengineering-f5d1def8</loc>
    <lastmod>2026-07-30T04:35:09.808Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-keyword-matches-for-winpwn-tool-execution-851fd622</loc>
    <lastmod>2026-07-30T04:35:07.321Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-rubeus-hacktool-execution-flags-3245cd30</loc>
    <lastmod>2026-07-30T04:35:05.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-security-software-discovery-via-get-process-piped-to-where-object-on--904e8e61</loc>
    <lastmod>2026-07-30T04:35:04.055Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-block-get-childitem-recursive-bookmark-collection-from-browser-e0565f5d</loc>
    <lastmod>2026-07-30T04:35:02.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-suspicious-get-adreplaccount-enumeration-with-all-and-server--060c3ef1</loc>
    <lastmod>2026-07-30T04:35:00.580Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-ad-group-enumeration-via-get-adgroup-cmdlet-8c3a6607</loc>
    <lastmod>2026-07-30T04:34:57.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-ad-computer-enumeration-via-get-adcomputer-36bed6b2</loc>
    <lastmod>2026-07-30T04:34:55.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-block-monitoring-for-service-registry-permission-weakness-chec-95afc12e</loc>
    <lastmod>2026-07-30T04:34:53.986Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-frombase64string-decoding-of-gzip-archive-in-script-block-df69cb1d</loc>
    <lastmod>2026-07-30T04:34:52.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-certificate-export-via-export-pfxcertificate-or-export-ce-aa7a3fce</loc>
    <lastmod>2026-07-30T04:34:50.701Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-disables-or-removes-etw-trace-providers-via-etw-cmdlets-115fdba9</loc>
    <lastmod>2026-07-30T04:34:49.032Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-enumerates-stored-windows-credential-manager-entries-via-vaultcmd-lis-603c6630</loc>
    <lastmod>2026-07-30T04:34:47.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-enable-windowsoptionalfeature-online-with-potentially-risky-featurena-55c925c1</loc>
    <lastmod>2026-07-30T04:34:45.445Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-enable-psremoting-command-execution-991a9744</loc>
    <lastmod>2026-07-30T04:34:42.681Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-credential-manager-credential-dumping-via-get-passwordvaultcredential-99c49d9c</loc>
    <lastmod>2026-07-30T04:34:41.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-alerts-for-dsinternals-module-cmdlet-usage-846c7a87</loc>
    <lastmod>2026-07-30T04:34:39.514Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-com-clsid-download-cradles-suspicious-gettypefromclsid-usage-3c7d1587</loc>
    <lastmod>2026-07-30T04:34:32.415Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-in-memory-assembly-loading-via-reflection-assembly-load-ddcd88cb</loc>
    <lastmod>2026-07-30T04:34:30.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-disable-windowsoptionalfeature-online-featurename-targeting-windows-d-99c4658d</loc>
    <lastmod>2026-07-30T04:34:28.657Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-removing-psreadline-via-remove-module-to-disable-comma-602f5669</loc>
    <lastmod>2026-07-30T04:34:27.165Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-ad-account-management-net-usage-for-group-computer-principal--b29a93fb</loc>
    <lastmod>2026-07-30T04:34:25.747Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-directorysearcher-active-directory-enumeration-via-directoryservices-1f6399cf</loc>
    <lastmod>2026-07-30T04:34:23.798Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-virtualization-environment-discovery-via-wmi-and-win32-acpi-queries-d93129cd</loc>
    <lastmod>2026-07-30T04:34:22.108Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-creates-volume-shadow-copy-via-win32-shadowcopy-class-afd12fed</loc>
    <lastmod>2026-07-30T04:34:20.568Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-new-adserviceaccount-creating-delegated-service-accounts-in-specific--02122374</loc>
    <lastmod>2026-07-30T04:34:19.069Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-local-account-creation-via-new-localuser-243de76f</loc>
    <lastmod>2026-07-30T04:34:17.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-registry-free-cor-profiler-environment-variable--23590215</loc>
    <lastmod>2026-07-30T04:34:15.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-copies-or-installs-dlls-into-windows-system32-or-syswow64-63bf8794</loc>
    <lastmod>2026-07-30T04:34:12.634Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-computer-discovery-and-export-using-get-adcomputer-db885529</loc>
    <lastmod>2026-07-30T04:34:10.998Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scheduled-task-creation-via-scheduledtasks-cmdlets-and-cim-wmi-calls--363eccc0</loc>
    <lastmod>2026-07-30T04:34:09.133Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-clears-console-history-via-clear-history-or-psreadline-history-path-d-bde47d4b</loc>
    <lastmod>2026-07-30T04:34:07.302Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-screen-capture-via-copyfromscreen-d4a11f63</loc>
    <lastmod>2026-07-30T04:34:04.086Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-automated-file-collection-using-get-childitem-with-recursive-include--c1dda054</loc>
    <lastmod>2026-07-30T04:34:02.086Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-data-exfiltration-via-audio-file-using-powershell-script-block-e4f93c99</loc>
    <lastmod>2026-07-30T04:34:00.368Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-get-aduser-enumeration-via-useraccountcontrol-dont-req-preaut-96c982fe</loc>
    <lastmod>2026-07-30T04:33:58.890Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-detect-silence-empire-eda-execution-and-dns-tunneling-script--3ceb2083</loc>
    <lastmod>2026-07-30T04:33:56.942Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-amsi-bypass-pattern-ref-assembly-gettype-and-setvalue-null-tr-e0d6c087</loc>
    <lastmod>2026-07-30T04:33:52.755Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-of-adrecon-ps1-for-active-directory-reconnaissance-bf72941a</loc>
    <lastmod>2026-07-30T04:33:51.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-capability-installation-via-powershell-add-windowscapability-script-bloc-155c7fd5</loc>
    <lastmod>2026-07-30T04:33:49.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-add-dnsclientnrptrule-changes-nrpt-namespace-4368354e</loc>
    <lastmod>2026-07-30T04:33:47.676Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-import-module-of-microsoft-activedirectory-management-dll-for-9e620995</loc>
    <lastmod>2026-07-30T04:33:43.049Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-access-to-browser-credential-database-files-fc028194</loc>
    <lastmod>2026-07-30T04:33:41.446Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-block-logging-aadinternals-cmdlets-add-aadint-invoke-a-91e69562</loc>
    <lastmod>2026-07-30T04:33:40.050Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-module-syncappvpublishingserver-exe-command-line-usage-fe5ce7eb</loc>
    <lastmod>2026-07-30T04:33:38.401Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-compress-archive-staging-in-windows-temp-or-appdata-local-temp-daf7eb81</loc>
    <lastmod>2026-07-30T04:33:36.720Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-module-get-smbshare-used-for-smb-share-enumeration-6942bd25</loc>
    <lastmod>2026-07-30T04:33:35.042Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-reset-computermachinepassword-computer-account-password-chang-e3818659</loc>
    <lastmod>2026-07-30T04:33:33.514Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-discovery-of-local-groups-via-get-localgroup-and-get-localgroupmember-cef24b90</loc>
    <lastmod>2026-07-30T04:33:31.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-module-execution-parameters-for-encoded-hidden-code-8ff28fdd</loc>
    <lastmod>2026-07-30T04:33:29.788Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-module-arguments-encoded-hidden-window-or-noninteractive-bbb80e91</loc>
    <lastmod>2026-07-30T04:33:27.907Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-get-nettcpconnection-module-use-for-network-connection-discovery-wind-aff815cc</loc>
    <lastmod>2026-07-30T04:33:26.245Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-module-activity-suspicious-system-net-webclient-downloadfile--de41232e</loc>
    <lastmod>2026-07-30T04:33:24.822Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-ad-enumeration-via-poshmodule-get-adprincipalgroupmembership-and-get--815bfc17</loc>
    <lastmod>2026-07-30T04:33:22.634Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-module-creation-with-remotefxphysicalvideoadapter-functioncon-38a7625e</loc>
    <lastmod>2026-07-30T04:33:20.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-remote-session-module-context-indicator-wsmprovhost-exe-96b9f619</loc>
    <lastmod>2026-07-30T04:33:19.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-match-known-malicious-poshmodule-cmdlets-and-framework-functi-7d0d0329</loc>
    <lastmod>2026-07-30T04:33:17.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-module-obfuscated-invocation-var-launcher-pattern-f3c89218</loc>
    <lastmod>2026-07-30T04:33:16.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-module-obfuscated-invoke-using-rundll32-and-shell32-dll-88a22f69</loc>
    <lastmod>2026-07-30T04:33:14.331Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-module-obfuscated-script-invocation-using-mshta-07ad2ea8</loc>
    <lastmod>2026-07-30T04:33:12.548Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-module-abuse-with-clip-exe-via-obfuscated-use-of-clipboard-payload-ebdf49d8</loc>
    <lastmod>2026-07-30T04:33:10.988Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-module-obfuscated-stdin-invoke-via-chained-set-and-invoke-expressions-c72aca44</loc>
    <lastmod>2026-07-30T04:33:09.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-module-logging-rundll32-shell32-obfuscation-with-powershell-a23791fe</loc>
    <lastmod>2026-07-30T04:33:07.526Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-module-payload-with-compress-obfuscation-and-ascii-encoding-7034cbbb</loc>
    <lastmod>2026-07-30T04:33:05.890Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-module-obfuscated-cmd-set-environment-variable-launcher-behav-6bfb8fa7</loc>
    <lastmod>2026-07-30T04:33:04.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-module-obfuscated-stdin-based-launcher-execution-9ac8b09b</loc>
    <lastmod>2026-07-30T04:33:02.715Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-module-obfuscated-invoke-expression-iex-payloads-from-invoke-obfuscat-2f211361</loc>
    <lastmod>2026-07-30T04:33:01.051Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-module-clip-launcher-obfuscation-via-cmd-clip-clipboard-and-system-st-a136cde0</loc>
    <lastmod>2026-07-30T04:32:59.440Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-get-clipboard-module-command-execution-4cbd4f12</loc>
    <lastmod>2026-07-30T04:32:56.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-suspicious-get-addbaccount-reads-ntds-dit-via-bootkey-b140afd9</loc>
    <lastmod>2026-07-30T04:32:54.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-module-execution-matching-known-offensive-script-names-poshmo-41025fd7</loc>
    <lastmod>2026-07-30T04:32:53.077Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-decompress-via-expand-archive-command-1ddc1472</loc>
    <lastmod>2026-07-30T04:32:51.295Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-artifacts-containing-common-offensive-string-markers-8d31a8ce</loc>
    <lastmod>2026-07-30T04:32:47.970Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-active-directory-module-load-via-import-module-74176142</loc>
    <lastmod>2026-07-30T04:32:29.503Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-classic-logs-suspicious-wsman-com-provider-use-without-powers-df9a0e0e</loc>
    <lastmod>2026-07-30T04:32:27.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-tampering-with-windows-defender-via-set-mppreference-allow-options-ec19ebab</loc>
    <lastmod>2026-07-30T04:32:25.908Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-classic-compress-archive-in-temp-staging-directories-71ff406e</loc>
    <lastmod>2026-07-30T04:32:23.951Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-get-nettcpconnection-invocation-for-network-connection-discov-b366adb4</loc>
    <lastmod>2026-07-30T04:32:22.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-classic-modulecontents-based-remotefxvgpudisablement-exe-load-order-h-f65e22f9</loc>
    <lastmod>2026-07-30T04:32:19.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-powershell-session-start-via-wsmprovhost-exe-ps-classic-60167e5c</loc>
    <lastmod>2026-07-30T04:32:17.396Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-command-start-with-powercat-invocation-c5b20776</loc>
    <lastmod>2026-07-30T04:32:15.820Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-launch-triggered-via-executable-version-mismatch-c70e019b</loc>
    <lastmod>2026-07-30T04:32:14.172Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-classic-net-webclient-download-via-downloadfile-downloadstring-3236fcd0</loc>
    <lastmod>2026-07-30T04:32:12.503Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-downgrade-indicators-on-windows-via-engineversion-and-hostversion-6331d09b</loc>
    <lastmod>2026-07-30T04:32:10.709Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-shadow-copy-deletion-via-powershell-get-wmiobject-win32-shadowcopy-87df9ee1</loc>
    <lastmod>2026-07-30T04:32:09.172Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-download-cradle-using-nslookup-and-txt-http-queries-on-windows-999bff6d</loc>
    <lastmod>2026-07-30T04:32:07.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexec-named-pipe-creation-from-suspicious-image-locations-pipename-psex-41504465</loc>
    <lastmod>2026-07-30T04:32:05.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-by-known-malware-pipe-names-fe3ac066</loc>
    <lastmod>2026-07-30T04:32:04.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-event-consumer-scrcons-exe-created-named-pipe-493fb4ab</loc>
    <lastmod>2026-07-30T04:32:02.743Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-remcom-named-pipe-creation-via-remcom-d36f87ea</loc>
    <lastmod>2026-07-30T04:32:01.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-paexec-default-named-pipe-creation-via-sysmon-f6451de4</loc>
    <lastmod>2026-07-30T04:31:59.139Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-csexec-default-csexecsvc-pipe-f318b911</loc>
    <lastmod>2026-07-30T04:31:57.337Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-created-for-powershell-host-pshost-ac7102b4</loc>
    <lastmod>2026-07-30T04:31:55.563Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipes-detect-alternate-powershell-host-pipe-creation-58cb02d5</loc>
    <lastmod>2026-07-30T04:31:53.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-koh-default-named-pipe-creation-by-pipe-name-0adc67e0</loc>
    <lastmod>2026-07-30T04:31:44.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-indicating-credential-dumping-tools-961d0ba2</loc>
    <lastmod>2026-07-30T04:31:43.277Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-with-pipe-and-pipe-srvsvc-pattern-efspotato-637f689e</loc>
    <lastmod>2026-07-30T04:31:41.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-detect-default-diagtrackeop-poc-pipe-name-1f7025a6</loc>
    <lastmod>2026-07-30T04:31:34.066Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-with-coercedpotato-pipe-name-pattern-4d0083b3</loc>
    <lastmod>2026-07-30T04:31:32.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-matching-cobalt-strike-malleable-c2-pipename-pattern-85adeb13</loc>
    <lastmod>2026-07-30T04:31:30.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-matching-cobalt-strike-malleable-c2-pipe-patterns-0e7163d4</loc>
    <lastmod>2026-07-30T04:31:29.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-matching-cobalt-strike-default-pipe-prefixes-d5601f8c</loc>
    <lastmod>2026-07-30T04:31:27.355Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-to-ad-fs-wid-sql-query-path-by-uncommon-process-1ea13e8c</loc>
    <lastmod>2026-07-30T04:31:25.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-script-interpreter-initiates-outbound-network-connections-to-non-local-i-992a6cae</loc>
    <lastmod>2026-07-30T04:31:22.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wscript-cscript-script-interpreter-initiated-local-network-connection-08249dc0</loc>
    <lastmod>2026-07-30T04:31:20.774Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wordpad-exe-makes-outbound-network-connections-to-uncommon-ports-786cdae8</loc>
    <lastmod>2026-07-30T04:31:18.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winlogon-exe-initiating-outbound-connections-to-public-ips-7610a4ea</loc>
    <lastmod>2026-07-30T04:31:17.427Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-outbound-smtp-connections-on-ports-25-465-587-2525-9976fa64</loc>
    <lastmod>2026-07-30T04:31:14.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-sync-center-mobsync-exe-network-connections-to-non-private-ips-9f2cc74d</loc>
    <lastmod>2026-07-30T04:31:12.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-outbound-kerberos-tcp-88-connection-on-windows-e54979bd</loc>
    <lastmod>2026-07-30T04:31:10.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-uncommon-destination-ports-8080-8888-6d8c3d20</loc>
    <lastmod>2026-07-30T04:31:09.231Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-known-malware-callback-ports-4b89abaa</loc>
    <lastmod>2026-07-30T04:31:07.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-from-processes-in-suspicious-or-uncommon-file-system-7b434893</loc>
    <lastmod>2026-07-30T04:31:05.955Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-processes-in-suspicious-directories-initiating-connections-to-file-shari-e0f8ab85</loc>
    <lastmod>2026-07-30T04:31:04.355Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msbuild-exe-network-connection-to-web-ports-80-443-with-initiated-sessio-50e54b8d</loc>
    <lastmod>2026-07-30T04:31:00.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-anydesk-incoming-remote-connection-non-initiated-network-sessions-d58ba5c6</loc>
    <lastmod>2026-07-30T04:30:57.513Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-exe-initiated-network-connection-c7e91a02</loc>
    <lastmod>2026-07-30T04:30:55.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regasm-exe-initiating-network-connections-to-public-ips-0531e43a</loc>
    <lastmod>2026-07-30T04:30:54.166Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-tcp-3389-initiated-connections-to-http-https-ports-80-443-b1e5da3b</loc>
    <lastmod>2026-07-30T04:30:52.673Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-svchost-rdp-using-reverse-ssh-tunnel-to-loopback-tcp-3389-5f699bc5</loc>
    <lastmod>2026-07-30T04:30:50.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-outbound-rdp-sessions-to-port-3389-initiated-by-non-standard-processes-ed74fe75</loc>
    <lastmod>2026-07-30T04:30:49.087Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-apps-initiate-network-connections-to-uncommon-destination-ports-3b5ba899</loc>
    <lastmod>2026-07-30T04:30:45.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-apps-initiating-network-connections-to-external-non-private-ips-75e33ce3</loc>
    <lastmod>2026-07-30T04:30:43.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-initiated-by-notepad-exe-e81528db</loc>
    <lastmod>2026-07-30T04:30:41.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/imewdbld-exe-initiated-network-connections-on-windows-8d7e392e</loc>
    <lastmod>2026-07-30T04:30:40.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connection-via-finger-exe-2fdaf50b</loc>
    <lastmod>2026-07-30T04:30:38.531Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-from-eqnedt32-exe-equation-editor-a66bc059</loc>
    <lastmod>2026-07-30T04:30:37.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-initiated-network-connections-to-visual-studio-code-tunnel-domai-4b657234</loc>
    <lastmod>2026-07-30T04:30:35.686Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-non-browser-process-connecting-to-api-telegram-org-c3dbbc9f</loc>
    <lastmod>2026-07-30T04:30:34.061Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-initiates-network-connection-to-portmap-io-domain-07837ab9</loc>
    <lastmod>2026-07-30T04:30:32.030Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-non-browser-process-communicating-with-notion-api-7e9cf7b6</loc>
    <lastmod>2026-07-30T04:30:30.664Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-executable-connects-to-ngrok-tunneling-domains-1d08ac94</loc>
    <lastmod>2026-07-30T04:30:28.946Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-initiated-to-ngrok-domains-18249279</loc>
    <lastmod>2026-07-30T04:30:27.120Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-api-mega-co-nz-or-mega-nz-fdeebdf0</loc>
    <lastmod>2026-07-30T04:30:25.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-localtonet-tunneling-subdomains-initiated-3ab65069</loc>
    <lastmod>2026-07-30T04:30:23.972Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-non-browser-network-traffic-to-google-apis-7e9cf7b6</loc>
    <lastmod>2026-07-30T04:30:22.358Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-external-ip-lookup-service-apis-edf3485d</loc>
    <lastmod>2026-07-30T04:30:20.905Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-dropbox-api-network-connections-from-non-dropbox-executables-25eabf56</loc>
    <lastmod>2026-07-30T04:30:19.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-devtunnels-ms-domains-9501f8e6</loc>
    <lastmod>2026-07-30T04:30:17.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-dead-drop-resolver-domains-from-non-browser-execu-297ae038</loc>
    <lastmod>2026-07-30T04:30:16.414Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-known-crypto-mining-pool-hostnames-fa5b1358</loc>
    <lastmod>2026-07-30T04:30:14.641Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-network-connections-to-cloudflared-tunnel-domains-7cd1dcdc</loc>
    <lastmod>2026-07-30T04:30:12.821Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-btunnel-domains-9e02c8ec</loc>
    <lastmod>2026-07-30T04:30:10.808Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-non-browser-process-connecting-to-azurewebsites-net-5c80b618</loc>
    <lastmod>2026-07-30T04:30:09.066Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-outbound-connections-initiated-by-dialer-exe-microsoft-phone-dialer-37e4024a</loc>
    <lastmod>2026-07-30T04:30:06.745Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-initiated-by-cmstp-exe-efafe0bf</loc>
    <lastmod>2026-07-30T04:30:05.196Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certutil-exe-initiating-network-connections-to-common-service-ports-0dba975d</loc>
    <lastmod>2026-07-30T04:30:03.611Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-network-connections-to-ad-web-services-adws-from-non-standard-p-b3ad3c0f</loc>
    <lastmod>2026-07-30T04:30:01.727Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-addinutil-exe-initiates-network-connection-5205613d</loc>
    <lastmod>2026-07-30T04:30:00.068Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-dll-hijack-via-wbemcomn-dll-loaded-by-wmiprvse-exe-7707a579</loc>
    <lastmod>2026-07-30T04:29:56.751Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-wmic-loading-javascript-or-vbscript-libraries-via-image-load-even-06ce37c2</loc>
    <lastmod>2026-07-30T04:29:54.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-persistence-via-command-line-event-consumers-wmiprvse-exe-loading-wb-05936ce2</loc>
    <lastmod>2026-07-30T04:29:53.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-trusted-path-bypass-via-spoofed-system-directory-with-extra-s-0cbe38c0</loc>
    <lastmod>2026-07-30T04:29:51.440Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-image-load-dbgcore-dll-dbghelp-dll-from-user-or-public-paths-416bc4a2</loc>
    <lastmod>2026-07-30T04:29:49.672Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mmc-loading-script-engine-dlls-vbscript-jscript-a9c73e8b</loc>
    <lastmod>2026-07-30T04:29:48.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-fake-dismcore-dll-loaded-by-dism-exe-a5ea83a7</loc>
    <lastmod>2026-07-30T04:29:46.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-iscsicpl-exe-loading-malicious-dll-from-path-9ed5959a</loc>
    <lastmod>2026-07-30T04:29:44.888Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-executes-unsigned-thor-scanner-binaries-ea5c131b</loc>
    <lastmod>2026-07-30T04:29:43.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-utility-loads-untrusted-dll-via-image-load-telemetry-b5de0c9a</loc>
    <lastmod>2026-07-30T04:29:41.460Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scripting-and-lolbins-loading-net-clr-dlls-4508a70e</loc>
    <lastmod>2026-07-30T04:29:39.791Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-process-loads-dll-from-suspicious-or-permissive-path-9e9a9002</loc>
    <lastmod>2026-07-30T04:29:36.340Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-clickonce-loads-unsigned-module-from-appdata-local-apps-2-0-060d5ad4</loc>
    <lastmod>2026-07-30T04:29:34.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-baaupdate-exe-suspicious-dll-loads-from-publicly-writable-paths-6e8fe0a8</loc>
    <lastmod>2026-07-30T04:29:32.469Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-imageloaded-wwlib-dll-associated-with-winword-e2e01011</loc>
    <lastmod>2026-07-30T04:29:30.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mpclient-dll-side-loading-via-mpcmdrun-exe-or-nissrv-exe-from-non-defaul-418dc89a</loc>
    <lastmod>2026-07-30T04:29:29.298Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-side-loading-indicators-for-wazuh-platform-libraries-via-imageload-e-db77ce78</loc>
    <lastmod>2026-07-30T04:29:27.692Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-monitoring-potential-waveedit-dll-dll-sideloading-71b31e99</loc>
    <lastmod>2026-07-30T04:29:25.906Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-flag-vmwarexferlogs-exe-loading-glib-2-0-dll-from-non-default-path-9313dc13</loc>
    <lastmod>2026-07-30T04:29:24.234Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vmmap-unsigned-dbghelp-dll-image-sideloading-attempt-on-windows-273a8dd8</loc>
    <lastmod>2026-07-30T04:29:22.547Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vmmap-loads-signed-dbghelp-dll-from-c-debuggers-path-potential-dll-sideloading-98ffaed4</loc>
    <lastmod>2026-07-30T04:29:20.825Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vmguestlib-dll-sideloading-via-wmiapsrv-imageload-70e8e9b4</loc>
    <lastmod>2026-07-30T04:29:19.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-of-vivaldi-elf-dll-suggesting-potential-dll-sideloading-2092cacb</loc>
    <lastmod>2026-07-30T04:29:17.599Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-fax-service-dll-search-order-hijack-via-ualapi-dll-side-loading-828af599</loc>
    <lastmod>2026-07-30T04:29:14.046Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-imageload-from-lenovo-and-toshiba-third-party-direct-f9df325d</loc>
    <lastmod>2026-07-30T04:29:12.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-solidpdfcreator-dll-sideloading-via-imageload-events-a2edbce1</loc>
    <lastmod>2026-07-30T04:29:10.553Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-smadhook32c-dll-or-smadhook64c-dll-image-load-24b6cf51</loc>
    <lastmod>2026-07-30T04:29:09.008Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-shelldispatch-dll-image-load-844f8eb2</loc>
    <lastmod>2026-07-30T04:29:07.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sidelo-ading-detect-image-loads-of-shellchromeapi-dll-ee4c5d06</loc>
    <lastmod>2026-07-30T04:29:05.616Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-roboform-dll-sideloading-via-image-load-of-roboform-dll-f64c9b2d</loc>
    <lastmod>2026-07-30T04:29:03.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rjvplatform-dll-dll-sideloading-by-systemresetplatform-exe-from-non-defa-0e0bc253</loc>
    <lastmod>2026-07-30T04:29:01.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-side-loading-systemresetplatform-exe-loading-rjvplatform-dll-from-sy-259dda31</loc>
    <lastmod>2026-07-30T04:28:54.286Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-imageloads-rcdll-dll-from-non-vs-windows-kits-paths-6e78b74f</loc>
    <lastmod>2026-07-30T04:28:52.438Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-dll-sideloading-via-outllib-dll-image-load-outside-expected-offic-829a3bdf</loc>
    <lastmod>2026-07-30T04:28:49.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-loading-from-system-directories-using-specific-phantom-dll-names-6b98b92b</loc>
    <lastmod>2026-07-30T04:28:47.710Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-dll-sideloading-via-loading-msocrsvc-dll-cdb15e19</loc>
    <lastmod>2026-07-30T04:28:45.966Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-dll-sideloading-via-mpsvc-dll-loads-5ba243e5</loc>
    <lastmod>2026-07-30T04:28:43.310Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mftrace-exe-dll-sideloading-of-unsigned-mfdetours-dll-948a0953</loc>
    <lastmod>2026-07-30T04:28:41.625Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-mfdetours-dll-loaded-from-current-directory-d2605a99</loc>
    <lastmod>2026-07-30T04:28:40.084Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-hijacking-libvlc-dll-sideloading-via-non-default-image-load-bf9808c4</loc>
    <lastmod>2026-07-30T04:28:38.348Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-dll-side-loading-keyscramblerie-dll-loaded-by-keyscrambler-ex-d2451be2</loc>
    <lastmod>2026-07-30T04:28:36.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-suspicion-via-image-load-of-jsschhlp-dll-68654bf0</loc>
    <lastmod>2026-07-30T04:28:34.444Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-iviewers-dll-image-loads-4c21b805</loc>
    <lastmod>2026-07-30T04:28:30.926Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-gup-exe-loading-libcurl-dll-from-uncommon-path-e49b5745</loc>
    <lastmod>2026-07-30T04:28:29.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-goopdate-dll-imageload-b6188d2f</loc>
    <lastmod>2026-07-30T04:28:27.734Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-indicators-via-imageloaded-of-system-dll-names-4fc0deee</loc>
    <lastmod>2026-07-30T04:28:25.546Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-side-loading-edputil-dll-loaded-from-non-system-paths-e4903324</loc>
    <lastmod>2026-07-30T04:28:23.623Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-potential-eacore-dll-sideloading-via-ea-desktop-edd3ddc3</loc>
    <lastmod>2026-07-30T04:28:21.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-suspicion-via-image-load-of-dbgmodel-dll-fef394cd</loc>
    <lastmod>2026-07-30T04:28:20.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-dll-sideloading-via-dbghelp-dll-image-loads-6414b5cd</loc>
    <lastmod>2026-07-30T04:28:18.402Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-dbgcore-dll-loaded-from-unusual-paths-9ca2bf31</loc>
    <lastmod>2026-07-30T04:28:15.669Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cpl-image-loads-from-non-system-paths-2b140a5c</loc>
    <lastmod>2026-07-30T04:28:14.103Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-coregen-exe-0fa66f66</loc>
    <lastmod>2026-07-30T04:28:12.600Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-attempts-via-comctl32-dll-in-local-directories-6360757a</loc>
    <lastmod>2026-07-30T04:28:11.064Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-side-loading-via-classicexplorer32-dll-loaded-from-non-classic-shell-caa02837</loc>
    <lastmod>2026-07-30T04:28:09.458Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-chrome-frame-helper-dll-sideloading-via-imageload-of-chrome-frame-helper-72ca7c75</loc>
    <lastmod>2026-07-30T04:28:07.877Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-attempts-ccleanerreactivator-dll-loaded-by-ccleanerreact-3735d5ac</loc>
    <lastmod>2026-07-30T04:28:06.073Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-ccleanerdu-dll-loaded-outside-ccleaner-binaries-1fbc0671</loc>
    <lastmod>2026-07-30T04:28:04.348Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-avkkid-dll-image-loads-952ed57c</loc>
    <lastmod>2026-07-30T04:28:02.628Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-search-order-hijacking-via-arubanetsvc-exe-dll-loads-90ae0469</loc>
    <lastmod>2026-07-30T04:28:01.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-appverifui-dll-loaded-from-non-standard-paths-ee6cea48</loc>
    <lastmod>2026-07-30T04:27:59.298Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-alerts-for-dll-sideloading-from-security-product-directories-552b6b65</loc>
    <lastmod>2026-07-30T04:27:57.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-abusable-dlls-from-suspicious-paths-potential-sideloading-799a5f48</loc>
    <lastmod>2026-07-30T04:27:56.112Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-potential-7za-dll-sideloading-via-untrusted-image-paths-4f6edb78</loc>
    <lastmod>2026-07-30T04:27:54.686Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wmi-activescripteventconsumer-activity-indications-via-scrcons-exe-loading-scrip-b439f47d</loc>
    <lastmod>2026-07-30T04:27:52.981Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-applications-loading-vbe-dlls-vba-runtime-indicators-e6ce8457</loc>
    <lastmod>2026-07-30T04:27:49.801Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-core-dll-loaded-by-office-applications-on-windows-bb2ba6fb</loc>
    <lastmod>2026-07-30T04:27:47.927Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/outlook-process-loads-outlvba-dll-microsoft-vba-add-in-on-windows-9a0b8719</loc>
    <lastmod>2026-07-30T04:27:46.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-excel-loads-xll-add-in-from-uncommon-path-af4c4609</loc>
    <lastmod>2026-07-30T04:27:44.969Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-apps-loading-gac-net-dlls-via-image-load-events-90217a70</loc>
    <lastmod>2026-07-30T04:27:43.329Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-clr-dll-loaded-by-microsoft-office-applications-d13c43f0</loc>
    <lastmod>2026-07-30T04:27:41.680Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-apps-load-net-dlls-from-c-windows-assembly-ff0f2b05</loc>
    <lastmod>2026-07-30T04:27:40.115Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unsigned-image-loaded-into-lsass-exe-windows-857c8db3</loc>
    <lastmod>2026-07-30T04:27:38.482Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dcom-internetexplorer-application-dll-hijack-via-iertutil-dll-image-load-f354eba5</loc>
    <lastmod>2026-07-30T04:27:37.024Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-load-sharpevtmute-evtmutehook-dll-imphash-49329257</loc>
    <lastmod>2026-07-30T04:27:33.594Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-of-vsstrace-dll-by-uncommon-executables-48bfd177</loc>
    <lastmod>2026-07-30T04:27:32.060Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-of-vssapi-dll-by-uncommon-executables-37774c23</loc>
    <lastmod>2026-07-30T04:27:30.487Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-unsigned-node-native-add-on-loaded-e5f5c693</loc>
    <lastmod>2026-07-30T04:27:26.712Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-of-tttracer-dlls-for-time-travel-debugging-utility-e76c8240</loc>
    <lastmod>2026-07-30T04:27:25.144Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-non-powershell-process-loads-powershell-system-management-automation-dll-092bc4b9</loc>
    <lastmod>2026-07-30T04:27:23.388Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msdt-exe-loading-sdiageng-dll-via-imageload-telemetry-ec8c4047</loc>
    <lastmod>2026-07-30T04:27:21.679Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-load-of-rstrtmgr-dll-by-uncommon-process-3669afd2</loc>
    <lastmod>2026-07-30T04:27:20.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-image-load-of-rstrtmgr-dll-by-windows-process-b48492dc</loc>
    <lastmod>2026-07-30T04:27:18.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-of-temp-module-containing-pcre-net-package-path-84b0a8f3</loc>
    <lastmod>2026-07-30T04:27:16.637Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-loads-unsigned-dbghelp-dll-or-dbgcore-dll-bdc64095</loc>
    <lastmod>2026-07-30T04:27:15.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-credui-dll-imageload-from-uncommon-process-9ae01559</loc>
    <lastmod>2026-07-30T04:27:13.490Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-loads-renamed-comsvcs-dll-for-process-memory-dump-8cde342c</loc>
    <lastmod>2026-07-30T04:27:11.948Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-microsoftaccounttokenprovider-dll-linked-to-azure-browser-sso-50f852e6</loc>
    <lastmod>2026-07-30T04:27:10.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-amsi-dll-loaded-by-living-off-the-land-processes-extexport-exe-odbcconf--6ec86d9e</loc>
    <lastmod>2026-07-30T04:27:02.626Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmstp-loads-dll-ocx-from-suspicious-paths-75e508f7</loc>
    <lastmod>2026-07-30T04:27:00.791Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-clfs-sys-image-loaded-from-potentially-suspicious-user-or-temp-paths-fb4e2211</loc>
    <lastmod>2026-07-30T04:26:59.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-new-sed-file-creation-consistent-with-self-extraction-directive-ab90dab8</loc>
    <lastmod>2026-07-30T04:26:55.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-c-windows-system32-wpbbin-exe-for-uefi-persistence-indi-e94b9ddc</loc>
    <lastmod>2026-07-30T04:26:52.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-file-drop-wbemcomn-dll-in-system32-wbem-for-wmi-dll-hijack-614a7e17</loc>
    <lastmod>2026-07-30T04:26:50.906Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmiexec-default-output-file-creation-via-file-events-8d5aca11</loc>
    <lastmod>2026-07-30T04:26:49.243Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-persistence-via-scrcons-exe-script-event-consumer-file-writes-33f41cdd</loc>
    <lastmod>2026-07-30T04:26:47.372Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-suspicious-winrm-vbscript-use-of-wsmpty-xsl-or-wsmtxt-xsl-ou-d353dac0</loc>
    <lastmod>2026-07-30T04:26:45.791Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrar-rar-creating-files-in-startup-folder-paths-74a2b37d</loc>
    <lastmod>2026-07-30T04:26:44.035Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-werfault-exe-wer-dll-created-in-uncommon-directory-28a452f3</loc>
    <lastmod>2026-07-30T04:26:37.152Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-suspicious-webshell-script-extensions-in-web-root-39f1f9f2</loc>
    <lastmod>2026-07-30T04:26:35.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-code-tunnel-json-indicating-non-vscode-vs-code-tunnelin-d102b8f5</loc>
    <lastmod>2026-07-30T04:26:34.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-node-exe-creates-files-in-vscode-server-history-via-vs-code-server-tunne-56e05d41</loc>
    <lastmod>2026-07-30T04:26:32.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-browser-processes-creating-vhd-vhdx-files-8468111a</loc>
    <lastmod>2026-07-30T04:26:30.676Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uac-bypass-using-windows-media-player-osksupport-dll-via-dllhost-exe-file-events-68578b43</loc>
    <lastmod>2026-07-30T04:26:29.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-event-detect-uac-bypass-attempt-via-winsat-exe-path-parsing-in-temp-155dbf56</loc>
    <lastmod>2026-07-30T04:26:26.747Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-attempt-via-ntfs-reparse-point-targeting-temp-dll-path-7fff6773</loc>
    <lastmod>2026-07-30T04:26:24.685Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-write-to-temp-pkgmgr-exe-via-msconfig-token-modification-uac-bypass-41bb431f</loc>
    <lastmod>2026-07-30T04:26:22.918Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-attempt-via-ieinstal-exe-writing-consent-exe-to-temp-bdd8157d</loc>
    <lastmod>2026-07-30T04:26:21.061Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-idiagnosticprofileuac-dllhost-exe-writing-dll-in-system32-48ea844d</loc>
    <lastmod>2026-07-30T04:26:19.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-event-viewer-recentviews-file-writes-63e4f530</loc>
    <lastmod>2026-07-30T04:26:17.777Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-net-code-profiler-and-mmc-exe-dll-write-to-temp-pe386-dll-93a19907</loc>
    <lastmod>2026-07-30T04:26:16.149Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uac-bypass-via-consent-exe-and-comctl32-dll-file-target-path-62ed5b55</loc>
    <lastmod>2026-07-30T04:26:14.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-mstsc-exe-writing-to-startup-folder-via-tsclient-share-52753ea4</loc>
    <lastmod>2026-07-30T04:26:12.826Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-taskmgr-exe-creating-lsass-dmp-in-temp-directory-69ca12af</loc>
    <lastmod>2026-07-30T04:26:10.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-flag-exe-local-dll-sideload-attempts-targeting-system32-comctl32-dll-07a99744</loc>
    <lastmod>2026-07-30T04:26:09.349Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexec-key-file-creation-via-c-windows-psexec-key-304afd73</loc>
    <lastmod>2026-07-30T04:26:07.729Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexec-service-file-creation-via-psexesvc-exe-259e5a6a</loc>
