<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://huntrule.com/</loc>
    <changefreq>daily</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules</loc>
    <changefreq>hourly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://huntrule.com/pricing</loc>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>
  <url>
    <loc>https://huntrule.com/about</loc>
    <changefreq>monthly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://huntrule.com/contact</loc>
    <changefreq>monthly</changefreq>
    <priority>0.2</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-java-execution-from-microsoft-teams-or-google-drive-directory-510c81b4</loc>
    <lastmod>2026-07-29T04:00:40.708Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-execution-of-denogate-backdoor-via-microsoft-teams-delivery-ed6483b0</loc>
    <lastmod>2026-07-29T03:57:50.557Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-windows-quick-assist-as-observed-in-unc6692-attacks-37cf84fe</loc>
    <lastmod>2026-07-28T21:13:17.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potential-unauthorized-use-of-atlas-ai-soc-customizations-655e1514</loc>
    <lastmod>2026-07-28T21:09:23.907Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-quick-assist-unsolicited-launch-d6cd3050</loc>
    <lastmod>2026-07-28T21:07:23.734Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-ultravnc-remote-access-software-via-process-creation</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shadow-copies-removal-via-operating-systems-utilities-via-process-creation</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deny-service-access-via-security-descriptor-manipulation-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-autoit-via-process-creation</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-logmein-execution-via-process-creation</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-gpscript-via-process-creation</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-wmiexec-default-powershell-command-via-process-creation</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-domain-trust-enumeration-through-dsquery-via-process-creation</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-obfuscation-powershell-via-ps-script</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-adreplaccount-via-ps-script</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-rdp-connections-over-non-standard-utilities-via-network-connection</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobaltstrike-service-installations-system-via-system</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-impacket-secretdump-remote-behavior-via-security</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wget-creating-files-in-tmp-directory-via-file-event</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-azure-new-cloudshell-via-activitylogs</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ingress-egress-security-group-change-via-cloudtrail</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-behavior-through-sasec-via-application</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-vnc-connection-attempt-via-application</loc>
    <lastmod>2026-07-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-globalflags-via-registry-set</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-full-dump-request-through-dumptype-registry-settings-via-registry-set</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-of-terminal-server-client-connection-history-registry-via-registry-delete</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-mavinject-exe-via-process-creation</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-link-exe-parent-process-via-process-creation</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ransomware-or-unauthorized-mbr-manipulation-through-bcdedit-exe-via-process-creation</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mount-diskimage-via-ps-script</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-obfuscated-iex-invocation-powershell-via-ps-script</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-anydesk-temporary-artefact-via-file-event</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-raw-paste-service-access-via-proxy</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-wizardupdate-malware-infection-via-process-creation</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-network-connections-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-app-assigned-to-azure-rbac-microsoft-entra-role-via-auditlogs</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-aws-user-login-profile-was-via-cloudtrail</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-rds-master-password-change-via-cloudtrail</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-user-login-failure-via-audit</loc>
    <lastmod>2026-07-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scripted-diagnostics-turn-off-check-enabled-registry-via-registry-set</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-private-keys-recon-through-commandline-utilities-via-process-creation</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-local-administrators-group-via-process-creation</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-schtasks-execution-appdata-folder-via-process-creation</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-stop-windows-service-through-powershell-stop-service-via-process-creation</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msexchange-transport-agent-deployment-via-process-creation</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-firewall-disabled-through-powershell-via-process-creation</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-operator-bloopers-cobalt-strike-commands-via-process-creation</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-web-access-feature-enabled-through-dism-via-process-creation</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-arbitrary-file-download-through-cmdl32-exe-via-process-creation</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certreq-command-to-download-via-process-creation</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-keywords-via-ps-script</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-clip-powershell-via-ps-script</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dotnet-assembly-dll-loaded-through-office-application-via-image-load</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-for-anonfiles-com-domain-sysmon-via-dns-query</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rtcore-suspicious-service-deployment-via-system</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-failed-dns-zone-transfer-via-dns-server</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-behavior-via-riskdetection</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-antivirus-relevant-file-paths-alerts-signature-via-antivirus</loc>
    <lastmod>2026-07-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-vulnerable-driver-blocklist-via-registry-set</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/new-timeproviders-registered-with-unusual-dll-name-via-registry-set</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-uac-bypass-through-sdclt-exe-via-process-creation</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/script-interpreter-execution-from-suspicious-folder-via-process-creation</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-file-type-extension-via-process-creation</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-command-via-process-creation</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-accounts-enumeration-via-process-creation</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-behavior-through-emoji-use-in-commandline-1-via-process-creation</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-system-restore-registry-change-through-commandline-via-process-creation</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codepage-switch-through-chcp-via-process-creation</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-indirect-command-execution-from-script-file-through-bash-exe-via-process-creation</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-free-process-scope-cor-profiler-via-ps-script</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-download-through-net-webclient-powershell-classic-via-ps-classic-start</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-iscsicpl-imageload-via-image-load</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-process-memory-dump-creation-through-taskmgr-exe-via-file-event</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-created-in-perflogs-via-file-event</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-drop-by-exchange-via-file-event</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-defender-tamper-protection-trigger-via-windefend</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-defender-threat-detection-service-via-system</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-obfuscated-iex-invocation-security-via-security</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-etw-logging-processing-option-disabled-on-iis-server-via-iis-configuration</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-server-error-failed-loading-the-serverlevelplugindll-via-dns-server</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-impacket-secretdump-remote-behavior-zeek-via-smb-files</loc>
    <lastmod>2026-07-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uninstall-sysinternals-sysmon-via-process-creation</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-redirection-to-local-admin-share-via-process-creation</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-system-informer-execution-via-process-creation</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pua-adfind-exe-via-process-creation</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-windows-feature-enabled-proccreation-via-process-creation</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rdp-tunneling-through-plink-via-process-creation</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-driver-dll-deployment-through-odbcconf-exe-via-process-creation</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-imewdbld-exe-via-process-creation</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpdpapi-execution-via-process-creation</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-generic-credentials-added-through-cmdkey-exe-via-process-creation</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-handlekatz-duplicating-lsass-handle-via-process-access</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-by-regsvr32-exe-via-network-connection</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-desktopimgdownldr-target-file-via-file-event</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-non-existent-system-dll-via-file-event</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-teams-application-related-objectacess-event-via-security</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-over-reverse-ssh-tunnel-wfp-via-security</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hybridconnectionmanager-service-deployment-via-security</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-standard-user-in-high-privileged-group-via-lsa-server</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-through-git-linux-via-process-creation</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bpfdoor-abnormal-process-id-or-lock-file-accessed-via-auditd</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-steganography-hide-files-with-steghide-via-auditd</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-smb-file-open-request-via-application</loc>
    <lastmod>2026-07-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hybridconnectionmanager-service-deployment-registry-via-registry-event</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-dismhost-via-process-creation</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-psexec-remote-via-process-creation</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-through-right-to-left-override-via-process-creation</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-jwt-token-search-through-cli-via-process-creation</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-jusched-exe-via-process-creation</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-pua-adidnsdump-execution-via-process-creation</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-invoke-webrequest-via-process-creation</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-perl-inline-command-via-process-creation</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lolbin-unregmp2-exe-use-as-proxy-via-process-creation</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-xml-execute-command-via-ps-script</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hyper-v-cmdlets-via-ps-script</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-screensaver-binary-file-creation-via-file-event</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-new-firewall-policy-added-via-event</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-crypto-mining-pool-connections-via-network-connection</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bpfdoor-tcp-ports-redirect-via-auditd</loc>
    <lastmod>2026-07-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-configuration-error-via-sysmon-error</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-psexec-service-via-process-creation</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-process-hacker-execution-via-process-creation</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-amsi-bypass-pattern-assembly-gettype-via-ps-script</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-consent-and-comctl32-file-via-file-event</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-creation-by-mysql-daemon-process-via-file-event</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-access-to-browser-credential-storage-via-file-access</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-important-windows-service-terminated-with-error-via-system</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-ad-health-service-agents-registry-keys-access-via-security</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-ad-health-monitoring-agent-registry-keys-access-via-security</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mssql-destructive-query-via-application</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-team-viewer-session-started-on-macos-host-via-process-creation</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-masquerading-as-linux-crond-process-via-auditd</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-admin-functions-access-through-proxy-via-okta</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-ca-policy-by-non-approved-actor-via-auditlogs</loc>
    <lastmod>2026-07-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-masquerading-as-system-processes-via-process-creation</loc>
    <lastmod>2026-07-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-notepad-password-files-enumeration-via-process-creation</loc>
    <lastmod>2026-07-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-core-dll-loaded-through-office-application-via-image-load</loc>
    <lastmod>2026-07-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-suspicious-outlook-macro-via-file-event</loc>
    <lastmod>2026-07-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-powershell-sessions-network-connections-winrm-via-security</loc>
    <lastmod>2026-07-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dc-shadow-attack-via-security</loc>
    <lastmod>2026-07-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wannacry-killswitch-domain-via-dns</loc>
    <lastmod>2026-07-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-point-to-site-vpn-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-query-via-database</loc>
    <lastmod>2026-07-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-visual-studio-utilities-for-office-via-registry-set</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outlook-enableunsafeclientmailrules-setting-enabled-registry-via-registry-set</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-displaying-hidden-files-feature-via-registry-set</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-wermgr-exe-via-process-creation</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wab-wabmig-unusual-parent-or-child-processes-via-process-creation</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-program-executed-via-proxy-local-command-through-ssh-exe-via-process-creation</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-name-as-guid-via-process-creation</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-crackmapexec-powershell-obfuscation-via-process-creation</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-assistive-technology-applications-execution-through-atbroker-exe-via-process-creation</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-bash-interactive-shell-via-process-creation</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-special-file-creation-through-mknod-syscall-via-auditd</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unix-shell-configuration-change-via-auditd</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-workspace-user-granted-admin-privileges-via-google-workspace-admin</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-inbox-manipulation-rules-via-riskdetection</loc>
    <lastmod>2026-07-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-lsa-extensions-via-registry-set</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-behavior-through-emoji-use-in-commandline-4-via-process-creation</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sqlite-chromium-profile-data-db-access-via-process-creation</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-screen-capture-behavior-through-psr-exe-via-process-creation</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-crackmapexec-execution-via-process-creation</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copy-from-volumeshadowcopy-through-cmd-exe-via-process-creation</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-removal-through-del-via-process-creation</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-in-suspicious-location-encoded-to-base64-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-binary-no-commandline-via-network-connection</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dotnet-clr-dll-loaded-by-scripting-applications-via-image-load</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-thread-creation-in-mstsc-exe-from-suspicious-location-via-create-remote-thread</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/clearing-of-critical-hive-in-suspicious-location-access-bits-via-system</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mssql-xpcmdshell-option-change-via-application</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-onelogin-user-account-locked-via-onelogin-events</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-added-owner-to-application-via-auditlogs</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-active-directory-hybrid-health-ad-fs-new-server-via-activitylogs</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-http-post-login-attempt-via-application</loc>
    <lastmod>2026-07-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-privacy-settings-experience-in-registry-via-registry-set</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-ultraviewer-execution-via-process-creation</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/csc-exe-execution-form-potentially-suspicious-parent-via-process-creation</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-decoded-from-base64-hex-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psasyncshell-asynchronous-tcp-reverse-shell-via-ps-script</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-initiated-network-connection-to-ngrok-domain-via-network-connection</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-crackmapexec-file-indicators-via-file-event</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/access-to-windows-credential-history-file-by-unusual-applications-via-file-access</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dpapi-domain-backup-key-extraction-via-security</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dcom-internetexplorer-application-iertutil-dll-hijack-security-via-security</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/new-firewall-rule-added-in-windows-firewall-exception-list-for-possible-suspicious-application-via-firewall-as</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-applocker-application-would-have-been-blocked-via-applocker</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-petitpotam-attack-through-efs-rpc-calls-via-dce-rpc</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-gui-input-capture-macos-via-process-creation</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-package-uninstall-via-process-creation</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-github-fork-private-repositories-setting-enabled-cleared-via-audit</loc>
    <lastmod>2026-07-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-extension-in-keyboard-layout-ime-file-registry-value-via-registry-set</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-eventlog-file-location-manipulation-via-registry-set</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-load-through-lsass-via-registry-event</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wusa-exe-executed-by-parent-process-located-in-suspicious-location-via-process-creation</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-path-change-via-process-creation</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-remote-access-utility-renamed-meshagent-windows-via-process-creation</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-anydesk-execution-with-known-revoked-signing-certificate-via-process-creation</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-attempt-via-new-networkprovider-cli-via-process-creation</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-advanced-ip-scanner-execution-via-process-creation</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-visual-basic-command-line-compiler-use-via-process-creation</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-exfiltration-and-tunneling-utilities-execution-via-process-creation</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-efspotato-named-pipe-creation-via-pipe-created</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-traffic-to-localtonet-tunneling-service-initiated-via-network-connection</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-vcruntime140-dll-sideloading-via-image-load</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-a-new-trust-was-created-to-a-domain-via-security</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-mitre-bzar-indicators-for-via-dce-rpc</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-through-sudoers-d-files-via-file-event</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-login-behavior-classified-by-google-via-google-workspace-login</loc>
    <lastmod>2026-07-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-shim-database-in-unusual-location-via-registry-set</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-bginfo-exe-custom-vbscript-registry-configuration-via-registry-set</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cab-file-extraction-through-wusa-exe-from-potentially-suspicious-paths-via-process-creation</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-restrictedadminmode-registry-value-manipulation-proccreation-via-process-creation</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lolbas-data-exfiltration-by-datasvcutil-exe-via-process-creation</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-netexec-execution-via-process-creation</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-event-viewer-child-process-via-process-creation</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntfs-alternate-data-stream-via-ps-script</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-exploit-guard-tamper-via-windefend</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-accessmask-requested-from-lsass-via-security</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-unmet-whql-requirements-for-loaded-kernel-module-via-codeintegrity-operational</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-modify-configuration-via-aaa</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-symlink-etc-passwd-via-linux</loc>
    <lastmod>2026-07-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tamper-with-sophos-av-registry-keys-via-registry-set</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-excel-add-in-registry-via-registry-set</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-qakbot-registry-behavior-via-registry-event</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-automated-collection-command-prompt-via-process-creation</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-extension-shim-database-deployment-through-sdbinst-exe-via-process-creation</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-com-objects-download-cradles-use-process-creation-via-process-creation</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cabinet-file-execution-through-msdt-exe-via-process-creation</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-certipy-execution-via-process-creation</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-encryption-via-gpg4win-via-process-creation</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-dumpminitool-via-process-creation</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-obfuscation-via-character-join-via-ps-script</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-event-consumer-created-named-pipe-via-pipe-created</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-remcom-default-named-pipe-via-pipe-created</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sliver-c2-default-service-deployment-via-system</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-meterpreter-or-cobalt-strike-getsystem-service-deployment-system-via-system</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-application-crashed-via-system</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-audit-rules-deleted-through-auditctl-via-process-creation</loc>
    <lastmod>2026-07-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-sensitive-settings-changed-to-zero-via-registry-set</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-service-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-systeminfo-via-process-creation</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nps-tunneling-tool-execution-via-process-creation</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-softperfect-netscan-execution-via-process-creation</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-msohtmed-exe-via-process-creation</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-bginfo-exe-via-process-creation</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-change-attempt-through-vbscript-powershell-via-ps-script</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-activescripteventconsumers-behavior-through-scrcons-exe-dll-load-via-image-load</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmiprvse-wbemcomn-dll-hijack-file-via-file-event</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-malware-protection-engine-crash-wer-via-application</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-linux-network-service-scanning-utilities-via-process-creation</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-multifactor-authentication-interrupted-via-signinlogs</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-cloudtrail-important-change-via-cloudtrail</loc>
    <lastmod>2026-07-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-administrative-share-creation-at-startup-via-registry-set</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-execution-with-image-extension-via-process-creation</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-spawned-through-explorer-exe-via-process-creation</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/regsvr32-execution-from-possible-suspicious-location-via-process-creation</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hiding-user-account-through-specialaccounts-registry-key-commandline-via-process-creation</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-non-interactive-powershell-process-spawned-via-process-creation</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-misuse-of-service-permissions-to-hide-services-through-set-service-via-process-creation</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-remote-exe-via-process-creation</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-iis-service-account-password-dumped-via-process-creation</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chromium-browser-headless-execution-to-mockbin-like-site-via-process-creation</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-with-headless-browser-via-process-creation</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-web-request-commands-and-cmdlets-scriptblock-via-ps-script</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-obfuscated-iex-invocation-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-silenttrinity-stager-msbuild-behavior-via-network-connection</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-visual-studio-code-tunnel-remote-file-creation-via-file-event</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-shell-scripting-application-file-write-to-suspicious-folder-via-file-event</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-utilities-host-service-install-via-system</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/touch-suspicious-service-file-via-process-creation</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bpftrace-unsafe-option-use-via-process-creation</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-privileged-account-creation-via-auditlogs</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pim-approvals-and-deny-elevation-via-auditlogs</loc>
    <lastmod>2026-07-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-registry-persistence-attempt-through-windows-telemetry-via-registry-set</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-outlook-home-page-via-registry-set</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-running-chrome-vpn-extensions-through-the-registry-2-vpn-extension-via-registry-set</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-signing-bypass-through-windows-developer-features-via-process-creation</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nircmd-execution-as-local-system-via-process-creation</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-xordump-execution-via-process-creation</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-krbrelayup-execution-via-process-creation</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/diskshadow-script-mode-execution-from-potential-suspicious-location-via-process-creation</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-configsecuritypolicy-exe-via-process-creation</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-autorun-registry-modified-through-wmi-via-process-creation</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-successful-account-login-through-wmi-via-security</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-kind-of-network-nkn-via-dns</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-system-accounts-enumeration-macos-via-process-creation</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clipboard-access-through-osascript-via-process-creation</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-account-created-and-deleted-within-a-close-time-frame-via-auditlogs</loc>
    <lastmod>2026-07-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-groups-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-svchost-parent-process-via-process-creation</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shadow-copies-creation-via-operating-systems-utilities-via-process-creation</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netsh-allow-group-policy-on-microsoft-defender-firewall-via-process-creation</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-msxsl-exe-via-process-creation</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hiding-files-with-attrib-exe-via-process-creation</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-to-visual-studio-code-tunnels-domain-via-network-connection</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-appended-extension-via-file-rename</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winrar-creating-files-in-startup-locations-via-file-event</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wce-wceaux-dll-access-via-security</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-external-remote-smb-logon-from-public-ip-via-security</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-blocked-driver-load-with-revoked-certificate-via-codeintegrity-operational</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-appx-deployment-full-trust-package-deployment-via-appxdeployment-server</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-federated-domain-added-via-audit</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-too-many-global-admins-via-pim</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitlocker-key-retrieval-via-auditlogs</loc>
    <lastmod>2026-07-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-space-characters-in-runmru-registry-path-clickfix-via-registry-set</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-autodialdll-via-registry-set</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-path-in-keyboard-layout-ime-file-registry-value-via-registry-set</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-etw-logging-disabled-in-net-processes-sysmon-registry-via-registry-set</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-remote-connection-between-anonymous-computer-allowanonymouscallback-via-registry-set</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/writing-of-malicious-files-to-the-fonts-folder-via-process-creation</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-wsudo-suspicious-execution-via-process-creation</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pua-iox-tunneling-utility-via-process-creation</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-windows-defender-definition-files-via-process-creation</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-c-il-code-compilation-through-ilasm-exe-via-process-creation</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-to-sensitive-file-extensions-via-security</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-security-via-security</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-babyshark-agent-default-url-pattern-via-proxy</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/http-request-to-low-reputation-tld-or-suspicious-file-extension-via-http</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-omigod-scx-runasprovider-executescript-via-process-creation</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-dns-zone-modified-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-vpn-connection-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rbac-permission-enumeration-attempt-via-application</loc>
    <lastmod>2026-07-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-through-new-sip-provider-via-registry-set</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-windows-defender-threat-severity-default-action-via-registry-event</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-taskmgr-as-local-system-via-process-creation</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-system-file-execution-location-anomaly-via-process-creation</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-through-masqueraded-xml-file-via-process-creation</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-obfuscated-powershell-msi-install-through-windowsinstaller-com-via-process-creation</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execute-code-with-pester-bat-as-parent-via-process-creation</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntlm-hash-leak-through-curl-ntlm-authentication-via-process-creation</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-zip-a-folder-with-powershell-for-staging-in-temp-powershell-module-via-ps-module</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-typical-hivenightmare-sam-file-export-via-file-event</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bloodhound-collection-files-via-file-event</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-csexec-service-deployment-via-system</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-kerberoasting-behavior-initial-query-via-security</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-java-children-processes-via-process-creation</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-setgid-capability-set-on-a-binary-through-setcap-utility-via-process-creation</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-to-unsanctioned-apps-via-threat-management</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-multi-factor-authentication-disabled-for-user-account-via-auditlogs</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-github-delete-action-invoked-via-audit</loc>
    <lastmod>2026-07-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-through-hhctrl-ocx-via-registry-set</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntlm-authentication-on-the-printer-spooler-service-via-process-creation</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-direct-autorun-keys-change-via-process-creation</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-provlaunch-exe-child-process-via-process-creation</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-quiet-install-from-remote-location-via-process-creation</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-trufflesnout-execution-via-process-creation</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-obfuscation-via-process-creation</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regasm-exe-initiating-network-connection-to-public-ip-via-network-connection</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dll-loaded-from-suspicious-location-through-cmspt-exe-via-image-load</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-mega-hosting-website-via-dns-query</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-defender-malware-detection-history-removal-via-windefend</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-metasploit-smb-authentication-via-security</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-delegated-permissions-granted-for-all-users-via-auditlogs</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-tftp-request-via-application</loc>
    <lastmod>2026-07-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-tamper-protection-on-windows-defender-via-registry-set</loc>
    <lastmod>2026-07-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-currentcontrolset-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-07-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-security-events-logging-adding-reg-key-minint-via-registry-event</loc>
    <lastmod>2026-07-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-registry-file-imported-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-07-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-fsharp-interpreters-via-process-creation</loc>
    <lastmod>2026-07-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-detect-virtualization-environment-via-ps-script</loc>
    <lastmod>2026-07-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-volume-shadow-copy-vss-ps-dll-load-via-image-load</loc>
    <lastmod>2026-07-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mssql-disable-audit-settings-via-application</loc>
    <lastmod>2026-07-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cisco-collect-data-via-aaa</loc>
    <lastmod>2026-07-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-pua-protection-on-windows-defender-via-registry-set</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-manipulation-with-security-products-through-wmic-via-process-creation</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-interesting-service-enumeration-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabled-volume-snapshots-via-process-creation</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/odbcconf-exe-suspicious-dll-location-via-process-creation</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-hollowreaper-execution-via-process-creation</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esentutl-gather-credentials-via-process-creation</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-root-certificate-installed-powershell-via-ps-script</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-initiated-connection-via-network-connection</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-ieinstal-file-via-file-event</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-ntds-dit-via-file-event</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mssql-spprocoption-set-via-application</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-atera-agent-deployment-via-application</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-linux-hacktool-via-process-creation</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invocation-of-shell-through-awk-linux-via-process-creation</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-storage-buckets-modified-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-nmap-fin-scan-via-application</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-rolebinding-change-via-audit</loc>
    <lastmod>2026-07-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/service-binary-in-suspicious-folder-via-registry-set</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-behavior-through-emoji-use-in-commandline-2-via-process-creation</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lol-binary-copied-from-system-directory-via-process-creation</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-msdt-exe-via-process-creation</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-greedy-compression-via-rar-exe-via-process-creation</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-seatbelt-execution-via-process-creation</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-downgrade-attack-via-process-creation</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-native-code-module-command-line-deployment-via-process-creation</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-hh-exe-via-process-creation</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-persistence-through-sticky-key-backdoor-via-process-creation</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execute-invoke-command-on-remote-host-via-ps-script</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-office-dll-sideload-via-image-load</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ripzip-attack-on-startup-folder-via-file-event</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-appx-package-downloaded-from-file-sharing-or-cdn-domain-via-appxdeployment-server</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-network-connections-enumeration-macos-via-process-creation</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-guest-account-enabled-through-sysadminctl-via-process-creation</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-install-root-certificate-via-process-creation</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-reset-by-user-account-via-auditlogs</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-azure-suppression-rule-via-activitylogs</loc>
    <lastmod>2026-07-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-always-install-elevated-msi-spawned-cmd-and-powershell-via-process-creation</loc>
    <lastmod>2026-07-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-extrac32-via-process-creation</loc>
    <lastmod>2026-07-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/new-connection-initiated-to-possible-dead-drop-resolver-domain-via-network-connection</loc>
    <lastmod>2026-07-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-dll-load-through-rundll32-exe-via-image-load</loc>
    <lastmod>2026-07-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-or-cscript-dropper-file-via-file-event</loc>
    <lastmod>2026-07-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windivert-driver-load-via-driver-load</loc>
    <lastmod>2026-07-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-successful-overpass-the-hash-attempt-via-security</loc>
    <lastmod>2026-07-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-new-administrator-account-created-via-event</loc>
    <lastmod>2026-07-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cleartext-protocol-use-via-firewall</loc>
    <lastmod>2026-07-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-esxi-vsan-information-enumeration-through-esxcli-via-process-creation</loc>
    <lastmod>2026-07-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-clipboard-collection-of-image-data-with-xclip-utility-via-auditd</loc>
    <lastmod>2026-07-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-dll-added-to-appcertdlls-registry-key-via-registry-event</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-process-of-winrar-exe-via-process-creation</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-service-creation-via-process-creation</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-run-once-task-execution-as-configured-in-registry-via-process-creation</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-mpclient-dll-sideloading-through-offlinescannershell-exe-via-process-creation</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-group-and-account-recon-behavior-via-net-exe-via-process-creation</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-hostname-via-process-creation</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-pypykatz-credentials-dumping-activity-via-process-creation</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-inveigh-execution-via-process-creation</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fax-service-dll-search-order-hijack-via-image-load</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vhd-image-download-through-browser-via-file-event</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-apt-user-agent-via-proxy</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-curl-use-on-linux-via-process-creation</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-network-acl-entry-added-via-cloudtrail</loc>
    <lastmod>2026-07-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-winrs-local-command-via-process-creation</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-system-user-process-creation-via-process-creation</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-control-panel-dll-load-via-process-creation</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-replace-exe-use-via-process-creation</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-meterpreter-cobaltstrike-behavior-via-process-creation</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-control-panel-items-via-process-creation</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-msxml-com-object-via-ps-script</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-zip-a-folder-with-powershell-for-staging-in-temp-powershell-via-powershell-classic</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vmguestlib-dll-sideload-via-image-load</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-certificate-services-denied-certificate-enrollment-request-via-system</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iso-image-mounted-via-security</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-publicly-accessible-rdp-service-via-rdp</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-through-macos-script-editor-via-process-creation</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-macos-remote-system-enumeration-via-process-creation</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-flag-set-on-file-directory-through-chflags-macos-via-process-creation</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-python-webserver-linux-via-process-creation</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-time-attribute-change-linux-via-auditd</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/kubernetes-possible-enumeration-behavior-via-audit</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-pod-in-system-namespace-via-application</loc>
    <lastmod>2026-07-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-renamed-sysinternals-utilities-registryset-via-registry-set</loc>
    <lastmod>2026-07-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/removal-of-possible-com-hijacking-registry-keys-via-registry-delete</loc>
    <lastmod>2026-07-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-computers-enumeration-with-get-adcomputer-via-ps-script</loc>
    <lastmod>2026-07-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-network-connection-initiated-by-cmstp-exe-via-network-connection</loc>
    <lastmod>2026-07-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-persistence-command-line-event-consumer-via-image-load</loc>
    <lastmod>2026-07-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-sysinternals-utilities-appx-versions-via-appmodel-runtime</loc>
    <lastmod>2026-07-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-unusual-volume-of-file-deletion-via-threat-management</loc>
    <lastmod>2026-07-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-azure-service-principal-via-auditlogs</loc>
    <lastmod>2026-07-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-azure-service-principal-via-auditlogs</loc>
    <lastmod>2026-07-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-guardduty-detector-deleted-or-updated-via-cloudtrail</loc>
    <lastmod>2026-07-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-ip-through-wget-exe-paths-via-process-creation</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-provisioning-registry-key-misuse-for-binary-proxy-via-process-creation</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outlook-enableunsafeclientmailrules-setting-enabled-via-process-creation</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-detection-of-powershell-execution-through-sqlps-exe-via-process-creation</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-and-execution-through-ieexec-exe-via-process-creation</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-csi-exe-use-via-process-creation</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-live-memory-dump-via-powershell-via-ps-script</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-add-name-resolution-policy-table-rule-via-ps-script</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-network-connection-initiated-by-certutil-exe-via-network-connection</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-service-terminated-with-error-via-system</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-startup-logon-script-added-to-group-policy-object-via-security</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-relevant-anti-virus-signature-keywords-in-application-log-via-application</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-base64-encoded-user-agent-via-proxy</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-root-sudoers-group-via-usermod-via-process-creation</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esxi-admin-permission-assigned-to-account-through-esxcli-via-process-creation</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-setuid-capability-set-on-a-binary-through-setcap-utility-via-process-creation</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-pst-export-alert-via-ediscovery-alert-via-threat-management</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-google-workspace-mfa-via-google-workspace-admin</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-primary-refresh-token-access-attempt-via-riskdetection</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-event-log-recon-via-application</loc>
    <lastmod>2026-06-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-base64-encoded-frombase64string-cmdlet-via-process-creation</loc>
    <lastmod>2026-06-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-embedding-parent-via-process-creation</loc>
    <lastmod>2026-06-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-manage-bde-wsf-misuse-to-proxy-via-process-creation</loc>
    <lastmod>2026-06-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-permission-misconfiguration-recon-through-findstr-exe-via-process-creation</loc>
    <lastmod>2026-06-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-customshellhost-via-process-creation</loc>
    <lastmod>2026-06-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-hidden-directory-creation-through-ntfs-index-allocation-stream-via-file-event</loc>
    <lastmod>2026-06-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ads-zone-identifier-deleted-by-unusual-application-via-file-delete</loc>
    <lastmod>2026-06-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-deployment-via-system</loc>
    <lastmod>2026-06-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-email-delivered-in-microsoft-365-via-audit</loc>
    <lastmod>2026-06-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-aws-ec2-startup-shell-script-change-via-cloudtrail</loc>
    <lastmod>2026-06-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-schedule-task-lateral-movement-through-itaskschedulerservice-via-application</loc>
    <lastmod>2026-06-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-file-read-vulnerability-in-jvm-based-application-via-application</loc>
    <lastmod>2026-06-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-binary-impersonating-sysinternals-utilities-via-process-creation</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-homoglyph-attack-via-lookalike-characters-via-process-creation</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-webdav-client-execution-through-rundll32-exe-via-process-creation</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-anydesk-silent-installation-via-process-creation</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-imports-registry-key-from-an-ads-via-process-creation</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-default-domain-gpo-change-through-gpme-via-process-creation</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-stdin-via-process-creation</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-impersonate-execution-via-process-creation</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-exported-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remove-account-from-domain-admin-group-via-ps-script</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-node-file-loaded-via-image-load</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-created-files-by-microsoft-sync-center-via-file-event</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-isatap-router-address-was-set-via-system</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ldap-attributes-used-via-security</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-crypto-commands-via-aaa</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-dev-tcp-via-linux</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-command-history-manipulation-via-linux</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-roles-assigned-outside-pim-via-pim</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-httpproxy-login-attempt-via-application</loc>
    <lastmod>2026-06-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-microsoft-defender-firewall-through-registry-via-registry-set</loc>
    <lastmod>2026-06-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-allow-rdp-remote-assistance-feature-via-registry-set</loc>
    <lastmod>2026-06-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-set-acl-on-windows-folder-via-process-creation</loc>
    <lastmod>2026-06-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-network-connections-enumeration-through-net-exe-via-process-creation</loc>
    <lastmod>2026-06-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-start-windows-service-through-net-exe-via-process-creation</loc>
    <lastmod>2026-06-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dllunregisterserver-function-call-through-msiexec-exe-via-process-creation</loc>
    <lastmod>2026-06-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-access-through-trolleyexpress-exclusion-via-process-creation</loc>
    <lastmod>2026-06-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sam-registry-hive-handle-request-via-security</loc>
    <lastmod>2026-06-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-use-of-hidden-paths-or-files-via-auditd</loc>
    <lastmod>2026-06-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-auditing-configuration-changes-on-linux-host-via-auditd</loc>
    <lastmod>2026-06-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bypass-uac-via-delegateexecute-via-registry-set</loc>
    <lastmod>2026-06-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-session-manager-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-06-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-file-download-through-powershell-invoke-webrequest-via-process-creation</loc>
    <lastmod>2026-06-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mstsc-exe-execution-with-local-rdp-file-via-process-creation</loc>
    <lastmod>2026-06-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-default-powersploit-empire-scheduled-task-creation-via-process-creation</loc>
    <lastmod>2026-06-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-remote-session-creation-via-ps-script</loc>
    <lastmod>2026-06-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vmmap-unsigned-dbghelp-dll-possible-sideloading-via-image-load</loc>
    <lastmod>2026-06-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/service-installed-by-unusual-client-system-via-system</loc>
    <lastmod>2026-06-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-netcat-reverse-shell-via-process-creation</loc>
    <lastmod>2026-06-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sharphound-recon-sessions-via-application</loc>
    <lastmod>2026-06-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-credential-editor-registry-via-registry-event</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-started-stopped-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-whoami-exe-execution-anomaly-via-process-creation</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webshell-utility-recon-behavior-via-process-creation</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-compressed-file-extraction-through-tar-exe-via-process-creation</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-compressed-file-creation-through-tar-exe-via-process-creation</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-schtasks-schedule-types-via-process-creation</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-team-viewer-session-started-on-windows-host-via-process-creation</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-quiet-deployment-via-process-creation</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-via-settingsynchost-exe-as-lolbin-via-process-creation</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-winpwn-scriptblock-via-ps-script</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-eacore-dll-sideloading-via-image-load</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-real-time-protection-failure-restart-via-windefend</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-anydesk-remote-access-software-service-deployment-via-system</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-clip-security-via-security</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-of-security-eventlog-via-security</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-integrity-protection-sip-enumeration-via-process-creation</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vim-gtfobin-misuse-linux-via-process-creation</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-app-granted-microsoft-permissions-via-auditlogs</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-rolebinding-clusterrolebinding-modified-and-deleted-via-activitylogs</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-dcom-wmi-lateral-movement-via-application</loc>
    <lastmod>2026-06-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-appcompat-registerapprestart-layer-via-registry-set</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sensitive-file-recovery-from-backup-through-wbadmin-exe-via-process-creation</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-suspect-svchost-behavior-via-process-creation</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-characteristics-due-to-missing-fields-via-process-creation</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-advanced-port-scanner-execution-via-process-creation</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-and-execute-pattern-via-process-creation</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-stop-windows-service-through-net-exe-via-process-creation</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-wfc-exe-via-process-creation</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-ttdinject-exe-via-process-creation</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-forfiles-command-via-process-creation</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dcom-internetexplorer-application-dll-hijack-image-load-via-image-load</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntds-exfiltration-filename-patterns-via-file-event</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-appx-package-deployment-attempts-through-appinstaller-exe-via-dns-query</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-local-privilege-escalation-indicator-tabtip-via-system</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-shadow-credentials-added-via-security</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-default-domain-gpo-change-via-security</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-new-vpn-ssl-web-portal-added-via-event</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-file-removal-via-aaa</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-logging-configuration-changes-on-linux-host-via-auditd</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-global-permission-changed-via-audit</loc>
    <lastmod>2026-06-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-chm-helper-dll-via-registry-set</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-netsh-helper-dll-registry-via-registry-set</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-credential-guard-registry-via-registry-set</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-idiagnostic-profile-via-process-creation</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-binary-directory-via-process-creation</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-parent-double-extension-file-via-process-creation</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dumping-process-through-sqldumper-exe-via-process-creation</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-winrm-access-through-evil-winrm-via-process-creation</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winlogon-helper-dll-via-ps-script</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-security-descriptors-scriptblock-via-ps-script</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winsxs-executable-file-creation-by-non-system-process-via-file-event</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-drop-binaries-into-spool-drivers-color-folder-via-file-event</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-suspicious-windows-anonymous-logon-local-account-via-security</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-schedule-task-lateral-movement-through-sasec-via-application</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-nmap-os-scan-via-application</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-github-secret-scanning-feature-via-audit</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-github-push-protection-bypass-detected-via-audit</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-django-framework-exceptions-via-application</loc>
    <lastmod>2026-06-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-crashcontrol-crashdump-via-registry-set</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xsl-script-execution-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-shell-folders-registry-change-through-commandline-via-process-creation</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-tap-installer-via-process-creation</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-involving-temp-folder-via-process-creation</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-execute-arbitrary-dll-via-process-creation</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-processes-spawned-by-java-exe-via-process-creation</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-clip-launcher-powershell-module-via-ps-module</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-to-btunnels-domains-via-network-connection</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/legitimate-application-writing-files-in-unusual-location-via-file-event</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/publisher-attachment-file-dropped-in-suspicious-location-via-file-event</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-smbexec-py-service-deployment-via-system</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-psexec-via-security</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-show-commands-input-via-aaa</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-shell-script-creation-in-profile-folder-via-file-event</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-password-policy-enumeration-linux-via-auditd</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-service-reload-or-start-linux-via-auditd</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-behavior-from-anonymous-ip-address-via-riskdetection</loc>
    <lastmod>2026-06-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-shim-database-change-via-registry-set</loc>
    <lastmod>2026-06-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-microsoft-compatibility-appraiser-via-process-creation</loc>
    <lastmod>2026-06-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-rundll32-powershell-module-via-ps-module</loc>
    <lastmod>2026-06-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmic-loading-scripting-libraries-via-image-load</loc>
    <lastmod>2026-06-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-dll-loaded-by-windows-utility-via-image-load</loc>
    <lastmod>2026-06-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/access-to-crypto-currency-wallets-by-unusual-applications-via-file-access</loc>
    <lastmod>2026-06-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-user-creation-via-security</loc>
    <lastmod>2026-06-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privilege-escalation-through-local-kerberos-relay-over-ldap-via-security</loc>
    <lastmod>2026-06-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-kubernetes-secrets-modified-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-06-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-pim-alert-setting-changes-to-via-auditlogs</loc>
    <lastmod>2026-06-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-aws-vpc-flow-logs-via-cloudtrail</loc>
    <lastmod>2026-06-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-outlook-loadmacroprovideronboot-setting-via-registry-set</loc>
    <lastmod>2026-06-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-disallowrun-execution-to-registry-via-registry-set</loc>
    <lastmod>2026-06-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codepage-change-through-mode-com-to-russian-language-via-process-creation</loc>
    <lastmod>2026-06-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-powershell-module-via-ps-module</loc>
    <lastmod>2026-06-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/office-application-initiated-network-connection-over-unusual-ports-via-network-connection</loc>
    <lastmod>2026-06-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-created-by-arcsoc-exe-via-file-event</loc>
    <lastmod>2026-06-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-replay-attack-detected-via-security</loc>
    <lastmod>2026-06-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-azure-container-registry-created-or-deleted-via-activitylogs</loc>
    <lastmod>2026-06-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-outlook-today-page-via-registry-set</loc>
    <lastmod>2026-06-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uefi-persistence-through-wpbbin-processcreation-via-process-creation</loc>
    <lastmod>2026-06-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-defender-manipulation-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-06-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-sysinternals-utilities-via-process-creation</loc>
    <lastmod>2026-06-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-office-document-executed-from-trusted-location-via-process-creation</loc>
    <lastmod>2026-06-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-structure-export-through-ldifde-exe-via-process-creation</loc>
    <lastmod>2026-06-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-conhost-exe-via-process-creation</loc>
    <lastmod>2026-06-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-grantedaccess-flags-on-lsass-via-process-access</loc>
    <lastmod>2026-06-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-teams-sensitive-file-access-by-unusual-applications-via-file-access</loc>
    <lastmod>2026-06-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-malware-user-agent-via-proxy</loc>
    <lastmod>2026-06-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-changes-to-device-registration-policy-via-auditlogs</loc>
    <lastmod>2026-06-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-proxy-execution-through-vshadow-via-process-creation</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-query-of-machineguid-via-process-creation</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-mspub-exe-via-process-creation</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-msi-download-through-devinit-exe-via-process-creation</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-with-suspicious-extension-downloaded-through-bitsadmin-via-process-creation</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-adplus-exe-misuse-via-process-creation</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-poshmodule-via-ps-module</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmiprvse-wbemcomn-dll-hijack-via-image-load</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-volume-shadow-copy-vssapi-dll-load-via-image-load</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-diagnostic-library-sdiageng-dll-loaded-by-msdt-exe-via-image-load</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/load-of-rstrtmgr-dll-by-a-suspicious-process-via-image-load</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rare-remote-thread-creation-by-unusual-source-image-via-create-remote-thread</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-outgoing-logon-with-new-credentials-via-security</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-source-code-enumeration-detection-by-keyword-via-webserver</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-query-with-b64-encoded-string-via-dns</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-jxa-in-memory-execution-through-osascript-via-process-creation</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-via-process-creation</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-malware-callback-traffic-linux-via-network-connection</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-user-session-start-through-an-anonymising-proxy-service-via-okta</loc>
    <lastmod>2026-06-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-through-wer-via-process-creation</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-stdin-launcher-via-process-creation</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmd-exe-missing-space-characters-execution-anomaly-via-process-creation</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-io-filestream-via-ps-script</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rcdll-dll-sideloading-via-image-load</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-profile-change-via-file-event</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-search-order-hijackig-through-additional-space-in-path-via-file-event</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netsupport-manager-service-install-via-system</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-clip-system-via-system</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-put-io-dns-client-via-dns-client</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-telegram-bot-api-request-via-dns</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-root-account-enable-through-dsenableroot-via-process-creation</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-execution-error-in-jvm-based-application-via-application</loc>
    <lastmod>2026-06-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/add-possible-suspicious-new-download-source-to-winget-via-process-creation</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-process-of-vscode-via-process-creation</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-loaded-module-enumeration-through-tasklist-exe-via-process-creation</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-diskshadow-script-mode-uncommon-script-extension-execution-via-process-creation</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-executed-from-headless-conhost-process-via-process-creation</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-calculator-use-via-process-creation</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-exclusions-added-powershell-via-ps-script</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-smtp-connections-via-network-connection</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/system-control-panel-item-loaded-from-unusual-location-via-image-load</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-devtunnels-domain-via-dns-query</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntlm-brute-force-via-ntlm</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-screen-capture-macos-via-process-creation</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-payload-decoded-and-decrypted-through-built-in-utilities-via-process-creation</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-roles-are-not-being-used-via-pim</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-firewall-rule-configuration-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-ssh-new-connection-attempt-via-application</loc>
    <lastmod>2026-06-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-recall-feature-enabled-registry-via-registry-set</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-exclusions-added-registry-via-registry-set</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmiprvse-child-process-via-process-creation</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmic-execution-through-office-process-via-process-creation</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shimcache-flush-via-process-creation</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-encryption-decryption-through-gpg4win-from-suspicious-locations-via-process-creation</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-capture-session-launched-through-dxcap-exe-via-process-creation</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-file-download-through-desktopimgdownldr-utility-via-process-creation</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-volume-shadow-copies-through-wmi-with-powershell-ps-script-via-ps-script</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-alternate-powershell-hosts-powershell-module-via-ps-module</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-coercedpotato-named-pipe-creation-via-pipe-created</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-service-deployment-via-system</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-behavior-via-security</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/petitpotam-suspicious-kerberos-tgt-request-via-security</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mimikatz-dc-sync-via-security</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-access-token-misuse-via-security</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-user-group-modified-via-event</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-container-enumeration-through-inodes-listing-via-process-creation</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-aws-bedrock-guardrail-via-cloudtrail</loc>