    <lastmod>2026-07-30T04:26:06.069Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-monitor-driver-sys-created-by-non-procmon-executables-a05baa88</loc>
    <lastmod>2026-07-30T04:26:04.465Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-explorer-driver-sys-created-by-non-process-explorer-binaries-de46c52b</loc>
    <lastmod>2026-07-30T04:26:02.808Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-livekd-driver-file-created-by-non-livekd-executable-059c5af9</loc>
    <lastmod>2026-07-30T04:26:00.821Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-livekd-driver-file-creation-via-livekd-exe-or-livek64-exe-16fe46bb</loc>
    <lastmod>2026-07-30T04:25:58.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-livekd-kernel-memory-dump-file-created-livekd-dmp-814ddeca</loc>
    <lastmod>2026-07-30T04:25:57.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-writes-by-adexplorer-creating-complete-ad-snapshot-dat-files-0a1255c5</loc>
    <lastmod>2026-07-30T04:25:55.945Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winsxs-exe-creation-by-non-system-processes-34746e8c</loc>
    <lastmod>2026-07-30T04:25:54.361Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-terminal-settings-json-modified-by-an-uncommon-command-line-process-9b64de98</loc>
    <lastmod>2026-07-30T04:25:52.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-suspicious-wdac-policy-file-creation-in-codeintegrity-path-1d2de8a6</loc>
    <lastmod>2026-07-30T04:25:50.599Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-vs-code-powershell-profile-script-creation-or-modification-3a9fa2ec</loc>
    <lastmod>2026-07-30T04:25:49.050Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-teamviewer-remote-session-log-file-creation-vprint-db-and-tvnetwork-log-162ab1e4</loc>
    <lastmod>2026-07-30T04:25:46.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-file-writes-to-system32-tasks-from-suspicious-paths-80e1f67a</loc>
    <lastmod>2026-07-30T04:25:45.430Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-writes-indicating-interactive-powershell-history-as-system-5b40a734</loc>
    <lastmod>2026-07-30T04:25:43.950Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-startup-folder-file-creation-with-suspicious-script-executable-extension-28208707</loc>
    <lastmod>2026-07-30T04:25:42.096Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-dll-exe-sys-creation-in-spool-drivers-color-folder-ce7066a6</loc>
    <lastmod>2026-07-30T04:25:40.521Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-event-detect-unicode-right-to-left-override-extension-spoofing-979baf41</loc>
    <lastmod>2026-07-30T04:25:38.851Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-creation-in-fake-recycle-bin-folder-paths-cd8b36ac</loc>
    <lastmod>2026-07-30T04:25:37.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-public-folder-file-creation-with-suspicious-script-or-binary-extensions-b447f7de</loc>
    <lastmod>2026-07-30T04:25:35.386Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-procexp152-sys-driver-created-in-appdata-local-temp-3da70954</loc>
    <lastmod>2026-07-30T04:25:33.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-powershell-profile-script-creation-or-modification-b5b78988</loc>
    <lastmod>2026-07-30T04:25:31.501Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-suspicious-lnk-double-extension-filenames-3215aa19</loc>
    <lastmod>2026-07-30T04:25:29.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-suspicious-legitimate-apps-dropping-script-files-7d604714</loc>
    <lastmod>2026-07-30T04:25:27.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-writing-by-executables-to-uncommon-locations-1cf465a1</loc>
    <lastmod>2026-07-30T04:25:25.741Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-executable-dropping-by-known-apps-and-lolbins-f0540f7e</loc>
    <lastmod>2026-07-30T04:25:24.026Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-executable-process-dropping-archive-files-zip-rar-7z-cab-appx-654fcc6d</loc>
    <lastmod>2026-07-30T04:25:22.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-flag-unicode-homoglyphs-in-targetfilename-4f1707b1</loc>
    <lastmod>2026-07-30T04:25:20.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hidden-directory-creation-via-ntfs-index-allocation-stream-in-file-event-a8f866e1</loc>
    <lastmod>2026-07-30T04:25:19.183Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-suspicious-get-variable-exe-under-windowsapps-0c3fac91</loc>
    <lastmod>2026-07-30T04:25:17.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-write-via-command-line-tools-to-sharepoint-layouts-web-assets-1f0489be</loc>
    <lastmod>2026-07-30T04:25:15.616Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-write-to-apache-tomcat-webapps-root-as-jsp-from-dotnet-j-89c42960</loc>
    <lastmod>2026-07-30T04:25:13.931Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-executable-file-creation-via-malicious-filenames-and-extensio-74babdd6</loc>
    <lastmod>2026-07-30T04:25:12.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msexchangemailboxreplication-writes-asp-aspx-files-7280c9f3</loc>
    <lastmod>2026-07-30T04:25:10.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-dpapi-backup-key-and-certificate-export-files-7892ec59</loc>
    <lastmod>2026-07-30T04:25:08.837Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-suspicious-double-extension-filenames-b4926b47</loc>
    <lastmod>2026-07-30T04:25:07.306Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-creation-of-diagcab-files-3d0ed417</loc>
    <lastmod>2026-07-30T04:24:59.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-desktopimgdownldr-writes-lock-screen-images-to-unusual-paths-fc4f4817</loc>
    <lastmod>2026-07-30T04:24:57.548Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-copied-suspicious-exe-dll-files-into-default-gpo-storage-path-5f87308a</loc>
    <lastmod>2026-07-30T04:24:55.414Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-files-created-by-microsoft-sync-center-mobsync-exe-409f8a98</loc>
    <lastmod>2026-07-30T04:24:53.811Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-colorcpl-exe-file-creation-targeting-system32-spool-drivers-p-e15b518d</loc>
    <lastmod>2026-07-30T04:24:52.270Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-startup-folder-file-write-for-persistence-t1547-001-2aa0a6b4</loc>
    <lastmod>2026-07-30T04:24:50.522Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-executables-writing-files-with-suspicious-extensions-b8fd0e93</loc>
    <lastmod>2026-07-30T04:24:48.925Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scripting-binaries-writing-files-to-suspicious-directories-1277f594</loc>
    <lastmod>2026-07-30T04:24:46.708Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-sed-directive-file-creation-in-suspicious-directories-760e75d8</loc>
    <lastmod>2026-07-30T04:24:45.029Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-potential-local-sam-database-export-artifact-4e87b8e2</loc>
    <lastmod>2026-07-30T04:24:43.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-detect-explorer-expanded-lnk-persistence-in-startup-folder-w-a6976974</loc>
    <lastmod>2026-07-30T04:24:41.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/screenconnect-rmm-temporary-file-creation-in-windows-user-documents-connectwisec-0afecb6e</loc>
    <lastmod>2026-07-30T04:24:39.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/screenconnect-temporary-installation-artefact-creation-windows-file-events-fec96f39</loc>
    <lastmod>2026-07-30T04:24:38.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remcomsvc-exe-service-file-creation-7eff1a7f</loc>
    <lastmod>2026-07-30T04:24:36.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regedit-exe-creating-a-pdf-file-145095eb</loc>
    <lastmod>2026-07-30T04:24:35.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-drops-matching-winnti-like-dll-and-batch-filenames-130c9e58</loc>
    <lastmod>2026-07-30T04:24:34.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-file-creation-triggered-by-uncommon-application-fccfb43e</loc>
    <lastmod>2026-07-30T04:24:32.514Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rclone-configuration-file-creation-in-user-profile-34986307</loc>
    <lastmod>2026-07-30T04:24:30.883Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-psscriptpolicytest-random-generated-by-uncommon-process-1027d292</loc>
    <lastmod>2026-07-30T04:24:29.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-creating-startup-shortcut-lnk-files-for-persistence-92fa78e7</loc>
    <lastmod>2026-07-30T04:24:27.347Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-module-file-creation-by-non-powershell-process-e3845023</loc>
    <lastmod>2026-07-30T04:24:25.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-new-module-file-created-in-modules-directories-e36941d0</loc>
    <lastmod>2026-07-30T04:24:22.616Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-known-offensive-powershell-script-dropper-filenames-f331aa1f</loc>
    <lastmod>2026-07-30T04:24:20.969Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-pwsh-dropping-ps1-files-via-powershell-exe-576426ad</loc>
    <lastmod>2026-07-30T04:24:19.472Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-creating-executable-or-script-files-matching-binary-dropper-p-7047d730</loc>
    <lastmod>2026-07-30T04:24:17.910Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-executable-archive-file-created-in-c-perflogs-bbb7e38c</loc>
    <lastmod>2026-07-30T04:24:16.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-creation-of-pcre-net-package-temp-files-via-appdata-local-temp-path-6e90ae7a</loc>
    <lastmod>2026-07-30T04:24:14.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-startup-folder-file-creation-with-uncommon-extension-a10a2c40</loc>
    <lastmod>2026-07-30T04:24:13.254Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-by-microsoft-office-with-executable-or-script-extensions-c7a74c80</loc>
    <lastmod>2026-07-30T04:24:11.539Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-document-drop-into-startup-folders-for-persistence-0e20c89d</loc>
    <lastmod>2026-07-30T04:24:09.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-publisher-attachment-file-created-in-suspicious-directory-3d2a2d59</loc>
    <lastmod>2026-07-30T04:24:08.207Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-creation-of-outlook-vbaproject-otm-macro-file-117d3d3a</loc>
    <lastmod>2026-07-30T04:24:06.806Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-attachment-file-created-in-outlook-temporary-directories-fabb0e80</loc>
    <lastmod>2026-07-30T04:24:05.147Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-outlook-form-creation-to-local-forms-path-persistence-risk-c3edc6a5</loc>
    <lastmod>2026-07-30T04:24:01.938Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-outlook-vbaproject-otm-macro-file-creation-8c31f563</loc>
    <lastmod>2026-07-30T04:24:00.278Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-onenote-temp-file-creation-with-suspicious-executable-extensions-fcc6d700</loc>
    <lastmod>2026-07-30T04:23:58.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-one-onepkg-file-created-in-suspicious-locations-7fd164ba</loc>
    <lastmod>2026-07-30T04:23:56.857Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-macro-file-creation-triggered-by-script-execution-binaries-b1c50487</loc>
    <lastmod>2026-07-30T04:23:55.163Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-macro-file-creation-via-browser-or-email-client-0e29e3a7</loc>
    <lastmod>2026-07-30T04:23:53.517Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-macro-file-creation-docm-xlsm-pptm-by-microsoft-office-executable-91174a41</loc>
    <lastmod>2026-07-30T04:23:51.907Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-office-startup-add-in-files-wll-xll-xlam-for-persistence-8e1cb247</loc>
    <lastmod>2026-07-30T04:23:50.082Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-with-ntds-dit-exfiltration-filename-patterns-3a8da4e0</loc>
    <lastmod>2026-07-30T04:23:48.488Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-ntds-dit-by-uncommon-or-suspicious-processes-11b1ed55</loc>
    <lastmod>2026-07-30T04:23:43.259Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-ntds-dit-created-0b8baa3f</loc>
    <lastmod>2026-07-30T04:23:39.621Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-new-notepad-plugin-dll-creation-outside-gup-exe-54127bd4</loc>
    <lastmod>2026-07-30T04:23:38.031Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scr-screen-saver-file-created-outside-system-directories-c048f047</loc>
    <lastmod>2026-07-30T04:23:36.526Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-script-executable-file-creation-in-non-standard-appdata-paths-d7b50671</loc>
    <lastmod>2026-07-30T04:23:35.065Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-unusual-file-creation-by-mysqld-exe-with-script-executable-extensions-c61daa90</loc>
    <lastmod>2026-07-30T04:23:31.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msdt-exe-creating-files-in-suspicious-directories-318557a5</loc>
    <lastmod>2026-07-30T04:23:29.336Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-octopus-scanner-malware-cache134-dat-or-explorersync-db-805c55d9</loc>
    <lastmod>2026-07-30T04:23:27.591Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-java-exe-in-appdata-roaming-oracle-bin-and-vbs-under-retri-0bcfabcb</loc>
    <lastmod>2026-07-30T04:23:25.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-werfault-creates-dump-files-referencing-lsass-process-memory-c3e76af5</loc>
    <lastmod>2026-07-30T04:23:24.151Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-crash-dump-dmp-present-in-crashdumps-directory-6902955a</loc>
    <lastmod>2026-07-30T04:23:22.540Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-memory-dump-file-creation-a5a2d357</loc>
    <lastmod>2026-07-30T04:23:20.611Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vbs-gathernetworkinfo-output-files-written-to-system32-config-f92a6f1e</loc>
    <lastmod>2026-07-30T04:23:18.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-recent-items-shows-iso-img-vhd-image-mount-shortcut-lnk-usage-4358e5a5</loc>
    <lastmod>2026-07-30T04:23:16.874Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iso-file-creation-in-user-temporary-folders-2f9356ae</loc>
    <lastmod>2026-07-30T04:23:15.117Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-malicious-dll-dropped-to-onedrive-teams-appdata-path-containing-iphlpapi-1908fcc1</loc>
    <lastmod>2026-07-30T04:23:12.728Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-teamviewer-desktop-exe-during-installation-9711de76</loc>
    <lastmod>2026-07-30T04:23:10.987Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-search-order-hijacking-suspicious-dll-writes-to-appdata-onedrive-tea-dbbd9f66</loc>
    <lastmod>2026-07-30T04:23:09.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-impacket-secretsdump-sessionresume-file-creation-indicators-03f4ca17</loc>
    <lastmod>2026-07-30T04:23:07.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-event-safetykatz-style-lsass-dump-file-named-temp-debug-bin-e074832a</loc>
    <lastmod>2026-07-30T04:23:06.169Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-crackmapexec-or-impacket-secretsdump-credential-dumping-temp-6e2a900a</loc>
    <lastmod>2026-07-30T04:23:04.733Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-quarkspwdump-credential-dump-file-written-to-temp-sam-dmp-847def9e</loc>
    <lastmod>2026-07-30T04:23:02.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-powerup-write-hijack-dll-abuse-creating-bat-on-windows-602a1f13</loc>
    <lastmod>2026-07-30T04:23:01.077Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-writes-to-nppspy-txt-or-nppspy-dll-indicates-hacktool-credential-du-cad1fe90</loc>
    <lastmod>2026-07-30T04:22:59.622Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netexec-execution-indicators-via-pyinstaller-mei-temp-file-drops-efc21479</loc>
    <lastmod>2026-07-30T04:22:57.814Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-file-creation-mimikatz-kirbi-and-mimilsa-log-detection-9e099d99</loc>
    <lastmod>2026-07-30T04:22:55.638Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-remotekrbrelay-smb-relay-module-temp-secrets-dumps-3ab79e90</loc>
    <lastmod>2026-07-30T04:22:54.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-inveigh-hacktool-execution-artefacts-via-dropped-files-bb09dd3e</loc>
    <lastmod>2026-07-30T04:22:52.192Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-activity-hivenightmare-style-sam-file-exports-6ea858a8</loc>
    <lastmod>2026-07-30T04:22:50.191Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-outflank-dumpert-default-dump-file-creation-93d94efc</loc>
    <lastmod>2026-07-30T04:22:48.506Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-event-indicators-for-crackmapexec-hacktool-artifacts-736ffa74</loc>
    <lastmod>2026-07-30T04:22:47.010Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-notepad-updater-gup-exe-creates-files-in-uncommon-locations-3b8f4c92</loc>
    <lastmod>2026-07-30T04:22:45.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gotoassist-temporary-installation-artefact-file-creation-windows-5d756aee</loc>
    <lastmod>2026-07-30T04:22:43.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-persistence-file-drop-errorhandler-cmd-in-c-windows-setup-scripts-15904280</loc>
    <lastmod>2026-07-30T04:22:39.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-dmp-hdmp-file-creation-via-shell-or-scripting-aba15bdd</loc>
    <lastmod>2026-07-30T04:22:37.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-search-order-hijacking-via-additional-space-in-dll-path-b6f91281</loc>
    <lastmod>2026-07-30T04:22:35.826Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-desktop-ini-file-creation-access-by-unusual-process-81315b50</loc>
    <lastmod>2026-07-30T04:22:34.297Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dcom-internetexplorer-application-dll-hijack-via-iertutil-dll-file-write-2f7979ae</loc>
    <lastmod>2026-07-30T04:22:32.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dynamic-c-compilation-creates-cmdline-artefact-e4a74e34</loc>
    <lastmod>2026-07-30T04:22:31.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-csexec-service-file-creation-via-csexecsvc-exe-f0e2b768</loc>
    <lastmod>2026-07-30T04:22:29.767Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wscript-cscript-script-file-dropper-via-file-write-to-scripting-extensio-002bdb95</loc>
    <lastmod>2026-07-30T04:22:28.122Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-with-credential-dump-related-filenames-8fbf3271</loc>
    <lastmod>2026-07-30T04:22:25.905Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-executing-program-exe-via-unquoted-file-path-8c3c76ca</loc>
    <lastmod>2026-07-30T04:22:24.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-system-process-executables-in-non-system-locations-d5866ddf</loc>
    <lastmod>2026-07-30T04:22:22.677Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-system-dll-names-in-uncommon-directories-13c02350</loc>
    <lastmod>2026-07-30T04:22:20.867Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-scr-screensaver-binary-file-creation-97aa2e88</loc>
    <lastmod>2026-07-30T04:22:19.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-new-custom-apppatch-shim-database-files-created-ee63c85c</loc>
    <lastmod>2026-07-30T04:22:17.578Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-deno-writing-files-to-appdata-from-remote-https-sources-6c0ce3b6</loc>
    <lastmod>2026-07-30T04:22:16.139Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-non-existent-system-dlls-in-system32-df6ecb8b</loc>
    <lastmod>2026-07-30T04:22:14.523Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-evtx-file-creation-in-non-standard-locations-65236ec7</loc>
    <lastmod>2026-07-30T04:22:07.278Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-creation-by-openedr-itsmservice-exe-using-executable-arc-9e4b7d3a</loc>
    <lastmod>2026-07-30T04:22:05.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-for-sharphound-bloodhound-collection-output-filenames-02773bed</loc>
    <lastmod>2026-07-30T04:22:03.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-new-dll-created-by-aspnet-compiler-exe-in-temporary-asp-net-assembly-pat-4c7f49ee</loc>
    <lastmod>2026-07-30T04:22:01.943Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-arcsoc-exe-creates-potentially-malicious-script-or-executable-files-e890acee</loc>
    <lastmod>2026-07-30T04:22:00.393Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-anydesk-binary-writes-except-gcapi-dll-2d367498</loc>
    <lastmod>2026-07-30T04:21:58.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/anydesk-temporary-artefact-file-writes-on-windows-0b9ad457</loc>
    <lastmod>2026-07-30T04:21:56.732Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/advanced-ip-scanner-execution-via-windows-temp-file-path-fed85bf9</loc>
    <lastmod>2026-07-30T04:21:55.160Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-adsi-schema-cache-sch-file-creation-by-uncommon-executables-75bf09fa</loc>
    <lastmod>2026-07-30T04:21:53.539Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-process-deletes-zone-identifier-alternate-data-stream-ads-3109530e</loc>
    <lastmod>2026-07-30T04:21:51.993Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-exe-deletes-files-not-targeting-dns-log-8f0b1fb1</loc>
    <lastmod>2026-07-30T04:21:50.410Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-deletion-using-sysinternals-sdelete-aaa-zzz-filename-suffixes-6ddab845</loc>
    <lastmod>2026-07-30T04:21:48.946Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-deletion-of-tomcat-web-server-log-files-270185ff</loc>
    <lastmod>2026-07-30T04:21:47.188Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-teamviewer-log-file-deletion-b1decb61</loc>
    <lastmod>2026-07-30T04:21:45.703Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-prefetch-pf-file-deletion-via-filedelete-0a1f9d29</loc>
    <lastmod>2026-07-30T04:21:44.089Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-console-history-file-deleted-psreadline-consolehost-history-t-ff301988</loc>
    <lastmod>2026-07-30T04:21:42.335Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-deletes-its-own-executable-image-f01d1f70</loc>
    <lastmod>2026-07-30T04:21:40.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-webserver-access-log-files-deleted-3eb8c339</loc>
    <lastmod>2026-07-30T04:21:39.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-exchange-powershell-cmdlet-history-log-files-deleted-a55349d8</loc>
    <lastmod>2026-07-30T04:21:37.778Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-event-log-evtx-file-deletion-from-system32-winevt-logs-63c779ba</loc>
    <lastmod>2026-07-30T04:21:36.148Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-deletion-of-backup-file-extensions-via-command-line-binaries-06125661</loc>
    <lastmod>2026-07-30T04:21:34.526Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-exe-modifies-unexpected-files-9f383dc0</loc>
    <lastmod>2026-07-30T04:21:32.364Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-processes-accessing-microsoft-teams-cookies-or-local-storage-le-65744385</loc>
    <lastmod>2026-07-30T04:21:30.684Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-by-non-browser-processes-to-browser-credential-storage-a1dfd976</loc>
    <lastmod>2026-07-30T04:21:27.341Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-to-dpapi-master-keys-by-uncommon-applications-46612ae6</loc>
    <lastmod>2026-07-30T04:21:24.031Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-to-crypto-wallet-files-by-uncommon-applications-f41b0311</loc>
    <lastmod>2026-07-30T04:21:22.547Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-credential-history-file-access-by-uncommon-image-paths-7a2a22ea</loc>
    <lastmod>2026-07-30T04:21:20.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-credential-manager-and-vault-access-from-unusual-process-images-407aecb1</loc>
    <lastmod>2026-07-30T04:21:19.349Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-windivert-driver-load-detection-via-loaded-driver-image-or-known-imphash-679085d5</loc>
    <lastmod>2026-07-30T04:21:17.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winring0-driver-load-via-imphash-or-image-path-match-1a42dfa6</loc>
    <lastmod>2026-07-30T04:21:15.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacksys-extreme-vulnerable-driver-hevd-sys-load-detection-295c9289</loc>
    <lastmod>2026-07-30T04:21:14.049Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-vulnerable-driver-load-by-known-file-name-72cd00d6</loc>
    <lastmod>2026-07-30T04:21:12.082Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-driver-load-with-image-path-containing-temp-2c4523d5</loc>
    <lastmod>2026-07-30T04:21:07.007Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-driver-load-for-system-informer-systeminformer-sys-with-known-hashes-10cb6535</loc>
    <lastmod>2026-07-30T04:21:05.412Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-driver-load-process-hacker-kernel-driver-processhacker-sys-67add051</loc>
    <lastmod>2026-07-30T04:21:03.582Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-malicious-driver-load-identified-by-known-driver-file-names-39b64854</loc>
    <lastmod>2026-07-30T04:21:01.648Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-malicious-driver-load-by-known-hash-match-05296024</loc>
    <lastmod>2026-07-30T04:20:59.949Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-for-visual-studio-code-tunnels-domain-b3e6418f</loc>
    <lastmod>2026-07-30T04:20:58.167Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-containing-ufile-io-1cbbeaaf</loc>
    <lastmod>2026-07-30T04:20:56.563Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-detect-dns-queries-for-onion-and-tor-gateway-proxy-domains-b55ca2a3</loc>
    <lastmod>2026-07-30T04:20:54.293Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-teamviewer-domain-queried-by-non-teamviewer-named-process-778ba9a8</loc>
    <lastmod>2026-07-30T04:20:52.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-for-public-ip-lookup-api-domains-by-non-browser-processes-ec82e2a5</loc>
    <lastmod>2026-07-30T04:20:51.102Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-to-remote-access-remote-support-domains-from-non-browser-pro-4d07b1f4</loc>
    <lastmod>2026-07-30T04:20:49.504Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-exe-dns-queries-detected-36e037c4</loc>
    <lastmod>2026-07-30T04:20:47.467Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-from-quickassist-exe-to-remoteassistance-support-services-mi-882e858a</loc>
    <lastmod>2026-07-30T04:20:45.736Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-onelaunch-update-domain-dns-queries-via-onelaunch-exe-df68f791</loc>
    <lastmod>2026-07-30T04:20:44.156Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-query-for-mega-userstorage-subdomains-613c03ba</loc>
    <lastmod>2026-07-30T04:20:42.501Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cobalt-strike-style-dns-beaconing-via-sysmon-on-windows-f356a9c4</loc>
    <lastmod>2026-07-30T04:20:41.017Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-query-contains-base64-kerberos-coercion-credential-target-signature-e7a21b5f</loc>
    <lastmod>2026-07-30T04:20:39.502Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-triggered-by-azure-hybridconnectionmanager-to-servicebus-win-7bd3902d</loc>
    <lastmod>2026-07-30T04:20:37.783Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-detection-for-notepad-gup-exe-queries-to-uncommon-domains-2074e137</loc>
    <lastmod>2026-07-30T04:20:35.842Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-finger-exe-dns-queries-indicating-potential-c2-command-fetching-c082c2b0</loc>
    <lastmod>2026-07-30T04:20:34.242Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-query-to-azurewebsites-net-by-non-browser-process-e043f529</loc>
    <lastmod>2026-07-30T04:20:32.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-server-discovery-via-ldap-query-to-ldap-domain-a21bcd7e</loc>
    <lastmod>2026-07-30T04:20:30.745Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-to-devtunnels-devtunnels-ms-1cb0c6ce</loc>
    <lastmod>2026-07-30T04:20:29.037Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-to-malware-hosting-and-url-shortener-domains-f8c1e80b</loc>
    <lastmod>2026-07-30T04:20:27.513Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-matching-cloudflared-tunnel-domains-a1d9eec5</loc>
    <lastmod>2026-07-30T04:20:25.857Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appinstaller-exe-dns-queries-during-ms-appinstaller-package-installation-7cff77e1</loc>
    <lastmod>2026-07-30T04:20:24.471Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-dns-query-for-anonfiles-com-domain-065cceea</loc>
    <lastmod>2026-07-30T04:20:22.858Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-download-indicators-of-suspicious-content-via-zip-tld-0bb4bbeb</loc>
    <lastmod>2026-07-30T04:20:20.912Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winget-installs-from-zone-identifier-marked-sources-in-temp-winget-a3f5c081</loc>
    <lastmod>2026-07-30T04:20:19.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-downloads-from-direct-ip-urls-with-executable-attachment-025bd229</loc>
    <lastmod>2026-07-30T04:20:17.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/regedit-exe-exports-a-registry-key-into-an-alternate-data-stream-windows-0d7a9363</loc>
    <lastmod>2026-07-30T04:20:15.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-stream-creation-matching-hack-tool-imphash-19b041f6</loc>
    <lastmod>2026-07-30T04:20:13.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-stream-downloads-from-file-sharing-domains-with-script-e-ae02ed70</loc>
    <lastmod>2026-07-30T04:20:12.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-file-download-via-file-sharing-domains-using-sysmon-stream-ha-52182dfb</loc>
    <lastmod>2026-07-30T04:20:10.249Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ads-creation-with-zone-identifier-markers-outside-browser-downloads-573df571</loc>
    <lastmod>2026-07-30T04:20:08.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-executable-hidden-in-ntfs-alternate-data-stream-via-imphash-marker-b69888d4</loc>
    <lastmod>2026-07-30T04:20:06.594Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-createremotethread-using-ttdinject-exe-as-proxy-c15e99a3</loc>
    <lastmod>2026-07-30T04:20:04.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-thread-creation-targeting-uncommon-image-processes-a1a144b7</loc>
    <lastmod>2026-07-30T04:20:03.194Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-thread-creation-triggered-from-uncommon-source-images-66d31e5f</loc>
    <lastmod>2026-07-30T04:20:01.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rare-remote-thread-creation-triggered-by-uncommon-source-images-02d1d718</loc>
    <lastmod>2026-07-30T04:19:59.553Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-remote-thread-creation-indicating-password-dumper-behavior-f239b326</loc>
    <lastmod>2026-07-30T04:19:57.581Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-remote-thread-creation-into-rundll32-exe-or-regsvr32-exe-99b97608</loc>
    <lastmod>2026-07-30T04:19:55.679Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-remote-thread-into-lsass-exe-for-potential-credential-dumping-fb656378</loc>
    <lastmod>2026-07-30T04:19:54.026Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-thread-creation-in-mstsc-exe-triggered-by-suspicious-source-paths-c0aac16a</loc>
    <lastmod>2026-07-30T04:19:52.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-thread-created-in-keepass-exe-77564cc2</loc>
    <lastmod>2026-07-30T04:19:50.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-createremotethread-with-startaddress-ending-in-0b80-0c7c-0c88-6309645e</loc>
    <lastmod>2026-07-30T04:19:49.025Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hacktool-cactustorch-remote-thread-creation-via-cscript-wscript-mshta-of-2e4e488a</loc>
    <lastmod>2026-07-30T04:19:47.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-persistence-via-event-filter-and-event-consumer-event-ids-5861-and-5-0b7889b4</loc>
    <lastmod>2026-07-30T04:19:45.372Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/failed-wmi-nteventlogfile-cleareventlog-attempts-on-windows-event-5858-d4f1a2b3</loc>
    <lastmod>2026-07-30T04:19:43.277Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-windefend-virus-scanning-disabled-event-id-5012-686c0b4b</loc>
    <lastmod>2026-07-30T04:19:41.401Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-windefend-logs-windows-defender-detections-and-remediation-actions-57b649ef</loc>
    <lastmod>2026-07-30T04:19:39.628Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-windefend-tamper-protection-blocked-microsoft-defender-setting-changes-49e5bc24</loc>
    <lastmod>2026-07-30T04:19:37.943Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-configuration-change-alerts-via-microsoft-defender-windefend-ev-801bd44f</loc>
    <lastmod>2026-07-30T04:19:36.445Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-windefend-antimalware-restores-file-from-quarantine-event-id-1009-bc92ca75</loc>
    <lastmod>2026-07-30T04:19:34.651Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-real-time-protection-feature-error-or-restart-windefend-dd80db93</loc>
    <lastmod>2026-07-30T04:19:33.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-windefend-windows-defender-real-time-protection-disabled-event-id-5001-b28e58e4</loc>
    <lastmod>2026-07-30T04:19:31.159Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-windefend-amsi-alert-event-id-1116-ea9bf0fa</loc>
    <lastmod>2026-07-30T04:19:29.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-malware-and-pua-scanning-disabled-event-id-5010-bc275be9</loc>
    <lastmod>2026-07-30T04:19:27.695Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-windefend-deletes-malware-detection-history-event-id-1013-2afe6582</loc>
    <lastmod>2026-07-30T04:19:26.099Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-windefend-automatic-sample-submission-disabled-via-antimalware--91903aba</loc>
    <lastmod>2026-07-30T04:19:24.649Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-exploit-guard-tamper-via-protectedfolders-or-allowedapplication-a3ab73f1</loc>
    <lastmod>2026-07-30T04:19:22.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-exclusions-added-via-windefend-event-id-5007-1321dc4e</loc>
    <lastmod>2026-07-30T04:19:21.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-exploit-guard-blocks-psexec-and-wmi-process-creations-windefend-97b9ce1e</loc>
    <lastmod>2026-07-30T04:19:19.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-asr-lsass-access-block-event-1121-detection-a0a278fe</loc>
    <lastmod>2026-07-30T04:19:17.904Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-antimalware-grace-period-expired-event-id-5101-windefend-360a1340</loc>
    <lastmod>2026-07-30T04:19:15.945Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-event-log-keyword-match-for-mimikatz-credential-dumping-and-kerberos-mod-06d71506</loc>
    <lastmod>2026-07-30T04:19:14.206Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ngrok-forwarding-to-local-rdp-port-via-terminalservices-eventid-21-64d51a51</loc>
    <lastmod>2026-07-30T04:19:12.435Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-task-scheduler-detect-scheduled-task-deleted-or-disabled-for-key-system--9e3cb244</loc>
    <lastmod>2026-07-30T04:19:10.600Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-execution-of-uncommon-binaries-via-taskscheduler-f0767f15</loc>
    <lastmod>2026-07-30T04:19:08.940Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-execution-from-suspicious-paths-424273ea</loc>
    <lastmod>2026-07-30T04:19:07.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-using-script-host-execution-event-id-7045-70f00d10</loc>
    <lastmod>2026-07-30T04:19:05.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-referencing-suspicious-programdata-root-exe-paths-e-1b2ae822</loc>
    <lastmod>2026-07-30T04:19:03.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rtcore64-service-installation-event-id-7045-91c49341</loc>
    <lastmod>2026-07-30T04:18:59.257Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-unexpected-termination-of-message-queuing-msmq-s-56abae0c</loc>
    <lastmod>2026-07-30T04:18:56.068Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-important-service-terminated-with-error-d6b5520d</loc>
    <lastmod>2026-07-30T04:18:54.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-service-terminated-with-error-eventid-7023-acfa2210</loc>
    <lastmod>2026-07-30T04:18:52.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-for-tap-driver-installation-service-control-manager-704-8e4cf0e5</loc>
    <lastmod>2026-07-30T04:18:49.016Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-tacticalrmm-agent-service-scm-event-id-7045-4bb79b62</loc>
    <lastmod>2026-07-30T04:18:47.152Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-psexec-service-installation-via-service-control-manager-event-id-7045-42c575ea</loc>
    <lastmod>2026-07-30T04:18:42.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-via-suspicious-command-line-imagepath-event-id-7045-1d61f71d</loc>
    <lastmod>2026-07-30T04:18:41.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installed-by-system-process-with-pid-0-71c276aa</loc>
    <lastmod>2026-07-30T04:18:39.459Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-detects-sliver-service-installation-via-default--31c51af6</loc>
    <lastmod>2026-07-30T04:18:37.942Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-utilities-host-service-installation-via-service-control-manager-7-85cce894</loc>
    <lastmod>2026-07-30T04:18:36.216Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-service-installation-of-remote-access-tools-1a31b18a</loc>
    <lastmod>2026-07-30T04:18:34.293Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-detects-remcomsvc-service-installation-9e36ed87</loc>
    <lastmod>2026-07-30T04:18:32.750Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-processhacker-privilege-elevation-via-service-control-m-c4ff1eac</loc>
    <lastmod>2026-07-30T04:18:31.101Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-pdqdeployrunner-service-installation-pdqdeploy-b98a10af</loc>
    <lastmod>2026-07-30T04:18:29.531Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-of-pdqdeploy-service-service-control-manager-event--ee9ca27c</loc>
    <lastmod>2026-07-30T04:18:27.831Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detects-paexec-service-installation-via-service-control-manager-event-id-de7ce410</loc>
    <lastmod>2026-07-30T04:18:26.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-netsupport-manager-client32-service-installation-via-service-control-man-2d510d8d</loc>
    <lastmod>2026-07-30T04:18:24.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-of-meshagent-exe-via-service-control-manager-event--e0d1ad53</loc>
    <lastmod>2026-07-30T04:18:22.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-hacktool-service-registration-or-execution-d26ce60c</loc>
    <lastmod>2026-07-30T04:18:21.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-csexec-service-installation-eventid-7045-a27e5fa9</loc>
    <lastmod>2026-07-30T04:18:19.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-of-anydesk-service-event-id-7045-530a6faa</loc>
    <lastmod>2026-07-30T04:18:17.458Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-executed-via-service-control-manager-event-id-7045-a2e5019d</loc>
    <lastmod>2026-07-30T04:18:15.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-moriya-rootkit-related-zznetsvc-via-service-control-man-25b9c01c</loc>
    <lastmod>2026-07-30T04:18:14.026Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-service-execution-of-credential-dumping-tools-via-service-control-4976aa50</loc>
    <lastmod>2026-07-30T04:18:10.412Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-for-krbscm-via-krbrelayup-tool-e97d9903</loc>
    <lastmod>2026-07-30T04:18:08.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-service-control-manager-detects-var-obfuscated-powershell-in-serv-14bcba49</loc>
    <lastmod>2026-07-30T04:18:07.018Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-execution-of-rundll32-with-obfuscated-powershell-641a4bfb</loc>
    <lastmod>2026-07-30T04:18:05.019Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-service-creation-using-mshta-with-vbscript-createobject-7e9c7999</loc>
    <lastmod>2026-07-30T04:18:03.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-clipboard-related-clip-exe-execution-via-system--63e3365d</loc>
    <lastmod>2026-07-30T04:18:01.409Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-event-7045-service-control-manager-runs-imagepath-with-invoke-env-487c7524</loc>
    <lastmod>2026-07-30T04:17:59.697Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-service-control-manager-rundll32-launching-powershell-via-shell32-11b52f18</loc>
    <lastmod>2026-07-30T04:17:57.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-service-creation-of-obfuscated-powershell-using-compress-obfuscat-175997c5</loc>
    <lastmod>2026-07-30T04:17:55.807Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-service-control-manager-cmd-c-r-setting-variables-with-f-in-image-8ca7004b</loc>
    <lastmod>2026-07-30T04:17:54.017Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-service-creates-cmd-launching-powershell-with-stdin-obfuscation-72862bf2</loc>
    <lastmod>2026-07-30T04:17:52.201Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-service-creation-with-obfuscated-powershell-iex-invocation-patter-51aa9387</loc>
    <lastmod>2026-07-30T04:17:50.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-service-control-manager-launches-cmd-with-obfuscated-clip-exe-to--f7385ee2</loc>
    <lastmod>2026-07-30T04:17:48.962Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-event-7045-for-smbexec-py-style-service-name-and-52a85084</loc>
    <lastmod>2026-07-30T04:17:47.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-windows-defender-threat-protection-service-stopp-6c0a7755</loc>
    <lastmod>2026-07-30T04:17:45.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-control-manager-7045-suspicious-cobalt-strike-service-imagepath--5a105d34</loc>
    <lastmod>2026-07-30T04:17:43.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-ntfs-event-id-55-corrupted-file-record-exploitation-activity-f14719ce</loc>
    <lastmod>2026-07-30T04:17:41.671Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-netlogon-secure-channel-connection-allowed-event-id-5829-a0cb7110</loc>
    <lastmod>2026-07-30T04:17:39.845Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-zerologon-exploitation-attempt-from-kali-host-using-mimikatz-18f37338</loc>
    <lastmod>2026-07-30T04:17:37.812Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-log-windows-update-client-errors-installation-connection-revert-13cfeb75</loc>
    <lastmod>2026-07-30T04:17:35.698Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-crash-dump-reporting-via-wer-event-id-1001-882fbe50</loc>
    <lastmod>2026-07-30T04:17:34.026Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-volume-shadow-copy-vss-mount-via-ntfs-event-98-f512acbf</loc>
    <lastmod>2026-07-30T04:17:32.380Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kernel-general-etw-reset-access-bits-for-temp-sam-security-hive-39f919f3</loc>
    <lastmod>2026-07-30T04:17:30.757Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kerberos-key-distribution-center-errors-no-suitable-key-or-unsupported-e-b1e0b3f5</loc>
    <lastmod>2026-07-30T04:17:28.592Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kerberos-kdc-event-39-41-certificate-valid-without-strong-user-mapping-993c2665</loc>
    <lastmod>2026-07-30T04:17:26.996Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-eventlog-cleared-event-id-104-100ef69e</loc>
    <lastmod>2026-07-30T04:17:25.357Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-event-log-cleared-microsoft-windows-eventlog-event-id-104-a62b37e0</loc>
    <lastmod>2026-07-30T04:17:23.842Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lpe-via-com-clsid-tabtip-exe-invoked-through-dcom-activation-microsoft-w-bc2e25ed</loc>
    <lastmod>2026-07-30T04:17:22.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dhcp-server-callout-dll-load-failures-event-ids-1031-1032-1034-75edd3fd</loc>
    <lastmod>2026-07-30T04:17:20.638Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dhcp-server-loads-callout-dll-via-registry-event-id-1033-13fc89a9</loc>
    <lastmod>2026-07-30T04:17:18.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-active-directory-certificate-services-denied-enrollment-requests-event-i-994bfd6d</loc>
    <lastmod>2026-07-30T04:17:17.130Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-isatap-router-address-configuration-set-microsoft-windows-iphlpsvc-d22df9cd</loc>
    <lastmod>2026-07-30T04:17:14.536Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-ntlmv1-logon-reported-between-client-and-server-lsasrv-6038-6039-e9d4ab66</loc>
    <lastmod>2026-07-30T04:17:12.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-application-error-popups-application-popup-event-id-26-4d7f1827</loc>
    <lastmod>2026-07-30T04:17:11.037Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-smb-server-share-access-without-signing-or-encryption-event-4000-8d91f6e4</loc>
    <lastmod>2026-07-30T04:17:09.491Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-smb-client-security-rejected-guest-logon-with-blank-username-71886b70</loc>
    <lastmod>2026-07-30T04:17:07.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-shell-core-suspicious-shortcut-app-resolver-cache-entries-zenmap-anydesk-83c161b6</loc>
    <lastmod>2026-07-30T04:17:06.172Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hybrid-connection-manager-service-events-with-service-bus-endpoints-b55d23e5</loc>
    <lastmod>2026-07-30T04:17:04.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-mitigations-blocked-unsigned-dlls-loaded-from-suspicious-paths-8289bf8c</loc>
    <lastmod>2026-07-30T04:17:02.435Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-blocked-mpcmdrun-and-nissrv-from-loading-unsigned-dlls-0b0ea3cc</loc>
    <lastmod>2026-07-30T04:17:00.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-remote-wmi-dll-hijack-via-wmiprvse-wbemcomn-dll-placed-in-syste-f6c68d5f</loc>
    <lastmod>2026-07-30T04:16:42.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-persistence-via-subscription-namespace-objecttype-security-event-466-f033f3f3</loc>
    <lastmod>2026-07-30T04:16:40.907Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-handle-write-access-requested-on-defender-exclusions-regi-e9c8808f</loc>
    <lastmod>2026-07-30T04:16:39.238Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-log-windows-defender-exclusions-registry-key-value-modified-46a68649</loc>
    <lastmod>2026-07-30T04:16:37.464Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-vssaudit-security-event-source-registration-event-ids-4904-4905-e9faba72</loc>
    <lastmod>2026-07-30T04:16:35.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4634-4647-user-logoff-events-0badd08f</loc>
    <lastmod>2026-07-30T04:16:34.066Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4673-seloaddriverprivilege-used-to-load-unload-kernel-drivers-f63508a0</loc>
    <lastmod>2026-07-30T04:16:31.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-local-user-creation-event-id-4720-66b6be3d</loc>
    <lastmod>2026-07-30T04:16:29.680Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-failed-lsaregisterlogonprocess-service-call-setcbprivilege-chec-6daac7fc</loc>
    <lastmod>2026-07-30T04:16:28.346Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4732-new-member-added-to-local-administrators-group-c265cf08</loc>
    <lastmod>2026-07-30T04:16:26.320Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-5145-credential-file-transfers-via-network-shares-910ab938</loc>
    <lastmod>2026-07-30T04:16:24.386Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-access-to-microsoft-teams-token-and-local-storage-objects-466-25cde13e</loc>
    <lastmod>2026-07-30T04:16:21.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4697-tap-driver-service-installation-tap0901-9c8afa4d</loc>
    <lastmod>2026-07-30T04:16:19.995Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-alerts-on-sysmon-channel-reference-deletion-18beca67</loc>
    <lastmod>2026-07-30T04:16:18.428Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-syskey-relevant-lsa-registry-keys-access-via-handle-and-object--9a4ff3b8</loc>
    <lastmod>2026-07-30T04:16:16.561Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4616-for-system-time-changes-by-non-system-processes-faa031b5</loc>
    <lastmod>2026-07-30T04:16:07.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4702-scheduled-task-content-change-with-suspicious-strings-614cf376</loc>
    <lastmod>2026-07-30T04:16:06.116Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-scheduled-task-deleted-or-disabled-important-task-names-7595ba94</loc>
    <lastmod>2026-07-30T04:16:04.464Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-suspicious-scheduled-task-creation-via-event-4698-and-taskconte-3a734d25</loc>
    <lastmod>2026-07-30T04:16:02.548Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4769-kerberos-service-tickets-requested-with-rc4-encrypti-496a0e47</loc>
    <lastmod>2026-07-30T04:16:00.627Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-network-share-access-to-sensitive-file-extensions-91c945bc</loc>
    <lastmod>2026-07-30T04:15:59.064Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-id-5136-msds-keycredentiallink-shadow-credentials-added-f598ea0c</loc>
    <lastmod>2026-07-30T04:15:55.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/uncommon-outbound-kerberos-port-88-connections-on-windows-security-events-5156-eca91c7c</loc>
    <lastmod>2026-07-30T04:15:53.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-password-protected-zip-opened-from-outlook-attachment-571498c8</loc>
    <lastmod>2026-07-30T04:15:51.809Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-opened-encrypted-zip-files-with-suspicious-invoice-order-filena-54f0434b</loc>
    <lastmod>2026-07-30T04:15:50.338Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-password-protected-zip-opened-eventid-5379-00ba9da1</loc>
    <lastmod>2026-07-30T04:15:48.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4661-sam-object-access-domain-administrator-group-recon-968eef52</loc>
    <lastmod>2026-07-30T04:15:46.502Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-alert-suspicious-accessmask-requests-to-lsass-4a1b6da0</loc>
    <lastmod>2026-07-30T04:15:44.649Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-password-dumping-via-lsass-handle-access-sam-domain-aa1697b7</loc>
    <lastmod>2026-07-30T04:15:42.879Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-remote-logon-using-explicit-credentials-941e5c45</loc>
    <lastmod>2026-07-30T04:15:41.266Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-suspicious-local-account-creation-with-anonymous-logon-account--1bbf25b9</loc>
    <lastmod>2026-07-30T04:15:39.458Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-5136-suspicious-ldap-display-names-used-in-directory-serv-d00a9a72</loc>
    <lastmod>2026-07-30T04:15:37.473Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-failed-kerberos-tgt-request-event-675-4768-4769-4771-f7644214</loc>
    <lastmod>2026-07-30T04:15:35.909Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-gpo-startup-logon-script-added-to-user-or-computer-extensions-123e4e6d</loc>
    <lastmod>2026-07-30T04:15:34.151Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-group-policy-object-attribute-change-adding-privileges-or-local-admins-1c480e10</loc>
    <lastmod>2026-07-30T04:15:32.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-failed-logons-with-suspicious-status-substatus-codes-4625-4776-9eb99343</loc>
    <lastmod>2026-07-30T04:15:30.382Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4794-dsrm-directory-services-restore-mode-account-password-chan-53ad8e36</loc>
    <lastmod>2026-07-30T04:15:22.885Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-suspicious-samtheadmin-computer-account-names-39698b3f</loc>
    <lastmod>2026-07-30T04:15:21.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-ad-account-sidhistory-added-or-modified-event-4765-4766-4738-2632954e</loc>
    <lastmod>2026-07-30T04:15:19.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-domain-trust-creation-event-id-4706-0255a820</loc>
    <lastmod>2026-07-30T04:15:17.487Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-5145-smb-write-to-admin-share-c-by-non-machine-accounts-b210394c</loc>
    <lastmod>2026-07-30T04:15:15.862Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-monitor-file-access-to-signal-desktop-config-json-and-db-sqlite-5d6c375a</loc>
    <lastmod>2026-07-30T04:15:14.206Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-via-unusual-client-clientprocessid-or-parentprocess-c4e92a97</loc>
    <lastmod>2026-07-30T04:15:12.202Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-of-remote-access-tools-event-id-4697-c8b00925</loc>
    <lastmod>2026-07-30T04:15:10.561Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-secure-deletion-via-sdelete-file-extensions-aaa-and-zzz-39a80702</loc>
    <lastmod>2026-07-30T04:15:08.875Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-non-system-access-uses-setakeownershipprivilege-on-scm-database-object-dae8171c</loc>
    <lastmod>2026-07-30T04:15:07.115Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-scm-database-handle-acquisition-failures-event-id-4656-13addce7</loc>
    <lastmod>2026-07-30T04:15:05.189Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-sam-registry-hive-handle-requests-eventid-4656-f8748f2c</loc>
    <lastmod>2026-07-30T04:15:03.282Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4649-flags-kerberos-replay-attempts-krb-ap-err-repeat-5a44727c</loc>
    <lastmod>2026-07-30T04:15:01.647Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-log-detect-winrm-powershell-remoting-inbound-connections-on-598-13acf386</loc>
    <lastmod>2026-07-30T04:15:00.002Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4663-detects-read-control-read-control-access-to-service-regist-11d00fff</loc>
    <lastmod>2026-07-30T04:14:58.263Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4611-new-trusted-logon-process-via-user32logonprocesss-12e6d621</loc>
    <lastmod>2026-07-30T04:14:56.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-5156-rdp-3389-over-loopback-via-svchost-reverse-ssh-tunne-5bed80b6</loc>
    <lastmod>2026-07-30T04:14:55.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-network-access-to-protected-storage-via-ipc-share-45545954</loc>
    <lastmod>2026-07-30T04:14:53.149Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-installed-as-a-service-event-id-4697-2a926e6a</loc>
    <lastmod>2026-07-30T04:14:51.645Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-dcshadow-like-spn-creation-gc-service-principal-names-32e19d25</loc>
    <lastmod>2026-07-30T04:14:49.877Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-alert-on-suspicious-kerberos-tgt-requests-with-certificate-thumbprints-e-6a53d871</loc>
    <lastmod>2026-07-30T04:14:48.004Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pcap-driver-installation-via-sys-file-names-security-4697-7b687634</loc>
    <lastmod>2026-07-30T04:14:44.380Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-password-policy-enumeration-via-event-id-4661-12ba6a38</loc>
    <lastmod>2026-07-30T04:14:42.692Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-denied-remote-desktop-logon-attempts-event-id-4825-8e5c03fa</loc>
    <lastmod>2026-07-30T04:14:40.803Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-new-or-renamed-user-account-name-contains-cfeed607</loc>
    <lastmod>2026-07-30T04:14:38.663Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-5145-remote-writes-to-desktop-ini-via-unc-share-35bc7e28</loc>
    <lastmod>2026-07-30T04:14:36.336Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-registry-netntlm-compatibilitylevel-and-ntlm-security-downgrade-d3abac66</loc>
    <lastmod>2026-07-30T04:14:34.530Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-via-smb-psexec-using-psexesvc-event-id-4697-6fb63b40</loc>
    <lastmod>2026-07-30T04:14:25.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/metasploit-smb-authentication-attempts-via-ntlm-windows-security-4624-4625-4776-72124974</loc>
    <lastmod>2026-07-30T04:14:23.259Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-events-wce-wceaux-dll-file-access-1de68c67</loc>
    <lastmod>2026-07-30T04:14:20.802Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-service-execution-of-credential-dumping-tools-event-id-4697-f0d1feba</loc>
    <lastmod>2026-07-30T04:14:19.436Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-detects-lsass-process-access-from-non-system-account-962fe167</loc>
    <lastmod>2026-07-30T04:14:17.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ad-dns-record-changes-containing-kerberos-credential-target-information--b07e58cf</loc>
    <lastmod>2026-07-30T04:14:14.053Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-events-kerberos-tgt-requests-with-preauth-disabled-and-rc4-hmac-3e2f1b2c</loc>
    <lastmod>2026-07-30T04:14:11.824Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4769-kerberoasting-precursor-query-rc4-tgt-service-requests-d04ae2b8</loc>
    <lastmod>2026-07-30T04:14:09.692Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-iso-image-mount-via-device-cdrom-0248a7bc</loc>
    <lastmod>2026-07-30T04:14:07.764Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4697-detects-var-launcher-obfuscated-powershell-in-servicefilen-4c54ba8f</loc>
    <lastmod>2026-07-30T04:14:05.908Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4697-obfuscated-command-execution-using-rundll32-and-shel-cd0f7229</loc>
    <lastmod>2026-07-30T04:14:04.265Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4697-mshta-script-obfuscation-indicators-9b8d9203</loc>
    <lastmod>2026-07-30T04:14:02.310Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-eid-4697-powershell-launching-via-clip-exe-pattern-1a0a2ff1</loc>
    <lastmod>2026-07-30T04:14:00.578Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-obfuscation-via-stdin-using-service-parameter-strings-windows-securit-80b708f3</loc>
    <lastmod>2026-07-30T04:13:58.907Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4697-obfuscated-powershell-execution-via-rundll32-shell32-dll-f241cf1b</loc>
    <lastmod>2026-07-30T04:13:56.998Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-obfuscated-powershell-using-compress-compression-stream--7a922f1b</loc>
    <lastmod>2026-07-30T04:13:54.849Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-eid-4697-cmd-exe-command-using-obfuscated-set-with-f-likely-lau-dcf2db1f</loc>
    <lastmod>2026-07-30T04:13:53.116Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-execution-via-obfuscated-cmdstdin-input-event-id-4697-0c718a5e</loc>
    <lastmod>2026-07-30T04:13:51.158Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4697-obfuscated-powershell-iex-invocation-pattern-from-in-fd0f5778</loc>
    <lastmod>2026-07-30T04:13:49.579Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4697-clip-exe-obfuscated-powershell-via-cmd-and-clipboard-strin-4edf51e1</loc>
    <lastmod>2026-07-30T04:13:47.540Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-installation-hybridconnectionmanager-event-id-4697-0ee4d8a5</loc>
    <lastmod>2026-07-30T04:13:42.261Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-nofilter-execution-via-ronpolicy-filtering-platform-indi-7b14c76a</loc>
    <lastmod>2026-07-30T04:13:40.758Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-edrsilencer-execution-via-filtering-platform-filter-added-98054878</loc>
    <lastmod>2026-07-30T04:13:37.108Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4720-hidden-local-user-account-creation-7b449a5e</loc>
    <lastmod>2026-07-30T04:13:35.501Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-detection-gpo-scheduled-task-persistence-via-sysvol-sched-a8f29a7b</loc>
    <lastmod>2026-07-30T04:13:33.240Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-log-usb-mass-storage-or-diskdrive-device-recognition-event-id-6-f69a87ea</loc>
    <lastmod>2026-07-30T04:13:31.679Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-dpapi-domain-master-key-backup-attempt-event-id-4692-39a94fd1</loc>
    <lastmod>2026-07-30T04:13:29.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-log-dpapi-domain-backup-key-extraction-via-lsa-secret-access-4ac1f50b</loc>
    <lastmod>2026-07-30T04:13:28.142Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-etw-disabled-for-net-via-complus-or-etwenabled-a4c90ea1</loc>
    <lastmod>2026-07-30T04:13:26.634Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4719-important-audit-policy-categories-disabled-ab4561b1</loc>
    <lastmod>2026-07-30T04:13:24.490Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-log-auditing-disabled-via-windows-audit-policy-change-event-id--69aeb277</loc>
    <lastmod>2026-07-30T04:13:22.238Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-log-device-installation-blocked-by-system-policy-event-id-6423-c9eb55c3</loc>
    <lastmod>2026-07-30T04:13:19.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-5136-default-domain-gpo-container-modification-e5ac86dd</loc>
    <lastmod>2026-07-30T04:13:18.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4662-detects-mimikatz-style-dc-sync-directory-replication-acces-611eab06</loc>
    <lastmod>2026-07-30T04:13:16.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-remote-dcom-ie-iertutil-dll-dll-hijack-via-network-file-write-5-c39f0c81</loc>
    <lastmod>2026-07-30T04:13:14.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-failed-code-integrity-checks-event-ids-5038-and-6281-470ec5fa</loc>
    <lastmod>2026-07-30T04:13:11.498Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4697-detects-suspicious-service-installations-with-c2-pow-d7a95147</loc>
    <lastmod>2026-07-30T04:13:09.900Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-processes-accessing-microphone-and-webcam-capability-consent-stores-8cd538a4</loc>
    <lastmod>2026-07-30T04:13:07.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-and-eventlog-clear-activity-event-ids-517-1102-d99b79d2</loc>
    <lastmod>2026-07-30T04:13:05.449Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ruler-tool-activity-on-windows-security-event-4776-and-4624-4625-24549159</loc>
    <lastmod>2026-07-30T04:13:02.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4738-kerberoast-risk-via-weak-encryption-enabled-uac-change-f6de9536</loc>
    <lastmod>2026-07-30T04:13:00.155Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-ad-user-backdoor-via-delegation-attributes-4738-5136-300bac00</loc>
    <lastmod>2026-07-30T04:12:52.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-seenabledelegationprivilege-assigned-via-ad-event-id-470-311b6ce2</loc>
    <lastmod>2026-07-30T04:12:50.853Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-access-to-admin-network-share-via-event-id-5140-098d7118</loc>
    <lastmod>2026-07-30T04:12:49.167Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-computer-added-or-removed-from-domain-controller-20d96d95</loc>
    <lastmod>2026-07-30T04:12:47.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-adcs-certificate-template-changes-with-risky-eku-and-enrollee-provided-s-bfbd3291</loc>
    <lastmod>2026-07-30T04:12:45.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ad-cs-detect-enrollment-template-using-ct-flag-enrollee-supplies-subject-5ee3a654</loc>
    <lastmod>2026-07-30T04:12:42.889Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4662-detects-ad-user-object-property-reads-from-non-machine-acc-ab6bffca</loc>
    <lastmod>2026-07-30T04:12:41.169Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4662-active-directory-replication-request-from-non-machine-acco-17d619c1</loc>
    <lastmod>2026-07-30T04:12:39.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-write-dac-changes-on-active-directory-domain-objects-ds--028c7842</loc>
    <lastmod>2026-07-30T04:12:37.542Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-privileged-user-group-sid-reconnaissance-via-sam-auditing-4661-35ba1d85</loc>
    <lastmod>2026-07-30T04:12:35.823Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detects-dcsync-extended-right-ace-changes-eventid-5136-via-powe-2c99737c</loc>
    <lastmod>2026-07-30T04:12:33.888Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-registry-access-to-azure-ad-health-agent-keys-1d2ab8ac</loc>
    <lastmod>2026-07-30T04:12:31.890Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-detection-access-to-azure-ad-health-monitoring-agent-regi-ff151c33</loc>
    <lastmod>2026-07-30T04:12:30.026Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wfp-blocked-connection-involving-edr-agent-binaries-bacf58c6</loc>
    <lastmod>2026-07-30T04:12:28.403Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-successful-logons-triggered-by-wmi-wmiprvse-exe-5af54681</loc>
    <lastmod>2026-07-30T04:12:26.703Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4624-logon-type-3-anonymous-local-ip-rottenpotato-like-pattern-16f5d8ca</loc>
    <lastmod>2026-07-30T04:12:24.851Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detects-suspicious-local-kerberos-logon-of-built-in-administrator-potent-749c9f5e</loc>
    <lastmod>2026-07-30T04:12:22.819Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4624-logontype-9-using-new-credentials-def8b624</loc>
    <lastmod>2026-07-30T04:12:20.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-failed-logons-from-public-ip-addresses-f88e112a</loc>
    <lastmod>2026-07-30T04:12:19.270Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-successful-smb-logon-event-id-4624-logontype-3-from-public-ips-78d5cab4</loc>
    <lastmod>2026-07-30T04:12:17.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-successful-logon-from-public-ip-event-id-4624-logontype-10-259a9cdf</loc>
    <lastmod>2026-07-30T04:12:15.862Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-logs-security-enabled-global-group-deletion-event-id-4730-634-b237c54b</loc>
    <lastmod>2026-07-30T04:12:14.010Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-logon-from-localhost-ip-127-0-0-1-1-51e33403</loc>
    <lastmod>2026-07-30T04:12:12.505Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-pass-the-hash-via-4624-logontype-3-9-ntlmssp-seclogo-8eef149c</loc>
    <lastmod>2026-07-30T04:12:10.804Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-successful-logon-type-9-newcredentials-via-negotiate-and-seclogo-192a0330</loc>
    <lastmod>2026-07-30T04:12:09.116Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-member-removed-from-a-security-enabled-global-group-02c39d30</loc>
    <lastmod>2026-07-30T04:12:06.681Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-log-member-added-to-security-enabled-global-group-4728-632-c43c26be</loc>
    <lastmod>2026-07-30T04:12:04.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-diagtrackeop-default-logon-username-eventid-4624-logontype-9-2111118f</loc>
    <lastmod>2026-07-30T04:12:03.097Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-admin-account-remote-logon-event-id-4624-logontype-10-0f63e1ef</loc>
    <lastmod>2026-07-30T04:12:01.346Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-potential-access-token-abuse-via-new-credentials-impersonation-02f7c9c1</loc>
    <lastmod>2026-07-30T04:11:59.406Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-openssh-server-starts-listening-on-ssh-socket-3ce8e9a4</loc>
    <lastmod>2026-07-30T04:11:57.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ntlm-logon-to-termsrv-target-not-domain-associated-host-ce5678bb</loc>
    <lastmod>2026-07-30T04:11:56.190Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ntlm-brute-force-via-common-spoofed-workstationname-values-9c8acf1a</loc>
    <lastmod>2026-07-30T04:11:54.393Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ntlm-logon-event-id-8002-98c3bcf1</loc>
    <lastmod>2026-07-30T04:11:52.736Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msexchange-management-failed-transport-agent-installation-install-transp-c7d16cae</loc>
    <lastmod>2026-07-30T04:11:51.254Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msexchange-management-transport-agent-installation-via-install-transport-4fe151c2</loc>
    <lastmod>2026-07-30T04:11:49.641Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-exchange-management-set-oabvirtualdirectory-externalurl-script-injecti-9db37458</loc>
    <lastmod>2026-07-30T04:11:48.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/exchange-management-remove-mailboxexportrequest-triggered-with-confirm-false-09570ae5</loc>
    <lastmod>2026-07-30T04:11:46.244Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-exchange-powershell-mailbox-export-to-unc-path-with-aspx-or-role-assig-516376b4</loc>
    <lastmod>2026-07-30T04:11:44.382Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/exchange-certificate-export-writes-csr-to-web-server-paths-or-aspx-suffixes-b7bc7038</loc>
    <lastmod>2026-07-30T04:11:42.698Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msexchange-management-post-proxylogon-set-oabvirtualdirectory-with-suspi-550d3350</loc>
    <lastmod>2026-07-30T04:11:40.904Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsa-event-300-standard-user-added-to-privileged-groups-administrator-adm-7ac407cc</loc>
    <lastmod>2026-07-30T04:11:39.327Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ldap-recon-detect-ad-enumeration-via-ldap-search-filters-event-id-30-31d68132</loc>
    <lastmod>2026-07-30T04:11:37.489Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-module-removal-via-iis-configuration-event-id-29-9e1a1fdf</loc>
    <lastmod>2026-07-30T04:11:35.673Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-new-http-module-added-via-iis-configuration-eventid-29-dd857d3e</loc>
    <lastmod>2026-07-30T04:11:34.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/iis-http-logging-disabled-via-system-webserver-httplogging-configuration-change-e8ebd53a</loc>
    <lastmod>2026-07-30T04:11:32.476Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-iis-configuration-change-disables-etw-logging-processing-option-a5b40a90</loc>
    <lastmod>2026-07-30T04:11:30.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-configuration-changed-event-ids-2002-2003-2008-2082-2083-00bb5bd5</loc>
    <lastmod>2026-07-30T04:11:29.341Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-firewall-reset-to-default-configuration-firewall-as-log-04b60639</loc>
    <lastmod>2026-07-30T04:11:27.614Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-service-failed-to-load-group-policy-event-id-2009-7ec15688</loc>
    <lastmod>2026-07-30T04:11:26.275Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-exception-rule-deletion-eventid-2006-2052-c187c075</loc>
    <lastmod>2026-07-30T04:11:24.739Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-rules-deleted-event-id-2033-2059-indicating-defense-impairment-79609c82</loc>
    <lastmod>2026-07-30T04:11:23.042Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-allow-rule-added-via-wmiprvse-exe-eca81e8d</loc>
    <lastmod>2026-07-30T04:11:21.428Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-exception-rule-added-for-application-in-suspicious-file-locatio-9e2575e7</loc>
    <lastmod>2026-07-30T04:11:18.857Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-exception-rule-added-unusual-via-firewall-as-events-cde0a575</loc>
    <lastmod>2026-07-30T04:11:17.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-usb-device-plugged-unplugged-events-driver-framework-user-mode-1a4bd6e3</loc>
    <lastmod>2026-07-30T04:11:15.665Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-server-plugin-dll-load-failure-serverlevelplugindll-via-dns-server-e-cbe51394</loc>
    <lastmod>2026-07-30T04:11:13.896Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-server-failed-dns-zone-transfer-event-id-6004-6d444368</loc>
    <lastmod>2026-07-30T04:11:11.891Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-client-detect-dns-queries-containing-ufile-io-090ffaad</loc>
    <lastmod>2026-07-30T04:11:10.321Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-client-query-for-tor-onion-or-tor2web-hidden-service-domains-8384bd26</loc>
    <lastmod>2026-07-30T04:11:08.834Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-client-queries-for-put-io-api-put-io-or-upload-put-io-8b69fd42</loc>
    <lastmod>2026-07-30T04:11:07.234Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-client-queries-for-mega-userstorage-subdomains-66474410</loc>
    <lastmod>2026-07-30T04:11:05.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cobalt-strike-dns-beaconing-via-windows-dns-client-event-id-3008-0d18728b</loc>
    <lastmod>2026-07-30T04:11:04.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-client-queryname-contains-anonfiles-com-29f171d7</loc>
    <lastmod>2026-07-30T04:11:02.077Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-kernel-module-loaded-despite-unmet-whql-requirements-even-2f8cd7a0</loc>
    <lastmod>2026-07-30T04:10:58.989Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-unsigned-image-loaded-event-id-3037-c92c24e7</loc>
    <lastmod>2026-07-30T04:10:57.053Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-unsigned-kernel-module-loaded-event-id-3001-951f8d29</loc>
    <lastmod>2026-07-30T04:10:55.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-revoked-image-loaded-events-3032-3035-881b7725</loc>
    <lastmod>2026-07-30T04:10:53.961Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-blocked-file-image-load-due-to-revoked-signing-certificat-6f156c48</loc>
    <lastmod>2026-07-30T04:10:52.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-operational-revoked-kernel-driver-loaded-event-id-3021-30-320fccbf</loc>
    <lastmod>2026-07-30T04:10:50.783Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-blocks-revoked-driver-loads-event-id-3023-9b72b82d</loc>
    <lastmod>2026-07-30T04:10:49.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-blocked-image-driver-load-due-to-signing-level-or-policy--e4be5675</loc>
    <lastmod>2026-07-30T04:10:47.406Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-blocked-disallowed-file-for-protected-processes-event-id--5daf11c3</loc>
    <lastmod>2026-07-30T04:10:45.668Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-integrity-operational-logs-file-load-rejected-for-unsatisfied-signi-f8931561</loc>
    <lastmod>2026-07-30T04:10:42.939Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-certificate-services-client-exported-certificate-from-local-store-58c0bff0</loc>
    <lastmod>2026-07-30T04:10:41.240Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-capi2-acquire-certificate-private-key-eventid-70-e2b5163d</loc>
    <lastmod>2026-07-30T04:10:39.830Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bits-client-job-downloads-to-suspicious-saved-file-locations-f8a56cb7</loc>
    <lastmod>2026-07-30T04:10:38.345Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bits-transfer-job-using-uncommon-or-suspicious-remote-domain-6d44fb93</loc>
    <lastmod>2026-07-30T04:10:36.788Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bits-client-job-downloads-from-direct-ip-addresses-90f138c1</loc>
    <lastmod>2026-07-30T04:10:35.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bits-client-download-from-file-sharing-domains-d635249d</loc>
    <lastmod>2026-07-30T04:10:33.210Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bits-transfer-job-writing-files-with-suspicious-executable-extensions-b85e5894</loc>
    <lastmod>2026-07-30T04:10:31.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-created-new-bits-job-event-id-3-fe3a2d49</loc>
    <lastmod>2026-07-30T04:10:29.868Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-bits-job-created-via-bitsadmin-exe-bits-client-eventid-3-1ff315dc</loc>
    <lastmod>2026-07-30T04:10:28.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-packaging-execute-packages-signed-with-a-known-suspicious-certifica-b5aa7d60</loc>
    <lastmod>2026-07-30T04:10:26.574Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-deployment-server-installs-unsigned-msix-appx-with-allowunsigned-9a025188</loc>
    <lastmod>2026-07-30T04:10:25.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-msix-full-trust-package-installation-via-appxdeployment-server-e54279c7</loc>
    <lastmod>2026-07-30T04:10:23.402Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-deployment-server-uncommon-appx-path-added-to-processing-pipeline-c977cb50</loc>
    <lastmod>2026-07-30T04:10:21.767Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-package-deployment-blocked-by-local-policy-appxdeployment-server-e021bbb5</loc>
    <lastmod>2026-07-30T04:10:19.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-appx-package-installation-attempts-on-windows-via-appx-deployment-ser-09d3b48b</loc>
    <lastmod>2026-07-30T04:10:18.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-deployment-app-package-from-common-staging-directories-added-to-pro-5cdeaf3d</loc>
    <lastmod>2026-07-30T04:10:16.571Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-deployment-fails-due-to-unsatisfied-signing-requirements-0x80073cff-898d5fc9</loc>
    <lastmod>2026-07-30T04:10:14.811Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-deployment-server-remote-appx-package-downloaded-from-file-sharing--8b48ad89</loc>
    <lastmod>2026-07-30T04:10:13.114Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-appx-package-deployment-blocked-by-applocker-appxdeployment-server-event-6ae53108</loc>
    <lastmod>2026-07-30T04:10:11.300Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-sysinternals-tools-via-appx-package-d29a20b2</loc>
    <lastmod>2026-07-30T04:10:09.455Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-applocker-audit-only-events-indicate-would-be-blocked-executions-557e3bd3</loc>
    <lastmod>2026-07-30T04:10:07.901Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-applocker-blocked-application-script-msi-or-packaged-app-execution-401e5d00</loc>
    <lastmod>2026-07-30T04:10:06.327Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-error-reporting-msmpeng-exe-crash-involving-mpengine-dll-eventid-1001-6c82cf5c</loc>
    <lastmod>2026-07-30T04:10:04.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/screenconnect-rmm-file-transfer-activity-on-windows-event-id-201-5d19eb78</loc>
    <lastmod>2026-07-30T04:10:02.937Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-remote-command-execution-via-application-event-200-076ebe48</loc>
    <lastmod>2026-07-30T04:10:01.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-xp-cmdshell-configuration-change-event-id-15457-d08dd86f</loc>
    <lastmod>2026-07-30T04:09:59.263Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-xp-cmdshell-execution-via-eventid-33205-7f103213</loc>
    <lastmod>2026-07-30T04:09:57.590Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mssql-sp-procoption-startup-execution-changed-via-exec-eventid-33205-b3d57a5c</loc>
    <lastmod>2026-07-30T04:09:55.113Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-failed-logons-event-id-18456-from-external-client-ips-ebfe73c2</loc>
    <lastmod>2026-07-30T04:09:53.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-failed-logon-event-id-18456-via-application-provider-name-218d2855</loc>
    <lastmod>2026-07-30T04:09:51.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-audit-policy-tampering-via-alter-drop-server-audit-350dfb37</loc>
    <lastmod>2026-07-30T04:09:49.801Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-server-audit-destructive-sql-statements-drop-truncate-00321fee</loc>
    <lastmod>2026-07-30T04:09:47.834Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-add-member-to-sysadmin-role-server-role-alter-eventid-33205-08200f85</loc>
    <lastmod>2026-07-30T04:09:46.063Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-successful-installation-of-atera-remote-monitoring-agent-via-msi-87261fb2</loc>
    <lastmod>2026-07-30T04:09:44.316Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msiinstaller-installs-a-remote-msi-from-a-url-5594e67a</loc>
    <lastmod>2026-07-30T04:09:42.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-installer-application-removal-msiinstaller-event-1034-11724-570ae5ec</loc>
    <lastmod>2026-07-30T04:09:39.149Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-blocked-application-access-enforced-by-software-restriction-polic-b4c8da4a</loc>
    <lastmod>2026-07-30T04:09:37.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-backup-catalog-deletion-microsoft-windows-backup-event-524-9703792d</loc>
    <lastmod>2026-07-30T04:09:35.857Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-application-audit-cve-microsoft-windows-audit-cve-eventid-1-from-cveeven-48d91a3a</loc>
    <lastmod>2026-07-30T04:09:34.365Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-esent-new-database-creation-for-ntds-dit-in-suspicious-paths-94dc4390</loc>
    <lastmod>2026-07-30T04:09:32.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ntdsutil-abuse-via-esent-events-containing-ntds-dit-e6e88853</loc>
    <lastmod>2026-07-30T04:09:30.549Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-microsoft-malware-protection-engine-msmpeng-exe-crash-events-545a5da6</loc>
    <lastmod>2026-07-30T04:09:28.207Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-application-error-lsass-lsass-exe-crash-events-event-id-1000-a18e0862</loc>
    <lastmod>2026-07-30T04:09:26.122Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-application-log-antivirus-signature-and-malware-keyword-matches-78bc5783</loc>
    <lastmod>2026-07-30T04:09:24.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-xss-payload-strings-in-get-request-urls-access-logs-65354b83</loc>
    <lastmod>2026-07-30T04:09:22.449Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-log-detection-for-windows-webshell-command-strings-in-get-parameters-7ff9db12</loc>
    <lastmod>2026-07-30T04:09:20.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-log-detection-of-regeorg-webshell-http-post-probing-uri-query-2ea44a60</loc>
    <lastmod>2026-07-30T04:09:19.321Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detect-suspicious-windows-path-strings-in-web-uri-query-windows-exfil-webshell-c-9f6a34b4</loc>
    <lastmod>2026-07-30T04:09:17.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detection-user-agent-contains-known-recon-and-scanning-tool-strings-19aa4f58</loc>
    <lastmod>2026-07-30T04:09:15.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/web-server-ssti-probe-strings-in-get-requests-ada3bc4f</loc>
    <lastmod>2026-07-30T04:09:14.196Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detect-potential-sql-injection-payloads-in-http-get-uris-webserver-logs-5513deaf</loc>
    <lastmod>2026-07-30T04:09:12.601Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-url-keyword-match-for-source-code-enumeration-via-git-paths-953d460b</loc>
    <lastmod>2026-07-30T04:09:10.970Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-path-traversal-exploitation-attempts-via-suspicious-uri-query-encoding-7745c2ea</loc>