    <lastmod>2026-06-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-user-account-associated-with-the-fax-service-via-registry-set</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-exchange-powershell-snap-ins-use-via-process-creation</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-msi-install-through-windowsinstaller-com-from-remote-location-via-process-creation</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mshta-execution-with-suspicious-file-extensions-via-process-creation</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-dns-exe-via-process-creation</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-cloudflared-quick-tunnel-via-process-creation</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-testing-use-of-uncommonly-used-port-via-ps-script</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windowsoptionalfeature-command-powershell-via-ps-script</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-monitor-driver-creation-by-non-sysinternals-binary-via-file-event</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-creation-behavior-from-fake-recycle-bin-folder-via-file-event</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-new-custom-shim-database-via-file-event</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-powershell-console-history-logs-via-file-delete</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-etw-logging-disabled-in-net-processes-registry-via-security</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kaspersky-endpoint-security-stopped-through-commandline-linux-via-process-creation</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-new-okta-user-via-okta</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sign-ins-from-non-compliant-devices-via-signinlogs</loc>
    <lastmod>2026-06-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-file-executable-creation-detected-via-sysmon</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-com-object-hijacking-through-change-of-default-system-clsid-default-value-via-registry-set</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-winapi-calls-through-commandline-via-process-creation</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-from-outlook-temporary-folder-via-process-creation</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arcsoc-exe-child-process-via-process-creation</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-zip-a-folder-with-powershell-for-staging-in-temp-powershell-script-via-ps-script</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-python-dll-sideloading-via-image-load</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-binaries-write-suspicious-extensions-via-file-event</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-powershell-module-file-via-file-event</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-files-with-system-process-name-in-unsuspected-locations-via-file-event</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-desktop-connection-to-non-domain-host-via-ntlm</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remove-exported-mailbox-from-exchange-webserver-via-msexchange-management</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-from-webdav-via-http</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-change-user-agents-linux-via-process-creation</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-workspace-out-of-domain-email-forwarding-via-google-workspace-login</loc>
    <lastmod>2026-06-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-lm-hash-storage-via-registry-set</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-process-created-through-taskmgr-exe-via-process-creation</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-userinit-child-process-via-process-creation</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-schtasks-schedule-type-with-high-privileges-via-process-creation</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-memory-dump-through-comsvcs-dll-via-process-creation</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mavinject-inject-dll-into-running-process-via-process-creation</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-git-clone-via-process-creation</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-cabinet-file-expansion-via-process-creation</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-openedr-spawning-command-shell-via-process-creation</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-browser-process-through-inline-url-via-process-creation</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-wmi-persistence-via-ps-script</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-non-existent-dlls-from-system-folders-via-image-load</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pdf-file-created-by-regedit-exe-via-file-event</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-services-have-been-installed-security-via-security</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-register-new-logon-process-by-rubeus-via-security</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dns-txt-answer-with-possible-execution-strings-via-dns</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-identity-center-identity-provider-change-via-cloudtrail</loc>
    <lastmod>2026-06-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enabling-cor-profiler-environment-variables-via-registry-set</loc>
    <lastmod>2026-06-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-verclsid-exe-runs-com-object-via-process-creation</loc>
    <lastmod>2026-06-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-renamed-rundll32-via-process-creation</loc>
    <lastmod>2026-06-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invocations-specific-processcreation-via-process-creation</loc>
    <lastmod>2026-06-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-obfuscation-through-reversed-commands-via-process-creation</loc>
    <lastmod>2026-06-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-openconsole-via-process-creation</loc>
    <lastmod>2026-06-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-gmer-rootkit-detector-and-remover-execution-via-process-creation</loc>
    <lastmod>2026-06-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remotefxvgpudisablement-exe-misuse-powershell-scriptblock-via-ps-script</loc>
    <lastmod>2026-06-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-winget-package-deployment-via-create-stream-hash</loc>
    <lastmod>2026-06-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wab-execution-from-non-default-location-via-process-creation</loc>
    <lastmod>2026-06-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-phishing-pattern-iso-in-archive-via-process-creation</loc>
    <lastmod>2026-06-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modify-group-policy-settings-via-process-creation</loc>
    <lastmod>2026-06-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rebuild-performance-counter-values-through-lodctr-exe-via-process-creation</loc>
    <lastmod>2026-06-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sysmoneop-execution-via-process-creation</loc>
    <lastmod>2026-06-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-smadhook-dll-sideloading-via-image-load</loc>
    <lastmod>2026-06-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-ufile-io-via-dns-query</loc>
    <lastmod>2026-06-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/service-installed-by-unusual-client-security-via-security</loc>
    <lastmod>2026-06-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-esxi-storage-information-enumeration-through-esxcli-via-process-creation</loc>
    <lastmod>2026-06-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-audit-log-configuration-updated-via-audit</loc>
    <lastmod>2026-06-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-sensitive-settings-changed-via-registry-set</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-root-or-ca-or-authroot-certificate-to-store-via-registry-set</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wow6432node-classes-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-amsi-provider-registry-keys-via-registry-delete</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/wlrmdr-exe-unusual-argument-or-child-process-via-process-creation</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tscon-start-as-system-via-process-creation</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-shutdown-to-log-out-via-process-creation</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-megasync-via-process-creation</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-restic-backup-tool-execution-via-process-creation</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-appx-deployment-attempt-via-add-appxpackage-via-process-creation</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-use-of-pcalua-for-via-process-creation</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-through-certoc-exe-via-process-creation</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-amsi-bypass-script-via-null-bits-via-ps-script</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-csexec-default-named-pipe-via-pipe-created</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-traffic-to-ngrok-tunneling-service-initiated-via-network-connection</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/abusable-dll-possible-sideloading-from-suspicious-location-via-image-load</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-startup-shortcut-persistence-through-powershell-exe-via-file-event</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-code-injection-by-ld-so-preload-via-linux</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-or-folder-permissions-change-via-auditd</loc>
    <lastmod>2026-06-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-change-for-oci-dll-redirection-via-registry-set</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cscript-wscript-potentially-suspicious-child-process-via-process-creation</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-shell-scripting-processes-spawning-suspicious-programs-via-process-creation</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-scheduled-task-creation-through-schtasks-exe-via-process-creation</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-spawning-explorer-via-process-creation</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gzip-archive-decode-through-powershell-via-process-creation</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-excel-exe-dcom-lateral-movement-through-activatemicrosoftapp-via-process-creation</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-diantz-alternate-data-stream-via-process-creation</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-webserver-log-removal-through-commandline-utilities-via-process-creation</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-binary-proxy-execution-through-dotnet-trace-exe-via-process-creation</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-call-to-win32-nteventlogfile-class-psscript-via-ps-script</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-veeam-backup-servers-credential-dumping-script-via-ps-script</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-decompress-commands-via-ps-module</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-shelldispatch-dll-sideloading-via-image-load</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-amsi-dll-loaded-through-lolbin-process-via-image-load</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-firewall-settings-have-been-changed-via-firewall-as</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-jamf-mdm-via-process-creation</loc>
    <lastmod>2026-06-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-encoded-scripts-in-a-wmi-consumer-via-wmi-event</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-unquoted-service-path-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-product-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-process-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vmtoolsd-suspicious-child-process-via-process-creation</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-response-file-execution-through-odbcconf-exe-via-process-creation</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-agent-skills-deployment-attempt-through-node-exe-via-process-creation</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-hh-exe-via-process-creation</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-direct-syscall-of-ntopenprocess-via-process-access</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-troubleshooting-pack-cmdlet-via-ps-script</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-dnsexfiltration-via-ps-script</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-files-in-default-gpo-folder-via-file-event</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-removal-of-its-own-executable-via-file-delete</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-scripts-installed-as-services-security-via-security</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msexchange-transport-agent-deployment-builtin-via-msexchange-management</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-the-windows-defender-firewall-service-failed-to-load-group-policy-via-firewall-as</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/osacompile-execution-by-potentially-suspicious-applet-osascript-via-process-creation</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-cron-task-job-macos-via-process-creation</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-security-software-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-device-registration-or-join-without-mfa-via-signinlogs</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-iam-s3browser-user-or-accesskey-creation-via-cloudtrail</loc>
    <lastmod>2026-06-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-network-sniffing-behavior-via-network-utilities-via-process-creation</loc>
    <lastmod>2026-06-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-executing-payload-from-registry-via-process-creation</loc>
    <lastmod>2026-06-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-remote-utilities-rat-rurat-via-process-creation</loc>
    <lastmod>2026-06-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-soaphound-execution-via-process-creation</loc>
    <lastmod>2026-06-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-event-logging-disabled-through-minint-registry-key-process-via-process-creation</loc>
    <lastmod>2026-06-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-localaccount-manipulation-via-ps-script</loc>
    <lastmod>2026-06-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dll-load-by-system-process-from-suspicious-locations-via-image-load</loc>
    <lastmod>2026-06-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-binary-or-script-dropper-through-powershell-via-file-event</loc>
    <lastmod>2026-06-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-indicator-removal-on-host-clear-mac-system-logs-via-process-creation</loc>
    <lastmod>2026-06-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-package-installed-linux-via-process-creation</loc>
    <lastmod>2026-06-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-stale-accounts-in-a-privileged-role-via-pim</loc>
    <lastmod>2026-06-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rdp-session-hijacking-behavior-via-process-creation</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-java-running-with-remote-debugging-via-process-creation</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-fake-instance-of-hxtsr-exe-via-process-creation</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpchisel-execution-via-process-creation</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-malware-callback-traffic-via-network-connection</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-internet-connection-via-network-connection</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ccleanerreactivator-dll-sideloading-via-image-load</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-screenconnect-temporary-deployment-artefact-via-file-event</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-with-unusual-extension-created-by-an-office-application-via-file-event</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-creation-in-suspicious-directory-by-msdt-exe-via-file-event</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-removal-of-previously-installed-iis-module-was-via-iis-configuration</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-appx-located-in-known-staging-directory-added-to-deployment-pipeline-via-appxdeployment-server</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-a-local-user-account-via-process-creation</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-hidden-files-and-directories-via-auditd</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-vpn-tunnel-modified-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-ad-account-credential-leaked-via-riskdetection</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-iam-s3browser-templated-s3-bucket-policy-creation-via-cloudtrail</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-bedrock-guardrail-updated-via-cloudtrail</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-github-outside-collaborator-detected-via-audit</loc>
    <lastmod>2026-06-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-code-execute-through-winrm-vbs-via-process-creation</loc>
    <lastmod>2026-06-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-rundll32-installscreensaver-via-process-creation</loc>
    <lastmod>2026-06-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nmap-zenmap-execution-via-process-creation</loc>
    <lastmod>2026-06-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-dmsa-service-account-created-in-specific-ous-via-process-creation</loc>
    <lastmod>2026-06-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-execute-batch-script-via-ps-script</loc>
    <lastmod>2026-06-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-created-through-onenote-application-via-file-event</loc>
    <lastmod>2026-06-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-or-unencrypted-smb-connection-to-share-established-via-smbserver-connectivity</loc>
    <lastmod>2026-06-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-service-behavior-through-svcctl-named-pipe-via-security</loc>
    <lastmod>2026-06-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-first-time-seen-remote-named-pipe-via-security</loc>
    <lastmod>2026-06-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-rundll32-security-via-security</loc>
    <lastmod>2026-06-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-multifactor-authentication-denied-via-signinlogs</loc>
    <lastmod>2026-06-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-common-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-execution-from-parent-process-in-public-folder-via-process-creation</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-proxy-execution-through-squirrel-exe-via-process-creation</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/veeam-backup-database-suspicious-query-via-process-creation</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-paexec-via-process-creation</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-email-exifiltration-through-powershell-via-process-creation</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unblock-file-via-ps-script</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gpo-enumeration-with-get-gpo-via-ps-script</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/livekd-driver-creation-by-unusual-process-via-file-event</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-extension-spoofing-via-right-to-left-override-via-file-event</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-via-security</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-to-sensitive-file-extensions-zeek-via-smb-files</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-log-entries-via-linux</loc>
    <lastmod>2026-06-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-userinit-child-process-via-process-creation</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scripting-commandline-process-spawned-regsvr32-via-process-creation</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-through-typedpaths-commandline-via-process-creation</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-function-execution-security-warning-disabled-in-excel-via-process-creation</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-pingcastle-execution-from-potentially-suspicious-parent-via-process-creation</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-powershell-script-execution-from-temp-folder-via-process-creation</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tamper-windows-defender-remove-mppreference-via-process-creation</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-dinjector-powershell-cradle-execution-via-process-creation</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-github-self-hosted-runner-via-process-creation</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-encoded-to-base64-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-computer-enumeration-and-export-through-get-adcomputer-cmdlet-powershell-via-ps-script</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/awl-bypass-with-winrm-vbs-and-malicious-wsmpty-xsl-wsmtxt-xsl-file-via-file-event</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-compress-obfuscation-system-via-system</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-persistence-security-via-security</loc>
    <lastmod>2026-06-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-uac-notification-via-registry-set</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-space-characters-in-typedpaths-registry-path-filefix-via-registry-set</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-com-hijack-through-sdclt-via-registry-set</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-pingcastle-binary-via-process-creation</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-access-utility-netsupport-execution-from-unusual-location-via-process-creation</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-office-child-process-via-process-creation</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-read-contents-from-stdin-through-cmd-exe-via-process-creation</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dump-credentials-from-windows-credential-manager-with-powershell-via-ps-script</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uefi-persistence-through-wpbbin-filecreation-via-file-event</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-process-dump-artefact-in-crashdumps-folder-via-file-event</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-group-policy-misuse-for-privilege-addition-via-security</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-and-execution-at-scale-through-gpo-scheduled-task-via-security</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webshell-regeorg-detection-through-web-logs-via-webserver</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-print-history-file-contents-via-process-creation</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-team-viewer-session-started-on-linux-host-via-process-creation</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-network-policy-change-via-activitylogs</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-container-with-a-hostpath-mount-via-application</loc>
    <lastmod>2026-06-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-scrobj-dll-com-hijacking-via-registry-set</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-com-object-hijacking-through-treatas-subkey-registry-via-registry-set</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-hotfix-updates-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-behavior-through-emoji-use-in-commandline-3-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copy-from-or-to-system-directory-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-commandline-obfuscation-via-escape-characters-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-execution-through-register-cimprovider-exe-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-child-process-from-outlook-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-rule-update-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-javascript-execution-through-mshta-exe-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-edr-freeze-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-dirlister-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-defaultpack-exe-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-from-file-sharing-website-through-bitsadmin-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-by-addinutil-exe-via-network-connection</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-through-vmware-xfer-via-image-load</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-renamed-comsvcs-dll-loaded-by-rundll32-via-image-load</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-livekd-kernel-memory-dump-file-via-file-event</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rottenpotato-like-attack-pattern-via-security</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mssql-server-failed-logon-from-external-network-via-application</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rclone-behavior-through-proxy-via-proxy</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/download-from-suspicious-tld-whitelist-via-proxy</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-nohup-via-process-creation</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-full-network-traffic-packet-capture-via-gcp-audit</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-google-cloud-storage-buckets-enumeration-via-gcp-audit</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-aws-ec2-disable-ebs-encryption-via-cloudtrail</loc>
    <lastmod>2026-05-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-atbroker-registry-change-via-registry-event</loc>
    <lastmod>2026-05-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-backup-deleted-through-wbadmin-exe-via-process-creation</loc>
    <lastmod>2026-05-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-recall-feature-enabled-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-05-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-icmp-exfiltration-via-ps-script</loc>
    <lastmod>2026-05-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dotnet-clr-use-log-artifact-via-file-event</loc>
    <lastmod>2026-05-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-gcc-linux-via-process-creation</loc>
    <lastmod>2026-05-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-and-directory-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-05-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-okta-identity-provider-via-okta</loc>
    <lastmod>2026-05-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-persistence-through-service-in-safe-mode-via-registry-set</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-runmru-registry-key-removal-registry-via-registry-delete</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-sysinternals-pssuspend-via-process-creation</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-powershell-search-order-hijacking-task-via-process-creation</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mshtml-dll-runhtmlapplication-suspicious-use-via-process-creation</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-cloudflared-exe-via-process-creation</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-exported-through-powershell-via-process-creation</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wscript-shell-run-in-commandline-via-process-creation</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powerview-add-domainobjectacl-dcsync-ad-extend-right-via-security</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-f5-big-ip-icontrol-rest-api-command-webserver-via-webserver</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-launch-agent-daemon-execution-through-launchctl-via-process-creation</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-crypto-mining-indicators-via-process-creation</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-added-credentials-to-existing-application-via-auditlogs</loc>
    <lastmod>2026-05-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysvol-domain-group-policy-access-via-process-creation</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-program-names-via-process-creation</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-access-utility-rurat-execution-from-unusual-location-via-process-creation</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-export-of-third-party-credentials-via-process-creation</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rar-use-with-password-and-compression-level-via-process-creation</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/fsutil-suspicious-invocation-via-process-creation</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-root-certificate-installed-through-certmgr-exe-via-process-creation</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sysmonente-execution-via-process-access</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ad-groups-or-users-enumeration-via-powershell-poshmodule-via-ps-module</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-dbgmodel-dll-via-image-load</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-idiagnostic-profile-file-via-file-event</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-scripts-filecreation-via-file-event</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-impacket-file-indicators-via-file-event</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-php-reverse-shell-via-process-creation</loc>
    <lastmod>2026-05-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-short-name-path-in-image-via-process-creation</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-base64-mz-header-in-commandline-via-process-creation</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pua-fast-reverse-proxy-frp-via-process-creation</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mmc20-lateral-movement-via-process-creation</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-import-ldap-data-interchange-format-file-through-ldifde-exe-via-process-creation</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-information-for-smb-share-powershell-module-via-ps-module</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-powershell-session-ps-classic-via-ps-classic-start</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-legitimate-application-dropped-executable-via-file-event</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-binary-writes-through-anydesk-via-file-event</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-azurewebsites-net-by-non-browser-process-via-dns-query</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-xterm-reverse-shell-via-process-creation</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-multi-factor-authentication-via-audit</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-virtual-network-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-s3-bucket-versioning-disable-via-cloudtrail</loc>
    <lastmod>2026-05-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bypass-uac-through-wsreset-exe-via-process-creation</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-ntfs-reparse-point-process-via-process-creation</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-recursive-takeown-via-process-creation</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-exports-registry-key-to-a-file-via-process-creation</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/reg-add-suspicious-paths-via-process-creation</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-files-added-to-an-archive-via-rar-exe-via-process-creation</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-token-obfuscation-process-creation-via-process-creation</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-provided-in-command-line-of-net-exe-via-process-creation</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpview-execution-via-process-creation</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobaltstrike-load-by-rundll32-via-process-creation</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-local-email-collection-via-ps-script</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-antivirus-software-dll-sideloading-via-image-load</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-adexplorer-writing-complete-ad-snapshot-into-dat-file-via-file-event</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-csexec-service-file-creation-via-file-event</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-attempt-through-powershell-remote-thread-via-create-remote-thread</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-stdin-system-via-system</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-protected-zip-file-opened-via-security</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/flash-player-update-from-suspicious-location-via-proxy</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-disabling-logging-via-aaa</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-invocation-through-ssh-linux-via-process-creation</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-through-nice-linux-via-process-creation</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-365-impossible-travel-activity-via-threat-management</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-applications-that-are-via-ropc-authentication-flow-via-signinlogs</loc>
    <lastmod>2026-05-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-regasm-exe-execution-without-commandline-flags-or-files-via-process-creation</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-screensave-change-by-reg-exe-via-process-creation</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powercfg-execution-to-change-lock-screen-timeout-via-process-creation</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-xsl-execution-through-msxsl-exe-via-process-creation</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpldapwhoami-execution-via-process-creation</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-iviewers-dll-sideloading-via-image-load</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dpapi-backup-keys-and-certificate-export-behavior-ioc-via-file-event</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-deleted-through-sysinternals-sdelete-via-file-delete</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-thread-creation-by-unusual-source-image-via-create-remote-thread</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-vssaudit-security-event-source-registration-via-security</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-behavior-via-find-macos-via-process-creation</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-security-utilities-builtin-via-syslog</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-relevant-clamav-message-via-clamav</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-legacy-authentication-protocols-via-signinlogs</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-saml-provider-removal-behavior-via-cloudtrail</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-kubernetes-events-via-application</loc>
    <lastmod>2026-05-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-com-object-execution-through-xwizard-exe-via-process-creation</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-persistence-script-event-consumer-via-process-creation</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-raccine-uninstall-via-process-creation</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/sdiagnhost-calling-suspicious-child-process-via-process-creation</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-manipulation-with-rdp-related-registry-keys-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-grpconv-via-process-creation</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-set-acl-on-windows-folder-psscript-via-ps-script</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-to-ip-lookup-service-apis-via-network-connection</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-jli-dll-side-loading-via-image-load</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-gathernetworkinfo-vbs-recon-script-output-via-file-event</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-weak-encryption-enabled-and-kerberoast-via-security</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-screenconnect-command-execution-via-application</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-time-attribute-change-via-process-creation</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-an-user-account-via-auditd</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-virtual-network-device-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-network-firewall-policy-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-efs-fileshare-mount-modified-or-deleted-via-cloudtrail</loc>
    <lastmod>2026-05-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lolbas-onedrivestandaloneupdater-exe-proxy-download-via-registry-set</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-new-download-source-to-winget-via-process-creation</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-write-protect-for-storage-via-process-creation</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-base64-encoded-invoke-keyword-via-process-creation</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pktmon-exe-via-process-creation</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-extrac32-alternate-data-stream-via-process-creation</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-trace-etw-session-tamper-through-logman-exe-via-process-creation</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-clip-launcher-via-process-creation</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-writing-local-admin-share-via-file-event</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-binaries-and-scripts-in-public-folder-via-file-event</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-defender-real-time-protection-via-windefend</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-external-remote-rdp-logon-from-public-ip-via-security</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-proxylogon-msexchange-oabvirtualdirectory-via-msexchange-management</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cross-site-scripting-strings-via-webserver</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-through-nscurl-macos-via-process-creation</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-unauthorized-access-to-a-resource-via-audit</loc>