    <lastmod>2026-07-30T04:09:09.340Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detection-for-jndi-exploit-kit-exploit-and-memshell-url-path-patterns-412d55bc</loc>
    <lastmod>2026-07-30T04:09:07.708Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/java-payload-indicators-in-web-access-logs-583aa0a2</loc>
    <lastmod>2026-07-30T04:09:06.015Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/successful-iis-shortname-fuzzing-scans-via-1-and-a-aspx-probe-http-7cb02516</loc>
    <lastmod>2026-07-30T04:09:04.460Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/f5-big-ip-icontrol-rest-api-bash-endpoint-command-execution-via-webserver-post-85254a62</loc>
    <lastmod>2026-07-30T04:09:02.825Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-external-webdav-downloads-leading-to-execution-via-proxy-logs-1ae64f96</loc>
    <lastmod>2026-07-30T04:09:01.095Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-user-agent-ending-with-indicating-potential-base64-encoding-894a8613</loc>
    <lastmod>2026-07-30T04:08:59.578Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-and-malformed-user-agent-strings-in-proxy-logs-7195a772</loc>
    <lastmod>2026-07-30T04:08:58.188Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-logs-rclone-user-agent-activity-via-default-rclone-v-prefix-2c03648b</loc>
    <lastmod>2026-07-30T04:08:56.276Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-web-access-user-agent-in-proxy-logs-c8557060</loc>
    <lastmod>2026-07-30T04:08:54.685Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-malware-user-agent-strings-in-proxy-logs-5c84856b</loc>
    <lastmod>2026-07-30T04:08:53.043Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-logs-suspicious-hack-tool-user-agent-strings-c42a3073</loc>
    <lastmod>2026-07-30T04:08:51.409Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-exploit-framework-user-agent-strings-in-proxy-logs-fdd1bfb5</loc>
    <lastmod>2026-07-30T04:08:49.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-http-requests-with-empty-user-agent-header-21e44d78</loc>
    <lastmod>2026-07-30T04:08:48.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-proxy-user-agents-for-crypto-miners-xmrig-ccminer-fa935401</loc>
    <lastmod>2026-07-30T04:08:46.549Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-bits-proxy-requests-to-uncommon-tlds-9eb68894</loc>
    <lastmod>2026-07-30T04:08:45.037Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-bits-proxy-traffic-to-ip-like-hostnames-uncommon-server-address-8ccd35a2</loc>
    <lastmod>2026-07-30T04:08:43.362Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-traffic-with-suspicious-base64-encoded-user-agent-prefixes-d443095b</loc>
    <lastmod>2026-07-30T04:08:36.668Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-apt-related-user-agent-strings-in-proxy-logs-6ec820f2</loc>
    <lastmod>2026-07-30T04:08:35.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-telegram-api-proxy-requests-without-telegram-user-agent-b494b165</loc>
    <lastmod>2026-07-30T04:08:33.128Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-requests-to-ipfs-urls-containing-email-addresses-eb6c2004</loc>
    <lastmod>2026-07-30T04:08:31.579Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-activity-flash-player-update-download-from-non-adobe-host-4922a5dd</loc>
    <lastmod>2026-07-30T04:08:29.913Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-requests-to-raw-paste-service-endpoints-5468045b</loc>
    <lastmod>2026-07-30T04:08:28.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-activity-download-requests-to-pwndrop-pwndrp-web-server-2b1ee7e4</loc>
    <lastmod>2026-07-30T04:08:26.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/advanced-ip-port-scanner-update-check-over-http-proxy-1a9bb21a</loc>
    <lastmod>2026-07-30T04:08:24.925Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-detects-empire-style-user-agent-with-post-to-common-php-admin-auth-paths-b923f7d6</loc>
    <lastmod>2026-07-30T04:08:23.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-traffic-matches-cobalt-strike-malleable-profile-indicators-uri-user-agent--f3f21ce1</loc>
    <lastmod>2026-07-30T04:08:21.538Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/babyshark-agent-default-c2-url-query-string-pattern-proxy-logs-304810ed</loc>
    <lastmod>2026-07-30T04:08:14.130Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-traffic-with-hello-world-1-0-user-agent-using-get-1712bafe</loc>
    <lastmod>2026-07-30T04:08:12.218Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/f5-big-ip-icontrol-rest-api-bash-endpoint-command-execution-via-post-proxy-b59c98c6</loc>
    <lastmod>2026-07-30T04:08:10.652Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-webdav-downloader-activity-via-proxy-user-agent-and-http-get-e09aed7a</loc>
    <lastmod>2026-07-30T04:08:09.055Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-flag-executable-downloads-from-non-whitelisted-suspicious-tlds-b5de2919</loc>
    <lastmod>2026-07-30T04:08:07.112Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-suspicious-tld-downloads-of-executable-and-office-file-types-00d0b5ab</loc>
    <lastmod>2026-07-30T04:08:05.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-downloads-of-executable-and-script-files-from-suspicious-dynamic-dns-hosts-195c1119</loc>
    <lastmod>2026-07-30T04:08:02.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/nginx-worker-core-dump-indicating-crash-or-possible-exploitation-59ec40bb</loc>
    <lastmod>2026-07-30T04:08:00.888Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/apache-error-log-threading-assertion-detected-e9a2b582</loc>
    <lastmod>2026-07-30T04:07:59.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/apache-service-crashes-segmentation-fault-message-in-apache-error-logs-1da8ce0b</loc>
    <lastmod>2026-07-30T04:07:57.685Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-smb-files-network-share-transfers-of-credential-related-file-names-2e69f167</loc>
    <lastmod>2026-07-30T04:07:54.077Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-smb-file-activity-access-to-sensitive-email-database-backup-and-credential--286b47ed</loc>
    <lastmod>2026-07-30T04:07:52.260Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-smb-files-impacket-secretdump-activity-via-admin-and-system32-tmp-drops-92dae1ed</loc>
    <lastmod>2026-07-30T04:07:45.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-rdp-connections-from-non-routable-public-ip-ranges-1fc0809e</loc>
    <lastmod>2026-07-30T04:07:42.745Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-http-webdav-user-agent-with-put-method-to-local-network-705072a5</loc>
    <lastmod>2026-07-30T04:07:40.459Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-http-requests-to-low-reputation-tlds-or-suspicious-executable-file-types-68c2c604</loc>
    <lastmod>2026-07-30T04:07:38.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-http-executable-download-over-webdav-by-detecting-webdav-user-agent-uri-and-aac2fd97</loc>
    <lastmod>2026-07-30T04:07:36.226Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dns-queries-to-tor-proxy-and-onion-domain-indicators-a8322756</loc>
    <lastmod>2026-07-30T04:07:34.382Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dns-nkn-seed-domain-lookups-for-potential-c2-over-nkn-org-fa7703d6</loc>
    <lastmod>2026-07-30T04:07:30.735Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dns-lookups-for-known-cryptocurrency-mining-pool-domains-bf74135c</loc>
    <lastmod>2026-07-30T04:07:29.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dns-detection-of-suspicious-kerberos-coercion-pattern-in-query-payload-5588576c</loc>
    <lastmod>2026-07-30T04:07:27.145Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-x509-default-cobalt-strike-certificate-serial-in-https-traffic-7100f7e3</loc>
    <lastmod>2026-07-30T04:07:25.599Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-smb-files-spoolss-named-pipe-access-via-ipc-bae2865c</loc>
    <lastmod>2026-07-30T04:07:24.101Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dce-rpc-encrypting-file-system-efs-rpc-operations-starting-with-efs-4096842a</loc>
    <lastmod>2026-07-30T04:07:22.649Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dce-rpc-indicators-of-windows-persistence-via-rpc-printer-logon-functions-53389db6</loc>
    <lastmod>2026-07-30T04:07:20.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dce-rpc-execution-indicators-via-jobadd-task-scheduler-wmi-and-service-cont-b640c0b8</loc>
    <lastmod>2026-07-30T04:07:18.397Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/juniper-bgp-missing-md5-digest-a7c0ae48</loc>
    <lastmod>2026-07-30T04:07:16.494Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/huawei-bgp-authentication-failure-events-a557ffe6</loc>
    <lastmod>2026-07-30T04:07:14.773Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-vpn-ssl-settings-edited-via-event-logs-8b5dacf2</loc>
    <lastmod>2026-07-30T04:07:13.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-user-group-edited-vpn-access-impact-69ffc84e</loc>
    <lastmod>2026-07-30T04:07:11.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-event-addition-of-vpn-ssl-web-portal-2bfb6216</loc>
    <lastmod>2026-07-30T04:07:10.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-local-user-added-user-local-via-event-logs-ddbbe845</loc>
    <lastmod>2026-07-30T04:07:09.037Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-new-firewall-policy-added-via-event-logs-f24ab7a8</loc>
    <lastmod>2026-07-30T04:07:07.171Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-firewall-address-object-added-5c8d7b41</loc>
    <lastmod>2026-07-30T04:07:05.533Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-administrator-account-added-via-system-admin-event-cd0a4943</loc>
    <lastmod>2026-07-30T04:07:04.053Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/firewall-logs-cleartext-protocol-traffic-to-common-service-ports-d7fb8f0e</loc>
    <lastmod>2026-07-30T04:07:02.482Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detect-wannacry-killswitch-domains-in-dns-queries-3eaf6218</loc>
    <lastmod>2026-07-30T04:07:00.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dns-txt-responses-containing-command-execution-strings-powershell-windows-8ae51330</loc>
    <lastmod>2026-07-30T04:06:59.593Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dns-queries-to-api-telegram-org-from-telegram-bot-api-clients-c64c5175</loc>
    <lastmod>2026-07-30T04:06:57.993Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-queries-containing-base64-delimiters-4153a907</loc>
    <lastmod>2026-07-30T04:06:56.216Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-lookups-for-monero-mining-pool-domains-b593fd50</loc>
    <lastmod>2026-07-30T04:06:54.382Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-beaconing-patterns-indicative-of-cobalt-strike-dns-2975af79</loc>
    <lastmod>2026-07-30T04:06:53.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dns-queries-to-oast-callback-service-domains-external-dns-interactions-aff715fa</loc>
    <lastmod>2026-07-30T04:06:51.456Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-ldp-authentication-failures-indicating-tcp-md5-auth-rejects-50e606bf</loc>
    <lastmod>2026-07-30T04:06:49.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-bgp-authentication-failures-on-tcp-179-56fa3cd6</loc>
    <lastmod>2026-07-30T04:06:48.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-aaa-monitor-span-rspan-capture-point-commands-b9e1f193</loc>
    <lastmod>2026-07-30T04:06:46.762Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-aaa-stage-data-using-tftp-rcp-copy-and-archive-commands-5e51acb2</loc>
    <lastmod>2026-07-30T04:06:45.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-aaa-cli-configuration-commands-http-https-kron-acl-ntp-modification-671ffc77</loc>
    <lastmod>2026-07-30T04:06:43.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-aaa-local-account-creation-modification-and-remote-authentication-configur-6d844f0f</loc>
    <lastmod>2026-07-30T04:06:41.539Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-aaa-captures-show-history-and-show-logging-command-input-b094d9fb</loc>
    <lastmod>2026-07-30T04:06:39.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-aaa-file-deletion-activity-via-erase-delete-or-format-keywords-71d65515</loc>
    <lastmod>2026-07-30T04:06:38.233Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-ios-ios-xe-aaa-logs-manual-802-1x-dot1x-port-authentication-disabled-ef0ff092</loc>
    <lastmod>2026-07-30T04:06:36.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-aaa-commands-triggering-shutdown-or-boot-mode-via-config-register-values-d94a35f0</loc>
    <lastmod>2026-07-30T04:06:34.575Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-aaa-command-keyword-discovery-via-show-and-dir-9705a6a1</loc>
    <lastmod>2026-07-30T04:06:32.709Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-aaa-logging-disabled-via-no-logging-and-no-aaa-new-model-9e8f6035</loc>
    <lastmod>2026-07-30T04:06:31.030Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-ios-aaa-crypto-pki-commands-for-key-export-or-certificate-import-1f978c6a</loc>
    <lastmod>2026-07-30T04:06:29.278Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-ios-command-output-collection-via-config-display-commands-cd072b25</loc>
    <lastmod>2026-07-30T04:06:27.811Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-network-os-clear-logging-commands-detected-aaa-ceb407f6</loc>
    <lastmod>2026-07-30T04:06:26.123Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-xcsset-infection-indicators-from-bash-launched-curl-osacompile-plutil-and--47d65ac0</loc>
    <lastmod>2026-07-30T04:06:24.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-gatekeeper-bypass-attempt-using-xattr-to-remove-com-apple-quarantine-f5141b6d</loc>
    <lastmod>2026-07-30T04:06:22.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-execution-indicators-for-wizardupdate-associated-malware-f68c4a4f</loc>
    <lastmod>2026-07-30T04:06:21.004Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detect-tmutil-adding-time-machine-exclusions-addexclusion-9acf45ed</loc>
    <lastmod>2026-07-30T04:06:19.336Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-disabling-time-machine-via-tmutil-process-execution-2c95fa8a</loc>
    <lastmod>2026-07-30T04:06:17.769Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-tmutil-time-machine-backup-deletion-command-attempt-452df256</loc>
    <lastmod>2026-07-30T04:06:16.105Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-bash-pipeline-tail-extracting-data-from-image-and-base64-decoding-output-09a910bf</loc>
    <lastmod>2026-07-30T04:06:14.578Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-creation-for-shutdown-reboot-or-halt-commands-40b1fbe2</loc>
    <lastmod>2026-07-30T04:06:12.731Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-discovery-via-system-profiler-with-targeted-data-types-4809c683</loc>
    <lastmod>2026-07-30T04:06:11.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-system-network-connections-discovery-via-who-w-last-lsof-netstat-9a7a0393</loc>
    <lastmod>2026-07-30T04:06:09.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-sysctl-execution-for-system-hardware-kernel-discovery-6ff08e55</loc>
    <lastmod>2026-07-30T04:06:07.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-sysadminctl-used-to-enable-guest-account-d7329412</loc>
    <lastmod>2026-07-30T04:06:06.163Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-sysadminctl-used-to-add-user-to-admin-group-652c098d</loc>
    <lastmod>2026-07-30T04:06:04.409Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-system-information-discovery-via-sw-vers-with-product-build-version-flags-5de06a6f</loc>
    <lastmod>2026-07-30T04:06:02.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detect-applet-osascript-execution-of-osacompile-via-process-command-line-a753a6af</loc>
    <lastmod>2026-07-30T04:06:01.053Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-local-network-discovery-via-network-configuration-commands-58800443</loc>
    <lastmod>2026-07-30T04:05:58.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-firmwarepasswd-password-manipulation-via-setpasswd-full-delete-check-7ed2c9f7</loc>
    <lastmod>2026-07-30T04:05:55.808Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-in-memory-download-and-compile-via-curl-and-osacompile-13db8d2e</loc>
    <lastmod>2026-07-30T04:05:54.098Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-creation-command-line-access-or-modification-of-shell-history-file-508a9374</loc>
    <lastmod>2026-07-30T04:05:52.095Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-execution-of-find-with-setuid-setgid-or-world-writable-permission--85de3a19</loc>
    <lastmod>2026-07-30T04:05:50.286Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-script-editor-spawning-unusual-processes-curl-shells-scripting-runtimes-6e4dcdd1</loc>
    <lastmod>2026-07-30T04:05:48.377Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-spawned-by-browsers-on-macos-via-shell-and-script-runti-0250638a</loc>
    <lastmod>2026-07-30T04:05:46.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-creation-of-split-used-to-divide-files-into-pieces-7f2bb9d5</loc>
    <lastmod>2026-07-30T04:05:44.743Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-command-line-and-image-with-trailing-space-after-filename-b6e2a2e3</loc>
    <lastmod>2026-07-30T04:05:43.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-security-tool-discovery-via-grep-of-known-agent-and-firewall-strings-0ed75b9c</loc>
    <lastmod>2026-07-30T04:05:40.673Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-creation-screencapture-used-for-screenshot-collection-0877ed01</loc>
    <lastmod>2026-07-30T04:05:38.837Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-cron-job-abuse-via-tmp-crontab-entries-7c3b43d8</loc>
    <lastmod>2026-07-30T04:05:37.256Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-remote-system-discovery-via-arp-or-ping-enumeration-10227522</loc>
    <lastmod>2026-07-30T04:05:35.511Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-execution-teamviewer-session-command-line-via-teamviewer-service-f459ccb4</loc>
    <lastmod>2026-07-30T04:05:34.008Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-meshagent-execution-with-renamed-instance-via-meshservicename-bd3b5eaa</loc>
    <lastmod>2026-07-30T04:05:32.218Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detect-meshagent-remote-access-execution-via-meshservicename-22c45af6</loc>
    <lastmod>2026-07-30T04:05:30.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-persistence-attempts-using-plistbuddy-to-configure-launchagents-launchdaem-65d506d3</loc>
    <lastmod>2026-07-30T04:05:29.006Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-openssl-decodes-and-decrypts-payloads-from-mounted-dmg-volumes-234dc5df</loc>
    <lastmod>2026-07-30T04:05:27.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-creation-osacompile-run-only-execution-via-inline-e-script-b9d9b652</loc>
    <lastmod>2026-07-30T04:05:24.591Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-suspicious-shell-python-child-processes-spawned-by-microsoft-office-apps-69483748</loc>
    <lastmod>2026-07-30T04:05:22.970Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-nscurl-file-download-via-command-line-options-6d8a7cf1</loc>
    <lastmod>2026-07-30T04:05:21.113Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-creation-detect-tcpdump-tshark-network-sniffing-tool-usage-adc9bcc4</loc>
    <lastmod>2026-07-30T04:05:19.445Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-network-service-enumeration-via-nc-netcat-nmap-or-telnet-84bae5d4</loc>
    <lastmod>2026-07-30T04:05:18.016Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-local-groups-discovery-via-dscacheutil-cat-dscl-enumeration-89bb1f97</loc>
    <lastmod>2026-07-30T04:05:16.441Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-local-system-account-discovery-via-dscl-dscacheutil-id-lsof-who-and-relate-ddf36b67</loc>
    <lastmod>2026-07-30T04:05:14.789Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-launchctl-submits-loads-starts-launch-agents-and-daemons-via-process-execu-ae9d710f</loc>
    <lastmod>2026-07-30T04:05:12.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-jxa-in-memory-javascript-execution-via-osascript-f1408a58</loc>
    <lastmod>2026-07-30T04:05:11.130Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-jamf-cli-command-execution-for-account-mdm-and-framework-changes-be2e3a5c</loc>
    <lastmod>2026-07-30T04:05:09.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detect-suspicious-child-processes-spawned-by-jamf-2316929c</loc>
    <lastmod>2026-07-30T04:05:07.907Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-monitoring-for-i-o-kit-registry-discovery-via-ioreg-2d5e7a8b</loc>
    <lastmod>2026-07-30T04:05:06.466Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-installer-script-spawning-suspicious-child-interpreter-processes-e0cfaecd</loc>
    <lastmod>2026-07-30T04:05:04.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detect-hdiutil-disk-image-mounting-via-attach-or-mount-commands-bf241472</loc>
    <lastmod>2026-07-30T04:05:03.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-hdiutil-disk-image-creation-execution-1cf98dc2</loc>
    <lastmod>2026-07-30T04:05:01.610Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-osascript-display-dialog-prompts-for-credential-capture-60f1ce20</loc>
    <lastmod>2026-07-30T04:04:59.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-activity-grep-for-password-and-lazagne-credential-extraction-53b1b378</loc>
    <lastmod>2026-07-30T04:04:57.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-file-and-directory-discovery-via-system-utilities-089dbdf6</loc>
    <lastmod>2026-07-30T04:04:56.042Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-root-account-enable-via-dsenableroot-821bcf4d</loc>
    <lastmod>2026-07-30T04:04:54.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-dseditgroup-used-to-add-a-user-to-the-admin-group-5d0fdb62</loc>
    <lastmod>2026-07-30T04:04:52.556Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-dscl-used-to-append-user-to-groups-admin-group-b743623c</loc>
    <lastmod>2026-07-30T04:04:50.858Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-unloading-security-agents-via-launchctl-or-disabling-gatekeeper-ff39f1a6</loc>
    <lastmod>2026-07-30T04:04:49.194Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-csrutil-sip-status-enumeration-via-process-command-line-53821412</loc>
    <lastmod>2026-07-30T04:04:47.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-csrutil-used-to-disable-system-integrity-protection-sip-3603f18a</loc>
    <lastmod>2026-07-30T04:04:46.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-keychain-password-dumping-via-usr-bin-security-command-lines-b120b587</loc>
    <lastmod>2026-07-30T04:04:44.287Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-hidden-user-creation-via-dscl-uniqueid-500-or-ishidden-true-b22a5b36</loc>
    <lastmod>2026-07-30T04:04:42.288Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-local-user-account-creation-via-dscl-or-sysadminctl-51719bf5</loc>
    <lastmod>2026-07-30T04:04:40.493Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-osascript-clipboard-access-via-applescript-7794fa3c</loc>
    <lastmod>2026-07-30T04:04:38.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-indicator-removal-process-deletion-of-local-logs-via-rm-unlink-shred-acf61bd8</loc>
    <lastmod>2026-07-30T04:04:37.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-execution-of-chflags-to-set-hidden-file-flags-3b2c1059</loc>
    <lastmod>2026-07-30T04:04:35.614Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-touch-timestamp-attribute-modification-via-command-line-88c0f9d8</loc>
    <lastmod>2026-07-30T04:04:34.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detect-dd-and-truncate-usage-for-binary-padding-95361ce5</loc>
    <lastmod>2026-07-30T04:04:32.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-base64-decoding-via-usr-bin-base64-d-719c22d7</loc>
    <lastmod>2026-07-30T04:04:30.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-execution-of-osascript-running-applescript-scripts-1bc2e6c5</loc>
    <lastmod>2026-07-30T04:04:28.787Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-startup-item-plist-created-in-startupitems-directories-dfe8b941</loc>
    <lastmod>2026-07-30T04:04:26.752Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-emond-launch-daemon-persistence-via-new-rule-plist-files-23c43900</loc>
    <lastmod>2026-07-30T04:04:24.981Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-using-xterm-with-display-1-reverse-shell-indicator-4e25af4b</loc>
    <lastmod>2026-07-30T04:04:22.948Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-wget-downloaded-files-to-tmp-cf610c15</loc>
    <lastmod>2026-07-30T04:04:21.286Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-web-server-process-child-commands-indicative-of-webshell-activity-818f7b24</loc>
    <lastmod>2026-07-30T04:04:19.778Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-vim-gtfobin-abuse-via-process-execution-flags-and-shell-commands-7ab8f73a</loc>
    <lastmod>2026-07-30T04:04:17.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-usermod-adds-user-to-root-or-sudoers-group-via-ag-6a50f16c</loc>
    <lastmod>2026-07-30T04:04:16.218Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-userdel-execution-indicates-account-deletion-08f26069</loc>
    <lastmod>2026-07-30T04:04:14.642Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-of-triple-cross-ebpf-rootkit-install-commands-via-sudo-t-22236d75</loc>
    <lastmod>2026-07-30T04:04:13.229Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-execve-hijack-execution-via-sudo-0326c3c8</loc>
    <lastmod>2026-07-30T04:04:11.398Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-detect-touch-used-on-service-files-31545105</loc>
    <lastmod>2026-07-30T04:04:09.936Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-systemctl-mask-used-to-disable-power-management-targets-c172b7b5</loc>
    <lastmod>2026-07-30T04:04:07.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-system-network-discovery-via-firewall-netstat-route-and-interface-commands-e7bd1cfa</loc>
    <lastmod>2026-07-30T04:04:05.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-system-network-connections-discovery-via-who-w-last-lsof-netstat-4c519226</loc>
    <lastmod>2026-07-30T04:04:04.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-system-information-discovery-via-common-system-command-execution-42df45e7</loc>
    <lastmod>2026-07-30T04:04:02.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-script-execution-from-tmp-via-shell-c-30bcce26</loc>
    <lastmod>2026-07-30T04:04:00.744Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-shell-execution-where-parent-process-runs-from-tmp-2fade0b6</loc>
    <lastmod>2026-07-30T04:03:57.957Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-executions-editing-sensitive-or-critical-files-via-shell-redirecti-86157017</loc>
    <lastmod>2026-07-30T04:03:56.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-script-interpreter-spawns-trufflehog-or-gitleaks-f0025a69</loc>
    <lastmod>2026-07-30T04:03:54.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-recon-command-line-indicators-for-suid-htpasswd-discovery-0cf7a157</loc>
    <lastmod>2026-07-30T04:03:52.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-reading-etc-sudoers-via-file-content-inspection-utilities-0f79c4d2</loc>
    <lastmod>2026-07-30T04:03:51.053Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-shell-command-piped-into-another-shell-880973f3</loc>
    <lastmod>2026-07-30T04:03:49.546Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-execution-of-network-scanning-and-recon-tools-3e102cd9</loc>
    <lastmod>2026-07-30T04:03:47.500Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-java-process-spawning-shells-and-downloaders-d292e0af</loc>
    <lastmod>2026-07-30T04:03:45.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-interactive-bash-launching-suspicious-child-commands-ea3ecad2</loc>
    <lastmod>2026-07-30T04:03:44.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-command-line-inode-directory-listing-for-container-discovery-43e26eb5</loc>
    <lastmod>2026-07-30T04:03:42.027Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-match-for-known-hacktool-and-scanning-binaries-a015e032</loc>
    <lastmod>2026-07-30T04:03:40.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-command-line-printing-of-shell-history-files-d7821ff1</loc>
    <lastmod>2026-07-30T04:03:38.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-history-file-deletion-via-rm-unlink-shred-commands-1182f3b3</loc>
    <lastmod>2026-07-30T04:03:36.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-of-git-clone-containing-exploit-or-vulnerability-keyword-cfec9d29</loc>
    <lastmod>2026-07-30T04:03:35.208Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-discovery-via-find-command-searching-setuid-sgid-and-writable-exec-8344c0e5</loc>
    <lastmod>2026-07-30T04:03:33.224Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-process-execution-from-tmp-directory-312b42b1</loc>
    <lastmod>2026-07-30T04:03:31.543Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-from-dev-shm-shared-memory-5cd16c8f</loc>
    <lastmod>2026-07-30T04:03:29.750Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-discovery-by-listing-dockerenv-via-common-file-utilities-11701de9</loc>
    <lastmod>2026-07-30T04:03:28.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-user-agent-changes-on-linux-via-process-creation-b86d356d</loc>
    <lastmod>2026-07-30T04:03:26.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-curl-process-uploads-files-via-form-upload-flags-00b90cc1</loc>
    <lastmod>2026-07-30T04:03:25.253Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-container-discovery-via-proc-virtual-filesystem-enumeration-746c86fb</loc>
    <lastmod>2026-07-30T04:03:23.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-amazon-ssm-agent-hijacking-via-suspicious-register-code-command-line-f9b3edc5</loc>
    <lastmod>2026-07-30T04:03:21.562Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-ssh-used-to-invoke-a-shell-via-proxycommand-and-embedded-local-command-opt-8737b7f6</loc>
    <lastmod>2026-07-30T04:03:19.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-chown-root-and-chmod-u-s-g-s-indicating-setuid-setgid-changes-c21c4eaa</loc>
    <lastmod>2026-07-30T04:03:18.095Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-service-management-tool-usage-to-stop-or-disable-services-de25eeb8</loc>
    <lastmod>2026-07-30T04:03:16.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-service-commands-stopping-or-disabling-security-tools-iptables-firewalld-c-e3a8a052</loc>
    <lastmod>2026-07-30T04:03:14.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-discovery-via-grep-egrep-searching-for-security-monitoring-tools-c9d8b7fd</loc>
    <lastmod>2026-07-30T04:03:12.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-cron-job-uploads-from-tmp-via-crontab-process-creation-6b14bac8</loc>
    <lastmod>2026-07-30T04:03:11.001Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-ruby-e-scripts-calling-tcpsocket-via-rsocket-b8bdac18</loc>
    <lastmod>2026-07-30T04:03:09.441Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-shell-spawned-by-rsync-without-expected-e-flag-297241f3</loc>
    <lastmod>2026-07-30T04:03:07.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-rsync-used-with-e-to-spawn-a-shell-e2326866</loc>
    <lastmod>2026-07-30T04:03:05.864Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-package-uninstall-commands-via-yum-apt-dpkg-rpm-95d61234</loc>
    <lastmod>2026-07-30T04:03:04.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-remote-system-discovery-via-arp-or-ping-enumeration-11063ec2</loc>
    <lastmod>2026-07-30T04:03:02.449Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-teamviewer-remote-session-start-via-teamviewer-desktop-command-line-1f6b8cd4</loc>
    <lastmod>2026-07-30T04:03:00.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-inline-python-c-calls-os-system-to-spawn-shell-2d2f44ff</loc>
    <lastmod>2026-07-30T04:02:59.129Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-python-reverse-shell-via-pty-and-socket-imports-32e62bc7</loc>
    <lastmod>2026-07-30T04:02:57.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-python-imports-pty-and-spawns-a-pseudo-tty-c4042d54</loc>
    <lastmod>2026-07-30T04:02:55.939Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-python-http-server-execution-via-command-line-http-server-simplehttpserver-3f0f5957</loc>
    <lastmod>2026-07-30T04:02:54.122Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-executions-of-python-base64-decoding-in-one-liners-55e862a8</loc>
    <lastmod>2026-07-30T04:02:52.610Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-of-trufflehog-with-secret-search-platform-arguments-d7a650c4</loc>
    <lastmod>2026-07-30T04:02:50.939Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-sets-http-proxy-https-proxy-environment-variables-72f4ab3f</loc>
    <lastmod>2026-07-30T04:02:49.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-command-lines-showing-pnscan-binary-data-transfer-usage-97de11cd</loc>
    <lastmod>2026-07-30T04:02:47.613Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-php-inline-code-using-r-and-fsockopen-for-reverse-shell-s-c6714a24</loc>
    <lastmod>2026-07-30T04:02:46.070Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-perl-reverse-shell-pattern-via-perl-e-with-socket-inet-and-connect-open-ex-259df6bc</loc>
    <lastmod>2026-07-30T04:02:43.978Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-nohupp-execution-from-tmp-457df417</loc>
    <lastmod>2026-07-30T04:02:38.178Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-nohup-execution-via-process-creation-nohu-p-command-path-e4ffe466</loc>
    <lastmod>2026-07-30T04:02:36.472Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-shell-execution-using-nice-utility-093d68c7</loc>
    <lastmod>2026-07-30T04:02:34.881Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-of-netcat-ncat-with-e-followed-by-shell-invocation-7f734ed0</loc>
    <lastmod>2026-07-30T04:02:32.894Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-mount-executed-with-hidepid-2-option-ec52985a</loc>
    <lastmod>2026-07-30T04:02:30.986Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-named-pipe-creation-via-mkfifo-from-tmp-999c3b12</loc>
    <lastmod>2026-07-30T04:02:29.316Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-named-pipe-creation-via-mkfifo-utility-9d779ce8</loc>
    <lastmod>2026-07-30T04:02:27.697Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-grep-command-used-to-locate-specific-malware-related-files-process-discove-e34cfa0c</loc>
    <lastmod>2026-07-30T04:02:26.261Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-local-system-groups-enumeration-via-groups-cat-to-etc-group-676381a6</loc>
    <lastmod>2026-07-30T04:02:24.720Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-local-account-discovery-via-system-account-and-password-file-viewing-b45e3d6f</loc>
    <lastmod>2026-07-30T04:02:21.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-iptables-ufw-chain-flush-commands-enabling-all-network-traffic-3be619f4</loc>
    <lastmod>2026-07-30T04:02:19.974Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-package-installation-commands-for-potential-recon-tool-deployment-700fb7e8</loc>
    <lastmod>2026-07-30T04:02:18.142Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-root-certificate-installation-via-update-ca-certificates-or-update-ca-trus-78a80655</loc>
    <lastmod>2026-07-30T04:02:16.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-groupdel-execution-identified-by-process-creation-8a46f16c</loc>
    <lastmod>2026-07-30T04:02:15.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-os-architecture-discovery-using-grep-for-cpu-arch-strings-d27ab432</loc>
    <lastmod>2026-07-30T04:02:13.357Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-git-invoked-with-shell-execution-via-redirected-stdin-to-bash-dash-sh-47b3bbd4</loc>
    <lastmod>2026-07-30T04:02:11.590Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-gcc-invocation-used-to-execute-shell-scripts-via-wrapper-9b5de532</loc>
    <lastmod>2026-07-30T04:02:09.749Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-flock-used-to-launch-an-interactive-shell-4b09c71e</loc>
    <lastmod>2026-07-30T04:02:08.008Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-find-command-using-exec-to-spawn-a-shell-6adfbf8f</loc>
    <lastmod>2026-07-30T04:02:06.327Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-deletion-via-rm-shred-or-unlink-process-creation-30aed7b6</loc>
    <lastmod>2026-07-30T04:02:04.705Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-and-directory-discovery-via-system-utilities-execution-d3feb4ee</loc>
    <lastmod>2026-07-30T04:02:03.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-of-esxcli-vsan-for-virtual-storage-information-discovery-d54c2f06</loc>
    <lastmod>2026-07-30T04:02:01.687Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-esxcli-vm-kill-shutdown-a-vm-on-esxi-2992ac4d</loc>
    <lastmod>2026-07-30T04:01:59.877Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-monitoring-esxi-vm-discovery-via-esxcli-vm-process-list-5f1573a7</loc>
    <lastmod>2026-07-30T04:01:58.188Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/esxi-user-account-creation-via-esxcli-command-execution-b28e4eb3</loc>
    <lastmod>2026-07-30T04:01:56.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-esxi-esxcli-system-discovery-commands-e80273e1</loc>
    <lastmod>2026-07-30T04:01:55.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/esxi-syslog-configuration-change-via-esxcli-on-linux-38eb1dbb</loc>
    <lastmod>2026-07-30T04:01:53.461Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-esxi-esxcli-storage-discovery-f41dada5</loc>
    <lastmod>2026-07-30T04:01:51.727Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-esxi-esxcli-used-to-set-admin-permission-on-an-account-9691f58d</loc>
    <lastmod>2026-07-30T04:01:50.048Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-esxi-esxcli-network-discovery-commands-33e814e0</loc>
    <lastmod>2026-07-30T04:01:48.456Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-detect-env-based-shell-invocation-using-common-interactive-shells-bed978f8</loc>
    <lastmod>2026-07-30T04:01:46.379Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-doas-tool-execution-process-creation-067d8238</loc>
    <lastmod>2026-07-30T04:01:44.492Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-attempt-to-disable-or-stop-ufw-firewall-via-ufw-init-or-ufw-disable-84c9e83c</loc>
    <lastmod>2026-07-30T04:01:43.115Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-dd-process-memory-overwrite-for-code-injection-via-proc-pid-mem-4cad6c64</loc>
    <lastmod>2026-07-30T04:01:41.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-dd-file-overwrite-deletion-attempt-via-of-and-dev-zero-dev-null-2953194b</loc>
    <lastmod>2026-07-30T04:01:39.536Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-curl-wget-download-to-temporary-dir-followed-by-sh-c-execution-a2d9e2f3</loc>
    <lastmod>2026-07-30T04:01:37.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-curl-execution-observed-via-process-start-ea34fb97</loc>
    <lastmod>2026-07-30T04:01:35.913Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-crypto-miner-command-line-indicators-9069ea3c</loc>
    <lastmod>2026-07-30T04:01:34.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-crontab-r-removes-current-user-crontab-c2e234de</loc>
    <lastmod>2026-07-30T04:01:32.856Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-crontab-l-enumeration-403ed92c</loc>
    <lastmod>2026-07-30T04:01:31.215Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-copy-passwd-or-shadow-from-tmp-using-cp-fa4aaed5</loc>
    <lastmod>2026-07-30T04:01:29.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-clipboard-collection-via-xclip-with-select-clip-output-sel-clip-o-ec127035</loc>
    <lastmod>2026-07-30T04:01:27.068Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-syslog-file-clearing-or-removal-via-common-system-utilities-3fcc9b35</loc>
    <lastmod>2026-07-30T04:01:25.387Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-activity-clearing-logs-with-rm-rmdir-shred-or-unlink-targeting-var-80915f59</loc>
    <lastmod>2026-07-30T04:01:23.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-sudo-chroot-command-execution-f2bed782</loc>
    <lastmod>2026-07-30T04:01:20.748Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-chmod-process-creation-targeting-sensitive-directory-paths-6419afd1</loc>
    <lastmod>2026-07-30T04:01:19.042Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-chattr-i-used-to-remove-immutable-file-attribute-34979410</loc>
    <lastmod>2026-07-30T04:01:17.336Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-capsh-invoked-with-shell-commandline-pattern-db1ac3be</loc>
    <lastmod>2026-07-30T04:01:15.929Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-capabilities-discovery-via-getcap-r-d8d97d51</loc>
    <lastmod>2026-07-30T04:01:14.363Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-setcap-sets-cap-setuid-on-a-binary-via-process-execution-ed447910</loc>
    <lastmod>2026-07-30T04:01:12.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-setcap-used-to-assign-cap-setgid-setgid-capability-to-a-binary-3a716279</loc>
    <lastmod>2026-07-30T04:01:09.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-bpftrace-commandline-use-of-unsafe-option-f8341cb2</loc>
    <lastmod>2026-07-30T04:01:07.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-enabling-bpf-kprobes-tracing-via-debugfs-and-probe-enable-7692f583</loc>
    <lastmod>2026-07-30T04:01:06.368Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-bash-launched-in-interactive-mode-via-i-6104e693</loc>
    <lastmod>2026-07-30T04:01:04.705Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-base64-encoded-shebang-in-command-line-fe2f9663</loc>
    <lastmod>2026-07-30T04:01:03.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-processes-using-base64-input-piped-to-shell-bash-sh-ba592c6d</loc>
    <lastmod>2026-07-30T04:01:01.263Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-base64-utility-decoding-via-base64-d-command-line-e2072cab</loc>
    <lastmod>2026-07-30T04:00:59.368Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-shell-invocation-via-awk-gawk-mawk-nawk-system-in-commandline-8c1a5675</loc>
    <lastmod>2026-07-30T04:00:57.767Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-kaspersky-endpoint-security-stopped-via-command-line-init-d-systemctl-36388120</loc>
    <lastmod>2026-07-30T04:00:55.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditctl-used-with-d-to-delete-all-audit-rules-bed26dea</loc>
    <lastmod>2026-07-30T04:00:54.352Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-at-atd-process-execution-for-scheduled-job-creation-d2d642d7</loc>
    <lastmod>2026-07-30T04:00:52.607Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-via-apt-apt-get-shell-proxy-option-bb382fd5</loc>
    <lastmod>2026-07-30T04:00:50.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-malware-callback-style-network-connections-to-known-suspicious-ports-dbfc7c98</loc>
    <lastmod>2026-07-30T04:00:48.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-network-connections-to-ngrok-tunnel-endpoints-19bf6fdb</loc>
    <lastmod>2026-07-30T04:00:46.938Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-network-connections-to-localtonet-tunneling-subdomains-c4568f5d</loc>
    <lastmod>2026-07-30T04:00:45.352Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-network-connections-to-known-monero-mining-pool-hosts-a46c93b7</loc>
    <lastmod>2026-07-30T04:00:43.458Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-reverse-shell-via-bin-bash-connecting-to-external-ips-83dcd9f6</loc>
    <lastmod>2026-07-30T04:00:41.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-wget-writes-files-to-tmp-or-var-tmp-35a05c60</loc>
    <lastmod>2026-07-30T04:00:40.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-ebpf-backdoor-file-creation-in-cron-d-and-sudoers-d-for-persistence-1a2ea919</loc>
    <lastmod>2026-07-30T04:00:38.007Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-alert-on-tmp-rootlog-creation-associated-with-triplecross-ebpf-rootkit-sta-c0239255</loc>
    <lastmod>2026-07-30T04:00:36.347Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-shell-script-creation-under-etc-profile-d-13f08f54</loc>
    <lastmod>2026-07-30T04:00:34.049Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-events-suspicious-filenames-embedding-base64-decoded-bash-commands-179b3686</loc>
    <lastmod>2026-07-30T04:00:32.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-cron-file-creation-in-cron-directories-6c4e2f43</loc>
    <lastmod>2026-07-30T04:00:30.007Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-persistence-attempts-by-creating-modifying-etc-sudoers-d-files-ddb26b76</loc>
    <lastmod>2026-07-30T04:00:27.966Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-doas-conf-file-creation-00eee2a5</loc>
    <lastmod>2026-07-30T04:00:26.491Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-vsftpd-suspicious-error-messages-indicating-potential-exploitation-attempt-377f33a1</loc>
    <lastmod>2026-07-30T04:00:25.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-syslog-suspicious-bind-named-error-messages-fatal-or-access-denied-c8e35e96</loc>
    <lastmod>2026-07-30T04:00:23.459Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-syslog-alert-for-stopping-security-tools-via-service-disruption-49f5dfc1</loc>
    <lastmod>2026-07-30T04:00:21.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-sshd-logs-suspicious-openssh-daemon-error-messages-e76b413a</loc>
    <lastmod>2026-07-30T04:00:20.334Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-command-line-symlink-attempts-targeting-etc-passwd-c67fc22a</loc>
    <lastmod>2026-07-30T04:00:18.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-jexboss-like-reverse-shell-command-sequence-via-bash-with-dev-tcp-8ec2c8b4</loc>
    <lastmod>2026-07-30T04:00:17.199Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-dev-tcp-shell-redirection-and-file-descriptor-usage-6cc5fceb</loc>
    <lastmod>2026-07-30T04:00:15.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-shellshock-function-body-expression-strings-in-logs-c67e0c98</loc>
    <lastmod>2026-07-30T04:00:14.068Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-reverse-shell-command-lines-on-linux-738d9bcf</loc>
    <lastmod>2026-07-30T04:00:12.132Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-logs-alert-on-suspicious-syslog-keywords-f64b6e9a</loc>
    <lastmod>2026-07-30T04:00:10.444Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-shell-command-execution-indicators-in-command-lines-2aa1440c</loc>
    <lastmod>2026-07-30T04:00:08.967Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-new-user-created-with-privileged-uid-gid-values-0ac15ec3</loc>
    <lastmod>2026-07-30T04:00:05.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-ebpf-warning-indicators-bpf-probe-write-user-helper-messages-0fadd880</loc>
    <lastmod>2026-07-30T04:00:03.924Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-code-injection-via-ld-so-preload-file-etc-ld-so-preload-7e3c4651</loc>
    <lastmod>2026-07-30T04:00:02.209Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-remote-file-copy-via-scp-rsync-sftp-with-remote-host-targeting-7a14080d</loc>
    <lastmod>2026-07-30T04:00:00.513Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-commands-clearing-or-removing-var-log-syslog-e09eb557</loc>
    <lastmod>2026-07-30T03:59:58.805Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-syslog-buffer-overflow-and-stack-smashing-attempt-keywords-18b042f0</loc>
    <lastmod>2026-07-30T03:59:56.856Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-execution-flagging-suspicious-shell-commands-from-equation-group-scripts-41e5c73d</loc>
    <lastmod>2026-07-30T03:59:54.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/guacamole-linux-alert-on-session-showing-two-users-present-anomaly-1edd77db</loc>
    <lastmod>2026-07-30T03:59:53.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-cron-suspicious-crontab-modification-via-replace-af202fd3</loc>
    <lastmod>2026-07-30T03:59:51.579Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-clamav-alerts-keyword-matched-trojan-webshell-rootkit-and-htran-detections-36aa86ca</loc>
    <lastmod>2026-07-30T03:59:50.127Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-webshell-like-remote-command-execution-via-execve-execveat-as-web-s-c0d3734d</loc>
    <lastmod>2026-07-30T03:59:47.414Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-audit-mknod-syscall-used-to-create-special-files-710bdbce</loc>
    <lastmod>2026-07-30T03:59:45.798Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-program-execution-from-suspicious-directories-a39d7fa7</loc>
    <lastmod>2026-07-30T03:59:44.208Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-sysinfo-syscall-used-for-system-information-discovery-b207d563</loc>
    <lastmod>2026-07-30T03:59:42.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-split-utility-used-to-divide-files-into-chunks-auditd-syscall-2dad0cba</loc>
    <lastmod>2026-07-30T03:59:40.979Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-process-executions-of-telnet-nmap-netcat-for-network-service-scanni-3761e026</loc>
    <lastmod>2026-07-30T03:59:39.401Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-kernel-module-load-via-insmod-kmod-106d7cbd</loc>
    <lastmod>2026-07-30T03:59:37.827Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-new-user-account-creation-via-useradd-syscall-or-add-user-audit-eve-759d0d51</loc>
    <lastmod>2026-07-30T03:59:36.329Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-clear-disable-kernel-ring-buffer-via-syslog-syscall-auditd-a0-5-6-eca5e022</loc>
    <lastmod>2026-07-30T03:59:34.802Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-service-stop-firewalld-iptables-or-ufw-firewall-disabled-53059bc0</loc>
    <lastmod>2026-07-30T03:59:32.889Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-alerts-on-unix-shell-configuration-file-modifications-a94cdd87</loc>
    <lastmod>2026-07-30T03:59:31.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-creation-of-systemd-unit-files-in-system-user-directories-1bac86ba</loc>
    <lastmod>2026-07-30T03:59:29.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-system-and-hardware-information-discovery-via-file-reads-1f358e2e</loc>
    <lastmod>2026-07-30T03:59:27.912Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-sysrq-trigger-or-configuration-path-access-ea61bb82</loc>
    <lastmod>2026-07-30T03:59:25.955Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-alerts-for-syslog-daemon-configuration-file-changes-c830f15d</loc>
    <lastmod>2026-07-30T03:59:24.379Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-ld-so-preload-file-modification-for-shared-object-injection-4b3cb710</loc>
    <lastmod>2026-07-30T03:59:22.841Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-executable-command-path-containing-hidden-files-or-hidden-directori-9e1bef8d</loc>
    <lastmod>2026-07-30T03:59:21.144Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-rule-for-bpfdoor-related-pid-and-lock-file-access-under-var-run-808146b2</loc>
    <lastmod>2026-07-30T03:59:19.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-detect-writes-to-audit-configuration-files-and-related-paths-977ef627</loc>
    <lastmod>2026-07-30T03:59:17.966Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-system-information-discovery-via-auditd-uname-uptime-lsmod-hostname-env-f34047d9</loc>
    <lastmod>2026-07-30T03:59:16.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-suspicious-command-line-tool-usage-for-c2-wget-curl-nc-ssh-nmap-etc-f7158a64</loc>
    <lastmod>2026-07-30T03:59:14.116Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-password-policy-discovery-via-chage-and-passwd-ca94a6db</loc>
    <lastmod>2026-07-30T03:59:12.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-pam-tty-auditing-change-via-auditd-path-events-49aae26c</loc>
    <lastmod>2026-07-30T03:59:10.819Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-aslr-disabled-via-personality-syscall-sysctl-or-proc-randomize-va-space-e497a24e</loc>
    <lastmod>2026-07-30T03:59:09.165Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-audio-capture-via-arecord-and-ecasound-memfd-create-a7af2487</loc>
    <lastmod>2026-07-30T03:59:07.347Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-system-owner-and-user-discovery-via-utility-execution-9a0d8ca0</loc>
    <lastmod>2026-07-30T03:59:05.641Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-unzip-extraction-from-jpg-png-files-for-hidden-data-edd595d7</loc>
    <lastmod>2026-07-30T03:59:04.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-detect-system-shutdown-reboot-halt-poweroff-via-execve-4cb57c2f</loc>
    <lastmod>2026-07-30T03:59:02.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-service-management-via-systemctl-service-start-or-reload-2625cc59</loc>
    <lastmod>2026-07-30T03:59:00.990Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-shell-history-file-access-via-executed-commands-eae8ce9f</loc>
    <lastmod>2026-07-30T03:58:59.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-suspicious-chmod-and-file-replacement-via-cp-1543ae20</loc>
    <lastmod>2026-07-30T03:58:57.886Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-steghide-steganography-extraction-via-steghide-extract-targeting-jpg-png-a5a827d9</loc>
    <lastmod>2026-07-30T03:58:56.150Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-detect-steghide-file-embedding-via-embed-command-ce446a9e</loc>
    <lastmod>2026-07-30T03:58:54.099Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-screen-capture-via-xwd-writing-xwd-output-files-e2f17c5d</loc>
    <lastmod>2026-07-30T03:58:52.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-screen-capture-via-imagemagick-import-tool-outputting-desktop-images-dbe4b9c5</loc>
    <lastmod>2026-07-30T03:58:50.734Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-detect-execution-of-tcpdump-or-tshark-with-interface-flag-f4d3748a</loc>
    <lastmod>2026-07-30T03:58:49.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-firewall-rule-deletions-via-iptables-firewall-cmd-ufw-or-nft-323ff3f5</loc>
    <lastmod>2026-07-30T03:58:47.117Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-masquerading-cp-via-bin-sh-ending-with-crond-9d4548fa</loc>
    <lastmod>2026-07-30T03:58:45.383Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-cat-command-appends-zip-data-to-jpg-png-45810b50</loc>
    <lastmod>2026-07-30T03:58:42.368Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-hidden-file-or-directory-creation-via-dot-prefixed-paths-d08722cd</loc>
    <lastmod>2026-07-30T03:58:40.772Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-grep-search-for-password-in-executed-commands-df3fcaea</loc>
    <lastmod>2026-07-30T03:58:39.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-chmod-and-chown-executions-indicating-file-or-folder-permission-cha-74c01ace</loc>
    <lastmod>2026-07-30T03:58:37.836Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-dd-overwrites-a-file-using-if-dev-null-or-if-dev-zero-37222991</loc>
    <lastmod>2026-07-30T03:58:36.392Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-wget-exfiltration-via-post-file-command-line-cb39d16b</loc>
    <lastmod>2026-07-30T03:58:34.877Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-execution-of-zip-gzip-tar-for-data-compression-a3b5e3e9</loc>
    <lastmod>2026-07-30T03:58:33.446Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-processes-using-cpu-priority-command-line-option-071d5e5a</loc>
    <lastmod>2026-07-30T03:58:31.833Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-clipboard-image-data-collection-via-xclip-f200dc3f</loc>
    <lastmod>2026-07-30T03:58:30.447Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-xclip-clipboard-collection-via-selection-and-output-option-214e7e6c</loc>
    <lastmod>2026-07-30T03:58:28.819Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-detect-chattr-removing-the-immutable-i-attribute-a5b977d6</loc>
    <lastmod>2026-07-30T03:58:27.014Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-file-timestamp-manipulation-via-touch-t-a-c-m-r-options-b3cec4e7</loc>
    <lastmod>2026-07-30T03:58:24.980Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-getcap-scans-for-capability-files-on-the-root-path-fe10751f</loc>
    <lastmod>2026-07-30T03:58:23.396Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-iptables-nat-redirect-from-attacker-ports-via-bpfdoor-tcp-redirecti-70b4156e</loc>
    <lastmod>2026-07-30T03:58:21.918Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-detect-dd-truncate-binary-padding-used-to-alter-on-disk-file-contents-c52a914f</loc>
    <lastmod>2026-07-30T03:58:20.112Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/onelogin-user-account-lock-or-suspension-via-api-events-a717c561</loc>
    <lastmod>2026-07-30T03:58:18.363Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/onelogin-events-user-assumed-another-user-account-event-type-id-3-62fff148</loc>
    <lastmod>2026-07-30T03:58:17.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-user-session-start-from-anonymizing-proxy-service-bde30855</loc>
    <lastmod>2026-07-30T03:58:15.618Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-user-lifecycle-create-event-for-new-user-accounts-b6c718dd</loc>
    <lastmod>2026-07-30T03:58:14.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-account-locked-out-after-max-sign-in-attempts-14701da0</loc>
    <lastmod>2026-07-30T03:58:12.731Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-unauthorized-app-access-attempt-via-system-log-display-message-6cc2b61b</loc>
    <lastmod>2026-07-30T03:58:11.259Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-user-reports-suspicious-activity-on-their-own-account-via-end-user-activity-07e97cc6</loc>
    <lastmod>2026-07-30T03:58:09.771Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-detects-security-threat-detected-events-from-threat-insight-5c82f0b9</loc>
    <lastmod>2026-07-30T03:58:08.335Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-policy-rule-updated-or-deleted-via-policy-rule-api-events-0c97c1d3</loc>
    <lastmod>2026-07-30T03:58:06.761Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-policy-lifecycle-update-or-deletion-events-1667a172</loc>
    <lastmod>2026-07-30T03:58:05.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-failed-login-where-password-like-alternateid-was-provided-91b76b84</loc>
    <lastmod>2026-07-30T03:58:03.948Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-new-or-positive-admin-console-access-heuristics-via-policy-evaluate-sign-on-a0b38b70</loc>
    <lastmod>2026-07-30T03:58:02.158Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-network-zone-deactivated-or-deleted-9f308120</loc>
    <lastmod>2026-07-30T03:58:00.514Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-mfa-factor-deactivation-or-reset-detection-50e068d7</loc>
    <lastmod>2026-07-30T03:57:59.113Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-identity-provider-creation-via-system-idp-lifecycle-create-969c7590</loc>
    <lastmod>2026-07-30T03:57:57.396Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-fastpass-phishing-blocked-mfa-authentication-failure-ee39a9f7</loc>
    <lastmod>2026-07-30T03:57:55.714Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-sign-on-policy-update-or-rule-deletion-8f668cc4</loc>
    <lastmod>2026-07-30T03:57:54.077Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-application-lifecycle-update-or-deletion-7899144b</loc>
    <lastmod>2026-07-30T03:57:52.186Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-detect-api-token-revocation-via-system-api-token-revoke-events-cf1dbc6b</loc>
    <lastmod>2026-07-30T03:57:50.799Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-api-token-creation-via-system-api-token-create-event-19951c21</loc>
    <lastmod>2026-07-30T03:57:49.439Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-admin-role-assignment-created-via-iam-resource-set-binding-add-139bdd4b</loc>
    <lastmod>2026-07-30T03:57:48.104Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-administrator-privilege-granted-to-user-or-group-413d4a81</loc>
    <lastmod>2026-07-30T03:57:46.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-admin-function-access-via-proxy-9058ca8b</loc>
    <lastmod>2026-07-30T03:57:45.194Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-duo-mfa-successful-login-using-bypass-code-reason-bypass-user-6f7e1c10</loc>
    <lastmod>2026-07-30T03:57:43.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-securitycompliancecenter-user-restricted-from-sending-email-succes-ff246f56</loc>
    <lastmod>2026-07-30T03:57:41.984Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-threat-management-high-volume-file-deletion-by-a-user-78a34b67</loc>
    <lastmod>2026-07-30T03:57:40.454Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-suspicious-oauth-app-file-downloads-from-sharepoint-onedrive-ee111937</loc>
    <lastmod>2026-07-30T03:57:38.896Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-threat-management-alert-on-suspicious-inbox-forwarding-6c220477</loc>
    <lastmod>2026-07-30T03:57:37.197Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/m365-pst-export-via-new-compliancesearchaction-export-in-securitycompliancecente-6897cd82</loc>
    <lastmod>2026-07-30T03:57:35.724Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-ediscovery-pst-export-alert-securitycompliancecenter-success-event-18b88d08</loc>
    <lastmod>2026-07-30T03:57:33.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-cloud-app-security-reports-potential-ransomware-uploads-bd132164</loc>
    <lastmod>2026-07-30T03:57:32.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/m365-securitycompliancecenter-successful-logon-from-risky-ip-address-in-sanction-c191e2fa</loc>
    <lastmod>2026-07-30T03:57:30.584Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-impossible-travel-activity-via-securitycompliancecenter-successful-d7eab125</loc>
    <lastmod>2026-07-30T03:57:29.007Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-cloud-app-security-successful-data-exfiltration-to-unsanctioned-ap-2b669496</loc>
    <lastmod>2026-07-30T03:57:27.249Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-cloud-app-security-success-events-from-infrequent-countries-0f2468a2</loc>
    <lastmod>2026-07-30T03:57:25.622Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-threat-management-activity-from-anonymous-proxy-ip-addresses-d8b0a4fe</loc>
    <lastmod>2026-07-30T03:57:23.976Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-cloud-app-security-activity-by-terminated-user-across-platforms-2e669ed8</loc>
    <lastmod>2026-07-30T03:57:22.259Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-cloud-app-security-successful-logins-from-microsoft-threat-intel-risky-a3501e8e</loc>
    <lastmod>2026-07-30T03:57:20.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/exchange-added-federated-domain-successfully-via-add-federateddomain-42127bdd</loc>
    <lastmod>2026-07-30T03:57:19.089Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-mail-delivery-of-suspicious-inbound-emails-to-inbox-or-junk-3569aefd</loc>
    <lastmod>2026-07-30T03:57:17.432Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-audit-new-federated-domain-added-via-domain-add-operation-58f88172</loc>
    <lastmod>2026-07-30T03:57:15.515Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-audit-disabling-strong-authentication-mfa-60de9b57</loc>
    <lastmod>2026-07-30T03:57:13.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/m365-audit-successful-intune-company-portal-login-tied-to-cmsi-request-13f2d3f5</loc>
    <lastmod>2026-07-30T03:57:12.404Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-workspace-logins-marked-suspicious-by-google-gcp-38360161</loc>
    <lastmod>2026-07-30T03:57:10.744Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-google-workspace-login-email-forwarding-out-of-domain-activity-2a0bb2dd</loc>
    <lastmod>2026-07-30T03:57:09.077Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-workspace-detect-gov-attack-warning-login-events-from-login-googleapis-co-eafe6f2b</loc>
    <lastmod>2026-07-30T03:57:07.521Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-google-workspace-admin-role-granted-to-user-2d1b83e4</loc>
    <lastmod>2026-07-30T03:57:05.629Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-workspace-admin-role-privilege-removed-via-remove-privilege-bf638ef7</loc>
    <lastmod>2026-07-30T03:57:04.186Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-workspace-admin-role-modified-or-deleted-via-admin-api-audit-events-6aef64e3</loc>
    <lastmod>2026-07-30T03:57:02.232Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-workspace-admin-api-mfa-enforcement-relaxed-by-setting-to-false-780601d1</loc>
    <lastmod>2026-07-30T03:57:00.814Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-google-workspace-admin-api-client-access-authorized-at-domain-level-04e2a23a</loc>
    <lastmod>2026-07-30T03:56:59.293Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-workspace-admin-audit-application-removed-from-domain-ee2803f0</loc>
    <lastmod>2026-07-30T03:56:57.505Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-admin-sdk-google-workspace-application-access-level-changed-via-contextaware-22f2fb54</loc>
    <lastmod>2026-07-30T03:56:55.949Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-cloud-vpn-tunnel-insert-or-delete-via-audit-logs-99980a85</loc>
    <lastmod>2026-07-30T03:56:54.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-cloud-sql-database-or-user-modified-deleted-via-audit-api-f346bbd5</loc>
    <lastmod>2026-07-30T03:56:52.710Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-service-account-modified-via-service-accounts-api-methods-6b67c12e</loc>
    <lastmod>2026-07-30T03:56:51.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-cloud-audit-service-account-disabled-or-deleted-13f81a90</loc>
    <lastmod>2026-07-30T03:56:49.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-kubernetes-audit-secrets-modified-or-deleted-via-kubernetes-api-methods-2f0bae2d</loc>
    <lastmod>2026-07-30T03:56:47.589Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-logs-kubernetes-rolebinding-and-clusterrolebinding-create-patch-update-0322d9f2</loc>
    <lastmod>2026-07-30T03:56:46.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-detects-kubernetes-cronjob-and-job-creation-requests-cd3a808c</loc>
    <lastmod>2026-07-30T03:56:44.475Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-kubernetes-admission-webhook-configuration-changes-via-audit-logs-6ad91e31</loc>
    <lastmod>2026-07-30T03:56:42.868Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-full-network-packet-mirroring-api-activity-980a7598</loc>
    <lastmod>2026-07-30T03:56:40.843Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-logs-firewall-rule-modified-or-deleted-fe513c69</loc>
    <lastmod>2026-07-30T03:56:39.270Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-cloud-dns-managed-zone-updated-patched-or-deleted-audit-logs-28268a8f</loc>
    <lastmod>2026-07-30T03:56:37.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-sensitive-data-re-identified-via-projects-content-reidentify-234f9f48</loc>
    <lastmod>2026-07-30T03:56:35.657Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/google-cloud-storage-buckets-modified-or-deleted-via-audit-api-4d9f2ee2</loc>
    <lastmod>2026-07-30T03:56:34.064Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-detects-google-cloud-storage-bucket-enumeration-via-list-apis-e2feb918</loc>
    <lastmod>2026-07-30T03:56:32.625Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-audit-log-break-glass-flag-kubernetes-pod-created-in-gke-cluster-76737c19</loc>
    <lastmod>2026-07-30T03:56:31.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/gcp-access-policy-deletion-via-accesscontextmanager-audit-logs-32438676</loc>
    <lastmod>2026-07-30T03:56:29.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-blocked-by-conditional-access-policy-token-issuance-denied-9a60e676</loc>
    <lastmod>2026-07-30T03:56:27.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-authentication-interruption-via-device-and-external-security-chall-8366030e</loc>
    <lastmod>2026-07-30T03:56:26.442Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-mfa-strong-authentication-failures-strong-auth-interrupted-5496ff55</loc>
    <lastmod>2026-07-30T03:56:24.690Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-mfa-denied-authenticationrequirement-e40f4962</loc>
    <lastmod>2026-07-30T03:56:23.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-sign-in-attempts-to-disabled-accounts-908655e0</loc>
    <lastmod>2026-07-30T03:56:21.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-legacy-authentication-protocols-used-by-account-60f6535a</loc>
    <lastmod>2026-07-30T03:56:20.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-failure-blocked-by-conditional-access-requirement-not-met-b4a6d707</loc>
    <lastmod>2026-07-30T03:56:18.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-sign-in-logs-account-disabled-or-blocked-on-failed-login-attempts-4afac85c</loc>
    <lastmod>2026-07-30T03:56:16.414Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-detect-ropc-authentication-flow-use-in-applications-55695bc0</loc>
    <lastmod>2026-07-30T03:56:14.642Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-application-using-device-code-authentication-flow-248649b7</loc>
    <lastmod>2026-07-30T03:56:13.022Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-sign-in-success-from-legacy-client-user-agents-suggesting-mfa-bypass-ri-53bb4f7f</loc>
    <lastmod>2026-07-30T03:56:11.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-sign-ins-by-unknown-devices-from-non-trusted-locations-4d136857</loc>
    <lastmod>2026-07-30T03:56:09.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-sign-ins-from-non-compliant-devices-4f77e1d7</loc>
    <lastmod>2026-07-30T03:56:07.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-risky-success-from-non-registered-device-without-mfa-requirement-572b12d4</loc>
    <lastmod>2026-07-30T03:56:05.664Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-sign-in-success-without-mfa-required-single-factor-authentication-28eea407</loc>
    <lastmod>2026-07-30T03:56:03.926Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-device-registration-or-join-successful-without-mfa-5afa454e</loc>
    <lastmod>2026-07-30T03:56:02.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-detect-azurehound-discovery-via-user-agent-after-successful-a-35b781cc</loc>
    <lastmod>2026-07-30T03:56:00.777Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-sign-in-logs-detect-account-lockout-after-too-many-failed-password-or-user-2b7d6fc0</loc>
    <lastmod>2026-07-30T03:55:59.307Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-alert-too-many-global-administrator-accounts-assigned-to-tenant-7bbc309f</loc>
    <lastmod>2026-07-30T03:55:57.786Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-redundant-privileged-role-assignments-not-being-used-8c6ec464</loc>
    <lastmod>2026-07-30T03:55:56.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-role-activation-without-mfa-alert-nomfaonroleactivationalertincident-94a66f46</loc>
    <lastmod>2026-07-30T03:55:54.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-role-activated-too-frequently-sequential-activation-renewals-645fd80d</loc>
    <lastmod>2026-07-30T03:55:53.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-alert-for-roles-assigned-outside-privileged-identity-management-b1bc08d1</loc>
    <lastmod>2026-07-30T03:55:51.702Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-invalid-license-alert-detection-58af08eb</loc>
    <lastmod>2026-07-30T03:55:50.020Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-stale-sign-in-alerts-for-privileged-roles-e402c26a</loc>
    <lastmod>2026-07-30T03:55:48.425Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-risk-detection-unfamiliar-sign-in-properties-events-128faeef</loc>
    <lastmod>2026-07-30T03:55:46.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-saml-token-issuer-anomaly-risk-event-e3393cba</loc>
    <lastmod>2026-07-30T03:55:45.153Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-risk-detection-threat-intelligence-sign-in-investigation-events-a2cb56ff</loc>
    <lastmod>2026-07-30T03:55:43.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-risk-detection-suspicious-browser-sign-in-activity-across-countries-and-te-944f6adb</loc>
    <lastmod>2026-07-30T03:55:41.985Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-riskdetection-attempted-primary-refresh-token-prt-access-a84fc3b1</loc>
    <lastmod>2026-07-30T03:55:40.440Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-id-risk-detection-successful-password-spray-activity-28ecba0a</loc>
    <lastmod>2026-07-30T03:55:38.906Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-risk-detection-new-country-sign-in-adf9f4d2</loc>
    <lastmod>2026-07-30T03:55:37.242Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-sign-in-risk-malware-infected-ip-address-sign-ins-821b4dc3</loc>
    <lastmod>2026-07-30T03:55:35.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-riskdetection-suspiciousipaddress-sign-in-from-known-malicious-ip-36440e1c</loc>
    <lastmod>2026-07-30T03:55:33.937Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-risk-detections-malicious-ip-sign-in-failure-rate-a3f55ebd</loc>
    <lastmod>2026-07-30T03:55:31.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-risk-detection-leaked-credentials-event-leakedcredentials-19128e5e</loc>
    <lastmod>2026-07-30T03:55:30.436Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-risk-detection-suspicious-inbox-manipulation-rules-set-to-delete-or-move-i-ceb55fd0</loc>
    <lastmod>2026-07-30T03:55:28.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-risk-detection-suspicious-inbox-forwarding-identity-protection-events-27e4f1d6</loc>
    <lastmod>2026-07-30T03:55:27.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-risk-impossible-travel-sign-in-detection-impossibletravel-b2572bf9</loc>
    <lastmod>2026-07-30T03:55:25.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-unlikelytravel-risk-events-indicating-atypical-travel-between-distan-1a41023f</loc>
    <lastmod>2026-07-30T03:55:23.685Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-riskdetection-anonymous-ip-address-sign-ins-53acd925</loc>
    <lastmod>2026-07-30T03:55:21.944Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-riskdetection-user-activity-triggered-by-risky-anonymous-proxy-ip-be4d9c86</loc>
    <lastmod>2026-07-30T03:55:20.476Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-risk-detection-anomalous-user-activity-riskeventtype-anomaloususeractiv-258b6593</loc>
    <lastmod>2026-07-30T03:55:19.005Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-id-riskdetection-anomalous-token-risk-events-6555754e</loc>
    <lastmod>2026-07-30T03:55:17.208Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-successful-password-reset-by-user-account-340ee172</loc>
    <lastmod>2026-07-30T03:55:15.616Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-audit-logs-strongauthenticationrequirement-set-to-disabled-or-state--b18454c8</loc>
    <lastmod>2026-07-30T03:55:14.030Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-management-ux-audit-user-risk-and-mfa-registration-policy-updated-d4c7758e</loc>
    <lastmod>2026-07-30T03:55:12.439Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-temporary-access-pass-added-to-an-account-fa84aaf5</loc>
    <lastmod>2026-07-30T03:55:10.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-auditlogs-permission-elevation-to-user-access-administrator-for-subscripti-ca9bf243</loc>
    <lastmod>2026-07-30T03:55:09.047Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-service-principal-removal-448fd1ea</loc>
    <lastmod>2026-07-30T03:55:07.163Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-service-principal-added-via-add-service-principal-operation-0ddcff6d</loc>
    <lastmod>2026-07-30T03:55:05.560Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-successful-admin-account-creation-via-add-user-to-role-f7b5b004</loc>
    <lastmod>2026-07-30T03:55:04.049Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-bulk-removal-of-privileged-role-members-102e11e3</loc>
    <lastmod>2026-07-30T03:55:02.524Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-user-added-to-privileged-role-49a268a4</loc>
    <lastmod>2026-07-30T03:55:00.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-pim-role-setting-updates-db6c06c4</loc>
    <lastmod>2026-07-30T03:54:59.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-pim-alert-disablement-in-audit-logs-aeaef14c</loc>
    <lastmod>2026-07-30T03:54:57.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-privileged-identity-management-pim-elevation-approval-or-denial-audit-e-039a7469</loc>
    <lastmod>2026-07-30T03:54:56.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-owner-removed-from-application-or-service-principal-636e30d5</loc>
    <lastmod>2026-07-30T03:54:54.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-successful-disable-strong-authentication-mfa-user-action-7ea78478</loc>
    <lastmod>2026-07-30T03:54:53.224Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-user-type-changed-from-guest-to-member-8dee7a0d</loc>
    <lastmod>2026-07-30T03:54:51.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-failed-guest-invitation-by-non-authorized-inviter-0b4b72e3</loc>
    <lastmod>2026-07-30T03:54:50.239Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-detect-member-removal-from-group-with-conditional-access-policy-modi-665e2d43</loc>
    <lastmod>2026-07-30T03:54:48.829Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-id-added-user-to-group-granted-conditional-access-policy-modificatio-91c95675</loc>
    <lastmod>2026-07-30T03:54:47.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-federation-settings-modified-via-audit-logs-352a54e1</loc>
    <lastmod>2026-07-30T03:54:45.555Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-device-no-longer-managed-or-compliant-542b9912</loc>
    <lastmod>2026-07-30T03:54:44.201Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-user-registers-new-security-info-authentication-method-change-4d78a000</loc>
    <lastmod>2026-07-30T03:54:42.337Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-application-deletion-via-entra-admin-operations-410d2a41</loc>
    <lastmod>2026-07-30T03:54:39.039Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-app-uri-updates-in-audit-logs-appaddress-property-changes-0055ad1f</loc>
    <lastmod>2026-07-30T03:54:37.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-service-principal-assigned-azure-rbac-microsoft-entra-roles-b04934b2</loc>
    <lastmod>2026-07-30T03:54:35.536Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-admin-adds-privileged-delegated-or-app-role-permissions-to-serv-5aecf3d5</loc>
    <lastmod>2026-07-30T03:54:33.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-app-granted-microsoft-graph-exchange-sharepoint-azure-ad-per-c1d147ae</loc>
    <lastmod>2026-07-30T03:54:32.454Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-log-owner-added-to-application-74298991</loc>
    <lastmod>2026-07-30T03:54:30.714Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-end-user-consent-blocked-for-risky-apps-by-risk-based-consent-7091372f</loc>
    <lastmod>2026-07-30T03:54:29.044Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-end-user-consent-to-application-9b2cc4c4</loc>
    <lastmod>2026-07-30T03:54:27.549Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-delegated-permissions-granted-for-all-users-a6355fbe</loc>
    <lastmod>2026-07-30T03:54:25.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-appid-uri-configuration-updates-for-applications-or-service--1b45b0d1</loc>
    <lastmod>2026-07-30T03:54:23.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-user-added-to-global-or-device-administrator-roles-11c767ae</loc>
    <lastmod>2026-07-30T03:54:21.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-logs-user-added-to-administrator-role-ebbeb024</loc>
    <lastmod>2026-07-30T03:54:19.750Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-audit-trustedcasforpasswordlessauth-root-ca-added-via-set-company-infor-4bb80281</loc>
    <lastmod>2026-07-30T03:54:18.167Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-device-registration-policy-changes-via-audit-logs-9494bff8</loc>
    <lastmod>2026-07-30T03:54:16.594Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-certificate-based-authentication-enabled-via-authentication-methods-pol-c2496b41</loc>
    <lastmod>2026-07-30T03:54:15.071Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-audit-logs-bitlocker-key-retrieval-via-read-bitlocker-key-a0413867</loc>
    <lastmod>2026-07-30T03:54:12.570Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-audit-logs-user-account-added-and-deleted-quickly-6f583da0</loc>
    <lastmod>2026-07-30T03:54:10.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-conditional-access-policy-added-by-non-approved-actor-0922467f</loc>
    <lastmod>2026-07-30T03:54:09.107Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-conditional-access-policy-updated-by-non-approved-actor-50a3c7aa</loc>
    <lastmod>2026-07-30T03:54:07.496Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-conditional-access-policy-deleted-by-non-approved-actor-26e7c5e2</loc>
    <lastmod>2026-07-30T03:54:05.807Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-vpn-gateway-connection-modified-or-deleted-61171ffc</loc>
    <lastmod>2026-07-30T03:54:02.909Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-log-virtual-network-modified-or-deleted-bcfcc962</loc>
    <lastmod>2026-07-30T03:54:01.442Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-alert-suppression-rule-created-92cc3e5d</loc>
    <lastmod>2026-07-30T03:53:58.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-permission-elevation-to-manage-all-subscriptions-09438caa</loc>
    <lastmod>2026-07-30T03:53:57.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-alert-on-rare-subscription-level-operations-from-new-source--c1182e02</loc>
    <lastmod>2026-07-30T03:53:55.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-cloud-shell-created-via-microsoft-portal-consoles-write-72af37e2</loc>
    <lastmod>2026-07-30T03:53:54.308Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-virtual-network-device-modified-or-deleted-15ef3fac</loc>
    <lastmod>2026-07-30T03:53:52.603Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-network-security-group-security-rules-modified-or-deleted-d22b4df4</loc>
    <lastmod>2026-07-30T03:53:50.490Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-point-to-site-vpn-gateway-modified-or-deleted-d9557b75</loc>