    <lastmod>2026-05-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-attachment-manager-settings-associations-tamper-via-registry-set</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-set-to-never-expire-through-wmi-via-process-creation</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-consent-and-comctl32-process-via-process-creation</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-powershell-in-link-file-pattern-via-process-creation</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-folder-exclusion-added-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-volume-shadow-copy-vsstrace-dll-load-via-image-load</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-request-by-regsvr32-exe-via-dns-query</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-defender-virus-scanning-feature-via-windefend</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-system-via-system</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-dumper-behavior-on-lsass-via-security</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-default-cobalt-strike-certificate-via-x509</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-git-clone-linux-via-process-creation</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-kubernetes-secrets-enumeration-via-application</loc>
    <lastmod>2026-05-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-dll-of-choice-via-wab-exe-via-registry-set</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-signing-bypass-through-windows-developer-features-registry-via-registry-set</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wow6432node-currentversion-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-chopper-webshell-process-pattern-via-process-creation</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-permission-check-through-accesschk-exe-via-process-creation</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-processes-of-sndvol-exe-via-process-creation</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-adfind-via-process-creation</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-webrequest-execution-with-directip-via-process-creation</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mstsc-exe-execution-with-local-rdp-file-via-process-creation</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-driver-install-by-pnputil-exe-via-process-creation</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-data-copied-to-clipboard-through-clip-exe-via-process-creation</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-7zip-compressing-dump-files-via-process-creation</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-unconstrained-delegation-enumeration-through-get-adcomputer-scriptblock-via-ps-script</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-packet-capture-behavior-through-start-neteventsession-scriptblock-via-ps-script</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-roboform-dll-sideloading-via-image-load</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-mpsvc-dll-via-image-load</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-through-classicexplorer32-dll-via-image-load</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-exclusions-added-via-windefend</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-services-have-been-installed-system-via-system</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-important-windows-event-auditing-via-security</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-replication-from-non-machine-account-via-security</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-filename-with-embedded-base64-commands-via-file-event</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-inbox-forwarding-identity-protection-via-riskdetection</loc>
    <lastmod>2026-05-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scripting-in-a-wmi-consumer-via-wmi-event</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-persistence-through-explorer-run-key-via-registry-set</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-logon-scripts-registry-via-registry-set</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-disable-system-restore-via-registry-set</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-serv-u-process-pattern-via-process-creation</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-advancedrun-execution-via-process-creation</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-script-proxy-execution-through-cl-mutexverifiers-ps1-via-process-creation</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-mimikatz-execution-via-process-creation</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-ntfs-symlink-behavior-change-via-process-creation</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-syncappvpublishingserver-execution-to-bypass-powershell-restriction-via-ps-script</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-sideloading-of-shellchromeapi-dll-via-image-load</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-a-member-was-removed-from-a-security-enabled-global-group-via-security</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-defender-firewall-has-been-reset-to-its-default-configuration-via-firewall-as</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-advanced-ip-port-scanner-update-check-via-proxy</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-cisco-dot1x-via-aaa</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-file-exclusion-added-to-time-machine-through-tmutil-macos-via-process-creation</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/download-file-to-potentially-suspicious-directory-through-wget-via-process-creation</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-user-account-locked-out-via-okta</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-policy-rule-modified-or-deleted-via-okta</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-okta-admin-role-assignment-via-okta</loc>
    <lastmod>2026-05-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-logging-disabled-through-registry-key-manipulation-via-registry-set</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-hardware-model-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-behavior-invoking-sys-file-via-process-creation</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-shellexec-rundll-via-process-creation</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-zoho-dctask64-via-process-creation</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ie-zonemap-setting-downgraded-to-mycomputer-zone-for-http-protocols-through-cli-via-process-creation</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-active-directory-diagnostic-utility-ntdsutil-exe-via-process-creation</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-downloaded-from-direct-ip-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-memory-dump-through-comsvcs-dll-via-process-access</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-sensitive-file-enumeration-via-ps-script</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-to-azurewebsites-net-by-non-browser-process-via-network-connection</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-vivaldi-elf-dll-sideloading-via-image-load</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-script-dropped-through-powershell-exe-via-file-event</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dll-file-dropped-in-the-teams-or-onedrive-folder-via-file-event</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-secure-removal-with-sdelete-via-security</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ntlm-logon-via-ntlm</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-invocation-through-env-command-linux-via-process-creation</loc>
    <lastmod>2026-05-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vsls-agent-command-with-agentextensionpath-load-via-process-creation</loc>
    <lastmod>2026-05-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/schedule-task-creation-from-env-variable-or-potentially-suspicious-path-through-schtasks-exe-via-process-creation</loc>
    <lastmod>2026-05-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-recovery-environment-disabled-through-reagentc-via-process-creation</loc>
    <lastmod>2026-05-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msiexec-web-install-via-process-creation</loc>
    <lastmod>2026-05-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-memory-dump-through-dotnet-dump-via-process-creation</loc>
    <lastmod>2026-05-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-process-of-clickonce-application-via-process-creation</loc>
    <lastmod>2026-05-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-compress-obfuscation-powershell-module-via-ps-module</loc>
    <lastmod>2026-05-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-variable-exe-creation-via-file-event</loc>
    <lastmod>2026-05-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-attempt-through-errorhandler-cmd-via-file-event</loc>
    <lastmod>2026-05-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-bitbucket-global-secret-scanning-rule-via-audit</loc>
    <lastmod>2026-05-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-antivirus-filter-driver-disallowed-on-dev-drive-registry-via-registry-set</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-internet-explorer-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-process-hollowing-behavior-via-process-tampering</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kernel-memory-dump-through-livekd-via-process-creation</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-runas-like-flag-combination-via-process-creation</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-office-binary-via-process-creation</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-script-run-in-appdata-via-process-creation</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-sticky-key-like-backdoor-via-process-creation</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-diagtrackeop-default-named-pipe-via-pipe-created</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/scheduled-task-executed-from-a-suspicious-location-via-taskscheduler</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-pdqdeploy-service-server-side-via-system</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-krbrelayup-service-deployment-via-system</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-empire-useragent-uri-combo-via-proxy</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cisco-stage-data-via-aaa</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-inline-python-spawn-shell-via-os-system-library-via-process-creation</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-equation-group-indicators-via-linux</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-systemd-service-creation-via-auditd</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-application-modified-or-deleted-via-okta</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-application-gateway-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-antivirus-remote-access-tools-signature-via-antivirus</loc>
    <lastmod>2026-05-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-odbc-driver-registered-via-registry-set</loc>
    <lastmod>2026-05-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/registry-manipulation-by-potentially-suspicious-processes-via-registry-event</loc>
    <lastmod>2026-05-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-visual-studio-code-tunnel-shell-via-process-creation</loc>
    <lastmod>2026-05-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-password-policy-enumeration-with-get-addefaultdomainpasswordpolicy-via-ps-script</loc>
    <lastmod>2026-05-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-wazuh-security-platform-dll-sideloading-via-image-load</loc>
    <lastmod>2026-05-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-download-from-direct-ip-address-via-create-stream-hash</loc>
    <lastmod>2026-05-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-no-suitable-encryption-key-found-for-generating-kerberos-ticket-via-system</loc>
    <lastmod>2026-05-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-psexec-zeek-via-smb-files</loc>
    <lastmod>2026-05-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-com-hijacking-through-treatas-via-registry-set</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-ieinstal-process-via-process-creation</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-allow-service-access-via-security-descriptor-manipulation-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-registry-key-manipulation-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dsinternals-suspicious-powershell-cmdlets-via-process-creation</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-execution-with-possible-decryption-capabilities-via-process-creation</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-chm-file-download-execution-through-hh-exe-via-process-creation</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-process-of-diskshadow-exe-via-process-creation</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-injection-through-acccheckconsole-via-process-creation</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-screen-capture-with-copyfromscreen-via-ps-script</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-rundll-launcher-security-via-security</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-osacompile-run-only-via-process-creation</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-triple-cross-ebpf-rootkit-default-lockfile-via-file-event</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-loading-of-kernel-module-through-insmod-via-auditd</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-okta-api-token-via-okta</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gcp-break-glass-container-workload-deployed-via-gcp-audit</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-firewall-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-aws-trufflehog-execution-via-cloudtrail</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-cronjob-job-change-via-audit</loc>
    <lastmod>2026-05-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sentinelone-shell-context-menu-scan-command-manipulation-via-registry-set</loc>
    <lastmod>2026-05-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bypass-uac-via-silentcleanup-task-via-registry-set</loc>
    <lastmod>2026-05-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remotefxvgpudisablement-misuse-through-atomictestharnesses-via-process-creation</loc>
    <lastmod>2026-05-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kerberos-ticket-request-through-powershell-script-scriptblock-via-ps-script</loc>
    <lastmod>2026-05-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-anydesk-incoming-connection-via-network-connection</loc>
    <lastmod>2026-05-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-created-by-notepad-updater-gup-exe-via-file-event</loc>
    <lastmod>2026-05-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-dmp-hdmp-file-creation-via-file-event</loc>
    <lastmod>2026-05-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enabled-user-right-in-ad-to-control-user-objects-via-security</loc>
    <lastmod>2026-05-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-reconnaissance-enumeration-through-ldap-via-ldap</loc>
    <lastmod>2026-05-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bits-transfer-job-with-unusual-or-suspicious-remote-tld-via-bits-client</loc>
    <lastmod>2026-05-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-network-service-scanning-auditd-via-auditd</loc>
    <lastmod>2026-05-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-cscript-wscript-unusual-script-extension-via-process-creation</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-by-web-server-process-via-process-creation</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-shell-command-execution-through-settingcontent-ms-via-process-creation</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-event-consumer-spawning-process-via-process-creation</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-procdump-via-process-creation</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-spawning-pretty-tty-on-windows-via-process-creation</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-aadinternals-powershell-cmdlets-proccesscreation-via-process-creation</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outlook-child-process-via-process-creation</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-vsiisexelauncher-exe-via-process-creation</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dllhost-exe-execution-anomaly-via-process-creation</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/command-line-execution-with-suspicious-url-and-appdata-strings-via-process-creation</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-access-through-malseclogon-via-process-access</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-get-process-lsass-in-scriptblock-via-ps-script</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-scripts-poshmodule-via-ps-module</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-as-rep-roasting-through-kerberos-tgt-requests-via-security</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-loading-diagcab-package-from-remote-path-via-diagnosis-scripted</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-anonymous-ip-address-via-riskdetection</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-network-route-added-via-cloudtrail</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-use-of-imds-credentials-outside-of-aws-infrastructure-via-cloudtrail</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-sip-request-via-application</loc>
    <lastmod>2026-05-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/awl-bypass-with-winrm-vbs-and-malicious-wsmpty-xsl-wsmtxt-xsl-via-process-creation</loc>
    <lastmod>2026-05-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lnk-command-line-padding-with-whitespace-characters-via-process-creation</loc>
    <lastmod>2026-05-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-setup16-exe-execution-with-custom-lst-file-via-process-creation</loc>
    <lastmod>2026-05-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-netsupport-execution-via-process-creation</loc>
    <lastmod>2026-05-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dropbox-api-use-via-network-connection</loc>
    <lastmod>2026-05-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-apache-segmentation-fault-via-apache</loc>
    <lastmod>2026-05-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-sniffing-via-aaa</loc>
    <lastmod>2026-05-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-decode-base64-encoded-text-macos-via-process-creation</loc>
    <lastmod>2026-05-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remove-immutable-file-attribute-via-process-creation</loc>
    <lastmod>2026-05-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-misuse-of-linux-magic-system-request-key-via-auditd</loc>
    <lastmod>2026-05-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-hide-function-from-user-via-registry-set</loc>
    <lastmod>2026-05-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-trustedpath-uac-bypass-pattern-via-process-creation</loc>
    <lastmod>2026-05-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-browsercore-exe-via-process-creation</loc>
    <lastmod>2026-05-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-manipulation-of-default-accounts-through-net-exe-via-process-creation</loc>
    <lastmod>2026-05-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-data-stealing-through-chromium-headless-debugging-via-process-creation</loc>
    <lastmod>2026-05-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-script-with-file-upload-capabilities-via-ps-script</loc>
    <lastmod>2026-05-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-traffic-initiated-to-portmap-io-domain-via-network-connection</loc>
    <lastmod>2026-05-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-thread-creation-through-powershell-in-unusual-target-via-create-remote-thread</loc>
    <lastmod>2026-05-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-kerberos-coercion-by-spoofing-spns-through-dns-manipulation-via-security</loc>
    <lastmod>2026-05-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-interpreter-spawning-credential-scanner-linux-via-process-creation</loc>
    <lastmod>2026-05-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/behavior-from-suspicious-ip-addresses-via-threat-detection</loc>
    <lastmod>2026-05-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-firewall-rule-collection-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-05-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-disk-cleanup-handler-registry-via-registry-add</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-proxy-execution-through-wuauclt-exe-via-process-creation</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-regsvr32-commandline-flag-anomaly-via-process-creation</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-change-from-ads-through-regini-exe-via-process-creation</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-user-enumeration-and-export-through-get-aduser-cmdlet-via-process-creation</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-process-injection-through-msra-exe-via-process-creation</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpldapmonitor-execution-via-process-creation</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-purplesharp-execution-via-process-creation</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dism-remove-online-package-via-process-creation</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-use-get-nettcpconnection-powershell-module-via-ps-module</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-dbgcore-dll-via-image-load</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scr-file-write-event-via-file-event</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dhcp-server-loaded-the-callout-dll-via-system</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scm-database-privileged-operation-via-security</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ruby-reverse-shell-via-process-creation</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-split-a-file-into-pieces-linux-via-auditd</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-sensitive-role-access-via-activitylogs</loc>
    <lastmod>2026-05-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-all-backups-deleted-through-wbadmin-exe-via-process-creation</loc>
    <lastmod>2026-05-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uninstall-crowdstrike-falcon-sensor-via-process-creation</loc>
    <lastmod>2026-05-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kerberos-ticket-request-through-cli-via-process-creation</loc>
    <lastmod>2026-05-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-for-cached-credentials-through-cmdkey-exe-via-process-creation</loc>
    <lastmod>2026-05-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ntlm-coercion-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-05-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-access-to-lsass-with-dbgcore-dbghelp-dlls-via-process-access</loc>
    <lastmod>2026-05-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-create-local-user-via-ps-script</loc>
    <lastmod>2026-05-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-ntfs-reparse-point-file-via-file-event</loc>
    <lastmod>2026-05-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msexchangemailboxreplication-aspx-write-via-file-event</loc>
    <lastmod>2026-05-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-disallowed-file-for-protected-processes-has-been-blocked-via-codeintegrity-operational</loc>
    <lastmod>2026-05-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitsadmin-to-unusual-tld-via-proxy</loc>
    <lastmod>2026-05-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-enable-or-disable-through-win32-terminalservicesetting-wmi-class-via-process-creation</loc>
    <lastmod>2026-05-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-chisel-tunneling-tool-execution-via-process-creation</loc>
    <lastmod>2026-05-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-x509enrollment-process-creation-via-process-creation</loc>
    <lastmod>2026-05-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-findstr-launching-lnk-file-via-process-creation</loc>
    <lastmod>2026-05-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-loaded-through-certoc-exe-via-process-creation</loc>
    <lastmod>2026-05-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-binary-proxy-execution-through-cdb-exe-via-process-creation</loc>
    <lastmod>2026-05-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-wow64-logger-dll-hijack-via-process-access</loc>
    <lastmod>2026-05-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-network-connection-to-public-ip-through-winlogon-via-network-connection</loc>
    <lastmod>2026-05-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aruba-network-service-possible-dll-sideloading-via-image-load</loc>
    <lastmod>2026-05-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-via-sw-vers-via-process-creation</loc>
    <lastmod>2026-05-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-end-user-consent-via-auditlogs</loc>
    <lastmod>2026-05-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-github-organization-member-added-via-audit</loc>
    <lastmod>2026-05-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-persistence-mechanisms-in-recycle-bin-via-registry-event</loc>
    <lastmod>2026-05-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-connection-to-active-directory-web-services-via-network-connection</loc>
    <lastmod>2026-05-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpevtmute-dll-load-via-image-load</loc>
    <lastmod>2026-05-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-ld-so-preload-via-auditd</loc>
    <lastmod>2026-05-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-clipboard-collection-with-xclip-utility-auditd-via-auditd</loc>
    <lastmod>2026-05-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-sql-exceptions-via-application</loc>
    <lastmod>2026-05-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-created-as-system-via-process-creation</loc>
    <lastmod>2026-05-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-always-install-elevated-windows-installer-via-process-creation</loc>
    <lastmod>2026-05-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-parent-process-via-process-creation</loc>
    <lastmod>2026-05-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mpclient-dll-sideloading-via-image-load</loc>
    <lastmod>2026-05-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-winnti-dropper-behavior-via-file-event</loc>
    <lastmod>2026-05-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-important-scheduled-task-deleted-disabled-via-security</loc>
    <lastmod>2026-05-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-ses-identity-has-been-via-cloudtrail</loc>
    <lastmod>2026-05-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-antivirus-hacktool-signature-via-antivirus</loc>
    <lastmod>2026-05-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-server-side-template-injection-in-velocity-via-application</loc>
    <lastmod>2026-05-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-http-get-request-via-application</loc>
    <lastmod>2026-05-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-open-registry-keys-manipulation-via-registry-event</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-psloglist-via-process-creation</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-adfind-suspicious-execution-via-process-creation</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-via-protocolhandler-exe-via-process-creation</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-windows-credential-editor-wce-via-process-creation</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hktl-sharpsuccessor-privilege-escalation-tool-execution-via-process-creation</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-safetykatz-execution-via-process-creation</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-addinutil-exe-via-process-creation</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-x509enrollment-ps-script-via-ps-script</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-eventlog-clear-via-ps-script</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-7za-dll-sideloading-via-image-load</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-assembly-dll-creation-through-aspnetcompiler-via-file-event</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-threat-detected-via-windefend</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unsigned-binary-loaded-from-suspicious-location-via-security-mitigations</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-agents-related-to-recon-utilities-via-webserver</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-in-memory-download-and-compile-of-payloads-via-process-creation</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-esxi-network-configuration-enumeration-through-esxcli-via-process-creation</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-steganography-unzip-hidden-information-from-picture-file-via-auditd</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-removed-from-group-with-ca-policy-change-access-via-auditlogs</loc>
    <lastmod>2026-05-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-terminal-service-process-spawn-via-process-creation</loc>
    <lastmod>2026-05-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-eventlog-clearing-or-configuration-change-behavior-via-process-creation</loc>
    <lastmod>2026-05-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-obfuscated-powershell-code-via-process-creation</loc>
    <lastmod>2026-05-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-hashcat-password-cracker-execution-via-process-creation</loc>
    <lastmod>2026-05-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-paexec-default-named-pipe-via-pipe-created</loc>
    <lastmod>2026-05-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rjvplatform-dll-sideloading-from-non-default-location-via-image-load</loc>
    <lastmod>2026-05-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-module-file-created-by-non-powershell-process-via-file-event</loc>
    <lastmod>2026-05-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dpapi-domain-master-key-backup-attempt-via-security</loc>
    <lastmod>2026-05-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-diagtrackeop-default-login-username-via-security</loc>
    <lastmod>2026-05-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/appx-located-in-unusual-directory-added-to-deployment-pipeline-via-appxdeployment-server</loc>
    <lastmod>2026-05-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-path-traversal-exploitation-attempts-via-webserver</loc>
    <lastmod>2026-05-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pnscan-binary-data-transmission-behavior-via-process-creation</loc>
    <lastmod>2026-05-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sqlite-firefox-profile-data-db-access-via-process-creation</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-invoking-inline-vbscript-via-process-creation</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-time-travel-debugging-utility-use-via-process-creation</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-volumeshadowcopy-symlink-creation-through-mklink-via-process-creation</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-extracting-information-with-powershell-via-ps-script</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-windows-console-history-via-ps-script</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rjvplatform-dll-sideloading-from-default-location-via-image-load</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-thread-created-in-keepass-exe-via-create-remote-thread</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-pdqdeploy-service-client-side-via-system</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mesh-agent-service-deployment-via-system</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-impacket-psexec-via-security</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-traffic-with-ipfs-via-proxy</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-time-machine-backup-disabled-through-tmutil-macos-via-process-creation</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pua-trufflehog-linux-via-process-creation</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sign-in-from-malware-infected-ip-via-riskdetection</loc>
    <lastmod>2026-05-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-in-registry-run-keys-via-registry-set</loc>
    <lastmod>2026-05-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-allowed-through-exploit-guard-via-registry-set</loc>
    <lastmod>2026-05-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-powershell-script-from-redirected-input-stream-via-process-creation</loc>
    <lastmod>2026-05-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hwp-sub-processes-via-process-creation</loc>
    <lastmod>2026-05-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpimpersonation-execution-via-process-creation</loc>
    <lastmod>2026-05-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-forfiles-exe-child-process-masquerading-via-process-creation</loc>
    <lastmod>2026-05-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-process-access-rights-for-target-image-via-process-access</loc>
    <lastmod>2026-05-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobaltstrike-named-pipe-via-pipe-created</loc>
    <lastmod>2026-05-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gotoassist-temporary-deployment-artefact-via-file-event</loc>
    <lastmod>2026-05-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hack-utility-user-agent-via-proxy</loc>
    <lastmod>2026-05-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-bpf-behavior-linux-via-linux</loc>
    <lastmod>2026-05-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-and-hardware-information-enumeration-via-auditd</loc>
    <lastmod>2026-05-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-register-app-vbs-lolscript-misuse-via-process-creation</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-zipexec-via-process-creation</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sliver-c2-implant-activity-pattern-via-process-creation</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-get-aduser-enumeration-via-useraccountcontrol-flags-via-ps-script</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-unsigned-thor-scanner-via-image-load</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-solidpdfcreator-dll-sideloading-via-image-load</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aspx-file-drop-by-exchange-via-file-event</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-mshta-system-via-system</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-webshell-strings-via-webserver</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-network-enumeration-macos-via-process-creation</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-perl-reverse-shell-via-process-creation</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-process-code-injection-through-dd-utility-via-process-creation</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-behavior-in-shell-commands-via-linux</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dcsync-attack-via-application</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-unauthorized-full-data-export-triggered-via-audit</loc>
    <lastmod>2026-05-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-register-new-ifiltre-for-persistence-via-registry-set</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-credential-manager-access-through-vaultcmd-via-process-creation</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-velociraptor-child-process-via-process-creation</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invocation-of-active-directory-diagnostic-utility-ntdsutil-exe-via-process-creation</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pubprn-vbs-proxy-via-process-creation</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execute-pcwrun-exe-to-leverage-follina-via-process-creation</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cloudflared-tunnel-connections-cleanup-via-process-creation</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-store-file-in-alternate-data-stream-via-ps-script</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-through-notepad-exe-via-network-connection</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-disabling-of-windows-defender-submit-sample-feature-via-windefend</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-exported-from-local-certificate-store-via-certificateservicesclient-lifecycle-system</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-kubernetes-cronjob-via-gcp-audit</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-dns-zone-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-loadbalancer-security-group-change-via-cloudtrail</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-nmap-null-scan-via-application</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-jndi-injection-exploitation-in-jvm-based-application-via-application</loc>
    <lastmod>2026-04-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-tacticalrmm-agent-registration-to-potentially-attacker-controlled-server-via-process-creation</loc>
    <lastmod>2026-04-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-dll-registered-through-odbcconf-exe-via-process-creation</loc>
    <lastmod>2026-04-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mstsc-shadowing-behavior-via-process-creation</loc>
    <lastmod>2026-04-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-jscript-compiler-via-process-creation</loc>
    <lastmod>2026-04-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-cloudflared-portable-via-process-creation</loc>
    <lastmod>2026-04-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/addinutil-exe-execution-from-unusual-directory-via-process-creation</loc>
    <lastmod>2026-04-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-rundll-launcher-system-via-system</loc>
    <lastmod>2026-04-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-external-disk-drive-or-usb-storage-device-was-recognized-by-the-system-via-security</loc>
    <lastmod>2026-04-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-file-upload-linux-via-process-creation</loc>