    <lastmod>2026-07-30T03:53:48.892Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-firewall-rule-collections-and-groups-modified-or-deleted-via-activity-logs-2a7d64cf</loc>
    <lastmod>2026-07-30T03:53:47.494Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-network-firewall-policy-modified-or-deleted-via-activity-logs-83c17918</loc>
    <lastmod>2026-07-30T03:53:45.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-kubernetes-service-account-write-delete-or-impersonate-12d027c3</loc>
    <lastmod>2026-07-30T03:53:44.080Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-kubernetes-service-activity-logs-secret-configmap-write-or-delete-7ee0b4aa</loc>
    <lastmod>2026-07-30T03:53:42.406Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-rolebinding-clusterrolebinding-created-patched-or-deleted-ku-25cb259b</loc>
    <lastmod>2026-07-30T03:53:40.581Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-kubernetes-rbac-roles-clusterroles-modified-or-deleted-818fee0c</loc>
    <lastmod>2026-07-30T03:53:38.821Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-kubernetes-pod-deletion-via-connected-clusters-api-b02f9591</loc>
    <lastmod>2026-07-30T03:53:37.275Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-kubernetes-network-policy-write-delete-operations-08d6ac24</loc>
    <lastmod>2026-07-30T03:53:35.749Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-kubernetes-event-deletion-in-activity-logs-225d8b09</loc>
    <lastmod>2026-07-30T03:53:34.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-kubernetes-cronjob-or-job-write-operations-1c71e254</loc>
    <lastmod>2026-07-30T03:53:32.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-kubernetes-connected-cluster-created-or-deleted-via-activity-logs-9541f321</loc>
    <lastmod>2026-07-30T03:53:31.239Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-kubernetes-admission-webhook-configuration-write-a61a3c56</loc>
    <lastmod>2026-07-30T03:53:29.610Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-key-vault-secrets-modified-or-deleted-via-activity-logs-b831353c</loc>
    <lastmod>2026-07-30T03:53:27.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-key-vault-write-delete-deployment-and-access-policy-changes-459a2970</loc>
    <lastmod>2026-07-30T03:53:26.495Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-key-vault-key-modified-or-deleted-via-activity-log-80eeab92</loc>
    <lastmod>2026-07-30T03:53:24.440Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-granting-role-permissions-via-roleassignments-write-from-new-a622fcd2</loc>
    <lastmod>2026-07-30T03:53:22.777Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-firewall-rule-collections-modified-or-deleted-activity-logs-025c9fe7</loc>
    <lastmod>2026-07-30T03:53:21.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-firewall-created-modified-or-deleted-via-azure-activity-logs-512cf937</loc>
    <lastmod>2026-07-30T03:53:19.756Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-dns-zone-modified-or-deleted-via-activity-logs-af6925b0</loc>
    <lastmod>2026-07-30T03:53:18.199Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-log-device-or-device-configuration-modified-or-deleted-46530378</loc>
    <lastmod>2026-07-30T03:53:16.584Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-high-rate-of-vm-creation-or-deployment-writes-d2d901db</loc>
    <lastmod>2026-07-30T03:53:14.891Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-container-registry-created-or-deleted-93e0ef48</loc>
    <lastmod>2026-07-30T03:53:13.434Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-application-security-group-modified-or-deleted-via-activity-logs-835747f1</loc>
    <lastmod>2026-07-30T03:53:12.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-application-gateway-modified-or-deleted-via-activity-logs-ad87d14e</loc>
    <lastmod>2026-07-30T03:53:10.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-activity-logs-deletion-of-azure-ad-hybrid-health-ad-fs-service-48739819</loc>
    <lastmod>2026-07-30T03:53:08.995Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-ad-hybrid-health-ad-fs-new-updated-service-member-server-via-administrativ-288a39fc</loc>
    <lastmod>2026-07-30T03:53:07.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-updateloginprofile-password-changes-for-other-users-055fb148</loc>
    <lastmod>2026-07-30T03:53:05.473Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-suspicious-saml-provider-updates-and-assumerolewithsaml-f43f5d2f</loc>
    <lastmod>2026-07-30T03:53:03.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-iamuser-getsessiontoken-activity-b45ab1d2</loc>
    <lastmod>2026-07-30T03:53:01.553Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-sts-getcalleridentity-user-agent-trufflehog-enumeration-9b1b8e9b</loc>
    <lastmod>2026-07-30T03:53:00.055Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-detect-assumerole-events-where-the-caller-is-an-assumed-role-905d389b</loc>
    <lastmod>2026-07-30T03:52:58.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-detects-aws-identity-center-identity-provider-changes-d3adb3ef</loc>
    <lastmod>2026-07-30T03:52:55.733Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-modify-ec2-snapshot-permissions-for-cross-account-access-abae8fec</loc>
    <lastmod>2026-07-30T03:52:54.131Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-security-hub-finding-evasion-via-finding-updates-and-deletions-cloudtrail-a607e1fe</loc>
    <lastmod>2026-07-30T03:52:52.460Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-s3-bucket-configuration-and-object-restore-tampering-via-manageme-78b3756a</loc>
    <lastmod>2026-07-30T03:52:50.874Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-route-53-domain-transferred-to-another-aws-account-b056de1a</loc>
    <lastmod>2026-07-30T03:52:48.936Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-route-53-domain-transfer-lock-disabled-via-cloudtrail-disabledomaintransferl-3940b5f1</loc>
    <lastmod>2026-07-30T03:52:47.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-root-user-activity-for-account-access-8ad1600d</loc>
    <lastmod>2026-07-30T03:52:45.594Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-public-rds-instance-restored-from-snapshot-c3f265c7</loc>
    <lastmod>2026-07-30T03:52:43.804Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-rds-cluster-modifydbcluster-or-deletedbcluster-activity-457cc9ac</loc>
    <lastmod>2026-07-30T03:52:42.311Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-rds-modifydbinstance-master-user-password-change-8a63cdd4</loc>
    <lastmod>2026-07-30T03:52:40.703Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-glue-development-endpoint-management-via-cloudtrail-api-4990c2e3</loc>
    <lastmod>2026-07-30T03:52:39.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-detects-lambda-layer-attach-via-updatefunctionconfiguration-97fbabf8</loc>
    <lastmod>2026-07-30T03:52:37.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-lambda-function-url-configuration-created-ec541962</loc>
    <lastmod>2026-07-30T03:52:35.889Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-kms-imported-key-material-use-importkeymaterial-deleteimportedkey-1279262f</loc>
    <lastmod>2026-07-30T03:52:34.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-s3-browser-creating-iam-user-or-access-key-db014773</loc>
    <lastmod>2026-07-30T03:52:32.695Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-s3-browser-creates-inline-iam-policy-with-default-bucket-placehol-db014773</loc>
    <lastmod>2026-07-30T03:52:31.104Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-s3-browser-enumerating-iam-loginprofiles-and-creating-missing-pro-db014773</loc>
    <lastmod>2026-07-30T03:52:29.297Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-iam-createaccesskey-for-another-user-potential-backdoor-keys-0a5177f4</loc>
    <lastmod>2026-07-30T03:52:27.491Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-guardduty-trusted-ip-set-updates-via-createipset-6e61ee20</loc>
    <lastmod>2026-07-30T03:52:25.759Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-s3-listbuckets-by-non-assumedrole-accounts-possible-bucket-enumer-f305fd62</loc>
    <lastmod>2026-07-30T03:52:24.201Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-elasticache-security-group-modified-or-deleted-cloudtrail-7c797da2</loc>
    <lastmod>2026-07-30T03:52:22.706Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-elasticache-cache-security-group-created-via-cloudtrail-4ae68615</loc>
    <lastmod>2026-07-30T03:52:21.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-eks-cluster-createcluster-or-deletecluster-via-cloudtrail-33d50d03</loc>
    <lastmod>2026-07-30T03:52:19.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-efs-mount-target-deleted-or-modified-6a7ba45c</loc>
    <lastmod>2026-07-30T03:52:18.183Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-efs-deletefilesystem-events-for-fileshare-modification-or-deletion-25cb1ba1</loc>
    <lastmod>2026-07-30T03:52:16.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-ecs-task-definitions-that-reference-container-credential-endpoint-uri-b94bf91e</loc>
    <lastmod>2026-07-30T03:52:14.745Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-detects-ec2-createinstanceexporttask-failure-54b9a76a</loc>
    <lastmod>2026-07-30T03:52:11.864Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-ec2-startup-script-userdata-modified-via-modifyinstanceattribute-1ab3c5ed</loc>
    <lastmod>2026-07-30T03:52:09.523Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-ec2-importkeypair-cloudtrail-activity-92f84194</loc>
    <lastmod>2026-07-30T03:52:08.051Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-ec2-disable-default-ebs-encryption-in-current-region-16124c2d</loc>
    <lastmod>2026-07-30T03:52:06.430Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-s3-bucket-versioning-disabled-via-putbucketversioning-cloudtrail-a136ac98</loc>
    <lastmod>2026-07-30T03:52:04.958Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-successful-deletion-of-saml-provider-ccd6a6c8</loc>
    <lastmod>2026-07-30T03:52:02.849Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-ses-identity-deletion-via-cloudtrail-deleteidentity-event-20f754db</loc>
    <lastmod>2026-07-30T03:52:01.246Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-getsignintoken-with-suspicious-console-user-agent-f8103686</loc>
    <lastmod>2026-07-30T03:51:59.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-detects-aws-config-delivery-channel-deletion-or-recorder-stopping-07330162</loc>
    <lastmod>2026-07-30T03:51:57.821Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-vpc-flow-logs-deleted-via-ec2-deleteflowlogs-e386b9b5</loc>
    <lastmod>2026-07-30T03:51:56.233Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-ssm-sendcommand-with-successful-execution-38e7f511</loc>
    <lastmod>2026-07-30T03:51:54.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-rds-security-group-rule-changes-via-cloudtrail-14f3f1c8</loc>
    <lastmod>2026-07-30T03:51:52.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-elb-alb-security-group-changes-via-applysecuritygroupstoloadbalan-7a4409fc</loc>
    <lastmod>2026-07-30T03:51:51.388Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-security-group-ingress-egress-rule-changes-6fb77778</loc>
    <lastmod>2026-07-30T03:51:49.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-enableregion-api-command-monitoring-for-account-region-enablement-a5ffb6ea</loc>
    <lastmod>2026-07-30T03:51:47.880Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-aws-cloudtrail-execution-of-trufflehog-via-trufflehog-user-agent-a840e606</loc>
    <lastmod>2026-07-30T03:51:46.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-createroute-new-network-route-added-to-route-table-c803b2ce</loc>
    <lastmod>2026-07-30T03:51:44.543Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-detect-createnetworkaclentry-new-network-acl-rule-added-e1f7febb</loc>
    <lastmod>2026-07-30T03:51:43.024Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-detect-assumed-role-imds-activity-outside-ssm-managed-instance-re-352a918a</loc>
    <lastmod>2026-07-30T03:51:41.345Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-guardduty-detector-deleted-or-disabled-via-deletedetector-updated-d2656e78</loc>
    <lastmod>2026-07-30T03:51:39.212Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-stoplogging-updatetrail-and-deletetrail-changes-4db60cc0</loc>
    <lastmod>2026-07-30T03:51:37.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-consolelogin-success-events-where-mfaused-is-no-77caf516</loc>
    <lastmod>2026-07-30T03:51:35.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-cloudtrail-consolelogin-failed-authentication-events-6393e346</loc>
    <lastmod>2026-07-30T03:51:34.393Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-s3-bucket-deletion-observed-in-cloudtrail-39c9f26d</loc>
    <lastmod>2026-07-30T03:51:32.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-bedrock-guardrail-updated-updateguardrail-api-via-cloudtrail-1c722651</loc>
    <lastmod>2026-07-30T03:51:30.547Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-bedrock-guardrail-deletion-via-cloudtrail-deleteguardrail-api-call-59b70e4d</loc>
    <lastmod>2026-07-30T03:51:29.016Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-keyword-matching-drop-truncate-dump-select-d84c0ded</loc>
    <lastmod>2026-07-30T03:51:27.334Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-web-shell-signature-alerts-asp-jsp-php-perl-vbs-and-related-backdoor-i-fdf135a2</loc>
    <lastmod>2026-07-30T03:51:25.761Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-remote-access-tool-detections-by-malware-family-signatures-agentb-agen-97233998</loc>
    <lastmod>2026-07-30T03:51:23.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-detections-for-executables-and-web-scripts-in-relevant-file-paths-c9a88268</loc>
    <lastmod>2026-07-30T03:51:22.287Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-ransomware-signature-alert-based-on-known-family-name-strings-4c6ca276</loc>
    <lastmod>2026-07-30T03:51:20.736Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-password-dumper-signature-match-pws-78cc2dd2</loc>
    <lastmod>2026-07-30T03:51:19.260Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-detect-hacktool-and-attack-tool-signatures-by-name-and-prefix-fa0c05b6</loc>
    <lastmod>2026-07-30T03:51:17.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-detections-matching-known-exploitation-framework-signatures-238527ad</loc>
    <lastmod>2026-07-30T03:51:15.780Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/antivirus-signature-hits-for-apt-malware-naming-patterns-101a1877</loc>
    <lastmod>2026-07-30T03:51:14.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/velocity-template-renderer-exceptions-indicating-possible-ssti-via-parseerrorexc-16c86189</loc>
    <lastmod>2026-07-30T03:51:12.673Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sql-error-message-keywords-indicating-potential-injection-probing-8a670c6d</loc>
    <lastmod>2026-07-30T03:51:11.017Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/spring-application-logs-potential-spel-injection-causing-expressionexception-err-e9edd087</loc>
    <lastmod>2026-07-30T03:51:08.841Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/spring-framework-security-exceptions-indicating-suspicious-access-and-csrf-handl-ae48ab93</loc>
    <lastmod>2026-07-30T03:51:07.367Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ruby-on-rails-application-exceptions-indicating-invalid-requests-0d2c3d4c</loc>
    <lastmod>2026-07-30T03:51:05.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharphound-discovery-via-rpc-firewall-opnum-12-sessions-6d580420</loc>
    <lastmod>2026-07-30T03:51:04.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sharphound-account-discovery-via-rpc-firewall-blocking-opnum-2-interface-uuid-ma-65f77b1e</loc>
    <lastmod>2026-07-30T03:51:03.022Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-sasec-scheduled-task-reconnaissance-opnum-0-1-via-ms-tsch-0a3ff354</loc>
    <lastmod>2026-07-30T03:51:01.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rpc-firewall-alerts-on-remote-scheduled-task-creation-or-execution-via-s-aff229ab</loc>
    <lastmod>2026-07-30T03:50:59.664Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-remote-efsr-encryption-service-calls-for-lateral-movement-10018e73</loc>
    <lastmod>2026-07-30T03:50:58.025Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-rpcfw-eventid-3-ms-srvs-interfaceuuid-abuse-indicators-b6ea3cc7</loc>
    <lastmod>2026-07-30T03:50:56.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-registry-remote-recon-via-rrp-interface-uuid-d8ffe17e</loc>
    <lastmod>2026-07-30T03:50:54.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-detects-remote-registry-modification-via-microsoft-rrp-interface-ca-35c55673</loc>
    <lastmod>2026-07-30T03:50:53.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detect-remote-dcom-wmi-rpc-connections-via-rpc-firewall-event-id-3-68050b10</loc>
    <lastmod>2026-07-30T03:50:51.169Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-rpc-firewall-remote-printing-rpc-interface-calls-bc3a4b0c</loc>
    <lastmod>2026-07-30T03:50:49.509Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-rpc-scheduled-task-recon-via-itaskschedulerservice-7f7c49eb</loc>
    <lastmod>2026-07-30T03:50:47.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-task-scheduler-lateral-movement-via-itaskschedulerservice-rpc-ace3ff54</loc>
    <lastmod>2026-07-30T03:50:46.123Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-detects-remote-windows-event-log-recon-via-even-even6-eventid-3-2053961f</loc>
    <lastmod>2026-07-30T03:50:42.531Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-detection-for-remote-ms-efsr-encrypting-file-system-abuse-5f92fff9</loc>
    <lastmod>2026-07-30T03:50:40.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-ms-drsr-opcode-detections-from-non-domain-controllers-56fda488</loc>
    <lastmod>2026-07-30T03:50:39.151Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-detects-remote-scheduled-task-reconnaissance-via-atscv-f177f2bc</loc>
    <lastmod>2026-07-30T03:50:37.101Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rpc-firewall-atsvc-remote-schedule-task-execution-opnum-0-1-detection-0fcd1c79</loc>
    <lastmod>2026-07-30T03:50:35.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/python-sql-exception-errors-pep-249-logged-by-applications-19aefed0</loc>
    <lastmod>2026-07-30T03:50:33.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-vnc-connection-attempt-on-instrumented-node-9db5446c</loc>
    <lastmod>2026-07-30T03:50:31.814Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-tftp-service-request-observed-b4e6b016</loc>
    <lastmod>2026-07-30T03:50:30.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-telnet-login-attempt-on-port-23-512cff7a</loc>
    <lastmod>2026-07-30T03:50:28.844Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-detects-new-ssh-connection-attempts-on-monitored-nodes-cd55f721</loc>
    <lastmod>2026-07-30T03:50:27.380Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-ssh-login-attempt-on-application-log-events-ff7139bc</loc>
    <lastmod>2026-07-30T03:50:25.836Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-snmp-oid-request-observed-e9856028</loc>
    <lastmod>2026-07-30T03:50:24.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-smb-file-open-request-observed-22777c9e</loc>
    <lastmod>2026-07-30T03:50:22.683Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-sip-request-activity-application-logs-e30de276</loc>
    <lastmod>2026-07-30T03:50:20.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-redis-action-command-attempt-547dfc53</loc>
    <lastmod>2026-07-30T03:50:19.282Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-rdp-service-new-connection-attempt-logged-598290cf</loc>
    <lastmod>2026-07-30T03:50:17.845Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-application-telemetry-syn-port-scan-targeting-a-host-974be8d2</loc>
    <lastmod>2026-07-30T03:50:16.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-network-service-logs-nmap-xmas-scan-targeting-detection-d7553d7b</loc>
    <lastmod>2026-07-30T03:50:14.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-nmap-os-scan-targeting-via-application-logtype-5002-e8a677fd</loc>
    <lastmod>2026-07-30T03:50:12.946Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-nmap-null-scan-targeting-logtype-5003-68b8547b</loc>
    <lastmod>2026-07-30T03:50:11.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-nmap-fin-scan-targeting-detection-application-logtype-5005-eae8c0c8</loc>
    <lastmod>2026-07-30T03:50:09.773Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-ntp-service-monlist-request-logged-7cded4b3</loc>
    <lastmod>2026-07-30T03:50:08.297Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-mysql-service-login-attempt-e7d79a1b</loc>
    <lastmod>2026-07-30T03:50:06.848Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-mssql-windows-authentication-login-attempt-6e78f90f</loc>
    <lastmod>2026-07-30T03:50:05.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-mssql-sqlauth-login-attempt-detected-3ec9a16d</loc>
    <lastmod>2026-07-30T03:50:03.435Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-httpproxy-login-attempt-proxy-request-5498fc09</loc>
    <lastmod>2026-07-30T03:50:01.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-http-form-post-login-attempt-application-logtype-3001-af1ac430</loc>
    <lastmod>2026-07-30T03:50:00.325Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-http-get-request-received-on-service-port-af6c3078</loc>
    <lastmod>2026-07-30T03:49:58.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-detects-git-clone-requests-on-git-service-4fe17521</loc>
    <lastmod>2026-07-30T03:49:57.153Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/opencanary-ftp-login-attempt-activity-6991bc2b</loc>
    <lastmod>2026-07-30T03:49:55.490Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/node-js-application-error-logs-indicating-potential-rce-via-child-process-97661d9d</loc>
    <lastmod>2026-07-30T03:49:54.003Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-api-audit-unauthorized-401-or-forbidden-403-access-attempts-0d933542</loc>
    <lastmod>2026-07-30T03:49:52.209Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-sidecar-injection-via-kubectl-patch-on-deployments-ad9012a6</loc>
    <lastmod>2026-07-30T03:49:50.590Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-serviceaccount-created-via-audit-logging-e31bae15</loc>
    <lastmod>2026-07-30T03:49:49.014Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-secrets-modified-or-deleted-via-api-verbs-58d31a75</loc>
    <lastmod>2026-07-30T03:49:47.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-logs-listing-secrets-for-enumeration-eeb3e9e1</loc>
    <lastmod>2026-07-30T03:49:45.500Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-rolebinding-clusterrolebinding-created-or-modified-via-rbac-api-10b97915</loc>
    <lastmod>2026-07-30T03:49:43.802Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-selfsubjectrulesreviews-rbac-permission-enumeration-attempt-84b777bd</loc>
    <lastmod>2026-07-30T03:49:42.082Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-privileged-pod-created-via-api-server-audit-logs-c5cd1b20</loc>
    <lastmod>2026-07-30T03:49:40.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-log-signals-potential-enumeration-via-shells-and-recon-tools-597a7e84</loc>
    <lastmod>2026-07-30T03:49:38.131Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-pod-creation-in-kube-system-namespace-via-api-audit-logs-a80d927d</loc>
    <lastmod>2026-07-30T03:49:36.043Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-pod-created-with-hostpath-volume-mount-402b955c</loc>
    <lastmod>2026-07-30T03:49:34.519Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-pod-container-exec-via-kubernetes-api-remote-command-execution-a1b0ca4e</loc>
    <lastmod>2026-07-30T03:49:32.712Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-events-deleted-3132570d</loc>
    <lastmod>2026-07-30T03:49:31.293Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-deployment-deleted-via-audit-logs-40967487</loc>
    <lastmod>2026-07-30T03:49:29.957Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-cronjob-job-create-or-modification-events-batch-api-0c9b3bda</loc>
    <lastmod>2026-07-30T03:49:28.512Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-audit-admission-webhook-configuration-changes-via-api-actions-eed82177</loc>
    <lastmod>2026-07-30T03:49:27.007Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/jvm-application-error-logs-indicating-possible-xxe-parsing-failures-c4e06896</loc>
    <lastmod>2026-07-30T03:49:25.226Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/jvm-process-execution-error-messages-indicating-failed-program-launch-d65f37da</loc>
    <lastmod>2026-07-30T03:49:23.402Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/jvm-application-error-logs-ognl-injection-exploitation-indicators-4d0af518</loc>
    <lastmod>2026-07-30T03:49:20.614Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/jvm-application-errors-indicating-local-file-read-path-traversal-attempts-e032f5bc</loc>
    <lastmod>2026-07-30T03:49:19.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/jvm-application-error-logs-indicating-jndi-injection-payloads-bb0e9cec</loc>
    <lastmod>2026-07-30T03:49:17.238Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-enterprise-audit-ssh-certificate-authority-config-change-2f575940</loc>
    <lastmod>2026-07-30T03:49:15.530Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-log-self-hosted-runner-configuration-change-alerts-f8ed0e8f</loc>
    <lastmod>2026-07-30T03:49:13.426Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-secret-scanning-disabled-audit-actions-for-enterprise-or-repository-3883d9a0</loc>
    <lastmod>2026-07-30T03:49:11.837Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-logs-repository-archived-unarchived-status-change-dca8991c</loc>
    <lastmod>2026-07-30T03:49:10.266Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-repository-or-organization-transfer-events-04ad83ef</loc>
    <lastmod>2026-07-30T03:49:08.882Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-secret-scanning-push-protection-disabled-ccd55945</loc>
    <lastmod>2026-07-30T03:49:07.163Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-secret-scanning-push-protection-bypass-activity-detected-02cf536a</loc>
    <lastmod>2026-07-30T03:49:05.648Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-log-repository-pages-changed-to-public-0c46d4f4</loc>
    <lastmod>2026-07-30T03:49:04.229Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-outside-collaborator-membership-and-permissions-changed-eaa9ac35</loc>
    <lastmod>2026-07-30T03:49:02.522Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-new-actions-secret-created-organization-environment-codespaces-or-r-f9405037</loc>
    <lastmod>2026-07-30T03:49:00.852Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-log-new-org-member-added-or-invited-3908d64a</loc>
    <lastmod>2026-07-30T03:48:59.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-private-repository-forking-policy-enabled-or-cleared-69b3bd1e</loc>
    <lastmod>2026-07-30T03:48:57.711Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-logs-dependabot-alerts-or-security-updates-disabled-34e1c7d4</loc>
    <lastmod>2026-07-30T03:48:56.061Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-organizational-high-risk-security-controls-disabled-8622c92d</loc>
    <lastmod>2026-07-30T03:48:54.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/github-audit-logs-codespaces-and-repo-delete-actions-16a71777</loc>
    <lastmod>2026-07-30T03:48:52.742Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/django-application-exceptions-suspicious-security-related-errors-fd435618</loc>
    <lastmod>2026-07-30T03:48:51.008Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-logs-user-permissions-export-attempt-87cc6698</loc>
    <lastmod>2026-07-30T03:48:49.331Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-ssh-user-login-failures-audit-authentication-events-d3f90469</loc>
    <lastmod>2026-07-30T03:48:47.742Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-user-login-failed-authentication-events-70ed1d26</loc>
    <lastmod>2026-07-30T03:48:41.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-logs-user-permissions-export-attempt-5259cbf2</loc>
    <lastmod>2026-07-30T03:48:40.271Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-unauthorized-full-data-export-triggered-34d81081</loc>
    <lastmod>2026-07-30T03:48:38.698Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-unauthorized-access-to-a-resource-7215374a</loc>
    <lastmod>2026-07-30T03:48:36.797Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-secret-scanning-rule-deleted-for-project-or-repository-ff91e3f0</loc>
    <lastmod>2026-07-30T03:48:35.363Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-secret-scanning-exempt-repository-added-b91e8d5e</loc>
    <lastmod>2026-07-30T03:48:33.841Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-project-secret-scanning-allowlist-rule-added-42ccce6d</loc>
    <lastmod>2026-07-30T03:48:32.097Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-log-configuration-updated-6aa12161</loc>
    <lastmod>2026-07-30T03:48:30.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-global-ssh-settings-changed-16ab6143</loc>
    <lastmod>2026-07-30T03:48:29.009Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-global-secret-scanning-rule-deleted-e16cf0f0</loc>
    <lastmod>2026-07-30T03:48:27.601Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-global-permission-added-or-removed-aac6c4f4</loc>
    <lastmod>2026-07-30T03:48:26.197Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitbucket-audit-logs-full-data-export-triggered-195e1b9d</loc>
    <lastmod>2026-07-30T03:48:24.729Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-shell-context-menu-command-tampering-via-shell-command-key-chan-868df2d1</loc>
    <lastmod>2026-07-30T03:48:23.402Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-imagepath-set-to-user-controlled-directory-via-registry-277dc340</loc>
    <lastmod>2026-07-30T03:48:21.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-run-dialog-command-history-in-runmru-registry-f9d091f6</loc>
    <lastmod>2026-07-30T03:48:20.149Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-modification-via-powershell-crypto-classes-in-shell-open-comman-1c2a3268</loc>
    <lastmod>2026-07-30T03:48:18.743Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-microsoft-office-trusted-locations-modified-a0bed973</loc>
    <lastmod>2026-07-30T03:48:16.308Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-created-via-registry-key-activity-93ff0ceb</loc>
    <lastmod>2026-07-30T03:48:14.732Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wusa-exe-cab-extraction-using-unsupported-extract-flag-59b39960</loc>
    <lastmod>2026-07-30T03:48:13.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-arbitrary-command-execution-via-wsl-wsl-exe-on-windows-dec44ca7</loc>
    <lastmod>2026-07-30T03:48:11.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detect-wscript-cscript-executing-javascript-vbscript-vba-vbe-wsf-wsh-files-on-wi-1e33157c</loc>
    <lastmod>2026-07-30T03:48:09.420Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmic-system-information-discovery-via-wmi-command-line-d85ecdd7</loc>
    <lastmod>2026-07-30T03:48:07.476Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-winscp-execution-from-non-default-install-path-7674f8ef</loc>
    <lastmod>2026-07-30T03:48:05.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winscp-cli-ftp-sftp-open-attempt-via-command-c1477deb</loc>
    <lastmod>2026-07-30T03:48:03.950Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-tasklist-exe-process-discovery-via-command-line-63332011</loc>
    <lastmod>2026-07-30T03:48:00.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-termination-using-taskkill-exe-86085955</loc>
    <lastmod>2026-07-30T03:47:58.946Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-script-interpreter-execution-from-extracted-compressed-files-7zip-winrar-95724fc1</loc>
    <lastmod>2026-07-30T03:47:56.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-self-launching-executable-running-as-sacrificial-proces-bafd07c6</loc>
    <lastmod>2026-07-30T03:47:54.675Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-browser-process-opens-html-from-downloads-folder-538c5851</loc>
    <lastmod>2026-07-30T03:47:52.524Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-lines-using-8-3-short-name-paths-1-2-349d891d</loc>
    <lastmod>2026-07-30T03:47:50.787Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-based-detection-of-file-and-folder-permission-changes-via-acl-to-37ae075c</loc>
    <lastmod>2026-07-30T03:47:49.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-common-tunneling-and-proxy-tools-c75309a3</loc>
    <lastmod>2026-07-30T03:47:47.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-from-web-server-root-directories-35efb964</loc>
    <lastmod>2026-07-30T03:47:45.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-guid-like-folder-paths-in-command-line-90b63c33</loc>
    <lastmod>2026-07-30T03:47:43.070Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-lines-query-event-logs-via-wevtutil-wmic-or-powershell-9cd55b6c</loc>
    <lastmod>2026-07-30T03:47:41.317Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-privileged-shell-spawn-via-elevated-logon-powershell-cmd-61065c72</loc>
    <lastmod>2026-07-30T03:47:39.415Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-command-line-parameters-for-7z-and-rar-compr-27a72a60</loc>
    <lastmod>2026-07-30T03:47:37.793Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-via-schtasks-exe-from-suspicious-parent-paths-9494479d</loc>
    <lastmod>2026-07-30T03:47:34.488Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sc-exe-service-query-execution-via-command-line-57712d7a</loc>
    <lastmod>2026-07-30T03:47:32.589Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-explicit-dllregisterserver-export-calls-from-non-standard-p-d81a9fc6</loc>
    <lastmod>2026-07-30T03:47:30.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-loads-dll-exports-by-ordinal-in-command-line-e79a9e79</loc>
    <lastmod>2026-07-30T03:47:29.363Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-remote-command-execution-via-clientservice-exe-process-cre-d1a401ab</loc>
    <lastmod>2026-07-30T03:47:27.509Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/anyviewer-rmm-remote-session-executes-cmd-exe-via-avcore-exe-bc533330</loc>
    <lastmod>2026-07-30T03:47:26.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ammy-admin-agent-execution-via-rundll32-7da7809e</loc>
    <lastmod>2026-07-30T03:47:24.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-action1-agent-and-remote-session-setup-aa3168fb</loc>
    <lastmod>2026-07-30T03:47:22.977Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-executes-dlls-with-s-and-e-from-uncommon-paths-implicit-dllregi-ce2c44b5</loc>
    <lastmod>2026-07-30T03:47:21.179Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-powershell-child-processes-spawned-by-powershell-exe-pwsh-exe-e4b6d2a7</loc>
    <lastmod>2026-07-30T03:47:19.397Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-new-netfirewallrule-adds-windows-allow-firewall-rule-51483085</loc>
    <lastmod>2026-07-30T03:47:17.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-process-import-module-execution-in-command-line-4ad74d01</loc>
    <lastmod>2026-07-30T03:47:15.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-process-command-line-uses-system-security-cryptography-classes-ad856965</loc>
    <lastmod>2026-07-30T03:47:14.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-alert-on-unusually-long-commandline-length-1000-characters-d0d28567</loc>
    <lastmod>2026-07-30T03:47:12.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-svchost-spawning-office-applications-via-com-instance-creation-9bdaf1e9</loc>
    <lastmod>2026-07-30T03:47:10.058Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-net-exe-mounting-smb-over-quic-via-transport-quic-2238d337</loc>
    <lastmod>2026-07-30T03:47:08.327Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-net-exe-or-net1-exe-execution-183e7ea8</loc>
    <lastmod>2026-07-30T03:47:06.538Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-code-page-change-via-mode-com-d48c5ffa</loc>
    <lastmod>2026-07-30T03:47:04.759Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-microsoft-workflow-compiler-exe-419dbf2b</loc>
    <lastmod>2026-07-30T03:47:03.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-iexpress-creating-self-extracting-packages-via-makecab-c2b478fc</loc>
    <lastmod>2026-07-30T03:47:01.591Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-findstr-exe-password-keyword-search-in-multiple-languages-1a0f6f16</loc>
    <lastmod>2026-07-30T03:46:59.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-extexport-exe-execution-indicative-of-dll-sideloading-fb0b815b</loc>
    <lastmod>2026-07-30T03:46:57.907Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-proxy-execution-explorer-exe-spawned-by-cmd-exe-or-powershell-9eb271b9</loc>
    <lastmod>2026-07-30T03:46:56.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-diskshadow-script-mode-execution-via-s-flag-0c2f8629</loc>
    <lastmod>2026-07-30T03:46:54.592Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-diskshadow-exe-spawning-child-processes-56b1dde8</loc>
    <lastmod>2026-07-30T03:46:52.874Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-clickonce-deployment-execution-via-dfsvc-exe-child-process-241d52b5</loc>
    <lastmod>2026-07-30T03:46:51.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-execution-using-custom-user-agent-option-3286d37a</loc>
    <lastmod>2026-07-30T03:46:49.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-flagged-curl-exe-upload-or-form-data-command-line-activity-00bca14a</loc>
    <lastmod>2026-07-30T03:46:47.955Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-process-execution-for-remote-file-transfer-bbeaed61</loc>
    <lastmod>2026-07-30T03:46:46.029Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-file-download-via-o-remote-name-or-output-9a517fca</loc>
    <lastmod>2026-07-30T03:46:44.530Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-csc-exe-dynamic-net-compilation-acf2807c</loc>
    <lastmod>2026-07-30T03:46:42.350Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-headless-child-process-spawned-via-conhost-exe-00ca75ab</loc>
    <lastmod>2026-07-30T03:46:40.693Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-set-p-file-append-override-pattern-65e4c134</loc>
    <lastmod>2026-07-30T03:46:38.879Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-uc-berkeley-boinc-related-software-execution-string-mat-0090b851</loc>
    <lastmod>2026-07-30T03:46:35.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-attrib-exe-run-with-s-flag-to-mark-files-as-system-files-bb19e94c</loc>
    <lastmod>2026-07-30T03:46:33.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-7-zip-extraction-of-password-protected-archives-using-p-b717b8fd</loc>
    <lastmod>2026-07-30T03:46:31.960Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-with-high-grantedaccess-to-wmi-provider-and-lsass-250ae82f</loc>
    <lastmod>2026-07-30T03:46:30.065Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-to-lsass-from-suspicious-source-folders-fa34b441</loc>
    <lastmod>2026-07-30T03:46:26.530Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-process-accessing-lsass-exe-for-possible-credential-dumping-0f920ebe</loc>
    <lastmod>2026-07-30T03:46:24.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winapi-function-calls-from-powershell-script-blocks-9f22ccd5</loc>
    <lastmod>2026-07-30T03:46:23.113Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scripts-calling-winapi-dlls-on-windows-19d65a1c</loc>
    <lastmod>2026-07-30T03:46:21.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-script-block-token-obfuscation-via-invoke-obfuscation-patterns-f3a98ce4</loc>
    <lastmod>2026-07-30T03:46:19.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-send-mailmessage-with-attachments-for-possible-smtp-data--9a7afa56</loc>
    <lastmod>2026-07-30T03:46:16.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-remove-item-used-to-delete-files-or-folders-b8af5f36</loc>
    <lastmod>2026-07-30T03:46:15.526Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-registry-reconnaissance-via-script-block-queries-windows-064060aa</loc>
    <lastmod>2026-07-30T03:46:13.728Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-smb-share-mapping-over-quic-new-smbmapping-6df07c3b</loc>
    <lastmod>2026-07-30T03:46:12.212Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-scriptblock-adds-windows-firewall-allow-rule-via-new-netfirewallrule-8d31dd2e</loc>
    <lastmod>2026-07-30T03:46:10.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-access-to-windows-mailapp-mailbox-data-paths-4e485d01</loc>
    <lastmod>2026-07-30T03:46:08.261Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/exchangepowershell-inbox-rule-creation-or-update-via-new-inboxrule-set-inboxrule-04580eed</loc>
    <lastmod>2026-07-30T03:46:06.261Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mail-forwarding-redirecting-via-exchangepowershell-cmdlets-on-windows-0c7686d5</loc>
    <lastmod>2026-07-30T03:46:04.633Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-compress-archive-cmdlet-execution-for-data-compression-6dc5d284</loc>