    <lastmod>2026-04-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-service-account-disabled-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-04-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xwizard-exe-execution-from-non-default-location-via-process-creation</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-sysinternals-pssuspend-suspicious-via-process-creation</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-start-of-nt-virtual-dos-machine-via-process-creation</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-for-3rd-party-creds-from-cli-via-process-creation</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-advancedrun-suspicious-execution-via-process-creation</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-powershell-script-from-ads-via-process-creation</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-netsh-helper-dll-via-process-creation</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-krbrelay-execution-via-process-creation</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-edrsilencer-execution-via-process-creation</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-and-subfolder-enumeration-through-dir-command-via-process-creation</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-network-connection-initiated-by-script-interpreter-via-network-connection</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-chrome-frame-helper-dll-sideloading-via-image-load</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cobalt-strike-dns-beaconing-sysmon-via-dns-query</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-access-from-non-system-account-via-security</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-network-security-configuration-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-cronjob-via-activitylogs</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-glue-development-endpoint-behavior-via-cloudtrail</loc>
    <lastmod>2026-04-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-internal-utilities-or-feature-in-registry-via-registry-set</loc>
    <lastmod>2026-04-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-product-class-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-04-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-from-office-domain-via-process-creation</loc>
    <lastmod>2026-04-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-commandlets-processcreation-via-process-creation</loc>
    <lastmod>2026-04-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-explorer-nouaccheck-flag-via-process-creation</loc>
    <lastmod>2026-04-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tamper-windows-defender-scriptblocklogging-via-ps-script</loc>
    <lastmod>2026-04-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-hotfix-enumeration-via-ps-script</loc>
    <lastmod>2026-04-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-locked-workstation-via-security</loc>
    <lastmod>2026-04-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-of-password-policy-via-security</loc>
    <lastmod>2026-04-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-spawning-pretty-tty-through-pty-module-via-process-creation</loc>
    <lastmod>2026-04-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wsl-kali-linux-use-via-process-creation</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-windows-media-player-process-via-process-creation</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-information-for-export-with-command-prompt-via-process-creation</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-presentationhost-exe-via-process-creation</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-non-powershell-wsman-com-provider-via-powershell-classic</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-netexec-file-indicators-via-file-event</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-file-creation-by-openedr-s-itsmservice-via-file-event</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-important-windows-service-terminated-unexpectedly-via-system</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-protected-zip-file-opened-email-attachment-via-security</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-failed-code-integrity-checks-via-security</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-bits-job-created-through-powershell-via-bits-client</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-has-been-deleted-through-userdel-via-process-creation</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-screen-capture-with-import-utility-via-auditd</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-capabilities-enumeration-via-auditd</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sign-in-failure-due-to-conditional-access-requirements-not-met-via-signinlogs</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-securityhub-findings-evasion-via-cloudtrail</loc>
    <lastmod>2026-04-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-office-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmiprvse-spawned-a-process-via-process-creation</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winrar-execution-in-non-standard-folder-via-process-creation</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-install-new-package-through-winget-local-manifest-via-process-creation</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ppl-manipulation-through-werfaultsecure-via-process-creation</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-service-creation-via-sc-exe-via-process-creation</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-screenconnect-remote-command-execution-via-process-creation</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-imports-registry-key-from-a-file-via-process-creation</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-findstr-gpp-passwords-via-process-creation</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-processes-spawned-by-conhost-via-process-creation</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-appvlp-exe-via-process-creation</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-item-from-mount-diskimage-via-ps-script</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-keyscramblerie-dll-through-keyscrambler-exe-via-image-load</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hijack-legit-rdp-session-to-move-laterally-via-file-event</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-process-memory-dump-files-via-file-event</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-ufile-io-dns-client-via-dns-client</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-c2-activities-via-auditd</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-subscription-permission-elevation-through-auditlogs-via-auditlogs</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-keyvault-key-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sharphound-recon-account-enumeration-via-application</loc>
    <lastmod>2026-04-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ransomware-behavior-via-legalnotice-message-via-registry-set</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-amsi-disabled-through-registry-change-via-registry-set</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-execution-through-dll-via-process-creation</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mpiexec-lolbin-via-process-creation</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-download-and-execute-combination-via-process-creation</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-directory-enumeration-via-ps-script</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-keylogging-via-ps-script</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-stdin-launcher-powershell-via-ps-script</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-create-scheduled-task-via-ps-script</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-trusted-path-bypass-through-windows-directory-spoofing-via-image-load</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/notepad-updater-dns-query-to-unusual-domains-via-dns-query</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-digital-signature-of-appx-package-via-appxpackaging-om</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deployment-appx-package-was-blocked-by-applocker-via-appxdeployment-server</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-admin-group-through-dseditgroup-via-process-creation</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-change-to-sensitive-critical-files-via-process-creation</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-git-clone-request-via-application</loc>
    <lastmod>2026-04-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modify-user-shell-folders-startup-value-via-registry-set</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-desktop-background-change-through-registry-via-registry-set</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-nircmd-exe-via-process-creation</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-port-forwarding-rule-added-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-unmount-share-through-net-exe-via-process-creation</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-devcon-execution-disabling-vmware-vmci-device-via-process-creation</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-local-file-read-via-curl-exe-via-process-creation</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-powershell-session-initiated-via-network-connection</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deno-file-written-from-remote-source-via-file-event</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-removal-of-teamviewer-log-file-via-file-delete</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-process-hacker-driver-load-via-driver-load</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-obfuscation-security-via-security</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-history-file-operations-via-process-creation</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unfamiliar-sign-in-properties-via-riskdetection</loc>
    <lastmod>2026-04-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-non-privileged-use-of-reg-or-powershell-via-process-creation</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-through-stordiag-exe-via-process-creation</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-registry-key-deleted-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-webbrowserpassview-execution-via-process-creation</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-windows-msix-package-support-framework-ai-stubs-via-process-creation</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-hydra-password-bruteforce-execution-via-process-creation</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gpresult-display-group-policy-information-via-process-creation</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-ip-url-through-curl-exe-via-process-creation</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enumerate-credentials-from-windows-credential-manager-with-powershell-via-ps-script</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-com-objects-download-cradles-use-ps-script-via-ps-script</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-failed-logon-from-public-ip-via-security</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-macos-network-service-scanning-via-process-creation</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-linux-webshell-indicators-via-process-creation</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modifying-crontab-via-cron</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-exfiltration-with-wget-via-auditd</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-azure-domain-federation-settings-via-auditlogs</loc>
    <lastmod>2026-04-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-security-privileges-enumeration-through-whoami-exe-via-process-creation</loc>
    <lastmod>2026-04-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-webdav-client-execution-through-rundll32-exe-high-confidence-via-process-creation</loc>
    <lastmod>2026-04-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-encoded-powershell-patterns-in-commandline-via-process-creation</loc>
    <lastmod>2026-04-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-koadic-execution-via-process-creation</loc>
    <lastmod>2026-04-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-dumpert-process-dumper-default-file-via-file-event</loc>
    <lastmod>2026-04-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-restricted-software-access-by-srp-via-application</loc>
    <lastmod>2026-04-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-group-with-ca-policy-change-access-via-auditlogs</loc>
    <lastmod>2026-04-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-app-granted-privileged-delegated-or-app-permissions-via-auditlogs</loc>
    <lastmod>2026-04-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-secrets-modified-or-deleted-via-audit</loc>
    <lastmod>2026-04-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-werfault-reflectdebugger-registry-value-misuse-via-registry-set</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-custom-protocol-handler-via-registry-set</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-via-debugpath-via-registry-set</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-key-from-download-via-registry-event</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmstp-uac-bypass-through-com-object-access-via-process-creation</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-etw-logging-tamper-in-net-processes-through-commandline-via-process-creation</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-security-descriptor-manipulation-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-createdump-utility-via-process-creation</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-net-webclient-casing-anomalies-via-process-creation</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kernel-dump-via-dtrace-via-process-creation</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-behavior-via-driverquery-exe-via-process-creation</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-unusual-addinutil-exe-commandline-via-process-creation</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-local-groups-information-powershell-via-ps-script</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-change-of-dmsa-link-attributes-via-ps-script</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-by-eqnedt32-exe-via-network-connection</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cisco-enumeration-via-aaa</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-login-bypassing-conditional-access-policies-via-audit</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-azure-ad-only-single-factor-authentication-required-via-signinlogs</loc>
    <lastmod>2026-04-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-change-to-hidden-file-extension-via-registry-set</loc>
    <lastmod>2026-04-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-file-association-via-exefile-via-registry-set</loc>
    <lastmod>2026-04-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-registered-com-objects-via-process-creation</loc>
    <lastmod>2026-04-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nircmd-execution-via-process-creation</loc>
    <lastmod>2026-04-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-driver-dll-deployment-through-odbcconf-exe-uncommon-extension-via-process-creation</loc>
    <lastmod>2026-04-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-compress-obfuscation-via-process-creation</loc>
    <lastmod>2026-04-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-stdin-launcher-system-via-system</loc>
    <lastmod>2026-04-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privileged-system-service-operation-seloaddriverprivilege-via-security</loc>
    <lastmod>2026-04-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-os-architecture-enumeration-through-grep-via-process-creation</loc>
    <lastmod>2026-04-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-saml-token-issuer-anomaly-via-riskdetection</loc>
    <lastmod>2026-04-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-azure-application-via-auditlogs</loc>
    <lastmod>2026-04-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-schedule-task-lateral-movement-through-atsvc-via-application</loc>
    <lastmod>2026-04-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-redmimicry-winnti-playbook-registry-manipulation-via-registry-event</loc>
    <lastmod>2026-04-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-processes-spawned-by-winrm-via-process-creation</loc>
    <lastmod>2026-04-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-ntfs-short-name-in-image-via-process-creation</loc>
    <lastmod>2026-04-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-network-recon-behavior-via-process-creation</loc>
    <lastmod>2026-04-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-launch-vsdevshell-ps1-proxy-via-process-creation</loc>
    <lastmod>2026-04-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dmsa-service-account-created-in-specific-ous-powershell-via-ps-script</loc>
    <lastmod>2026-04-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/vmmap-signed-dbghelp-dll-possible-sideloading-via-image-load</loc>
    <lastmod>2026-04-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-image-loaded-into-lsass-process-via-image-load</loc>
    <lastmod>2026-04-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-wdac-policy-file-creation-via-file-event</loc>
    <lastmod>2026-04-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-time-machine-backup-removal-attempt-through-tmutil-macos-via-process-creation</loc>
    <lastmod>2026-04-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-security-utilities-via-process-creation</loc>
    <lastmod>2026-04-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windows-event-logging-through-registry-via-registry-set</loc>
    <lastmod>2026-04-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-explorer-process-with-whitespace-padding-clickfix-filefix-via-process-creation</loc>
    <lastmod>2026-04-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-safeboot-keys-through-reg-utility-via-process-creation</loc>
    <lastmod>2026-04-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/hacktool-potential-impacket-lateral-movement-activity-via-process-creation</loc>
    <lastmod>2026-04-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-xxe-exploitation-attempt-in-jvm-based-application-via-application</loc>
    <lastmod>2026-04-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-trust-access-disable-for-vbapplications-via-registry-set</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-event-logging-disabled-through-minint-registry-key-registry-set-via-registry-set</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmstp-execution-registry-event-via-registry-event</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-newactivescripteventconsumer-creation-attempt-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-change-of-ms-settings-protocol-handler-via-process-creation</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-through-windows-defender-mpcmprun-exe-via-process-creation</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-console-codepage-lookup-through-chcp-via-process-creation</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-mshta-powershell-via-ps-script</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-evil-winrm-powershell-module-via-ps-module</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-vulnerable-driver-load-by-name-via-driver-load</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-exports-registry-key-to-an-alternate-data-stream-via-create-stream-hash</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-removal-via-process-creation</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chmod-targeting-sensitive-directories-via-process-creation</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-ecs-task-definition-that-queries-the-credential-endpoint-via-cloudtrail</loc>
    <lastmod>2026-04-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netntlm-downgrade-attack-registry-via-registry-event</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esentutl-volume-shadow-copy-service-keys-via-registry-event</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-pe-execution-by-microsoft-visual-studio-debugger-via-process-creation</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nsudo-execution-via-process-creation</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sensitive-file-dump-through-print-exe-via-process-creation</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-exe-execution-patterns-via-process-creation</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-explorer-process-tree-break-via-process-creation</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmstp-execution-process-creation-via-process-creation</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-change-default-file-association-through-assoc-via-process-creation</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-agentexecutor-powershell-via-process-creation</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-by-imewdbld-exe-via-network-connection</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-inveigh-execution-artefacts-via-file-event</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-access-to-admin-network-share-via-security</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-appx-package-deployment-failed-due-to-signing-requirements-via-appxdeployment-server</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ufw-disable-attempt-via-process-creation</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-scheduled-task-job-at-via-process-creation</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-based-authentication-enabled-via-auditlogs</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privileged-container-deployed-via-application</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-command-execution-in-pod-container-via-application</loc>
    <lastmod>2026-04-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-disable-exploit-guard-network-protection-on-windows-defender-via-registry-set</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windows-security-center-notifications-via-registry-set</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clickonce-trust-prompt-manipulation-via-registry-set</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-created-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-creation-with-curl-and-powershell-execution-combo-via-process-creation</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-schtasks-via-process-creation</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-python-inline-command-via-process-creation</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-arbitrary-code-execution-through-node-exe-via-process-creation</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-dumpert-process-dumper-execution-via-process-creation</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-behavior-through-lsass-via-process-access</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-write-eventlog-use-via-ps-script</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-nishang-powershell-commandlets-via-ps-script</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invocations-generic-powershell-module-via-ps-module</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/self-extraction-directive-file-created-in-potentially-suspicious-location-via-file-event</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-outbound-kerberos-connection-security-via-security</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-system-integrity-protection-sip-via-process-creation</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credentials-from-password-stores-keychain-via-process-creation</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-through-rsync-linux-via-process-creation</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-connection-proxy-via-process-creation</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-esxi-system-information-enumeration-through-esxcli-via-process-creation</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-spring-framework-exceptions-via-application</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ruby-on-rails-framework-exceptions-via-application</loc>
    <lastmod>2026-04-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-lsass-process-dump-through-procdump-via-process-creation</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-quickassist-via-process-creation</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-share-and-session-enumeration-via-net-exe-via-process-creation</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-share-mount-through-net-exe-via-process-creation</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-visualuiaverifynative-exe-via-process-creation</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-pe-metadata-via-process-creation</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-doppelanger-lsass-dumper-execution-via-process-creation</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-to-devtunnels-domain-via-network-connection</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-mscorsvc-dll-via-image-load</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dcom-internetexplorer-application-dll-hijack-via-file-event</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-addition-of-sid-history-to-active-directory-object-via-security</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-add-or-remove-computer-from-dc-via-security</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credentials-in-files-linux-via-auditd</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-secret-or-config-object-access-via-activitylogs</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-key-vault-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-route-53-domain-transferred-to-another-account-via-cloudtrail</loc>
    <lastmod>2026-04-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-splwow64-without-params-via-process-creation</loc>
    <lastmod>2026-04-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-rundll32-exe-execution-of-udl-file-via-process-creation</loc>
    <lastmod>2026-04-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-microsoft-teams-via-process-creation</loc>
    <lastmod>2026-04-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-pingcastle-execution-via-process-creation</loc>
    <lastmod>2026-04-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-connection-allowed-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-04-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-powershell-policies-to-an-insecure-level-powershell-via-ps-script</loc>
    <lastmod>2026-04-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-nofilter-execution-via-security</loc>
    <lastmod>2026-04-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-jndiexploit-pattern-via-webserver</loc>
    <lastmod>2026-04-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aslr-disabled-through-sysctl-or-direct-syscall-linux-via-auditd</loc>
    <lastmod>2026-04-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-keyboard-layout-load-via-registry-set</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-reflectdebugger-content-execution-through-werfault-exe-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-through-vmwaretoolboxcmd-exe-vm-state-change-script-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-database-snapshot-through-adexplorer-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-abused-debug-privilege-by-arbitrary-parent-processes-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-delete-important-scheduled-task-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-dacl-misuse-to-hide-services-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-powershell-with-base64-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-base64-encoded-wmi-classes-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsa-ppl-protection-setting-change-through-commandline-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-register-app-vbs-proxy-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-file-download-through-findstr-exe-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-desktopimgdownldr-command-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-wmi-win32-product-install-msi-via-ps-script</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-initial-access-through-dll-search-order-hijacking-via-file-event</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-pcap-drivers-via-security</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-revoked-image-loaded-via-codeintegrity-operational</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-behavior-via-find-linux-via-process-creation</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-temporary-access-pass-added-to-an-account-via-auditlogs</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-mssql-login-attempt-via-sqlauth-via-application</loc>
    <lastmod>2026-04-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shim-database-patching-behavior-via-registry-set</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-whoami-via-process-creation</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-script-change-permission-through-set-acl-via-process-creation</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windows-defender-av-security-monitoring-via-process-creation</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-convertto-securestring-cmdlet-use-through-commandline-via-process-creation</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-audio-capture-through-powershell-via-process-creation</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shells-spawn-by-java-utility-keytool-via-process-creation</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-rubeus-scriptblock-via-ps-script</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/network-traffic-initiated-to-file-sharing-domains-from-process-located-in-suspicious-folder-via-network-connection</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-to-http-or-https-target-ports-via-network-connection</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-dll-sideloading-from-non-system-locations-via-image-load</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-through-comctl32-dll-via-image-load</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-driver-load-from-a-temporary-directory-via-driver-load</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-creation-of-hacktool-named-file-stream-via-create-stream-hash</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-amsi-trigger-detected-via-windefend</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-credential-dumping-utilities-service-system-via-system</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-of-eventlog-via-system</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-user-logoff-event-via-security</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mitre-bzar-indicators-for-persistence-via-dce-rpc</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-admin-group-through-dscl-via-process-creation</loc>
    <lastmod>2026-04-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-uac-via-registry-set</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-double-extension-file-via-process-creation</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-remote-desktop-users-group-via-process-creation</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-code-execution-through-pcwutl-dll-via-process-creation</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-installutil-without-log-via-process-creation</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-behavior-through-dnscmd-exe-via-process-creation</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-user-agents-with-webrequest-via-ps-script</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clear-powershell-history-powershell-via-ps-script</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-data-exfiltration-through-audio-file-via-ps-script</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-screenconnect-temporary-file-via-file-event</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-xcsset-malware-infection-via-process-creation</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-new-cron-file-via-file-event</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-github-new-secret-via-audit</loc>
    <lastmod>2026-04-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windows-defender-functionalities-through-registry-keys-via-registry-set</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-clickfix-execution-pattern-registry-via-registry-set</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-behavior-via-secedit-via-process-creation</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-bloodhound-sharphound-execution-via-process-creation</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-ip-through-curl-exe-via-process-creation</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-generic-process-access-via-process-access</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-eventvwr-via-file-event</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-filtering-platform-blocked-connection-from-edr-agent-binary-via-security</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pass-the-hash-behavior-2-via-security</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-system-firewall-via-auditd</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-unauthorized-access-to-app-via-okta</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-oauth-app-file-download-activities-via-threat-management</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-user-details-export-attempt-detected-via-audit</loc>
    <lastmod>2026-04-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-ngrok-execution-via-process-creation</loc>
    <lastmod>2026-04-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mmc-spawning-windows-shell-via-process-creation</loc>
    <lastmod>2026-04-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-localpotato-execution-via-process-creation</loc>
    <lastmod>2026-04-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-command-output-piped-to-findstr-exe-via-process-creation</loc>
    <lastmod>2026-04-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netntlm-downgrade-attack-via-security</loc>
    <lastmod>2026-04-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-cron-task-job-linux-via-process-creation</loc>
    <lastmod>2026-04-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-net-ngenassemblyusagelog-registry-key-tamper-via-registry-set</loc>
    <lastmod>2026-04-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-binary-proxy-execution-through-vsdiagnostics-exe-via-process-creation</loc>
    <lastmod>2026-04-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-devtoolslauncher-exe-executes-specified-binary-via-process-creation</loc>
    <lastmod>2026-04-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-coercedpotato-execution-via-process-creation</loc>
    <lastmod>2026-04-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-module-loaded-by-clickonce-application-via-image-load</loc>
    <lastmod>2026-04-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ccleanerdu-dll-sideloading-via-image-load</loc>
    <lastmod>2026-04-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-syskey-registry-keys-access-via-security</loc>
    <lastmod>2026-04-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-strings-in-uri-via-webserver</loc>
    <lastmod>2026-04-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-container-residence-enumeration-through-proc-virtual-fs-via-process-creation</loc>
    <lastmod>2026-04-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-roles-activated-too-frequently-via-pim</loc>
    <lastmod>2026-04-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-risk-and-mfa-registration-policy-updated-via-auditlogs</loc>
    <lastmod>2026-04-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-consolelogin-failed-authentication-via-cloudtrail</loc>
    <lastmod>2026-04-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-camera-and-microphone-access-via-registry-event</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-computer-system-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-audio-capture-through-soundrecorder-via-process-creation</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ssh-tunnel-persistence-install-via-a-scheduled-task-via-process-creation</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/html-help-hh-exe-suspicious-child-process-via-process-creation</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-ntdllpipe-like-behavior-via-process-creation</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-through-bitsadmin-via-process-creation</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmimplant-hack-utility-via-ps-script</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-non-browser-network-traffic-with-telegram-api-via-network-connection</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-microsoft-office-add-in-via-file-event</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/account-manipulation-suspicious-failed-logon-reasons-via-security</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deployment-of-the-appx-package-was-blocked-by-the-policy-via-appxdeployment-server</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-injection-strings-in-uri-via-webserver</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-firmware-behavior-via-process-creation</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-installer-package-child-process-via-process-creation</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-new-admin-console-behaviours-via-okta</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-login-to-disabled-account-via-signinlogs</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-account-disabled-or-blocked-for-sign-in-attempts-via-signinlogs</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-antivirus-apt-malware-signature-via-antivirus</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-redis-action-command-attempt-via-application</loc>
    <lastmod>2026-04-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-internet-explorer-disablefirstruncustomize-enabled-via-registry-set</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-whoami-as-parameter-via-process-creation</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-remote-access-utility-possible-meshagent-windows-via-process-creation</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-xor-encoded-powershell-command-via-process-creation</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-program-location-whitelisted-in-firewall-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-process-of-keyscrambler-exe-via-process-creation</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-f-secure-c3-load-by-rundll32-via-process-creation</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-potentially-over-permissive-permissions-granted-via-dsacls-exe-via-process-creation</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-silenttrinity-stager-dll-load-via-image-load</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vulnerable-winring0-driver-load-via-driver-load</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-defender-exclusion-registry-key-write-access-requested-via-security</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-failed-msexchange-transport-agent-deployment-via-msexchange-management</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/interactive-bash-suspicious-children-via-process-creation</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-setuid-and-setgid-via-process-creation</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-base64-encoded-pipe-to-shell-via-process-creation</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mfa-bypass-via-legacy-client-authentication-via-signinlogs</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-impossible-travel-via-riskdetection</loc>
    <lastmod>2026-04-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-the-fax-dll-via-registry-set</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-over-https-enabled-by-registry-via-registry-set</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deployment-of-wsl-kali-linux-via-process-creation</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-procdump-via-process-creation</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-launched-without-image-name-via-process-creation</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nimscan-execution-via-process-creation</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-via-process-creation</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-googleupdate-child-process-via-process-creation</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-windows-defender-context-menu-via-process-creation</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/powershell-suspicious-win32-pnpentity-via-ps-script</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-psdrive-to-admin-share-via-ps-script</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-addbaccount-use-via-ps-module</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-over-reverse-ssh-tunnel-via-network-connection</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clr-dll-loaded-through-office-applications-via-image-load</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rdp-file-created-by-unusual-application-via-file-event</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iso-file-created-within-temp-folders-via-file-event</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/service-deployment-in-suspicious-folder-via-system</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-federated-domain-added-exchange-via-exchange</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabled-mfa-to-bypass-authentication-mechanisms-via-auditlogs</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-sts-getsessiontoken-misuse-via-cloudtrail</loc>
    <lastmod>2026-04-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-microsoft-office-protected-view-via-registry-set</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-memory-dumping-behavior-through-livekd-via-process-creation</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-kernel-driver-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ping-hex-ip-via-process-creation</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-harvesting-of-wifi-credentials-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-veeam-dabatase-via-process-creation</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-runscripthelper-exe-via-process-creation</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-ppid-spoofing-selectmyparent-tool-execution-via-process-creation</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-redmimicry-winnti-playbook-execution-via-process-creation</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-koh-default-named-pipe-via-pipe-created</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-quarkspwdump-dump-file-via-file-event</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-teamviewer-domain-query-by-non-teamviewer-application-via-dns-query</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-blocked-image-driver-load-for-policy-violation-via-codeintegrity-operational</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-docker-container-enumeration-through-dockerenv-listing-via-process-creation</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-network-sniffing-linux-via-auditd</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-365-potential-ransomware-activity-via-threat-management</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-active-directory-hybrid-health-ad-fs-service-delete-via-activitylogs</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-aws-elasticache-security-group-via-cloudtrail</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-removal-of-bitbucket-secret-scanning-rule-via-audit</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-psexec-service-via-process-creation</loc>
    <lastmod>2026-04-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-privilege-escalation-through-named-pipe-impersonation-via-process-creation</loc>
    <lastmod>2026-04-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-ntfs-short-name-in-command-line-via-process-creation</loc>
    <lastmod>2026-04-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rdp-tunneling-through-ssh-via-process-creation</loc>
    <lastmod>2026-04-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-for-credentials-in-registry-via-process-creation</loc>
    <lastmod>2026-04-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-powershell-script-in-public-folder-via-process-creation</loc>
    <lastmod>2026-04-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-jlaive-in-memory-assembly-via-process-creation</loc>
    <lastmod>2026-04-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-clip-via-process-creation</loc>
    <lastmod>2026-04-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-wuauclt-network-connection-via-network-connection</loc>
    <lastmod>2026-04-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-remote-system-enumeration-via-process-creation</loc>
    <lastmod>2026-04-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-github-repository-archive-status-changed-via-audit</loc>
    <lastmod>2026-04-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-local-manifest-deployment-with-winget-via-registry-set</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-office-macros-warning-via-registry-set</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-group-membership-recon-through-whoami-exe-via-process-creation</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-sysinternals-debugview-via-process-creation</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-exports-critical-registry-keys-to-a-file-via-process-creation</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-sql-server-via-process-creation</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-boot-configuration-manipulation-through-bcdedit-exe-via-process-creation</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-winapi-calls-through-powershell-scripts-via-ps-script</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-mshta-powershell-module-via-ps-module</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/office-macro-file-creation-from-suspicious-process-via-file-event</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-thread-creation-ttdinject-exe-proxy-via-create-remote-thread</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-metasploit-or-impacket-service-deployment-through-smb-psexec-via-security</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-local-user-creation-via-security</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-module-module-added-to-iis-server-via-iis-configuration</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-blocked-image-load-with-revoked-certificate-via-codeintegrity-operational</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-z-flag-bit-set-via-dns</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-groups-enumeration-macos-via-process-creation</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esxi-account-creation-through-esxcli-via-process-creation</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-workspace-role-modified-or-deleted-via-google-workspace-admin</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-github-high-risk-configuration-via-audit</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-user-permissions-export-attempt-via-audit</loc>
    <lastmod>2026-03-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dhcp-callout-dll-deployment-via-registry-set</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clickfix-filefix-execution-pattern-via-process-creation</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-query-use-to-exfil-data-via-process-creation</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-quarks-pwdump-execution-via-process-creation</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-filter-driver-unloaded-through-fltmc-exe-via-process-creation</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-defender-threat-severity-default-action-set-to-allow-or-noaction-via-process-creation</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/manageengine-endpoint-central-dctask64-exe-possible-misuse-via-process-creation</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-credential-guard-registry-manipulation-through-commandline-via-process-creation</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-bitlocker-access-agent-update-utility-via-process-creation</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modify-group-policy-settings-scriptblocklogging-via-ps-script</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-local-groups-information-via-ps-module</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-nslookup-powershell-download-cradle-via-ps-classic-start</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-msconfig-token-change-file-via-file-event</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ntds-dit-creation-by-unusual-process-via-file-event</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-tor-onion-address-sysmon-via-dns-query</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-mimikatz-use-via-windows</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-paexec-service-deployment-via-system</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-adcs-certificate-template-configuration-vulnerability-via-security</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bulk-removal-changes-to-privileged-account-permissions-via-auditlogs</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-printing-misuse-for-lateral-movement-via-application</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-through-event-viewer-via-registry-set</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-old-tls1-0-tls1-1-protocol-version-enabled-via-registry-set</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-database-snapshot-through-adexplorer-high-confidence-via-process-creation</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-electron-application-child-processes-via-process-creation</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-registry-change-through-regini-exe-via-process-creation</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rasdial-behavior-via-process-creation</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-provlaunch-exe-binary-proxy-execution-misuse-via-process-creation</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-exported-through-powershell-scriptblock-via-ps-script</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-network-connection-initiated-to-mega-nz-via-network-connection</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outbound-network-connection-initiated-by-microsoft-dialer-via-network-connection</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ntfs-vulnerability-exploitation-via-system</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clearing-of-important-windows-eventlog-via-system</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ad-object-writedac-access-via-security</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-plistbuddy-via-process-creation</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-via-azurehound-via-signinlogs</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ip-address-sign-in-failure-rate-via-riskdetection</loc>
    <lastmod>2026-03-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vulnerable-driver-blocklist-registry-manipulation-through-commandline-via-process-creation</loc>
    <lastmod>2026-03-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-ultravnc-via-process-creation</loc>
    <lastmod>2026-03-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-event-viewer-recentviews-via-process-creation</loc>
    <lastmod>2026-03-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-etw-trace-evasion-behavior-via-process-creation</loc>
    <lastmod>2026-03-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-for-loop-with-recursive-directory-search-in-cmd-via-process-creation</loc>
    <lastmod>2026-03-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-one-time-only-scheduled-task-at-00-00-via-process-creation</loc>
    <lastmod>2026-03-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-php-inline-command-via-process-creation</loc>
    <lastmod>2026-03-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-dll-registered-through-odbcconf-exe-via-process-creation</loc>
    <lastmod>2026-03-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-node-process-executions-via-process-creation</loc>
    <lastmod>2026-03-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-utilities-keyword-lookup-through-findstr-exe-via-process-creation</loc>
    <lastmod>2026-03-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-schedule-task-recon-through-itaskschedulerservice-via-application</loc>
    <lastmod>2026-03-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-script-interpreter-spawning-credential-scanner-windows-via-process-creation</loc>
    <lastmod>2026-03-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-encoded-powershell-command-line-via-process-creation</loc>
    <lastmod>2026-03-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-firewall-rule-added-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-03-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/mstsc-exe-execution-from-unusual-parent-via-process-creation</loc>
    <lastmod>2026-03-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-mshta-via-process-creation</loc>
    <lastmod>2026-03-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-insensitive-subfolder-search-through-findstr-exe-via-process-creation</loc>
    <lastmod>2026-03-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-bitlockertogo-exe-via-process-creation</loc>
    <lastmod>2026-03-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-littlecorporal-generated-maldoc-injection-via-process-access</loc>
    <lastmod>2026-03-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-werfault-lsass-process-memory-dump-via-file-event</loc>
    <lastmod>2026-03-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-t1047-wmiprvse-wbemcomn-dll-hijack-via-security</loc>
    <lastmod>2026-03-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-named-error-via-syslog</loc>
    <lastmod>2026-03-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-account-lockout-via-signinlogs</loc>
    <lastmod>2026-03-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-mouse-lock-execution-via-process-creation</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-network-trace-capture-started-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-cloudflared-tunnel-via-process-creation</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntlmv1-logon-between-client-and-server-via-system</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-win-susp-computer-name-containing-samtheadmin-via-security</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ad-privileged-users-or-groups-recon-via-security</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-private-key-acquired-via-capi2</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-f5-big-ip-icontrol-rest-api-command-proxy-via-proxy</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-network-sniffing-macos-via-process-creation</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mask-system-power-settings-through-systemctl-via-process-creation</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-network-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-nohup-via-process-creation</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-malicious-use-of-cloudtrail-system-manager-via-cloudtrail</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-attachment-manager-settings-attachments-tamper-via-registry-set</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wow6432node-windows-nt-currentversion-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-use-of-qemu-via-process-creation</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-windows-remote-management-via-ps-script</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/baaupdate-exe-suspicious-dll-load-via-image-load</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-outlook-form-via-file-event</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-office-macro-file-download-via-file-event</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-all-rules-have-been-deleted-from-the-windows-firewall-configuration-via-firewall-as</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-query-tor-onion-address-dns-client-via-dns-client</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-of-sudoers-file-content-via-process-creation</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/okta-suspicious-behavior-reported-by-end-user-via-okta</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-network-zone-deactivated-or-deleted-via-okta</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-root-certificate-authority-added-via-auditlogs</loc>
    <lastmod>2026-03-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-through-sdclt-via-registry-set</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-through-raw-disk-access-by-unusual-utilities-via-raw-access-thread</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-call-to-win32-nteventlogfile-class-via-process-creation</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/lolbin-execution-from-abnormal-drive-via-process-creation</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-browser-launch-from-document-reader-process-via-process-creation</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execute-from-alternate-data-streams-via-process-creation</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-rundll32-behavior-via-process-creation</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/xbap-execution-from-unusual-locations-through-presentationhost-exe-via-process-creation</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-manage-engine-servicedesk-via-process-creation</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-exe-download-via-process-creation</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-access-detected-through-attack-surface-reduction-via-windefend</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-processhacker-privilege-elevation-via-system</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-shutdown-reboot-macos-via-process-creation</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-and-directory-enumeration-macos-via-process-creation</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-user-creation-via-process-creation</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ca-policy-updated-by-non-approved-actor-via-auditlogs</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sidecar-injection-into-running-deployment-via-application</loc>
    <lastmod>2026-03-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-script-execution-policy-enabled-via-registry-set</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-app-paths-default-property-via-registry-set</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-currentversion-nt-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-sysinternals-sdelete-via-process-creation</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-get-clipboard-cmdlet-through-cli-via-process-creation</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-iis-connection-strings-decryption-via-process-creation</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cobaltstrike-process-patterns-via-process-creation</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-dns-serverlevelplugindll-installed-through-dnscmd-exe-via-process-creation</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-sideloading-by-vmware-xfer-utility-via-process-creation</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-through-registry-queries-via-process-creation</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bad-opsec-powershell-code-artifacts-via-ps-module</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-excel-add-in-loaded-from-unusual-location-via-image-load</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pcre-net-package-temp-files-via-file-event</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-new-outlook-macro-via-file-event</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dynamic-csharp-compile-artefact-via-file-event</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/evtx-created-in-unusual-location-via-file-event</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-volume-shadow-copy-mount-via-system</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-smb-create-remote-file-admin-share-via-security</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-audit-cve-event-via-application</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cisco-bgp-authentication-failures-via-bgp</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-error-messages-via-application</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-github-ssh-certificate-configuration-changed-via-audit</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-new-amsi-providers-registry-via-registry-set</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-windows-credential-guard-related-registry-value-registry-via-registry-delete</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-virtual-smart-card-created-through-tpmvscmgr-exe-via-process-creation</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-encoded-and-obfuscated-reflection-assembly-load-function-call-via-process-creation</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-binary-in-user-directory-spawned-from-office-application-via-process-creation</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mmc-executing-files-with-reversed-extensions-via-rtlo-misuse-via-process-creation</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copying-sensitive-files-with-credential-data-via-process-creation</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-through-deviceenroller-exe-via-process-creation</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-audit-policy-manipulation-through-auditpol-via-process-creation</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cmstp-execution-process-access-via-process-access</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-misuse-of-service-permissions-to-hide-services-through-set-service-ps-via-ps-script</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-security-software-enumeration-through-powershell-script-via-ps-script</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vba-dll-loaded-through-office-application-via-image-load</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-remotekrbrelay-smb-relay-secrets-dump-module-indicators-via-file-event</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-tomcat-webserver-logs-via-file-delete</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kerberos-network-traffic-rc4-ticket-encryption-via-kerberos</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-tor-proxies-via-dns</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-external-service-interaction-domains-via-dns</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-admin-group-through-sysadminctl-via-process-creation</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-via-ioreg-via-process-creation</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-reverse-shell-execution-through-pty-and-socket-modules-via-process-creation</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-signins-from-a-non-registered-device-via-signinlogs</loc>
    <lastmod>2026-03-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-open-command-registry-change-via-registry-set</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-driver-added-to-disallowed-images-in-hvci-registry-via-registry-set</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cobaltstrike-service-installations-registry-via-registry-set</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-port-forwarding-behavior-through-ssh-exe-via-process-creation</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-runmru-registry-key-removal-via-process-creation</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-csexec-execution-via-process-creation</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-smb-relay-attack-utility-via-process-creation</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-stdin-powershell-module-via-ps-module</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-query-for-ip-lookup-service-apis-via-dns-query</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-exchange-set-oabvirtualdirectory-externalurl-property-via-msexchange-management</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-firewall-rule-added-in-windows-firewall-exception-list-through-wmiprvse-exe-via-firewall-as</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-privileged-user-has-been-via-linux</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-google-cloud-service-account-via-gcp-audit</loc>
    <lastmod>2026-03-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-command-line-path-traversal-evasion-attempt-via-process-creation</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-debugger-registration-cmdline-via-process-creation</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-defendercheck-execution-via-process-creation</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uninstall-of-windows-defender-feature-through-powershell-via-process-creation</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-console-history-access-attempt-through-history-file-via-process-creation</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-amsi-related-registry-manipulation-through-commandline-via-process-creation</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invocations-generic-via-ps-script</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/import-powershell-modules-from-suspicious-directories-via-ps-script</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-syncappvpublishingserver-bypass-powershell-restriction-ps-module-via-ps-module</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-with-fake-dll-via-image-load</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/ntds-dit-creation-by-unusual-parent-process-via-file-event</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-mega-hosting-website-dns-client-via-dns-client</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-gobrat-file-enumeration-through-grep-via-process-creation</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-traffic-to-localtonet-tunneling-service-initiated-linux-via-network-connection</loc>
    <lastmod>2026-03-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-installed-via-registry-set</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-port-monitor-persistence-in-registry-via-registry-set</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-lateral-movement-through-windows-remote-shell-via-process-creation</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privilege-escalation-to-local-system-via-process-creation</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-masquerading-as-svchost-exe-via-process-creation</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-execution-from-fake-recycle-bin-folder-via-process-creation</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/regsvr32-dll-execution-with-unusual-extension-via-process-creation</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dosfuscation-behavior-via-process-creation</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-powershell-command-history-via-ps-script</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/load-of-rstrtmgr-dll-by-an-unusual-process-via-image-load</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-possible-suspicious-powershell-module-file-via-file-event</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/access-to-potentially-sensitive-sysvol-files-by-unusual-applications-via-file-access</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ngrok-use-with-remote-desktop-service-via-terminalservices-localsessionmanager</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-exploit-framework-user-agent-via-proxy</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/download-from-suspicious-tld-blacklist-via-proxy</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-webshell-remote-command-via-auditd</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-history-file-operations-linux-via-auditd</loc>
    <lastmod>2026-03-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-directory-service-restore-mode-dsrm-registry-value-manipulation-via-registry-set</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-bginfo-exe-custom-db-path-registry-configuration-via-registry-set</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winekey-registry-change-via-registry-event</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-binary-executed-from-wsl-via-process-creation</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-recon-behavior-through-gathernetworkinfo-vbs-via-process-creation</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-potential-pe-metadata-tamper-using-rcedit-via-process-creation</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invocation-from-script-engines-via-process-creation</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-iex-execution-patterns-via-process-creation</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-assembly-loading-through-cl-loadassembly-ps1-via-process-creation</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msdt-execution-through-answer-file-via-process-creation</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-through-installutil-exe-via-process-creation</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-tor-client-browser-via-process-creation</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-write-to-system32-tasks-via-file-event</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-invocation-through-apt-linux-via-process-creation</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invalid-pim-license-via-pim</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-subscription-permission-elevation-through-activitylogs-via-activitylogs</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-antivirus-web-shell-detection-signature-via-antivirus</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ognl-injection-exploitation-in-jvm-based-application-via-application</loc>
    <lastmod>2026-03-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabled-windows-defender-eventlog-via-registry-set</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winrar-compressing-dump-files-via-process-creation</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-eventlog-recon-behavior-via-log-query-utilities-via-process-creation</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-shutdown-via-process-creation</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-autohotkey-exe-via-process-creation</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-ping-copy-command-combination-via-process-creation</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-zerologon-exploitation-via-well-known-utilities-via-system</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-credential-dumping-utilities-service-security-via-security</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-juniper-bgp-missing-md5-via-bgp</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-doas-conf-file-creation-via-file-event</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-okta-policy-modified-or-deleted-via-okta</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-number-of-resource-creation-or-deployment-activities-via-activitylogs</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-encrypting-file-system-misuse-via-application</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-filefix-command-evidence-in-typedpaths-via-registry-set</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-obfuscated-ip-download-behavior-via-process-creation</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-ruby-inline-command-via-process-creation</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-attempt-through-run-keys-via-reg-exe-via-process-creation</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-trufflehog-execution-via-process-creation</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-obfuscation-through-wchar-char-via-process-creation</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lolbin-runexehelper-use-as-proxy-via-process-creation</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-aspnetcompiler-via-process-creation</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-firewall-profile-via-ps-script</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-downgrade-attack-powershell-via-ps-classic-start</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-query-indicating-kerberos-coercion-through-dns-object-spn-spoofing-via-dns-query</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-service-deployment-image-path-via-system</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-syslog-clearing-or-removal-through-system-utilities-via-process-creation</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-to-authentication-method-via-auditlogs</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-bitbucket-project-secret-scanning-allowlist-added-via-audit</loc>
    <lastmod>2026-03-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-typedpaths-via-registry-set</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-application-in-appcompat-via-registry-set</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-macro-runtime-scan-scope-via-registry-set</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-one-liners-with-base64-decoding-via-process-creation</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-windows-capability-through-powershell-cmdlet-via-process-creation</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/curl-web-request-with-possible-custom-user-agent-via-process-creation</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-conhost-exe-commandline-path-traversal-via-process-creation</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-cmd-shell-output-redirect-via-process-creation</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gettypefromclsid-shellexecute-via-ps-script</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-registry-permissions-weakness-check-via-ps-script</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-commandlets-poshmodule-via-ps-module</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-waveedit-dll-sideloading-via-image-load</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-explorer-driver-creation-by-non-sysinternals-binary-via-file-event</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-a-diagcab-via-file-event</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-tap-driver-deployment-security-via-security</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-microsoft-malware-protection-engine-crash-via-application</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-webdav-put-request-via-http</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-365-user-restricted-from-sending-email-via-threat-management</loc>
    <lastmod>2026-03-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-change-of-ie-registry-settings-via-registry-set</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-portproxy-registry-entry-added-via-registry-event</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-through-wsreset-via-registry-event</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-schtasks-creation-or-change-with-system-privileges-via-process-creation</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rundll32-execution-with-unusual-dll-extension-via-process-creation</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-3proxy-execution-via-process-creation</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-powershell-adrecon-via-ps-script</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-local-network-connection-initiated-by-script-interpreter-via-network-connection</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-windows-media-player-file-via-file-event</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-startup-folder-persistence-via-file-event</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-a-suspicious-ads-file-outside-a-browser-download-via-create-stream-hash</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-access-utility-screenconnect-file-transfer-via-application</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copy-passwd-or-shadow-from-tmp-path-via-process-creation</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-workspace-granted-domain-api-access-via-google-workspace-admin</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/azure-unusual-authentication-interruption-via-signinlogs</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-snmp-oid-request-via-application</loc>
    <lastmod>2026-03-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bad-opsec-defaults-sacrificial-processes-with-improper-arguments-via-process-creation</loc>
    <lastmod>2026-03-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sdclt-child-processes-via-process-creation</loc>