    <lastmod>2026-07-30T03:46:02.762Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-local-firewall-rule-enumeration-using-get-netfirewallrule-show-netfir-ea207a23</loc>
    <lastmod>2026-07-30T03:46:01.174Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-classic-detect-bxor-operator-in-consolehost-command-line-812837bb</loc>
    <lastmod>2026-07-30T03:45:59.592Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-uncommon-hostapplication-values-in-ps-classic-start-telemetry-d7326048</loc>
    <lastmod>2026-07-30T03:45:57.708Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-psexec-default-pipe-psexesvc-f3f3a972</loc>
    <lastmod>2026-07-30T03:45:56.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connection-from-process-in-c-users-public-folder-bcb03938</loc>
    <lastmod>2026-07-30T03:45:54.382Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-connections-to-azurefd-net-excluding-common-browsers-and-known-f-8cb4d14e</loc>
    <lastmod>2026-07-30T03:45:52.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-initiated-network-connections-1f21ec3f</loc>
    <lastmod>2026-07-30T03:45:51.005Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msiexec-exe-initiated-outbound-http-s-connection-on-ports-80-443-8e5e38e4</loc>
    <lastmod>2026-07-30T03:45:49.194Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-hh-exe-initiates-http-s-network-connections-468a8cea</loc>
    <lastmod>2026-07-30T03:45:47.638Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dllhost-exe-network-connection-to-non-local-ip-address-cfed2f44</loc>
    <lastmod>2026-07-30T03:45:46.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dfsvc-exe-initiated-network-connection-on-uncommon-destination-ports-windows-4c5fba4a</loc>
    <lastmod>2026-07-30T03:45:44.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dfsvc-exe-initiated-network-connections-to-non-local-ip-addresses-on-windows-3c21219b</loc>
    <lastmod>2026-07-30T03:45:42.714Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wmi-dll-modules-loaded-by-uncommon-image-paths-671bb7e3</loc>
    <lastmod>2026-07-30T03:45:41.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/werfaultsecure-loads-dbgcore-dll-or-dbghelp-dll-windows-image-load-8a2f4b1c</loc>
    <lastmod>2026-07-30T03:45:38.393Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-microsoft-word-loads-wll-add-in-files-1337afba</loc>
    <lastmod>2026-07-30T03:45:34.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-excel-loads-an-xll-add-in-via-excel-exe-image-load-c5f4b5cb</loc>
    <lastmod>2026-07-30T03:45:33.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-task-scheduler-dll-taskschd-dll-loaded-from-uncommon-paths-by-a-process-3b92a1d0</loc>
    <lastmod>2026-07-30T03:45:31.837Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-loads-system-drawing-ni-dll-666ecfc7</loc>
    <lastmod>2026-07-30T03:45:29.894Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-process-loads-bitsproxy-dll-via-image-load-e700ff14</loc>
    <lastmod>2026-07-30T03:45:26.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-amsi-dll-loaded-by-uncommon-process-facd1549</loc>
    <lastmod>2026-07-30T03:45:24.587Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-webdav-temporary-files-created-with-suspicious-extensions-4c55738d</loc>
    <lastmod>2026-07-30T03:45:20.978Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-create-of-code-tunnel-json-indicates-vs-code-tunneling-usage-9661ec9d</loc>
    <lastmod>2026-07-30T03:45:17.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-txt-creation-in-user-desktop-via-cmd-exe-caf02a0a</loc>
    <lastmod>2026-07-30T03:45:16.023Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-executable-file-creation-where-a-parent-executable-writes-another-exe-297afac9</loc>
    <lastmod>2026-07-30T03:45:14.310Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-created-via-file-creation-in-system-task-directories-a762e74f</loc>
    <lastmod>2026-07-30T03:45:12.585Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-creation-of-python-pth-path-configuration-files-in-site-packages-e3652ba3</loc>
    <lastmod>2026-07-30T03:45:10.944Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pfx-file-creation-via-file-write-events-dca1b3e8</loc>
    <lastmod>2026-07-30T03:45:08.845Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-dmp-hdmp-memory-dump-files-3a525307</loc>
    <lastmod>2026-07-30T03:45:07.348Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-deletion-of-zone-identifier-alternate-data-stream-7eac0a16</loc>
    <lastmod>2026-07-30T03:45:05.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-time-changed-to-an-earlier-year-possible-timestomping-558eebe5</loc>
    <lastmod>2026-07-30T03:45:04.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-to-unattend-xml-in-panther-directory-76a26006</loc>
    <lastmod>2026-07-30T03:45:02.449Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-to-hive-and-reg-backups-by-uncommon-applications-337a31c6</loc>
    <lastmod>2026-07-30T03:45:00.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-to-outlook-unistore-data-by-uncommon-processes-fc3e237f</loc>
    <lastmod>2026-07-30T03:44:56.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-to-browser-credential-stores-by-uncommon-processes-91cb43db</loc>
    <lastmod>2026-07-30T03:44:54.489Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-uncommon-processes-access-chromium-browser-cookie-and-history-files-c5f37810</loc>
    <lastmod>2026-07-30T03:44:52.386Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-thread-creation-via-cmd-exe-or-powershell-exe-windows-a9d4d3fa</loc>
    <lastmod>2026-07-30T03:44:50.599Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-remote-thread-creation-via-createremotethread-eeb2e3dc</loc>
    <lastmod>2026-07-30T03:44:48.958Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-createremotethread-with-loadlibrarya-for-dll-injection-052ec6f6</loc>
    <lastmod>2026-07-30T03:44:47.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4699-scheduled-task-deletion-detection-4f86b304</loc>
    <lastmod>2026-07-30T03:44:45.587Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-access-to-browser-credential-files-by-uncommon-processes-4b60e527</loc>
    <lastmod>2026-07-30T03:44:44.208Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-remote-wmi-activescripteventconsumers-via-scrcons-exe-event-id--9599c180</loc>
    <lastmod>2026-07-30T03:44:42.321Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-firewall-exception-rule-modified-event-ids-2005-2073-5570c4d9</loc>
    <lastmod>2026-07-30T03:44:40.553Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-successful-msix-appx-package-installation-via-event-id-854-appxdeploymen-289dfa9e</loc>
    <lastmod>2026-07-30T03:44:38.743Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-requests-for-class-uri-extensions-53c15703</loc>
    <lastmod>2026-07-30T03:44:37.209Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dns-queries-to-low-reputation-etlds-alphasoc-list-cf5ee356</loc>
    <lastmod>2026-07-30T03:44:35.754Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-clipboard-data-collection-via-pbpaste-command-execution-d8af0da1</loc>
    <lastmod>2026-07-30T03:44:34.250Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-python-pth-file-creation-in-site-packages-path-4f394635</loc>
    <lastmod>2026-07-30T03:44:32.379Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-discovery-via-common-cli-enumeration-tools-4e2f5868</loc>
    <lastmod>2026-07-30T03:44:30.625Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-termination-via-kill-pkill-killall-commands-64c41342</loc>
    <lastmod>2026-07-30T03:44:28.998Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-creation-long-filename-pattern-100-chars-excluding-known-system-paths-11629c4d</loc>
    <lastmod>2026-07-30T03:44:27.265Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-python-pth-file-creation-in-site-packages-fb96c26c</loc>
    <lastmod>2026-07-30T03:44:25.708Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-password-health-report-endpoint-accessed-via-reports-password-health-0d58814b</loc>
    <lastmod>2026-07-30T03:44:24.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-audit-inbox-rule-creation-or-update-with-email-hiding-actions-d3577be1</loc>
    <lastmod>2026-07-30T03:44:22.389Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/o365-audit-detect-mail-forwarding-and-redirect-rule-changes-c726e007</loc>
    <lastmod>2026-07-30T03:44:20.543Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-entra-id-sign-in-using-axios-user-agent-ea1a07f0</loc>
    <lastmod>2026-07-30T03:44:18.769Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-indicators-of-litellm-supply-chain-backdoor-activity-lite-36603778</loc>
    <lastmod>2026-07-30T03:44:17.022Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-persistence-file-creation-via-python3-paths-for-sysmon-py-and-systemd-user-81c0b7f5</loc>
    <lastmod>2026-07-30T03:44:15.090Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-execution-of-tanstack-runner-js-via-bun-exe-run-9b4f3d2e</loc>
    <lastmod>2026-07-30T03:44:13.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-execution-of-bun-runner-for-tanstack-supply-chain-comprom-3c6f5e4a</loc>
    <lastmod>2026-07-30T03:44:11.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-file-creation-of-tanstack-runner-and-router-init-persistence-arti-8a3f2c1e</loc>
    <lastmod>2026-07-30T03:44:09.623Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-creation-indicators-for-tanstack-related-supply-chain-runner-and-pers-2b5e4d3f</loc>
    <lastmod>2026-07-30T03:44:07.668Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-to-git-tanstack-com-and-filev2-getsession-org-for-tanstack-s-ac5a4e3f</loc>
    <lastmod>2026-07-30T03:44:05.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detection-of-libredtail-http-user-agent-inbound-requests-6fd25dd1</loc>
    <lastmod>2026-07-30T03:44:04.127Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-outbound-request-to-eviltokens-phaas-phishing-infrastructure-cloudflare-wo-e0e121d0</loc>
    <lastmod>2026-07-30T03:44:02.522Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-chain-for-axios-npm-compromise-cscript-vbs-temp-deletion-curl-c2-f6c27ecc</loc>
    <lastmod>2026-07-30T03:44:00.909Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-detects-axios-npm-compromise-process-chain-using-osascript-curl-download-a-a09ee860</loc>
    <lastmod>2026-07-30T03:43:58.430Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-axios-npm-plain-crypto-js-compromise-chain-via-curl-nohup-and-python3-0a23a62d</loc>
    <lastmod>2026-07-30T03:43:56.402Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detect-suspicious-dns-queries-to-axios-supply-chain-c2-domains-73e5d24f</loc>
    <lastmod>2026-07-30T03:43:54.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-indicators-for-axios-npm-compromise-drops-node-exe-powersh-cd6386fa</loc>
    <lastmod>2026-07-30T03:43:52.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-file-creation-indicators-for-axios-npm-supply-chain-compromise-2db0458c</loc>
    <lastmod>2026-07-30T03:43:50.826Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-drop-indicator-for-axios-npm-supply-chain-compromise-curl-to-tmp-ld-p-b7cb840c</loc>
    <lastmod>2026-07-30T03:43:49.139Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-defender-windefend-flags-tieringengineservice-exe-eicar-test-staging-by--a7c3e5f2</loc>
    <lastmod>2026-07-30T03:43:47.598Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-created-redsun-redsun-9b4e7c2a</loc>
    <lastmod>2026-07-30T03:43:42.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-tieringengineservice-exe-in-rs-prefixed-temp-directory-f2e4b7d9</loc>
    <lastmod>2026-07-30T03:43:40.754Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-user-agent-wp2shell-indicates-wp2shell-poc-activity-a7c4e2f9</loc>
    <lastmod>2026-07-30T03:43:38.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wordpress-wp2shell-webshell-plugin-path-access-webserver-c9e6f412</loc>
    <lastmod>2026-07-30T03:43:37.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wordpress-rest-batch-endpoint-wp2shell-exploitation-via-post-with-rest-route-bat-b8d5f301</loc>
    <lastmod>2026-07-30T03:43:35.599Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lsass-crash-with-netlogon-dll-fault-and-status-stack-buffer-overrun-f8a66a02</loc>
    <lastmod>2026-07-30T03:43:33.885Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-detect-authencesn-crypto-module-load-via-modprobe-cve-2026-31431-indicator-474b415a</loc>
    <lastmod>2026-07-30T03:43:29.455Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auditd-af-alg-address-family-38-socket-syscall-creation-474b415a</loc>
    <lastmod>2026-07-30T03:43:27.359Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-curl-exe-execution-using-tor-socks-proxy-socks-and-onion-in-command-line-e99375eb</loc>
    <lastmod>2026-07-30T03:43:25.445Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-creation-of-funksec-files-used-as-funklocker-ransomware-extension-2c76a22b</loc>
    <lastmod>2026-07-30T03:43:23.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-npm-install-of-known-malicious-packages-sh-bae7c70b</loc>
    <lastmod>2026-07-30T03:43:21.657Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-bun-environment-js-executed-via-bun-exe-from-node-exe-5299fadf</loc>
    <lastmod>2026-07-30T03:43:19.142Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-matching-shai-hulud-command-line-indicators-540703fb</loc>
    <lastmod>2026-07-30T03:43:17.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-curl-data-exfiltration-attempt-from-npm-package-to-webhook-site-efd2eb09</loc>
    <lastmod>2026-07-30T03:43:15.823Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-npm-installs-known-shai-hulud-2-0-malicious-packages-and--514f533b</loc>
    <lastmod>2026-07-30T03:43:13.885Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-bun-runtime-execution-of-bun-environment-js-from-node-parent-process-eb827bbd</loc>
    <lastmod>2026-07-30T03:43:11.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-shai-hulud-and-sha1hulud-command-line-indicators-11bb9b26</loc>
    <lastmod>2026-07-30T03:43:09.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-creation-of-malicious-github-workflows-shai-hulud-workflow-yamls-0aba5685</loc>
    <lastmod>2026-07-30T03:43:08.250Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-http-connections-with-suspicious-user-agent-containing-katz-ontop-834c6d2f</loc>
    <lastmod>2026-07-30T03:43:06.356Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dns-queries-to-katz-stealer-associated-domains-6b0c762f</loc>
    <lastmod>2026-07-30T03:43:04.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-image-load-of-katz-stealer-dlls-e6c7ab7c</loc>
    <lastmod>2026-07-30T03:43:03.080Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-queries-to-known-katz-stealer-domains-9c3d6e32</loc>
    <lastmod>2026-07-30T03:43:01.365Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-grixba-reconnaissance-tool-command-line-parameter-combo-af688c76</loc>
    <lastmod>2026-07-30T03:42:59.683Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-process-creation-filegrabber-or-curl-post-exfiltration-indicators-for-amos-e710a880</loc>
    <lastmod>2026-07-30T03:42:57.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macos-file-persistence-indicators-for-atomic-macos-stealer-artifacts-e710a880</loc>
    <lastmod>2026-07-30T03:42:55.986Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-attempts-to-enable-suid-core-dumps-via-proc-sys-fs-suid-dumpable-33b3cfb1</loc>
    <lastmod>2026-07-30T03:42:54.343Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-application-logs-wsus-deserialization-exploitation-indicators-for-cve-20-e5f66e87</loc>
    <lastmod>2026-07-30T03:42:52.562Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmd-exe-and-powershell-child-processes-of-wsus-wsusservice-exe-on-win-43259cc4</loc>
    <lastmod>2026-07-30T03:42:50.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-commvault-qlogin-argument-injection-hints-for-localadmi-ff0225a0</loc>
    <lastmod>2026-07-30T03:42:48.754Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-commvault-qoperation-exe-webshell-drop-via-file-to-jsp--bd3b3fff</loc>
    <lastmod>2026-07-30T03:42:47.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-commvault-qlogin-exe-targeting-publicsharinguser-with-a-guid-password-917789e1</loc>
    <lastmod>2026-07-30T03:42:45.456Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-child-process-spawned-by-node-js-parent-react2shell-pattern-c70834fa</loc>
    <lastmod>2026-07-30T03:42:41.729Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-crushftp-spawns-powershell-cmd-and-lolbins-indicative-o-0fdc7c7f</loc>
    <lastmod>2026-07-30T03:42:39.711Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/iis-web-logs-sharepoint-toolpane-and-spinstall0-post-get-indicative-of-cve-2025--48d053db</loc>
    <lastmod>2026-07-30T03:42:37.680Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-indicators-of-sharepoint-spinstall0-aspx-encoded-comman-7477881c</loc>
    <lastmod>2026-07-30T03:42:35.904Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-in-sharepoint-web-server-extensions-indicative-of-cve-2025-ba479447</loc>
    <lastmod>2026-07-30T03:42:18.413Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-regsvr32-use-by-notepad-installer-for-cve-20-933f0bb5</loc>
    <lastmod>2026-07-30T03:42:16.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-process-behavior-from-solarwinds-webhelpdesk-webhelpdes-8c7f4a2d</loc>
    <lastmod>2026-07-30T03:41:57.379Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-cve-2025-33053-webdav-rce-via-iediagcmd-exe-or-customshellhost-abe06362</loc>
    <lastmod>2026-07-30T03:41:55.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-indicating-rce-attempt-via-cve-2025-33053-and-webdav-host-9a2d8b3e</loc>
    <lastmod>2026-07-30T03:41:53.169Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-alert-on-nsswitch-conf-creation-outside-standard-paths-10ac0730</loc>
    <lastmod>2026-07-30T03:41:49.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-java-webshell-upload-attempts-via-post-to-sap-netviewer-uris-639b893f</loc>
    <lastmod>2026-07-30T03:41:47.149Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detections-for-sap-netviewer-jsp-webshell-command-execution-via-cmd-pa-94e12f41</loc>
    <lastmod>2026-07-30T03:41:45.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-sap-netweaver-on-windows-using-command-and-script-in-5b304bcb</loc>
    <lastmod>2026-07-30T03:41:44.020Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-command-child-process-from-sap-netweaver-work-root-directories-69dea60b</loc>
    <lastmod>2026-07-30T03:41:42.383Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-suspicious-sap-netweaver-jsp-java-class-file-creation-86a7c91f</loc>
    <lastmod>2026-07-30T03:41:40.343Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-events-sap-netweaver-jsp-java-class-webshell-file-creation-5b91409c</loc>
    <lastmod>2026-07-30T03:41:38.030Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/crushftp-service-spawning-suspicious-script-and-shell-child-processes-on-windows-459628e3</loc>
    <lastmod>2026-07-30T03:41:36.404Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmd-exe-spawned-by-w3wp-exe-with-centrestack-portal-config-parent-com-2d79e371</loc>
    <lastmod>2026-07-30T03:41:34.705Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-library-ms-file-creation-by-7z-winrar-explorer-5a7132c0</loc>
    <lastmod>2026-07-30T03:41:33.027Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-asa-webvpn-get-requests-via-proxy-logs-indicating-exploitation--15697955</loc>
    <lastmod>2026-07-30T03:41:31.192Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-goanywhere-mft-exploitation-suspicious-powershell-and-cmd-child-process--6c76b3d0</loc>
    <lastmod>2026-07-30T03:41:29.355Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-screenconnect-slashandgrab-exploitation-dropper-artifacts-05164d17</loc>
    <lastmod>2026-07-30T03:41:27.755Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-protocol-handler-clsid-server-dll-set-in-registry-d807056b</loc>
    <lastmod>2026-07-30T03:41:25.664Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detects-specific-forest-blizzard-tool-execution-via-has-07db928c</loc>
    <lastmod>2026-07-30T03:41:22.096Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-javascript-file-creation-in-driverstore-filerepository-ec7c4e9b</loc>
    <lastmod>2026-07-30T03:41:20.305Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-programdata-suspicious-driver-script-file-creation-pattern-b92d1d19</loc>
    <lastmod>2026-07-30T03:41:18.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-chain-rdpinit-exe-spawning-notepad-that-executes-cmd-exe-6676896b</loc>
    <lastmod>2026-07-30T03:41:16.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-query-indicators-for-dprk-c2-domains-4d16c9a6</loc>
    <lastmod>2026-07-30T03:41:14.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kapeka-backdoor-scheduled-task-creation-on-windows-security-event-4698-6c130acd</loc>
    <lastmod>2026-07-30T03:41:13.263Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-seed-value-under-cryptography-providers-path-persistence-cbaa3ef3</loc>
    <lastmod>2026-07-30T03:41:11.411Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kapeka-backdoor-autorun-registry-persistence-on-windows-run-keys-c0c67b21</loc>
    <lastmod>2026-07-30T03:41:09.552Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kapeka-backdoor-execution-via-rundll32-exe-with-ordinal-export-1-and-d-argument--e98f741c</loc>
    <lastmod>2026-07-30T03:41:07.976Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kapeka-backdoor-persistence-via-schtasks-or-run-registry-key-64a871dd</loc>
    <lastmod>2026-07-30T03:41:06.154Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kapeka-backdoor-loaded-via-rundll32-exe-a7e6b1f9</loc>
    <lastmod>2026-07-30T03:41:04.337Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-drop-indicator-for-kapeka-decrypted-backdoor-wll-in-appdata-common--20228d05</loc>
    <lastmod>2026-07-30T03:41:02.722Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-zonemap-proxy-policy-tampering-via-setvaluekeyint-16a4c7b3</loc>
    <lastmod>2026-07-30T03:41:00.800Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-shell32-control-rundll-execution-of-user-temp-cpl-92020b88</loc>
    <lastmod>2026-07-30T03:40:59.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-oleview-and-aclui-dll-side-loading-on-windows-0f3a9db2</loc>
    <lastmod>2026-07-30T03:40:57.190Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-more-com-spawning-vbc-exe-lummac-stealer-behavior-19b3806e</loc>
    <lastmod>2026-07-30T03:40:55.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-winlogon-shell-modification-using-powershell-like-values-c9b86500</loc>
    <lastmod>2026-07-30T03:40:54.116Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-exe-weekly-task-creation-with-forced-user-shutdown-command-fe9e8ba9</loc>
    <lastmod>2026-07-30T03:40:52.403Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winword-start-menu-shortcut-via-cmd-exe-launching-a-doc-lnk-24474469</loc>
    <lastmod>2026-07-30T03:40:50.661Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-targeting-rat-client-config-files-in-roaming-appdata-2f3039c8</loc>
    <lastmod>2026-07-30T03:40:48.869Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-darkgate-loader-drop-and-execute-via-c-temp-autoit-artifacts-df49c691</loc>
    <lastmod>2026-07-30T03:40:46.926Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-csharp-streamer-rat-net-image-loaded-from-temp-tmp-path-windows-6f6afac3</loc>
    <lastmod>2026-07-30T03:40:45.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-cmd-exe-and-powershell-encodedcommand-from-c-f007b877</loc>
    <lastmod>2026-07-30T03:40:43.767Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-application-error-possible-cve-2024-49113-ldap-nightmare-attempt-lsass-e-3f2c93c7</loc>
    <lastmod>2026-07-30T03:40:41.937Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-suspicious-updates-to-domain-group-esx-admins-47a1658b</loc>
    <lastmod>2026-07-30T03:40:39.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-net-exe-or-powershell-creates-esx-admins-domain-group-c408acfe</loc>
    <lastmod>2026-07-30T03:40:38.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-suspicious-ksproxy-ax-loading-potential-cve-2024-35250-activit-17ce9373</loc>
    <lastmod>2026-07-30T03:40:36.105Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/palo-alto-globalprotect-os-command-injection-indicators-via-cve-2024-3400-f130a5f1</loc>
    <lastmod>2026-07-30T03:40:34.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/palo-alto-globalprotect-file-creation-indicators-of-cve-2024-3400-os-command-inj-bcd95697</loc>
    <lastmod>2026-07-30T03:40:32.495Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-suspicious-root-shell-spawned-by-sshd-suggesting-cve-2024-3094-exploitatio-9aa27839</loc>
    <lastmod>2026-07-30T03:40:30.715Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-screenconnect-service-modifies-temporary-xml-user-database-files-4109cb6a</loc>
    <lastmod>2026-07-30T03:40:29.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detection-of-screenconnect-setupwizard-authentication-bypass-exploitat-d27eabad</loc>
    <lastmod>2026-07-30T03:40:27.552Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-modification-of-screenconnect-temporary-xml-user-database-1a821580</loc>
    <lastmod>2026-07-30T03:40:26.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/progress-kemp-loadmaster-unauthenticated-command-injection-exploitation-via-acce-eafb8bd5</loc>
    <lastmod>2026-07-30T03:40:20.727Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-of-named-binaries-commonly-used-for-seaspy-deployment-f6a711f3</loc>
    <lastmod>2026-07-30T03:40:19.073Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-execution-wget-downloading-tar-via-untrusted-ip-with-certificate-b-23835beb</loc>
    <lastmod>2026-07-30T03:40:17.420Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-wget-downloads-zip-rar-from-temp-sh-60d050c4</loc>
    <lastmod>2026-07-30T03:40:15.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-openssl-s-client-connection-to-ip-port-for-ssl-certificate-exfiltration-60911c07</loc>
    <lastmod>2026-07-30T03:40:13.973Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-indicators-matching-suspected-barracuda-esg-exploitation-artifacts-5627c337</loc>
    <lastmod>2026-07-30T03:40:12.004Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-file-creation-with-mail-tmp-3-alnum-3-digits-tar-gz-pattern-0785f462</loc>
    <lastmod>2026-07-30T03:40:10.288Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-log-detection-of-get-requests-to-api-core-command-init-restart-paths-b8225208</loc>
    <lastmod>2026-07-30T03:40:08.676Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-with-specific-suspicious-command-line-string-2e7bbd54</loc>
    <lastmod>2026-07-30T03:40:07.147Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-child-processes-spawned-by-pc-app-exe-0934ac71</loc>
    <lastmod>2026-07-30T03:40:05.804Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-downloads-setup-msi-via-invoke-webrequest-fo-de1bd0b6</loc>
    <lastmod>2026-07-30T03:40:04.301Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-adfs-inetmgr-exe-path-used-by-onyx-sleet-2fef4fd9</loc>
    <lastmod>2026-07-30T03:40:02.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-user-created-activated-for-svc-network-backup-account-00a8e92a</loc>
    <lastmod>2026-07-30T03:40:01.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-used-for-solidpdfcreator-dll-copy-and-run--7806bb49</loc>
    <lastmod>2026-07-30T03:39:59.696Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-manageengine-servicedesk-java-parent-spawns-suspicious-powershell-or-cre-58d8341a</loc>
    <lastmod>2026-07-30T03:39:58.191Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wstomcatservice-exe-parent-spawning-processes-log4j-wst-7c97c625</loc>
    <lastmod>2026-07-30T03:39:56.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-asperafaspex-parent-spawning-suspicious-powershell-lsas-91048c0d</loc>
    <lastmod>2026-07-30T03:39:54.553Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-imageloaded-from-programshared-programdata-and-arm-p-24007168</loc>
    <lastmod>2026-07-30T03:39:52.412Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-sysaid-user-exe-hash-based-malware-loader-execution-745ea50b</loc>
    <lastmod>2026-07-30T03:39:50.634Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-powershell-downloadstring-used-to-fetch-cobalt-strike-aa5b0a40</loc>
    <lastmod>2026-07-30T03:39:48.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-launcher-script-referencing-sysaid-tomcat-paths-and-user-exe--37dc5463</loc>
    <lastmod>2026-07-30T03:39:47.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-evidence-cleanup-script-with-cleanll-and-while-1-loop-b377ddab</loc>
    <lastmod>2026-07-30T03:39:45.597Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-file-creation-targeting-specific-sysaidserver-user-fil-e94486ea</loc>
    <lastmod>2026-07-30T03:39:43.934Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-execution-matching-powertrash-indicators-4e19528a</loc>
    <lastmod>2026-07-30T03:39:40.414Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-scriptblock-executing-powerhold-like-logic-via-wscript-71c432c4</loc>
    <lastmod>2026-07-30T03:39:38.906Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-script-file-creation-with-64refl-ps1-or-host-ip-ps1-a88d9f45</loc>
    <lastmod>2026-07-30T03:39:36.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-traffic-to-suspect-c2-domains-matching-operation-triangulation-beaconing-i-aa03c712</loc>
    <lastmod>2026-07-30T03:39:35.366Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-operation-triangulation-dns-c2-beaconing-to-known-domains-7fc30d63</loc>
    <lastmod>2026-07-30T03:39:33.897Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-event-4698-scheduled-task-creation-for-teamcity-settings-ui-3b8e5084</loc>
    <lastmod>2026-07-30T03:39:32.337Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-event-scheduled-taskcache-tree-key-creation-for-teamcity-exploi-9f9f92ba</loc>
    <lastmod>2026-07-30T03:39:30.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detects-command-line-string-utynkfkxhizrx3kj-b5495d8d</loc>
    <lastmod>2026-07-30T03:39:29.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-sideloading-via-programdata-clip-exe-wsmprovhost-exe-imageload-d1b65d98</loc>
    <lastmod>2026-07-30T03:39:27.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-indicators-for-programdata-payloads-e1212b32</loc>
    <lastmod>2026-07-30T03:39:25.578Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-query-detection-for-diamond-sleet-related-domains-fba38e0f</loc>
    <lastmod>2026-07-30T03:39:24.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-task-scheduler-svr-graphicalproton-known-malicious-scheduled-task-names-2bfc1373</loc>
    <lastmod>2026-07-30T03:39:22.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-creation-using-svr-specific-task-names-8fa65166</loc>
    <lastmod>2026-07-30T03:39:20.943Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-imageload-of-svr-graphicalproton-backdoor-dll-names-e64c8ef3</loc>
    <lastmod>2026-07-30T03:39:19.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-web-requests-downloading-ico-from-3cxdesktopapp-icon-storage-potential-c2--76bc1601</loc>
    <lastmod>2026-07-30T03:39:17.513Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-logs-potential-beaconing-to-3cx-related-domains-3c4b3bbf</loc>
    <lastmod>2026-07-30T03:39:15.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-3cxdesktopapp-updater-fetching-known-compromised-update-e7581747</loc>
    <lastmod>2026-07-30T03:39:14.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-child-processes-spawned-by-3cxdesktopapp-exe-63f3605b</loc>
    <lastmod>2026-07-30T03:39:07.334Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-known-compromised-3cxdesktopapp-binaries-by-hash-93bbde78</loc>
    <lastmod>2026-07-30T03:39:05.580Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-load-triggered-by-known-compromised-3cxdesktopapp-module-hashes-d0b65ad3</loc>
    <lastmod>2026-07-30T03:38:47.087Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wscript-initiated-dns-queries-to-regex-matched-domains-potential-c2-70761fe8</loc>
    <lastmod>2026-07-30T03:38:27.431Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-redirection-to-appdata-temp-bin-during-explorer-initiated-execut-7aaa5739</loc>
    <lastmod>2026-07-30T03:38:25.892Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-for-werfaultsvc-from-winsxs-werfault-exe-b2e60816</loc>
    <lastmod>2026-07-30T03:38:24.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-uncommon-wav-openwithprogids-value-creation-7e163e96</loc>
    <lastmod>2026-07-30T03:38:22.382Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-events-targeting-security-policy-secrets-for-snake-malware-pers-d0fa35db</loc>
    <lastmod>2026-07-30T03:38:20.661Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-werfault-child-process-from-winsxs-path-f7536642</loc>
    <lastmod>2026-07-30T03:38:19.156Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-jpinst-exe-jpsetup-exe-binary-used-in-snake-inst-d91ff53f</loc>
    <lastmod>2026-07-30T03:38:17.705Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-jpsetup-exe-cli-argument-hash-iv-sequence-indicator-02cbc035</loc>
    <lastmod>2026-07-30T03:38:14.731Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-event-non-system-creation-of-werfault-exe-in-winsxs-64827580</loc>
    <lastmod>2026-07-30T03:38:13.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-snake-malware-installer-filename-indicators-99eccc2b</loc>
    <lastmod>2026-07-30T03:38:11.580Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-create-write-indicator-for-snake-kernel-driver-comadmin-dat-d6d9d23f</loc>
    <lastmod>2026-07-30T03:38:10.035Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rorschach-ransomware-execution-behavior-on-windows-via-command-line-indicators-0e9e6c63</loc>
    <lastmod>2026-07-30T03:38:07.877Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-rundll32-launching-nsis-module-via-nsis-uns-5cdbc2e8</loc>
    <lastmod>2026-07-30T03:38:05.901Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-of-qakbot-uninstaller-qbotuninstall-exe-bc309b7a</loc>
    <lastmod>2026-07-30T03:38:04.158Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-rundll32-executed-dll-like-path-without-dll-extension-bfd34392</loc>
    <lastmod>2026-07-30T03:38:02.401Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-qakbot-like-rundll32-exports-via-script-or-cmd-parent-339ed3d6</loc>
    <lastmod>2026-07-30T03:38:00.969Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-launched-via-lolbin-chain-from-cmd-cscript-powershell-mshta-cf879ffb</loc>
    <lastmod>2026-07-30T03:37:59.320Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-execution-with-s-and-calc-keyword-0033cf83</loc>
    <lastmod>2026-07-30T03:37:57.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-launched-with-non-dll-extension-via-lolbin-parents-1bf0ba65</loc>
    <lastmod>2026-07-30T03:37:55.800Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-parent-with-select-binary-execution-indicative-of-process-hollo-d8937fe7</loc>
    <lastmod>2026-07-30T03:37:53.940Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-discovery-commands-triggered-via-rundll32-and-search-host-parent-698d4431</loc>
    <lastmod>2026-07-30T03:37:52.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cmd-exe-suspicious-command-chains-indicative-of-pikabot-style-execution-e5144106</loc>
    <lastmod>2026-07-30T03:37:50.488Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-executes-1-dll-dllregisterserver-via-single-digit-dll-2bd8e100</loc>
    <lastmod>2026-07-30T03:37:47.171Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/guloader-activity-injected-browser-parent-spawns-rundll32-exe-on-windows-89e1490f</loc>
    <lastmod>2026-07-30T03:37:45.377Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-line-matches-griffon-malware-execution-pattern-bcc6f179</loc>
    <lastmod>2026-07-30T03:37:43.252Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-local-user-creation-via-net-exe-using-darkgate-and-safemode-arguments-bf906d7b</loc>
    <lastmod>2026-07-30T03:37:41.633Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-autoit3-exe-execution-with-suspicious-parent-process-f8e9aa1c</loc>
    <lastmod>2026-07-30T03:37:39.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-autoit3-exe-by-curl-exe-or-other-uncommon-parent-proces-1a433e1d</loc>
    <lastmod>2026-07-30T03:37:38.106Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-via-service-control-manager-7045-with-svchost-exe-image-3ced239c</loc>
    <lastmod>2026-07-30T03:37:36.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-set-new-user-profile-created-with-anonymous-and-domainuser-mark-95214813</loc>
    <lastmod>2026-07-30T03:37:34.488Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-svchost-exe-with-specific-k-flags-9f9cd389</loc>
    <lastmod>2026-07-30T03:37:32.624Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-cleanup-export-execution-from-svchost-msupdate-services-88516f06</loc>
    <lastmod>2026-07-30T03:37:31.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-by-anonymous-user-with-system32-appdata-parent-image-e01b6eb5</loc>
    <lastmod>2026-07-30T03:37:29.262Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-svchost-exe-loads-suspicious-dll-from-appdata-roaming-potential-persiste-1d7a57da</loc>
    <lastmod>2026-07-30T03:37:27.192Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-persistence-via-appdata-roaming-newdev-dll-file-creation-1fea93a2</loc>
    <lastmod>2026-07-30T03:37:25.689Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-dllhost-exe-in-public-documents-for-coldsteel-rat-varia-c708a93f</loc>
    <lastmod>2026-07-30T03:37:24.019Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-potential-pre-auth-rce-exploitation-via-dhcpserver-svch-6d5b8176</loc>
    <lastmod>2026-07-30T03:37:22.302Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-logs-possible-cve-2023-4966-probing-on-citrix-adc-via-long-host-header-a4e068b5</loc>
    <lastmod>2026-07-30T03:37:19.888Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-logs-detect-cve-2023-4966-probing-on-citrix-adc-netscaler-oidc-endpoin-87c83d8e</loc>
    <lastmod>2026-07-30T03:37:18.050Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/citrix-adc-proxy-logs-cve-2023-4966-sensitive-info-disclosure-probe-via-oidc-con-ff349b81</loc>
    <lastmod>2026-07-30T03:37:16.073Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/citrix-adc-proxy-get-to-oauth-openid-configuration-with-excessive-host-header-le-aee7681f</loc>
    <lastmod>2026-07-30T03:37:14.342Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/f5-big-ip-webserver-rce-exploit-indicators-post-mgmt-tm-util-bash-and-tmui-form--e9928831</loc>
    <lastmod>2026-07-30T03:37:12.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/f5-big-ip-proxy-exploitation-attempt-targeting-mgmt-tm-util-bash-cve-2023-46747-f195b2ff</loc>
    <lastmod>2026-07-30T03:37:10.685Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/web-exploitation-attempt-of-cve-2023-46214-against-splunk-enterprise-via-insecur-ba5268de</loc>
    <lastmod>2026-07-30T03:37:08.821Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cve-2023-46214-rce-probe-against-splunk-enterprise-via-xsl-post-request-04017cd5</loc>
    <lastmod>2026-07-30T03:37:06.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-access-logs-indicate-potential-cve-2023-43261-exploitation-and-informa-a2bcca38</loc>
    <lastmod>2026-07-30T03:37:04.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-get-requests-targeting-lang-log-httpd-log-for-cve-2023-43261-disclosure-f48f5368</loc>
    <lastmod>2026-07-30T03:37:02.571Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrar-exe-application-error-crash-with-version-below-6-23-e5a29b54</loc>
    <lastmod>2026-07-30T03:37:00.796Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winrar-rev-file-creation-potential-exploitation-cve-2023-40477-c3bd6c55</loc>
    <lastmod>2026-07-30T03:36:58.910Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winrar-child-process-execution-attempt-cve-2023-38331-on-windows-ec3a3c2f</loc>
    <lastmod>2026-07-30T03:36:56.046Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-suspicious-double-extension-filename-with-space-via-winrar-e4556676</loc>
    <lastmod>2026-07-30T03:36:54.039Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-share-access-mshtml-c7-with-ip-like-naming-pattern-3df95076</loc>
    <lastmod>2026-07-30T03:36:52.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/http-get-requests-containing-mshtml-c7-url-marker-proxy-e59f71ff</loc>
    <lastmod>2026-07-30T03:36:50.412Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-proxy-get-requests-for-file-download-paths-indicative-of-cve-2023-368-6af1617f</loc>
    <lastmod>2026-07-30T03:36:48.773Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detects-suspicious-proxy-get-requests-targeting-ip-parameters-in-url-query-strin-d9365e39</loc>
    <lastmod>2026-07-30T03:36:46.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-detection-of-get-requests-targeting-mshtml-c7-with-ip-parameter-0066d244</loc>