    <lastmod>2026-03-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-startuptype-change-through-powershell-set-service-via-process-creation</loc>
    <lastmod>2026-03-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-root-certificate-installed-from-susp-locations-via-process-creation</loc>
    <lastmod>2026-03-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-aspnetcompiler-via-process-creation</loc>
    <lastmod>2026-03-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invocations-specific-powershell-module-via-ps-module</loc>
    <lastmod>2026-03-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-vba-for-outlook-addin-loaded-through-outlook-via-image-load</loc>
    <lastmod>2026-03-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-windows-defender-exclusion-list-via-security</loc>
    <lastmod>2026-03-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-petitpotam-coerce-authentication-attempt-via-security</loc>
    <lastmod>2026-03-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-state-changed-from-guest-to-member-via-auditlogs</loc>
    <lastmod>2026-03-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-s3-data-management-manipulation-via-cloudtrail</loc>
    <lastmod>2026-03-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-mpnotify-via-registry-set</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-currentversion-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-overwrite-through-sysinternals-sdelete-via-process-creation</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sysinternals-procdump-evasion-via-process-creation</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-visual-studio-nodejstools-pressanykey-arbitrary-binary-via-process-creation</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-crackmapexec-process-patterns-via-process-creation</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-binary-execution-via-gup-utility-via-process-creation</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-code-executed-through-office-add-in-xll-file-via-ps-script</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gac-dll-loaded-through-office-applications-via-image-load</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-persistence-script-event-consumer-file-write-via-file-event</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-teamviewer-remote-session-via-file-event</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/access-to-windows-dpapi-master-keys-by-unusual-applications-via-file-access</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-webdav-user-agent-via-proxy</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esxi-syslog-configuration-change-through-esxcli-via-process-creation</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-clipboard-collection-with-xclip-utility-via-process-creation</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-end-user-consent-blocked-via-auditlogs</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-server-service-misuse-for-lateral-movement-via-application</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wdigest-enable-uselogoncredential-via-registry-set</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-through-lsass-silentprocessexit-technique-via-registry-event</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-office-application-startup-office-test-via-registry-event</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-registry-entries-for-azorult-malware-via-registry-event</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-weak-or-abused-passwords-in-cli-via-process-creation</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-highly-privileged-group-via-process-creation</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-important-scheduled-task-via-process-creation</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-shelldispatch-dll-functionality-misuse-via-process-creation</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-vmnat-exe-via-process-creation</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-meshagent-command-execution-via-meshcentral-via-process-creation</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-arbitrary-dll-load-via-winword-via-process-creation</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-csharp-interactive-console-via-process-creation</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-audit-policy-manipulation-through-nt-resource-kit-auditpol-via-process-creation</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-windows-feature-enabled-via-ps-script</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-adwind-rat-jrat-file-artifact-via-file-event</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-mshta-security-via-security</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-amazon-ssm-agent-hijacking-via-process-creation</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-kubernetes-admission-controller-via-gcp-audit</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-github-self-hosted-runner-changes-detected-via-audit</loc>
    <lastmod>2026-03-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-volume-shadow-copies-through-wmi-with-powershell-via-process-creation</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-obfuscated-powershell-oneliner-via-process-creation</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windows-iis-http-logging-via-process-creation</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpevtmute-execution-via-process-creation</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ad-groups-or-users-enumeration-via-powershell-scriptblock-via-ps-script</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-mfdetours-dll-sideloading-via-image-load</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-remote-access-software-domain-from-non-browser-app-via-dns-query</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/password-protected-zip-file-opened-suspicious-filenames-via-security</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ntdsutil-misuse-via-application</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-task-creation-through-atsvc-named-pipe-zeek-via-smb-files</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-groups-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-info-enumeration-through-sysinfo-syscall-via-auditd</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-sql-database-modified-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-eks-cluster-created-or-deleted-via-cloudtrail</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-antivirus-password-dumper-signature-via-antivirus</loc>
    <lastmod>2026-03-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-execution-without-parameters-via-process-creation</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-execution-without-commandline-parameters-via-process-creation</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-empire-powershell-uac-bypass-via-process-creation</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-powershell-user-profile-via-add-content-via-ps-script</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clear-powershell-history-powershell-module-via-ps-module</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/credential-manager-access-by-unusual-applications-via-file-access</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-persistence-via-wmi</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rejected-smb-guest-logon-from-ip-via-smbclient-security</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dcerpc-smb-spoolss-named-pipe-via-security</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-adcs-certificate-template-configuration-vulnerability-with-risky-eku-via-security</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-usb-device-plugged-via-driver-framework</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msi-deployment-from-web-via-application</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-through-sysctl-macos-via-process-creation</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-capabilities-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remove-immutable-file-attribute-auditd-via-auditd</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-psexec-via-process-creation</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-runxcmd-execution-via-process-creation</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-defender-disable-scan-feature-via-process-creation</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-admin-share-mount-through-net-exe-via-process-creation</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-attempts-of-kerberos-coercion-through-dns-spn-spoofing-via-process-creation</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-parent-process-for-cmd-exe-via-process-creation</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copy-dmp-dump-files-from-remote-share-through-cmd-exe-via-process-creation</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-ip-based-url-through-certoc-exe-via-process-creation</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-started-with-remote-debugging-via-process-creation</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-dacl-change-through-set-service-cmdlet-ps-via-ps-script</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tcp-tunnel-through-powershell-script-via-ps-script</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-powershell-via-ps-script</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-spel-injection-in-spring-framework-via-application</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-secret-scanning-exempt-repository-added-via-audit</loc>
    <lastmod>2026-03-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-screensaver-registry-key-set-via-registry-set</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-dump-keyword-in-commandline-via-process-creation</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-hidden-directory-creation-through-ntfs-index-allocation-stream-cli-via-process-creation</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-scheduled-tasks-via-process-creation</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-sam-copy-via-process-creation</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msbuild-execution-by-unusual-parent-process-via-process-creation</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpwsus-wsuspendu-execution-via-process-creation</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/cmd-launched-with-hidden-start-flags-to-suspicious-targets-via-process-creation</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-svchost-process-access-via-process-access</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmic-unquoted-services-path-lookup-powershell-via-ps-script</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/adfs-database-named-pipe-connection-by-unusual-utility-via-pipe-created</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-outbound-kerberos-connection-via-network-connection</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-appverifui-dll-sideloading-via-image-load</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rclone-config-file-creation-via-file-event</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-ad-user-enumeration-from-non-machine-account-via-security</loc>
    <lastmod>2026-03-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-debugger-entry-to-hangs-key-for-persistence-via-registry-set</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-system-information-enumeration-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-filefix-execution-pattern-via-process-creation</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-shim-database-persistence-through-sdbinst-exe-via-process-creation</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pua-kernel-driver-utility-kdu-via-process-creation</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-msdt-parent-process-via-process-creation</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-silenttrinity-stager-execution-via-process-creation</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-from-direct-ip-through-bitsadmin-via-process-creation</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-python-image-load-by-non-python-process-via-image-load</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pcre-net-package-image-load-via-image-load</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-cactustorch-remote-thread-creation-via-create-remote-thread</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bits-transfer-job-download-to-possible-suspicious-folder-via-bits-client</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-hello-world-scraper-botnet-behavior-via-proxy</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-kubernetes-rolebinding-via-gcp-audit</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-new-kubernetes-service-account-via-application</loc>
    <lastmod>2026-03-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-configuration-change-via-sysmon-status</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wfp-filter-added-through-registry-via-registry-set</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-explorer-policy-change-via-registry-set</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-support-provider-ssp-added-to-lsa-configuration-via-registry-event</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-veeambackup-database-credentials-dump-through-sqlcmd-exe-via-process-creation</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-access-utility-screenconnect-potential-suspicious-remote-command-execution-via-process-creation</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-reg-add-bitlocker-via-process-creation</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-base64-encoded-mppreference-cmdlet-via-process-creation</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-arbitrary-file-download-via-office-application-via-process-creation</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-spawned-by-odbcconf-exe-via-process-creation</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/self-extracting-package-creation-through-iexpress-exe-from-potentially-suspicious-location-via-process-creation</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dynamic-net-compilation-through-csc-exe-via-process-creation</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remotefxvgpudisablement-exe-misuse-via-powershell-classic</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-creation-in-unusual-appdata-folder-via-file-event</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-configuration-changes-via-windefend</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kerberos-rc4-ticket-encryption-via-security</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-huawei-bgp-authentication-failures-via-bgp</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-local-accounts-via-aaa</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-triple-cross-ebpf-rootkit-install-commands-via-process-creation</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-gcp-access-policy-via-gcp-audit</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-azure-kubernetes-events-via-activitylogs</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-device-or-configuration-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-application-security-group-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-bucket-enumeration-on-aws-via-cloudtrail</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rds-database-security-group-change-via-cloudtrail</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rce-exploitation-attempt-in-nodejs-via-application</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-etw-logging-disabled-for-scm-via-registry-set</loc>
    <lastmod>2026-03-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-compress-data-and-lock-with-password-for-exfiltration-with-winzip-via-process-creation</loc>
    <lastmod>2026-03-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-via-coregen-exe-via-image-load</loc>
    <lastmod>2026-03-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-task-creation-through-atsvc-named-pipe-via-security</loc>
    <lastmod>2026-03-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cobalt-strike-dns-beaconing-via-dns</loc>
    <lastmod>2026-03-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-or-stop-services-via-process-creation</loc>
    <lastmod>2026-03-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-aws-ec2-vm-export-failure-via-cloudtrail</loc>
    <lastmod>2026-03-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-enableregion-command-monitoring-via-cloudtrail</loc>
    <lastmod>2026-03-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-schedule-task-recon-through-atscv-via-application</loc>
    <lastmod>2026-03-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-parameter-substring-via-process-creation</loc>
    <lastmod>2026-03-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-stracciatella-execution-via-process-creation</loc>
    <lastmod>2026-03-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-explorer-folder-opened-via-explorer-folder-shortcut-through-shell-via-process-creation</loc>
    <lastmod>2026-03-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-http-logging-disabled-on-iis-server-via-iis-configuration</loc>
    <lastmod>2026-03-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-logs-clearing-attempts-via-process-creation</loc>
    <lastmod>2026-03-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-spray-behavior-via-riskdetection</loc>
    <lastmod>2026-03-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-sts-getcalleridentity-enumeration-through-trufflehog-via-cloudtrail</loc>
    <lastmod>2026-03-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sensitive-file-access-through-volume-shadow-copy-backup-via-process-creation</loc>
    <lastmod>2026-03-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-powershell-session-ps-module-via-ps-module</loc>
    <lastmod>2026-03-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mmc-loading-script-engines-dlls-via-image-load</loc>
    <lastmod>2026-03-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/credui-dll-loaded-by-unusual-process-via-image-load</loc>
    <lastmod>2026-03-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sam-database-dump-via-file-event</loc>
    <lastmod>2026-03-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-advanced-ip-scanner-file-event-via-file-event</loc>
    <lastmod>2026-03-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-file-download-from-zip-tld-via-create-stream-hash</loc>
    <lastmod>2026-03-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-edrsilencer-filter-added-via-security</loc>
    <lastmod>2026-03-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-new-local-user-created-via-event</loc>
    <lastmod>2026-03-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-buffer-overflow-attempts-via-linux</loc>
    <lastmod>2026-03-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-via-device-code-authentication-flow-via-signinlogs</loc>
    <lastmod>2026-03-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-command-executed-through-run-dialog-box-registry-via-registry-set</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-spool-service-child-process-via-process-creation</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-powershell-policies-to-an-insecure-level-via-process-creation</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-enumeration-via-ad-module-proccreation-via-process-creation</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-behavior-through-gathernetworkinfo-vbs-via-process-creation</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-eventlog-autologger-session-registry-change-through-commandline-via-process-creation</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-information-for-export-with-powershell-via-ps-script</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-procexp152-sys-file-created-in-tmp-via-file-event</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-created-in-office-startup-folder-via-file-event</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-dns-query-to-common-malware-hosting-and-shortener-services-via-dns-query</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-file-sharing-websites-file-stream-via-create-stream-hash</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-use-with-no-strong-mapping-via-system</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mailbox-export-to-exchange-webserver-via-msexchange-management</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-clear-logs-via-aaa</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-triple-cross-ebpf-rootkit-execve-hijack-via-process-creation</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esxi-vm-kill-through-esxcli-via-process-creation</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pst-export-alert-via-new-compliancesearchaction-via-threat-management</loc>
    <lastmod>2026-03-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-pendingfilerenameoperations-manipulation-via-registry-set</loc>
    <lastmod>2026-02-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-microsoft-office-trusted-location-added-via-registry-set</loc>
    <lastmod>2026-02-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-response-file-execution-through-odbcconf-exe-uncommon-extension-via-process-creation</loc>
    <lastmod>2026-02-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysaidserver-child-via-process-creation</loc>
    <lastmod>2026-02-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-module-registration-via-process-creation</loc>
    <lastmod>2026-02-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-adcspwn-execution-via-process-creation</loc>
    <lastmod>2026-02-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobaltstrike-service-installations-security-via-security</loc>
    <lastmod>2026-02-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-remote-access-utility-possible-meshagent-macos-via-process-creation</loc>
    <lastmod>2026-02-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-driver-altitude-change-via-registry-set</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wdigest-credguard-registry-change-via-registry-event</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-amazon-ssm-agent-hijacking-via-process-creation</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-memory-dump-through-rdrleakdiag-exe-via-process-creation</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/folder-compress-to-potentially-suspicious-output-through-compress-archive-cmdlet-via-process-creation</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-execution-of-hacktool-imphash-via-process-creation</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-get-current-user-via-ps-script</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-shellintel-powershell-commandlets-via-ps-script</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-enumeration-via-ad-module-psscript-via-ps-script</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-called-from-an-executable-version-mismatch-via-ps-classic-start</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-avkkid-dll-sideloading-via-image-load</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-double-extension-files-via-file-event</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-backup-files-via-file-delete</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-by-finger-utility-via-dns-query</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-installed-via-shell-core</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-stdin-security-via-security</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-download-and-execute-pattern-through-curl-wget-via-process-creation</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-registry-lateral-movement-via-application</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hiding-user-account-through-specialaccounts-registry-key-via-registry-set</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winsock2-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-dacl-change-through-set-service-cmdlet-via-process-creation</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-syncappvpublishingserver-vbs-execute-arbitrary-powershell-code-via-process-creation</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hypervisor-protected-code-integrity-hvci-related-registry-manipulation-through-commandline-via-process-creation</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-remotekrbrelay-execution-via-process-creation</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-gup-use-via-process-creation</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-insecure-proxy-doh-transfer-through-curl-exe-via-process-creation</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ping-del-command-combination-via-process-creation</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmiexec-default-output-file-via-file-event</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-protected-storage-service-access-via-security</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disk-image-creation-through-hdiutil-macos-via-process-creation</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-behavior-performed-by-terminated-user-via-threat-management</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-admission-controller-via-activitylogs</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-snapshot-backup-exfiltration-via-cloudtrail</loc>
    <lastmod>2026-02-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-changepk-and-slui-via-process-creation</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysprep-on-appdata-folder-via-process-creation</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-startuptype-change-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-through-binary-rename-via-process-creation</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-security-service-disabled-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-process-spawned-by-java-exe-via-process-creation</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/imagingdevices-unusual-parent-child-processes-via-process-creation</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-powertool-execution-via-process-creation</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-lsass-process-recon-through-findstr-exe-via-process-creation</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-rundll-launcher-powershell-via-ps-script</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tamper-windows-defender-psclassic-via-ps-classic-provider-start</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-potentially-suspicious-self-extraction-directive-file-via-file-executable-detected</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-remote-execution-file-artefact-via-file-event</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vscode-powershell-profile-change-via-file-event</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-service-registry-key-read-access-request-via-security</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-execution-from-tmp-folder-via-process-creation</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-audio-capture-via-auditd</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-logon-from-a-risky-ip-address-via-threat-management</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-antivirus-exploitation-framework-signature-via-antivirus</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-host-port-scan-syn-scan-via-application</loc>
    <lastmod>2026-02-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-ip-through-wget-exe-via-process-creation</loc>
    <lastmod>2026-02-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shellexec-rundll-call-through-ordinal-via-process-creation</loc>
    <lastmod>2026-02-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-screenconnect-execution-via-process-creation</loc>
    <lastmod>2026-02-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/onenote-exe-execution-of-malicious-embedded-scripts-via-process-creation</loc>
    <lastmod>2026-02-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-winpwn-execution-via-process-creation</loc>
    <lastmod>2026-02-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-lsass-process-access-through-windows-remote-management-via-process-access</loc>
    <lastmod>2026-02-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-start-process-passthru-via-ps-script</loc>
    <lastmod>2026-02-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-vscode-code-tunnel-file-indicator-via-file-event</loc>
    <lastmod>2026-02-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-file-copy-via-linux</loc>
    <lastmod>2026-02-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-modify-system-firewall-via-auditd</loc>
    <lastmod>2026-02-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-mycomputer-registry-keys-via-registry-set</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-svchost-command-line-parameter-via-process-creation</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-rundll32-execution-with-dll-stored-in-ads-via-process-creation</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-dit-snapshot-viewer-via-process-creation</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-defender-av-bypass-through-dump64-exe-rename-via-process-creation</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-delete-volume-shadow-copies-through-wmi-with-powershell-via-ps-classic-start</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-third-party-software-dll-sideloading-via-image-load</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-deployment-script-via-system</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bits-transfer-job-download-from-direct-ip-via-bits-client</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mssql-add-account-to-sysadmin-role-via-application</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-guacamole-two-users-sharing-session-anomaly-via-guacamole</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/program-executions-in-suspicious-folders-via-auditd</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-screen-capture-with-xwd-via-auditd</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-mysql-login-attempt-via-application</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-github-repository-organization-transferred-via-audit</loc>
    <lastmod>2026-02-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-blocked-file-shredding-via-sysmon</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/scheduled-taskcache-change-by-unusual-program-via-registry-set</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-psfactorybuffer-com-hijacking-via-registry-set</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tasks-folder-evasion-via-process-creation</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scan-loop-network-via-process-creation</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-anydesk-execution-via-process-creation</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-child-process-of-regsvr32-via-process-creation</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-logon-scripts-commandline-via-process-creation</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-pattern-via-process-creation</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-bginfo-exe-via-process-creation</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-enumeration-with-get-process-via-ps-script</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/psexec-utility-execution-from-suspicious-locations-pipename-via-pipe-created</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-change-on-directory-service-restore-mode-dsrm-account-via-security</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-linux-recon-indicators-via-process-creation</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-inbox-forwarding-via-threat-management</loc>
    <lastmod>2026-02-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-microsoft-dynamic-data-exchange-via-registry-set</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-system-scripts-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-sd-value-to-hide-schedule-task-registry-via-registry-delete</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wsl-child-process-anomaly-via-process-creation</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-electron-application-commandline-via-process-creation</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-stop-windows-service-through-sc-exe-via-process-creation</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-amsi-bypass-through-net-reflection-via-process-creation</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-user-enumeration-and-export-through-get-aduser-cmdlet-powershell-via-ps-script</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-powershell-script-via-ps-script</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-appx-deployment-attempt-via-add-appxpackage-psscript-via-ps-script</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-renamed-powershell-under-powershell-channel-via-ps-classic-start</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-traffic-with-crypto-mining-pool-via-network-connection</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-files-with-system-dll-name-in-unsuspected-locations-via-file-event</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-access-of-signal-desktop-sensitive-data-via-security</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scm-database-handle-failure-via-security</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-malicious-appx-package-deployment-attempts-via-appxdeployment-server</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-github-push-protection-via-audit</loc>
    <lastmod>2026-02-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-wmi-lateral-movement-wmiprvse-spawned-powershell-via-process-creation</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-visual-studio-code-tunnel-via-process-creation</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-disk-cleanup-via-process-creation</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/elevated-system-shell-spawned-from-unusual-parent-location-via-process-creation</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-executing-encoded-payload-from-registry-via-process-creation</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-key-manager-access-via-process-creation</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-command-line-obfuscation-via-process-creation</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remotely-hosted-hta-file-executed-through-mshta-exe-via-process-creation</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sysmon-enumeration-through-default-driver-altitude-via-findstr-exe-via-process-creation</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-insecure-transfer-through-curl-exe-via-process-creation</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-mailbox-export-to-share-ps-via-ps-script</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-create-volume-shadow-copy-with-powershell-via-ps-script</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-net-code-profiler-on-mmc-via-file-event</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mount-execution-with-hidepid-parameter-via-process-creation</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-laps-credential-dump-from-entra-id-via-auditlogs</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-guardduty-important-change-via-cloudtrail</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-ftp-login-attempt-via-application</loc>
    <lastmod>2026-02-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-provisioning-registry-key-misuse-for-binary-proxy-reg-via-registry-set</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dropper-script-execution-through-wscript-cscript-mshta-via-process-creation</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sensitive-file-dump-through-wbadmin-exe-via-process-creation</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-access-utility-anydesk-execution-from-suspicious-folder-via-process-creation</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-get-process-lsass-via-process-creation</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-base64-encoded-reflective-assembly-load-via-process-creation</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-port-forwarding-rule-added-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-scriptrunner-exe-via-process-creation</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-root-certificate-installed-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-access-of-msmpeng-by-werfaultsecure-edr-freeze-via-process-access</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dsinternals-suspicious-powershell-cmdlets-scriptblock-via-ps-script</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-stdin-launcher-powershell-module-via-ps-module</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-azure-browser-sso-misuse-via-image-load</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-driver-load-via-driver-load</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-server-side-template-injection-strings-via-webserver</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-http-request-with-empty-user-agent-via-proxy</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-first-time-seen-remote-named-pipe-zeek-via-smb-files</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-root-credentials-via-cloudtrail</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-anydesk-piped-password-via-cli-via-process-creation</loc>
    <lastmod>2026-02-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-detected-windows-software-enumeration-powershell-via-ps-script</loc>
    <lastmod>2026-02-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-new-firewall-rule-added-in-windows-firewall-exception-list-via-firewall-as</loc>
    <lastmod>2026-02-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-named-pipe-created-through-mkfifo-via-process-creation</loc>
    <lastmod>2026-02-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-behavior-from-anonymous-ip-addresses-via-threat-management</loc>
    <lastmod>2026-02-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-firewall-modified-or-deleted-via-gcp-audit</loc>
    <lastmod>2026-02-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-update-agent-empty-cmdline-via-process-creation</loc>
    <lastmod>2026-02-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-language-enumeration-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-02-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-wsass-execution-via-process-creation</loc>