    <lastmod>2026-07-30T03:36:45.055Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-recent-folder-file-drop-c-users-recent-file001-url-8023d3a2</loc>
    <lastmod>2026-07-30T03:36:36.743Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-renamed-cmd-powershell-powershell-ise-as-wermgr-exe-50dbc08b</loc>
    <lastmod>2026-07-30T03:36:35.023Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-creation-of-fake-wermgr-exe-in-uncommon-directories-ad0960eb</loc>
    <lastmod>2026-07-30T03:36:33.321Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wer-report-wer-creation-in-uncommon-reportarchive-subfolders-possible-cv-92389a99</loc>
    <lastmod>2026-07-30T03:36:31.570Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-get-requests-to-moveit-human2-aspx-paths-indicating-cve-2023-34362-exp-435e41f2</loc>
    <lastmod>2026-07-30T03:36:29.720Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-csc-exe-launched-by-w3wp-exe-for-moveit-pool-39ac1fb0</loc>
    <lastmod>2026-07-30T03:36:28.169Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-event-indicators-of-moveit-transfer-cve-2023-34362-exploitation-art-c3b2a774</loc>
    <lastmod>2026-07-30T03:36:26.355Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortigate-web-logs-indicators-of-cve-2023-27997-exploitation-attempt-31e4e649</loc>
    <lastmod>2026-07-30T03:36:24.361Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-hta-file-creation-in-startup-folder-by-foxitpdfreader-exe-9cae055f</loc>
    <lastmod>2026-07-30T03:36:22.400Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ruckus-wireless-admin-http-get-injection-attempt-likely-targeting-cve-2023-25717-043c1609</loc>
    <lastmod>2026-07-30T03:36:20.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-geoserver-sql-injection-exploitation-attempt-via-ows-cql-filter-c0341543</loc>
    <lastmod>2026-07-30T03:36:19.160Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/joomla-web-endpoint-get-requests-matching-cve-2023-23752-exploitation-parameters-0e1ebc5a</loc>
    <lastmod>2026-07-30T03:36:17.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-smb-client-failed-smb-session-network-connections-to-internet-facing-ser-de96b824</loc>
    <lastmod>2026-07-30T03:36:15.893Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-outlook-exe-registry-query-for-webclient-lanmanworkstation-network-provi-73c59189</loc>
    <lastmod>2026-07-30T03:36:14.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-changes-for-outlook-task-note-reminder-trigger-fc06e655</loc>
    <lastmod>2026-07-30T03:36:12.393Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-sshd-flag-failed-curve25519-key-generation-suggesting-libssh-authenticatio-8b244735</loc>
    <lastmod>2026-07-30T03:36:10.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/confluence-webserver-cve-2023-22518-post-requests-to-vulnerable-setup-restore-en-a902d249</loc>
    <lastmod>2026-07-30T03:36:08.823Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-http-post-to-confluence-setup-and-admin-json-endpoints-cve-2023-22518-27d2cdde</loc>
    <lastmod>2026-07-30T03:36:06.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-confluence-child-process-spawning-cmd-exe-or-powershell-on-windows-1ddaa9a4</loc>
    <lastmod>2026-07-30T03:36:04.995Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-indicators-for-cve-2023-22518-confluence-exploitation-via-f8987c03</loc>
    <lastmod>2026-07-30T03:36:03.257Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msmq-corrupted-packet-detected-event-id-2027-ae94b10d</loc>
    <lastmod>2026-07-30T03:36:01.217Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-ios-xe-web-ui-exploitation-indicators-for-cve-2023-20198-2ece8816</loc>
    <lastmod>2026-07-30T03:35:59.580Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-unauthenticated-command-injection-attempts-via-tp-link-archer-ax21-cgi-6c7defa9</loc>
    <lastmod>2026-07-30T03:35:57.783Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detects-suspicious-powershell-command-line-for-mercury--a62298a3</loc>
    <lastmod>2026-07-30T03:35:56.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-scheduled-task-persistence-via-schtasks-create-and-vbsc-e1118a8f</loc>
    <lastmod>2026-07-30T03:35:54.437Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-mssql-extended-stored-procedure-execution-with-providername-mssqlserver--711ab2fe</loc>
    <lastmod>2026-07-30T03:35:52.590Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-socgholish-fakeupdates-execution-via-wscript-launching-cmd-or-powershell-97805087</loc>
    <lastmod>2026-07-30T03:35:50.841Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-scheduled-task-payload-execution-via-cmd-powershell-system-eventid-wrapp-d5eb7432</loc>
    <lastmod>2026-07-30T03:35:48.913Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-lines-referencing-dot-suffixed-file-paths-a35c97c8</loc>
    <lastmod>2026-07-30T03:35:47.188Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-raspberry-robin-initial-execution-via-cmd-exe-launching-msiexec--2c6bea3a</loc>
    <lastmod>2026-07-30T03:35:45.624Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-raspberry-robin-command-execution-via-fodhelper-rundll32-and-regsvr32-d52d2e87</loc>
    <lastmod>2026-07-30T03:35:43.418Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-patterns-indicating-hermetic-wiper-style-execution-and-powershel-2f974656</loc>
    <lastmod>2026-07-30T03:35:41.387Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-lnk-emotet-loader-execution-via-cmd-powershell-process-creation-1f32d820</loc>
    <lastmod>2026-07-30T03:35:39.799Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-chromeloader-execution-via-scheduled-task-and-chrome-extension-loading-0a74c5a9</loc>
    <lastmod>2026-07-30T03:35:38.017Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-remote-thread-creation-via-rundll32-exe-from-wabmig-exe-or-wab-exe-994cac2b</loc>
    <lastmod>2026-07-30T03:35:36.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-access-to-bluesky-files-and-shares-used-in-bluesky-ransomware-artifacts-eee8311f</loc>
    <lastmod>2026-07-30T03:35:34.492Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detects-web-exploitation-attempts-against-cacti-remote-agent-php-cve-2022-46169--738cb115</loc>
    <lastmod>2026-07-30T03:35:32.361Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-centos-web-panel-7-rce-probe-via-post-login-index-php-1b2eeb27</loc>
    <lastmod>2026-07-30T03:35:30.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fortios-sslvpnd-cve-2022-42475-exploitation-indicators-via-sensitive-file-paths-293ccb8c</loc>
    <lastmod>2026-07-30T03:35:28.873Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sysmon-process-creation-where-sysmon-spawned-a-child-process-6d1058a4</loc>
    <lastmod>2026-07-30T03:35:27.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/owa-ssrf-exploitation-attempt-via-webserver-post-to-owa-mastermailbox-and-powers-92d78c63</loc>
    <lastmod>2026-07-30T03:35:25.549Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-owassrf-exploitation-attempt-via-exchange-owa-backend-webserver-181f49fa</loc>
    <lastmod>2026-07-30T03:35:23.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/owa-ssrf-exploitation-attempt-via-proxy-to-owa-mastermailbox-and-powershell-fdd7e904</loc>
    <lastmod>2026-07-30T03:35:22.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-http-post-to-owa-powershell-backend-with-encoded-user-info-owassrf-1ddf4596</loc>
    <lastmod>2026-07-30T03:35:20.058Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-event-42-kerberos-kdc-rc4-hmac-downgrade-exploit-activity-cve-202-e6f81941</loc>
    <lastmod>2026-07-30T03:35:18.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/atlassian-bitbucket-archive-api-command-injection-attempt-cve-2022-36804-in-web--65c0a0ab</loc>
    <lastmod>2026-07-30T03:35:16.340Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/apache-spark-shell-command-injection-attempt-in-web-server-logs-doas-1a9a04fd</loc>
    <lastmod>2026-07-30T03:35:14.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-processcreation-apache-spark-shell-command-injection-indicators-via-id-gn-c8a5f584</loc>
    <lastmod>2026-07-30T03:35:12.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-cve-2022-31659-rce-activity-via-post-to-workspace-one-access-tenant-mi-efdb2003</loc>
    <lastmod>2026-07-30T03:35:11.350Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-attempts-exploiting-cve-2022-31656-in-vmware-workspace-one-access-fcf1101d</loc>
    <lastmod>2026-07-30T03:35:09.628Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-suspicious-hkcr-ms-msdt-setvalue-for-msdt-protocol-2d9403d5</loc>
    <lastmod>2026-07-30T03:35:07.958Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-nimbuspwn-path-traversal-attempts-targeting-networkd-dispatcher-7ba05b43</loc>
    <lastmod>2026-07-30T03:35:06.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-suspicious-command-execution-spawned-by-7zfm-exe-for-cve-2022-29072-9a4ccd1a</loc>
    <lastmod>2026-07-30T03:35:04.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zimbra-webmail-server-unauthenticated-post-to-mboximport-backup-servlet-leading--dd218fb6</loc>
    <lastmod>2026-07-30T03:35:02.582Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-svchost-rpcss-service-spawns-suspicious-child-process-attempt-a7cd7306</loc>
    <lastmod>2026-07-30T03:35:00.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-process-creation-atlassian-confluence-spawning-shell-utility-child-process-7fb14105</loc>
    <lastmod>2026-07-30T03:34:58.826Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-webadministration-psm1-during-cve-2022-24527-lpe-attemp-e0a41412</loc>
    <lastmod>2026-07-30T03:34:56.796Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-rule-for-powershell-cmd-spawned-by-prunsrv-exe-vmware-w-5660d8db</loc>
    <lastmod>2026-07-30T03:34:54.916Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-user-profiles-service-events-1511-indicating-possible-lpe-attempts-tied--52a85084</loc>
    <lastmod>2026-07-30T03:34:52.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detect-post-attempts-to-oracle-e-business-suite-uueupload-endpoints-cv-d033cb8a</loc>
    <lastmod>2026-07-30T03:34:50.668Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-queuejumper-exploitation-attempt-via-mqsvc-exe-spawning-scripting-and-ut-53207cc2</loc>
    <lastmod>2026-07-30T03:34:48.911Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dewmode-webshell-access-via-uri-parameters-webserver-fdf96c90</loc>
    <lastmod>2026-07-30T03:34:47.283Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-and-registry-changes-associated-with-sourgum-actor-behaviors-7ba08e95</loc>
    <lastmod>2026-07-30T03:34:45.714Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-privatelog-image-load-svchost-exe-loading-clfsw32-dll-33a2d1dd</loc>
    <lastmod>2026-07-30T03:34:43.940Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detects-suspicious-post-requests-targeting-microsoft-exchange-owa-ecp-paths-67bce556</loc>
    <lastmod>2026-07-30T03:34:40.925Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspected-exchange-server-exploitation-via-file-temp-du-bbb2dedd</loc>
    <lastmod>2026-07-30T03:34:39.193Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-run-key-persistence-with-small-sieve-typos-in-value-data-65c6e3c1</loc>
    <lastmod>2026-07-30T03:34:37.525Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-http-get-to-telegram-api-with-small-sieve-indicators-potential-c2-b0422664</loc>
    <lastmod>2026-07-30T03:34:35.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-commandline-ends-with-exe-platypus-indicator-21117127</loc>
    <lastmod>2026-07-30T03:34:34.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-detect-small-sieve-typo-based-filename-indicators-and-outloo-39466c42</loc>
    <lastmod>2026-07-30T03:34:32.131Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-pingback-backdoor-process-execution-via-updata-exe-with-msdtc-config-sta-b2400ffb</loc>
    <lastmod>2026-07-30T03:34:30.393Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-load-of-oci-dll-by-msdtc-exe-for-pingback-backdoor-icmp-tunneling-35a7dc42</loc>
    <lastmod>2026-07-30T03:34:28.752Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-drop-indicators-for-pingback-backdoor-updata-exe-to-oci-dll-2bd63d53</loc>
    <lastmod>2026-07-30T03:34:27.085Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-persistence-indicators-for-netwire-related-keys-1d218616</loc>
    <lastmod>2026-07-30T03:34:25.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-creation-of-moriyastreamwatchmen-sys-driver-file-a1507d71</loc>
    <lastmod>2026-07-30T03:34:24.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-for-goofy-guineapig-backdoor-persistence-via-rundll32-8c15dd74</loc>
    <lastmod>2026-07-30T03:34:22.286Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-web-requests-to-static-tcplog-com-using-chrome-like-user-agent-for-possibl-4f573bb6</loc>
    <lastmod>2026-07-30T03:34:20.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-googleupdate-exe-self-spawn-from-uncommon-path-bdbab15a</loc>
    <lastmod>2026-07-30T03:34:19.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-commandline-matching-choice-t-d-d-y-n-nul-for-potential-backdoor-477a5ed3</loc>
    <lastmod>2026-07-30T03:34:17.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-ioc-match-for-goofy-guineapig-backdoor-indicators-f0bafe60</loc>
    <lastmod>2026-07-30T03:34:15.852Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-foggyweb-backdoor-dll-hijacking-via-loading-version-dll-640dc51c</loc>
    <lastmod>2026-07-30T03:34:14.222Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-recon-via-wscript-cmd-redirection-to-appdata-devil-bait-e8954be4</loc>
    <lastmod>2026-07-30T03:34:11.258Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-by-uncommon-processes-in-appdata-roaming-microsoft-txt-xml-93d5f1b4</loc>
    <lastmod>2026-07-30T03:34:09.249Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-darkside-ransomware-helper-command-line-pattern-965fff6c</loc>
    <lastmod>2026-07-30T03:34:07.698Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-sqlcmd-database-dumping-commands-indicative-of-ransomware-activity-2f47f1fd</loc>
    <lastmod>2026-07-30T03:34:05.865Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detects-vss-shadow-copy-listing-via-vssadmin-7b30e0a7</loc>
    <lastmod>2026-07-30T03:34:00.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/blackbyte-ransomware-registry-modifications-on-windows-83314318</loc>
    <lastmod>2026-07-30T03:33:58.760Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-command-line-indicators-of-blackbyte-ransomware-activity-999e8307</loc>
    <lastmod>2026-07-30T03:33:57.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sonicwall-ssl-vpn-jarrewrite-exploit-attempts-via-suspicious-http-query-and-user-6f55f047</loc>
    <lastmod>2026-07-30T03:33:55.518Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-systemnightmare-exploitation-attempt-via-printnightmare-cli-indicators-c01f7bd6</loc>
    <lastmod>2026-07-30T03:33:53.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-razerinstaller-explorer-subprocess-with-system-integrity-level-a4eaf250</loc>
    <lastmod>2026-07-30T03:33:52.234Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-activity-indicating-successful-proxyshell-exploit-targeting-exchange-992be1eb</loc>
    <lastmod>2026-07-30T03:33:50.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/exchange-proxyshell-url-probing-via-autodiscover-json-and-powershell-related-pat-23eee45e</loc>
    <lastmod>2026-07-30T03:33:48.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-log-detection-of-log4j-cve-2021-44228-jndi-strings-in-user-agent-uri-q-9be472ed</loc>
    <lastmod>2026-07-30T03:33:46.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detections-for-log4shell-cve-2021-44228-jndi-injection-exploit-strings-5ea8faa8</loc>
    <lastmod>2026-07-30T03:33:44.839Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-vmware-horizon-tomcat-service-spawning-cmd-exe-or-power-3eb91f0a</loc>
    <lastmod>2026-07-30T03:33:43.140Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-creation-of-msiexec-exe-under-manageengine-supportcenter-plus-bin-7b501acf</loc>
    <lastmod>2026-07-30T03:33:41.254Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/grafana-webserver-path-traversal-exploitation-cve-2021-43798-via-uri-query-7b72b328</loc>
    <lastmod>2026-07-30T03:33:39.579Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msexchange-management-indicators-of-exchange-rce-attempt-for-cve-2021-42-c92f1896</loc>
    <lastmod>2026-07-30T03:33:37.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-directory-services-sam-account-name-validation-failures-indicative-of-cv-e80a0fee</loc>
    <lastmod>2026-07-30T03:33:35.622Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-detect-computer-account-renamed-to-missing-suffix-45eb2ae2</loc>
    <lastmod>2026-07-30T03:33:33.834Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-kerberos-kdc-pac-requestor-anomaly-cve-2021-42278-exploitation-attempts-44bbff3e</loc>
    <lastmod>2026-07-30T03:33:31.747Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sitecore-pre-auth-rce-exploitation-attempts-via-report-ashx-cve-2021-42237-on-we-20c6ed1c</loc>
    <lastmod>2026-07-30T03:33:29.913Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/apache-webserver-path-traversal-attempt-for-cve-2021-41773-patterns-3007fec6</loc>
    <lastmod>2026-07-30T03:33:28.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-msi-installer-event-logs-for-poc-strings-indicating-cve-2021-41379-explo-7dbb86de</loc>
    <lastmod>2026-07-30T03:33:26.565Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-potential-cve-2021-41379-installerfiletakeover-privilege-escalation-atte-af8bbce4</loc>
    <lastmod>2026-07-30T03:33:24.667Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-create-msiexec-creating-elevation-service-exe-under-edge-applicatio-3be82d5d</loc>
    <lastmod>2026-07-30T03:33:22.795Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/detects-cve-2021-40539-zoho-manageengine-adselfservice-plus-rest-api-auth-bypass-fcbb4a77</loc>
    <lastmod>2026-07-30T03:33:20.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/adselfservice-exploitation-attempts-via-suspicious-web-url-paths-cve-2021-40539-6702b13c</loc>
    <lastmod>2026-07-30T03:33:19.227Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-office-applications-spawning-child-processes-with-directory-traversal-st-868955d9</loc>
    <lastmod>2026-07-30T03:33:17.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cve-2021-40444-control-exe-and-office-parent-process-exploitation-attemp-894397c6</loc>
    <lastmod>2026-07-30T03:33:16.216Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winword-creates-inetcache-cab-and-temp-inf-files-60c0a111</loc>
    <lastmod>2026-07-30T03:33:14.133Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-auth-logs-keyword-match-for-pwnkit-cve-2021-4034-pkexec-exploitation-indic-0506a799</loc>
    <lastmod>2026-07-30T03:33:12.472Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-http-post-to-wsman-without-authorization-header-indicates-omigod-rce-attemp-ab6b1a39</loc>
    <lastmod>2026-07-30T03:33:10.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-serv-u-cve-2021-35211-exploitation-via-whoami-and-clien-75578840</loc>
    <lastmod>2026-07-30T03:33:08.647Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-inprocserver32-clsid-targets-indicative-of-cve-2021-31979-33771-32b5db62</loc>
    <lastmod>2026-07-30T03:33:06.784Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-access-indicators-tied-to-cve-2021-31979-and-cve-2021-33771-exploit-ad7085ac</loc>
    <lastmod>2026-07-30T03:33:04.849Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-telemetry-detects-exchange-proxytoken-exploitation-attempts-targeting--56973b50</loc>
    <lastmod>2026-07-30T03:33:02.908Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-exchange-exploitation-attempt-behavior-for-cve-2021-28480-via-owa-cale-a2a9d722</loc>
    <lastmod>2026-07-30T03:33:00.878Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-cve-2021-27905-exploitation-attempt-against-apache-solr-via-specific-h-0bbcd74b</loc>
    <lastmod>2026-07-30T03:32:58.765Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/iis-webserver-ssrf-proxylogon-reset-virtual-directory-via-ecp-setobject-post-effee1f6</loc>
    <lastmod>2026-07-30T03:32:56.742Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-exchange-unified-messaging-process-drops-suspicious-files-indicating-cve-b06335b3</loc>
    <lastmod>2026-07-30T03:32:54.302Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-exchange-umworkerprocess-subprocess-launching-indicative-of-cve-2021-268-cd479ccc</loc>
    <lastmod>2026-07-30T03:32:52.435Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wazuh-rce-exploitation-attempt-via-traversal-in-manager-files-path-parameter-b9888738</loc>
    <lastmod>2026-07-30T03:32:50.447Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detects-potential-ognl-injection-exploitation-of-confluence-cve-2021-2-38825179</loc>
    <lastmod>2026-07-30T03:32:48.901Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-atlassian-confluence-java-spawning-suspicious-child-processes-cve-245f92e3</loc>
    <lastmod>2026-07-30T03:32:46.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pulse-connect-secure-web-exploitation-attempts-matching-cve-2021-22893-uri-patte-5525edac</loc>
    <lastmod>2026-07-30T03:32:44.495Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-rule-fortinet-waf-cve-2021-22123-exploitation-attempt-via-post-to-saml-f425637f</loc>
    <lastmod>2026-07-30T03:32:42.915Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vmware-vcenter-server-file-upload-exploitation-attempt-cve-2021-22005-via-web-po-b014ea07</loc>
    <lastmod>2026-07-30T03:32:40.811Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-post-to-vmware-view-planner-logupload-endpoint-with-cve-2021-21978-pro-77586a7f</loc>
    <lastmod>2026-07-30T03:32:38.948Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-post-to-ui-vropspluginui-rest-services-uploadova-indicates-cve-2021-21-179ed852</loc>
    <lastmod>2026-07-30T03:32:37.275Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-detection-weblogic-jndibindinghandle-ldap-probe-cve-2021-2109-687f6504</loc>
    <lastmod>2026-07-30T03:32:35.620Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/arcadyan-router-exploit-attempts-via-web-path-traversal-and-unauthenticated-conf-f0500377</loc>
    <lastmod>2026-07-30T03:32:33.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/zeek-dce-rpc-remote-printer-driver-and-print-processor-installation-activity-pri-7b33baef</loc>
    <lastmod>2026-07-30T03:32:31.407Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-print-spooler-exploitation-unidrv-mimispool-driver-load-in-event-id-316-f34d942d</loc>
    <lastmod>2026-07-30T03:32:28.158Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-print-spooler-module-load-failures-indicating-possible-cve-2021-1675-exp-4e64668a</loc>
    <lastmod>2026-07-30T03:32:26.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-monitoring-for-print-driver-path-names-used-by-mimikatz-ba6b9e43</loc>
    <lastmod>2026-07-30T03:32:23.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-spooler-spoolsv-exe-loads-dll-from-spool-drivers-subdirectories-02fb90de</loc>
    <lastmod>2026-07-30T03:32:21.906Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-events-detect-poc-style-print-spooler-filename-targeting-cve-2021-1-2131cfb3</loc>
    <lastmod>2026-07-30T03:32:19.650Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-deletion-monitoring-for-spooler-driver-folder-dll-removal-5b2bbc47</loc>
    <lastmod>2026-07-30T03:32:17.742Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-printernightmare-exploit-file-drop-via-antivirus-detection-6fe1719e</loc>
    <lastmod>2026-07-30T03:32:16.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-winnti-pipemon-setup-exe-command-line-flags-73d70463</loc>
    <lastmod>2026-07-30T03:32:14.434Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-rule-for-winnti-related-hk-university-campaign-dropped--3121461b</loc>
    <lastmod>2026-07-30T03:32:12.857Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-identify-taidoor-rat-dll-load-via-rundll32-command-line-patterns-d1aa3382</loc>
    <lastmod>2026-07-30T03:32:11.238Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/solarwinds-supernova-webshell-access-via-logoimagehandler-ashx-requests-a2cee20b</loc>
    <lastmod>2026-07-30T03:32:09.498Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-inline-vbscript-unc2452-un2452-pattern-20c3f09d</loc>
    <lastmod>2026-07-30T03:32:07.765Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-command-line-pattern-using-wmi-to-launch-rundll32-b7155193</loc>
    <lastmod>2026-07-30T03:32:06.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-7z-archive-with-specific-extensions-via-wscript-and-run-9be34ad0</loc>
    <lastmod>2026-07-30T03:32:04.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-key-activity-for-run-ntkd-persistence-path-70d43542</loc>
    <lastmod>2026-07-30T03:32:02.441Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-command-line-patterns-used-in-lazarus-activity-tests-24c4d154</loc>
    <lastmod>2026-07-30T03:32:00.801Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-executions-associated-with-greenbug-style-powershell-and-reverse-3711eee4</loc>
    <lastmod>2026-07-30T03:31:59.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-server-analytics-detects-gallium-linked-suspicious-qnames-eventid-25-3db10f25</loc>
    <lastmod>2026-07-30T03:31:57.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-ioc-matching-for-gallium-cyber-espionage-indicators-440a56bf</loc>
    <lastmod>2026-07-30T03:31:55.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-regsvr32-silent-ocx-execution-from-appdata-roaming-8acf3cfa</loc>
    <lastmod>2026-07-30T03:31:53.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-rundll32-exe-launching-wermgr-exe-via-dllregisterserver-58bf96d9</loc>
    <lastmod>2026-07-30T03:31:51.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-indicative-of-maze-ransomware-word-droppers-29fd07fc</loc>
    <lastmod>2026-07-30T03:31:49.977Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-hardening-changes-via-process-command-line-indicative-of-ke3cha-7b544661</loc>
    <lastmod>2026-07-30T03:31:48.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-markers-in-hardware-keys-and-printresponsor-path-5118765f</loc>
    <lastmod>2026-07-30T03:31:46.297Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-exe-executions-ending-with-rundll-or-control-rundll-54e57ce3</loc>
    <lastmod>2026-07-30T03:31:44.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/turla-comrat-proxy-http-requests-to-index-php-h-7857f021</loc>
    <lastmod>2026-07-30T03:31:43.133Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-servicedll-path-ending-in-currentcontrolset-services-wer-92b0b372</loc>
    <lastmod>2026-07-30T03:31:41.537Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-com-hijack-attempts-via-sc-exe-and-wmic-exe-blue-mockingbird-c3198a27</loc>
    <lastmod>2026-07-30T03:31:39.799Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/citrix-adc-netscaler-web-exploitation-indicators-for-cve-2020-8193-and-cve-2020--0d0d9a8a</loc>
    <lastmod>2026-07-30T03:31:38.190Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/web-exploit-attempt-f5-big-ip-cve-2020-5902-uri-pattern-44b53b1c</loc>
    <lastmod>2026-07-30T03:31:36.409Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cisco-asa-ftd-web-exploitation-of-cve-2020-3452-http-200-aba47adc</loc>
    <lastmod>2026-07-30T03:31:34.514Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/terramaster-tos-cve-2020-28188-web-exploit-attempt-via-suspicious-makecvs-php-ge-15c312b9</loc>
    <lastmod>2026-07-30T03:31:32.900Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/oracle-weblogic-exploitation-attempts-via-crafted-console-url-parameters-cve-202-85d466b0</loc>
    <lastmod>2026-07-30T03:31:31.139Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-zerologon-poc-execution-via-cmd-exe-launching-cool-exe-or-zero-exe-dcc6a01e</loc>
    <lastmod>2026-07-30T03:31:29.430Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dns-service-dns-exe-process-anomalies-indicating-cve-2020-1350-rce-explo-b5281f31</loc>
    <lastmod>2026-07-30T03:31:27.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-change-new-print-port-entries-with-executable-script-extensions-7ec912f2</loc>
    <lastmod>2026-07-30T03:31:25.520Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-add-printerport-commands-with-executable-dll-bat-paths-cc08d590</loc>
    <lastmod>2026-07-30T03:31:23.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-java-deserialization-exploitation-via-desktopcentral-se-846b866e</loc>
    <lastmod>2026-07-30T03:31:21.805Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/solarwinds-orion-api-auth-bypass-probing-via-suspicious-webresource-axd-and-i18n-5a35116f</loc>
    <lastmod>2026-07-30T03:31:19.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-microsoft-exchange-control-panel-error-with-viewstate-parameter-indicati-d6266bf5</loc>
    <lastmod>2026-07-30T03:31:17.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-exchange-exploitation-web-requests-using-ecp-owa-and-viewstate-http-ge-fce2c2e2</loc>
    <lastmod>2026-07-30T03:31:15.338Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-http-request-indicators-for-cve-2020-0688-exploitation-attempts-7c64e577</loc>
    <lastmod>2026-07-30T03:31:13.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-4799-checkadmin-exe-targeting-administrators-during-operation-w-74ad4314</loc>
    <lastmod>2026-07-30T03:31:11.408Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-wtaks-exe-winwsh-exe-parameters-resembling-mustang-pand-2d87d610</loc>
    <lastmod>2026-07-30T03:31:07.877Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-export-dll-u-or-trailing-dll-u-in-commandline-d465d1d8</loc>
    <lastmod>2026-07-30T03:31:05.853Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-jscript-execution-via-temp-errors-bat-10152a7b</loc>
    <lastmod>2026-07-30T03:31:04.006Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/proxy-detection-suspicious-chrome-36-user-agent-to-api-dropbox-com-5ba715b6</loc>
    <lastmod>2026-07-30T03:31:00.405Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-regsvr32-launches-appdata-local-dlls-referencing-dllentry-bd70d3f8</loc>
    <lastmod>2026-07-30T03:30:57.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ursnif-related-registry-key-creation-indicators-on-windows-21f17060</loc>
    <lastmod>2026-07-30T03:30:55.570Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ursnif-dropper-download-url-pattern-via-proxy-php-query-leading-to-cab-with-http-a36ce77e</loc>
    <lastmod>2026-07-30T03:30:53.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ursnif-c2-traffic-via-proxy-url-base64-encoded-path-with-avi-image-pattern-932ac737</loc>
    <lastmod>2026-07-30T03:30:52.009Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-snatch-ransomware-dropper-safe-mode-reboot-indicators-5325945e</loc>
    <lastmod>2026-07-30T03:30:49.686Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-command-lines-indicative-of-ryuk-style-ransomware-staging-c37510b8</loc>
    <lastmod>2026-07-30T03:30:47.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-qbot-execution-on-windows-via-wscript-winrar-parent-ping-type-and-regs-4fcac6eb</loc>
    <lastmod>2026-07-30T03:30:45.948Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/lockergoga-ransomware-command-line-pattern-windows-process-creation-74db3488</loc>
    <lastmod>2026-07-30T03:30:44.131Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-formbook-style-exe-command-lines-deleting-dropper-from--032f5fb3</loc>
    <lastmod>2026-07-30T03:30:42.689Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-emotet-like-powershell-wmi-command-line-indicators-d02e8cf5</loc>
    <lastmod>2026-07-30T03:30:40.929Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-indicator-for-dtrack-rat-recon-commands-f1531fa4</loc>
    <lastmod>2026-07-30T03:30:39.192Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-dridex-linked-svchost-and-regsvr32-execution-e6eb5a96</loc>
    <lastmod>2026-07-30T03:30:37.231Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/chafer-malware-c2-http-requests-matching-asp-asp-ui-pattern-fb502828</loc>
    <lastmod>2026-07-30T03:30:35.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-powershell-mshta-command-line-indicators-of-baby-shark-malware-activity-2b30fa36</loc>
    <lastmod>2026-07-30T03:30:33.852Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/confluence-web-exploit-attempt-via-path-traversal-in-post-upload-action-cve-2019-e9bc39ae</loc>
    <lastmod>2026-07-30T03:30:31.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/citrix-netscaler-directory-traversal-attempts-targeting-vpns-portal-scripts-and--ac5a6409</loc>
    <lastmod>2026-07-30T03:30:30.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-sudo-privilege-escalation-attempt-matching-cve-2019-14287-command-line-pat-f74107df</loc>
    <lastmod>2026-07-30T03:30:28.319Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-sudo-cve-2019-14287-exploit-attempt-via-suspicious-user-value-patterns-7fcc54cb</loc>
    <lastmod>2026-07-30T03:30:26.512Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cve-2019-1388-privilege-escalation-via-uac-consent-spawning-internet-exp-02e0b2ea</loc>
    <lastmod>2026-07-30T03:30:24.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-setupcomplete-cmd-partnersetupcomplete-cmd-e-1c373b6d</loc>
    <lastmod>2026-07-30T03:30:23.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pulse-secure-exploitation-attempt-cve-2019-11510-via-guacamole-uri-pattern-2dbc10d7</loc>
    <lastmod>2026-07-30T03:30:21.346Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rdp-termdd-error-events-indicating-possible-cve-2019-0708-exploitation-aaa5b30d</loc>
    <lastmod>2026-07-30T03:30:19.720Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-log-detects-4625-rdp-failure-pattern-from-scanner-poc-for-bluek-8400629e</loc>
    <lastmod>2026-07-30T03:30:16.733Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-task-scheduler-schtasks-exe-change-tn-ru-rp-seen-indicating-bearlpe-atte-931b6802</loc>
    <lastmod>2026-07-30T03:30:14.874Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-commandline-match-for-tropictrooper-campaign-indicators-8c7090c3</loc>
    <lastmod>2026-07-30T03:30:13.063Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-disabling-scheduled-defrag-task-via-event-id-4701-c5a178bf</loc>
    <lastmod>2026-07-30T03:30:11.547Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-schtasks-deletion-modification-of-scheduleddefrag-task-958d81aa</loc>
    <lastmod>2026-07-30T03:30:09.750Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-system-service-creation-for-scheduled-scan-and-updatmachine-53ba33fd</loc>
    <lastmod>2026-07-30T03:30:08.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-security-scheduled-task-persistence-via-4698-for-sc-scheduled-scan-and-u-c0580559</loc>
    <lastmod>2026-07-30T03:30:06.581Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-event-oilrig-style-run-key-persistence-via-ume-ut-subkeys-7bdf2a7c</loc>
    <lastmod>2026-07-30T03:30:04.878Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-scheduled-task-and-autoit3-exe-activity-consistent-with-oilrig-ma-ce6e34ca</loc>
    <lastmod>2026-07-30T03:30:03.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-mshta-powershell-and-system-survey-behavior-36222790</loc>
    <lastmod>2026-07-30T03:30:01.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-match-commandline-indicators-of-cozy-bear-2018-phishing-7453575c</loc>
    <lastmod>2026-07-30T03:29:42.616Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-file-event-indicators-for-ds7002-lnk-ds7002-pdf-and-ds7002-zip-3a3f81ca</loc>
    <lastmod>2026-07-30T03:29:40.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-rundll32-trojan-loader-command-line-with-appdata-path-ba778144</loc>
    <lastmod>2026-07-30T03:29:39.131Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-dll-side-loading-svchost-exe-launched-from-appdata-by-sllauncher-exe-9aa01d62</loc>
    <lastmod>2026-07-30T03:29:37.403Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-elise-backdoor-related-dll-deletion-and-execution-via-s-e507feb7</loc>
    <lastmod>2026-07-30T03:29:35.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-access-to-webshell-in-weblogic-keystore-folder-37e8369b</loc>
    <lastmod>2026-07-30T03:29:33.784Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/linux-sshd-buffer-parsing-error-indicative-of-cve-2018-15473-exploit-attempts-4c9d903d</loc>
    <lastmod>2026-07-30T03:29:32.201Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/webserver-request-indicates-fortinet-ssl-vpn-path-traversal-attempt-cve-2018-133-a2e97350</loc>
    <lastmod>2026-07-30T03:29:30.470Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-creation-werfaultsvc-scm-event-7045-for-turla-png-dropper-indica-1228f8e2</loc>
    <lastmod>2026-07-30T03:29:28.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-install-system-event-7045-for-turla-associated-service-names-1df8b3da</loc>
    <lastmod>2026-07-30T03:29:27.010Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-named-pipe-creation-matching-turla-associated-pipe-names-739915e4</loc>
    <lastmod>2026-07-30T03:29:25.337Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-registry-event-implant-service-key-under-currentcontrolset-services-null-47e0852a</loc>
    <lastmod>2026-07-30T03:29:23.789Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-masqueraded-system-binaries-executed-from-non-default-paths-msdtc-exe-gp-3f7f5b0b</loc>
    <lastmod>2026-07-30T03:29:22.102Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/firewall-alerts-for-equation-group-c2-ip-communications-881834a4</loc>
    <lastmod>2026-07-30T03:29:20.462Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-ps-exe-commandline-renaming-of-sysinternals-pstool-execution-18da1007</loc>
    <lastmod>2026-07-30T03:29:19.188Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-indicating-cscript-vbscript-and-csvde-web-shell-droppi-966e4016</loc>
    <lastmod>2026-07-30T03:29:17.563Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-wannacry-ransomware-process-execution-indicators-41d40bff</loc>
    <lastmod>2026-07-30T03:29:15.985Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-service-install-ntssrv-via-service-control-manager-7045-9e987c6c</loc>
    <lastmod>2026-07-30T03:29:13.196Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-suspicious-plugx-side-loading-executables-from-uncommon-aeab5ec5</loc>
    <lastmod>2026-07-30T03:29:11.493Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-notpetya-activity-wevtutil-log-clearing-and-drive-c-usn-delete-via-fsuti-79aeeb41</loc>
    <lastmod>2026-07-30T03:29:09.897Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-access-verclsid-exe-receiving-shellcode-injection-from-microsoft-b7967e22</loc>
    <lastmod>2026-07-30T03:29:07.937Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-rundll32-exe-installarchersvc-execution-3d4aebe0</loc>
    <lastmod>2026-07-30T03:29:06.379Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-detect-installation-of-javamtsup-service-via-security-event-4697-cb062102</loc>
    <lastmod>2026-07-30T03:29:04.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-execution-javaw-exe-in-appdata-roaming-oracle-path-adwind-jrat-p-1fac1481</loc>
    <lastmod>2026-07-30T03:29:02.179Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-winword-spawning-csc-exe-sub-process-fdd84c68</loc>
    <lastmod>2026-07-30T03:29:00.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-cve-2017-11882-droppers-launching-eqnedt32-exe-and-child-processes-678eb5f4</loc>
    <lastmod>2026-07-30T03:28:58.761Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winword-launches-fltldr-exe-for-cve-2017-0261-style-exploitation-864403a1</loc>
    <lastmod>2026-07-30T03:28:56.568Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-winword-launching-microscmgmt-exe-for-cve-2015-1641-exploitation-7993792c</loc>
    <lastmod>2026-07-30T03:28:54.988Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-process-creation-detect-suspicious-turla-related-command-lines-may-2020-9e2e51c5</loc>
    <lastmod>2026-07-30T03:28:52.743Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-zxshell-activity-via-rundll32-exe-using-zxfunction-and-remotediskxxxxx-f0b70adb</loc>
    <lastmod>2026-07-30T03:28:49.249Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rejetto-hfs-exploit-attempt-http-search-query-probing-for-command-or-script-exec-a133193c</loc>
    <lastmod>2026-07-30T03:28:47.571Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/web-exploitation-attempt-modx-manager-lfi-traversal-in-tvs-php-class-key-cve-201-a4a899e8</loc>
    <lastmod>2026-07-30T03:28:45.733Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/qualys-scan-indicates-firewall-product-not-detected-6b2066c8</loc>
    <lastmod>2026-07-30T03:28:43.814Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/qualys-vulnerability-scan-flags-default-credentials-findings-1a395cbc</loc>
    <lastmod>2026-07-30T03:28:41.987Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cleartext-protocol-traffic-on-netflow-ports-indicative-of-credential-exposure-7e4bfe58</loc>
    <lastmod>2026-07-30T03:28:40.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
</urlset>