    <lastmod>2026-02-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privilege-escalation-attempt-through-exe-local-technique-via-file-event</loc>
    <lastmod>2026-02-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-eventlog-evtx-file-via-file-delete</loc>
    <lastmod>2026-02-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tacticalrmm-service-deployment-via-system</loc>
    <lastmod>2026-02-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vsftpd-error-messages-via-vsftpd</loc>
    <lastmod>2026-02-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-pchunter-execution-via-process-creation</loc>
    <lastmod>2026-02-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-obfuscated-iex-invocation-via-process-creation</loc>
    <lastmod>2026-02-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-createdump-process-dump-via-process-creation</loc>
    <lastmod>2026-02-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-get-information-for-smb-share-via-ps-script</loc>
    <lastmod>2026-02-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-frombase64string-use-on-gzip-archive-ps-script-via-ps-script</loc>
    <lastmod>2026-02-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-credential-dumping-tools-named-pipe-created-via-pipe-created</loc>
    <lastmod>2026-02-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-through-finger-exe-via-network-connection</loc>
    <lastmod>2026-02-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-named-pipe-created-through-mkfifo-via-process-creation</loc>
    <lastmod>2026-02-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-disabling-of-aws-route-53-domain-transfer-lock-via-cloudtrail</loc>
    <lastmod>2026-02-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-abusing-winsat-path-parsing-registry-via-registry-set</loc>
    <lastmod>2026-02-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-sysinternals-psservice-via-process-creation</loc>
    <lastmod>2026-02-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-rclone-execution-via-process-creation</loc>
    <lastmod>2026-02-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-firewall-configuration-enumeration-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-02-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-with-colorcpl-via-file-event</loc>
    <lastmod>2026-02-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/desktop-ini-created-by-unusual-process-via-file-event</loc>
    <lastmod>2026-02-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-moriya-rootkit-system-via-system</loc>
    <lastmod>2026-02-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-firewall-address-object-added-via-event</loc>
    <lastmod>2026-02-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invocation-of-shell-through-rsync-via-process-creation</loc>
    <lastmod>2026-02-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-steganography-extract-files-with-steghide-via-auditd</loc>
    <lastmod>2026-02-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-behavior-from-infrequent-country-via-threat-management</loc>
    <lastmod>2026-02-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hide-schedule-task-through-index-value-tamper-via-registry-set</loc>
    <lastmod>2026-02-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-bginfo-exe-custom-wmi-query-registry-configuration-via-registry-set</loc>
    <lastmod>2026-02-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-creation-attempt-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-02-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-web-request-commands-and-cmdlets-via-process-creation</loc>
    <lastmod>2026-02-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-safeboot-registry-key-deleted-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-02-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-reverseshell-connection-via-process-creation</loc>
    <lastmod>2026-02-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-disabled-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-02-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-child-process-of-notepad-updater-gup-exe-via-process-creation</loc>
    <lastmod>2026-02-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-interactive-at-job-via-process-creation</loc>
    <lastmod>2026-02-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-of-process-located-in-tmp-directory-via-process-creation</loc>
    <lastmod>2026-02-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-blocked-executable-via-sysmon</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-windows-app-behavior-via-process-creation</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-ftp-exe-via-process-creation</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-suspicious-activedirectory-enumeration-through-adfind-exe-via-process-creation</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-amsi-bypass-via-null-bits-via-process-creation</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-monitoring-for-persistence-through-bits-via-process-creation</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-compress-data-and-lock-with-password-for-exfiltration-with-7-zip-via-process-creation</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-psattack-via-ps-script</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-homoglyph-attack-via-lookalike-characters-in-filename-via-file-event</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-driver-load-by-name-via-driver-load</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-unauthorized-system-time-change-via-security</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-agent-via-proxy</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-bpf-kprobes-tracing-via-process-creation</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-reverse-shell-indicator-via-network-connection</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-deployment-deleted-from-kubernetes-cluster-via-application</loc>
    <lastmod>2026-02-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-pkgmgr-and-dism-via-process-creation</loc>
    <lastmod>2026-02-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-crassus-execution-via-process-creation</loc>
    <lastmod>2026-02-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/import-powershell-modules-from-suspicious-directories-proccreation-via-process-creation</loc>
    <lastmod>2026-02-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-rubeus-execution-via-process-creation</loc>
    <lastmod>2026-02-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-impacket-tools-execution-via-process-creation</loc>
    <lastmod>2026-02-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-data-export-from-mssql-table-through-bcp-exe-via-process-creation</loc>
    <lastmod>2026-02-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-invocations-specific-via-ps-script</loc>
    <lastmod>2026-02-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wsman-provider-image-loads-via-image-load</loc>
    <lastmod>2026-02-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-terminal-profile-settings-change-by-unusual-process-via-file-event</loc>
    <lastmod>2026-02-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-sign-ins-by-unknown-devices-via-signinlogs</loc>
    <lastmod>2026-02-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/rare-subscription-level-operations-in-azure-via-activitylogs</loc>
    <lastmod>2026-02-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-config-disabling-channel-recorder-via-cloudtrail</loc>
    <lastmod>2026-02-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-file-sharing-domain-through-wget-exe-via-process-creation</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-through-icmluautil-via-process-creation</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bypass-uac-through-fodhelper-exe-via-process-creation</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-start-locations-via-process-creation</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-windows-defender-wmi-autologger-session-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-through-lsass-process-clone-via-process-creation</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-diantz-download-and-compress-into-a-cab-file-via-process-creation</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-icacls-to-hide-file-to-everyone-via-process-creation</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-devicecredentialdeployment-via-process-creation</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-function-call-from-undocumented-com-interface-editionupgrademanager-via-process-access</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-script-change-permission-through-set-acl-psscript-via-ps-script</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-clip-powershell-module-via-ps-module</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-removal-by-dns-exe-via-file-delete</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tap-driver-deployment-via-system</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-compress-obfuscation-security-via-security</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-unsigned-kernel-module-loaded-via-codeintegrity-operational</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-external-webdav-via-proxy</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-smb-spoolss-name-piped-use-via-smb-files</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-capsh-shell-invocation-linux-via-process-creation</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-owner-or-user-enumeration-linux-via-auditd</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-admin-role-assigned-to-an-user-or-group-via-okta</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-google-workspace-application-via-google-workspace-admin</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-roles-activation-doesn-t-require-mfa-via-pim</loc>
    <lastmod>2026-02-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-winget-admin-settings-change-via-registry-set</loc>
    <lastmod>2026-02-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-abusing-winsat-path-parsing-process-via-process-creation</loc>
    <lastmod>2026-02-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-parents-via-process-creation</loc>
    <lastmod>2026-02-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-child-process-of-setres-exe-via-process-creation</loc>
    <lastmod>2026-02-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-screenconnect-server-web-shell-execution-via-process-creation</loc>
    <lastmod>2026-02-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-inline-execution-from-a-file-via-process-creation</loc>
    <lastmod>2026-02-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remotefxvgpudisablement-exe-misuse-powershell-module-via-ps-module</loc>
    <lastmod>2026-02-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-werfault-exe-wer-dll-in-unusual-folder-via-file-event</loc>
    <lastmod>2026-02-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-defender-blocked-from-loading-unsigned-dll-via-security-mitigations</loc>
    <lastmod>2026-02-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-fastpass-phishing-via-okta</loc>
    <lastmod>2026-02-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-privilege-role-via-auditlogs</loc>
    <lastmod>2026-02-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-elasticache-security-group-modified-or-deleted-via-cloudtrail</loc>
    <lastmod>2026-02-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-activate-suppression-of-windows-security-center-notifications-via-registry-set</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enumerate-all-information-with-whoami-exe-via-process-creation</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webshell-detection-with-command-line-keywords-via-process-creation</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-redirect-via-tscon-via-process-creation</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-inline-javascript-execution-through-nodejs-binary-via-process-creation</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-lethalhta-technique-via-process-creation</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-msedge-proxy-exe-via-process-creation</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-securityxploded-execution-via-process-creation</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-certify-execution-via-process-creation</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-from-file-sharing-domain-through-curl-exe-via-process-creation</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-invoke-mimikatz-powershell-script-via-ps-script</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-install-a-dll-in-system-directory-via-ps-script</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-aadinternals-powershell-cmdlets-psscript-via-ps-script</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-win-defender-restored-quarantine-file-via-windefend</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-application-uninstalled-via-application</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-efs-fileshare-modified-or-deleted-via-cloudtrail</loc>
    <lastmod>2026-02-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-autologger-sessions-manipulation-via-registry-set</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-obfuscated-ip-through-cli-via-process-creation</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pdq-deploy-remote-adminstartion-utility-via-process-creation</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-nltest-exe-via-process-creation</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-infdefaultinstall-exe-inf-via-process-creation</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-createminidump-execution-via-process-creation</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chromium-browser-instance-executed-with-custom-extension-via-process-creation</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-windows-capability-through-powershell-script-via-ps-script</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-libcurl-dll-through-gup-exe-via-image-load</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-goopdate-dll-sideloading-via-image-load</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-unsigned-dbghelp-dbgcore-dll-loaded-via-image-load</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-hybridconnectionmanager-service-bus-via-dns-query</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-local-administrator-group-via-security</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-powershell-user-agent-via-proxy</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-events-related-to-mining-pools-via-dns</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-fortigate-vpn-ssl-settings-modified-via-event</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-successful-console-login-without-mfa-via-cloudtrail</loc>
    <lastmod>2026-02-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-windows-firewall-by-registry-via-registry-set</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-manipulation-through-wmi-stdregprov-via-process-creation</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vboxdrvinst-exe-parameters-via-process-creation</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpup-privesc-tool-execution-via-process-creation</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/traffic-to-unusual-destination-ports-via-network-connection</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-core-dll-loaded-by-non-powershell-process-via-image-load</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-startup-folder-file-write-via-file-event</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cred-dump-utilities-dropped-files-via-file-event</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-exchange-powershell-cmdlet-history-via-file-delete</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bits-transfer-job-downloading-file-possible-suspicious-extension-via-bits-client</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-nginx-core-dump-via-nginx</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-azure-kubernetes-cluster-created-or-deleted-via-activitylogs</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-suspicious-saml-behavior-via-cloudtrail</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-restore-public-aws-rds-instance-via-cloudtrail</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-nmap-xmas-scan-via-application</loc>
    <lastmod>2026-02-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-configuration-change-via-sysmon</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-location-of-wermgr-exe-via-process-creation</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-potentially-suspicious-webdav-lnk-via-process-creation</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-recovery-from-backup-through-wbadmin-exe-via-process-creation</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-copy-from-or-to-admin-share-or-sysvol-folder-via-process-creation</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rundll32-setupapi-dll-behavior-via-process-creation</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-gotoassist-execution-via-process-creation</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-execution-policy-manipulation-proccreation-via-process-creation</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-cleanwipe-execution-via-process-creation</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-utilityfunctions-ps1-proxy-dll-via-process-creation</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-htran-natbypass-execution-via-process-creation</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-wwlib-dll-sideloading-via-image-load</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-exe-for-service-with-unquoted-path-via-file-event</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-system-informer-driver-load-via-driver-load</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-obfuscation-system-via-system</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-meterpreter-or-cobalt-strike-getsystem-service-deployment-security-via-security</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-esxi-vm-list-enumeration-through-esxcli-via-process-creation</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-steganography-hide-zip-information-in-picture-file-via-auditd</loc>
    <lastmod>2026-02-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-run-once-task-configuration-in-registry-via-registry-event</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-dll-added-to-appinit-dlls-registry-key-via-registry-event</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-visual-studio-code-tunnel-service-deployment-via-process-creation</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-through-windows-firewall-snap-in-hijack-via-process-creation</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-rundll32-unc-path-via-process-creation</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-boinc-client-via-process-creation</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dropping-of-password-filter-dll-via-process-creation</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-dumpminitool-via-process-creation</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-asp-net-compilation-through-aspnetcompiler-via-process-creation</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-connection-to-remote-account-via-ps-script</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-shellcode-via-ps-script</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-of-etw-trace-powershell-via-ps-script</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/network-connection-initiated-from-process-located-in-potentially-suspicious-or-unusual-location-via-network-connection</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-couldn-t-call-a-privileged-service-lsaregisterlogonprocess-via-security</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-stdin-launcher-security-via-security</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-jexboss-command-sequence-via-linux</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-device-no-longer-managed-or-compliant-via-auditlogs</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-github-repository-pages-site-changed-to-public-via-audit</loc>
    <lastmod>2026-02-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winlogon-allowmultipletssessions-enable-via-registry-set</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-execution-policy-manipulation-via-registry-set</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-periodic-backup-for-system-registry-hives-enabled-via-registry-set</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-dns-serverlevelplugindll-installed-via-registry-set</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-defense-evasion-through-rename-of-highly-relevant-binaries-via-process-creation</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dumping-of-sensitive-hives-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-use-get-nettcpconnection-via-ps-classic-start</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mfdetours-dll-sideloading-via-image-load</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-interactive-powershell-as-system-via-file-event</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-legitimate-application-dropped-archive-via-file-event</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-grace-period-expired-via-windefend</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-linux-doas-utility-via-process-creation</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-linux-sudo-chroot-via-process-creation</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-ntp-monlist-request-via-application</loc>
    <lastmod>2026-02-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windowsterminal-child-processes-via-process-creation</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-workstation-locking-through-rundll32-via-process-creation</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-configuration-and-service-recon-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-the-sftp-exe-binary-as-a-lolbin-via-process-creation</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-commandline-path-traversal-through-cmd-exe-via-process-creation</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-automated-collection-bookmarks-via-get-childitem-powershell-via-ps-script</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-computer-machine-password-by-powershell-via-ps-module</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-office-application-initiated-network-connection-to-non-local-ip-via-network-connection</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-executable-file-creation-via-file-event</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/scheduled-task-executed-unusual-lolbin-via-taskscheduler</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-removal-of-a-security-enabled-global-group-was-via-security</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-monero-crypto-coin-mining-pool-lookup-via-dns</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-split-a-file-into-pieces-via-process-creation</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shellshock-expression-via-linux</loc>
    <lastmod>2026-02-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-gpg-exe-via-process-creation</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-onenote-child-process-via-process-creation</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-winpeas-execution-via-process-creation</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-decryption-via-gpg4win-via-process-creation</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-esentutl-steals-browser-information-via-process-creation</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-credential-prompt-via-ps-script</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-new-powershell-instance-via-pipe-created</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-service-registration-or-execution-via-system</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-denied-access-to-remote-desktop-via-security</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-disabling-of-windows-event-auditing-via-security</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-gatekeeper-bypass-through-xattr-via-process-creation</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disable-security-utilities-via-process-creation</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-scripting-interpreter-applescript-via-process-creation</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-through-find-linux-via-process-creation</loc>
    <lastmod>2026-02-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outlook-macro-execution-without-warning-setting-enabled-via-registry-set</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/new-netsh-helper-dll-registered-from-a-suspicious-location-via-registry-set</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-classes-autorun-keys-change-via-registry-set</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-index-value-to-hide-schedule-task-registry-via-registry-delete</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-registry-change-attempt-through-vbscript-via-process-creation</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-configuration-update-via-process-creation</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/regsvr32-dll-execution-with-suspicious-file-extension-via-process-creation</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-service-creation-via-powershell-via-process-creation</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-user-created-through-net-exe-via-process-creation</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-active-directory-structure-export-through-csvde-exe-via-process-creation</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-agentexecutor-powershell-via-process-creation</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-keylogger-behavior-via-ps-script</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powerview-powershell-cmdlets-scriptblock-via-ps-script</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-a-rule-has-been-deleted-from-the-windows-firewall-exception-list-via-firewall-as</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/bitsadmin-to-unusual-ip-server-address-via-proxy</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-binary-padding-macos-via-process-creation</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-or-removal-of-an-aws-rds-cluster-via-cloudtrail</loc>
    <lastmod>2026-02-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-etw-logging-disabled-for-rpcrt4-dll-via-registry-set</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-sysinternals-utilities-registry-via-registry-set</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-a-local-hidden-user-account-by-registry-via-registry-event</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-delete-defender-scan-shellex-context-menu-registry-key-via-registry-delete</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/regsvr32-execution-from-highly-suspicious-location-via-process-creation</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpmove-tool-execution-via-process-creation</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-sharpersist-execution-via-process-creation</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-empire-powershell-launch-parameters-via-process-creation</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cookies-session-hijacking-via-process-creation</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-tamper-windows-defender-remove-mppreference-scriptblocklogging-via-ps-script</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-of-dbghelp-dll-via-image-load</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-psexec-service-file-creation-via-file-event</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/onenote-attachment-file-dropped-in-suspicious-location-via-file-event</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-google-workspace-role-privilege-via-google-workspace-admin</loc>
    <lastmod>2026-01-31T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-registry-trust-record-change-via-registry-event</loc>
    <lastmod>2026-01-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-radmin-viewer-utility-execution-via-process-creation</loc>
    <lastmod>2026-01-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-frombase64string-use-on-gzip-archive-process-creation-via-process-creation</loc>
    <lastmod>2026-01-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execute-code-with-pester-bat-via-process-creation</loc>
    <lastmod>2026-01-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-livekd-driver-creation-via-file-event</loc>
    <lastmod>2026-01-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remcom-service-file-creation-via-file-event</loc>
    <lastmod>2026-01-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-clip-launcher-system-via-system</loc>
    <lastmod>2026-01-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-clip-launcher-security-via-security</loc>
    <lastmod>2026-01-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bits-transfer-job-download-from-file-sharing-domains-via-bits-client</loc>
    <lastmod>2026-01-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-browser-child-process-macos-via-process-creation</loc>
    <lastmod>2026-01-30T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-hypervisor-enforced-paging-translation-via-registry-set</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-taskkill-symantec-endpoint-protection-via-process-creation</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-file-download-through-ms-appinstaller-protocol-handler-via-process-creation</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privilege-escalation-through-service-permissions-weakness-via-process-creation</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-memory-dump-mount-via-memprocfs-via-process-creation</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-execution-of-pdqdeployrunner-via-process-creation</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-user-created-through-net-exe-with-never-expire-option-via-process-creation</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mftrace-exe-misuse-via-process-creation</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-directory-removal-through-rmdir-via-process-creation</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/set-suspicious-files-as-system-files-via-attrib-exe-via-process-creation</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-directorysearcher-powershell-exploitation-via-ps-script</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cloudflared-tunnels-related-dns-requests-via-dns-query</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-unsigned-image-loaded-via-codeintegrity-operational</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-onelogin-user-assumed-another-user-via-onelogin-events</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-cloud-re-identifies-sensitive-information-via-gcp-audit</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-sts-assumerole-misuse-via-cloudtrail</loc>
    <lastmod>2026-01-29T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-webshell-hacking-behavior-patterns-via-process-creation</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-wsreset-via-process-creation</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-screenconnect-installation-execution-via-process-creation</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-enable-lm-hash-storage-proccreation-via-process-creation</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-dumping-behavior-by-python-based-utility-via-process-access</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-windowstyle-option-via-ps-script</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-replace-desktop-wallpaper-by-powershell-via-ps-script</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-rundll32-powershell-via-ps-script</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-group-enumeration-with-get-adgroup-via-ps-script</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-obfuscated-iex-invocation-system-via-system</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-remote-access-utility-renamed-meshagent-macos-via-process-creation</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-commands-linux-via-auditd</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-binary-padding-linux-via-auditd</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-ssh-login-attempt-via-application</loc>
    <lastmod>2026-01-28T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-winevt-channel-access-permission-through-registry-via-registry-set</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-indirect-command-execution-through-sftp-proxycommand-via-process-creation</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sql-client-utilities-powershell-session-via-process-creation</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-mshta-child-process-via-process-creation</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-portable-gpg-exe-via-process-creation</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-access-from-potentially-white-listed-processes-via-process-access</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-memory-access-by-utility-with-dump-keyword-in-name-via-process-access</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-get-clipboard-via-ps-module</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-non-browser-network-traffic-with-google-api-via-network-connection</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-network-connection-initiated-to-cloudflared-tunnels-domains-via-network-connection</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/msi-deployment-from-suspicious-locations-via-application</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credentials-in-files-via-process-creation</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-ad-threat-intelligence-via-riskdetection</loc>
    <lastmod>2026-01-27T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-pua-sysinternals-utilities-registry-via-registry-set</loc>
    <lastmod>2026-01-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-recall-feature-enabled-disableaidataanalysis-value-deleted-via-registry-delete</loc>
    <lastmod>2026-01-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-visual-studio-code-tunnel-via-process-creation</loc>
    <lastmod>2026-01-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-service-child-process-execution-as-local-system-via-process-creation</loc>
    <lastmod>2026-01-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-curl-file-upload-to-file-sharing-websites-via-process-creation</loc>
    <lastmod>2026-01-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-loaded-through-certoc-exe-uncommon-location-via-process-creation</loc>
    <lastmod>2026-01-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-notepad-plugins-via-file-event</loc>
    <lastmod>2026-01-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-nppspy-hacktool-usage-via-file-event</loc>
    <lastmod>2026-01-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dd-file-overwrite-via-process-creation</loc>
    <lastmod>2026-01-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-reverse-shell-command-line-via-linux</loc>
    <lastmod>2026-01-26T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-wmic-remote-command-via-process-creation</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-speech-runtime-binary-child-process-via-process-creation</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-execution-of-regasm-regsvcs-with-unusual-extension-via-process-creation</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-abusing-print-executable-via-process-creation</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kavremover-dropped-binary-lolbin-use-via-process-creation</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-downloaded-from-file-sharing-website-through-certutil-exe-via-process-creation</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-var-launcher-obfuscation-powershell-module-via-ps-module</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-legitimate-application-dropped-script-via-file-event</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-channel-reference-removal-via-security</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-rdp-login-from-localhost-via-security</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-creation-of-startup-item-file-macos-via-file-event</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-group-has-been-deleted-through-groupdel-via-process-creation</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-coin-miner-cpu-priority-param-via-auditd</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-kms-imported-key-material-use-via-cloudtrail</loc>
    <lastmod>2026-01-25T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wmi-event-subscription-via-wmi-event</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vbscript-payload-stored-in-registry-via-registry-set</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-persistence-through-disk-cleanup-handler-autorun-via-registry-set</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-event-log-access-manipulation-through-registry-via-registry-set</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-custom-file-open-handler-executes-powershell-via-registry-set</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-powershell-session-host-process-winrm-via-process-creation</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bypass-uac-through-cmstp-via-process-creation</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-squirrel-exe-via-process-creation</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-spn-enumeration-through-setspn-exe-via-process-creation</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-advpack-call-through-rundll32-exe-via-process-creation</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-wordpad-outbound-connections-via-network-connection</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-libvlc-dll-sideloading-via-image-load</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-windows-update-error-via-system</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-processes-accessing-the-microphone-and-webcam-via-security</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-admin-user-remote-logon-via-security</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-base64-encoded-user-agent-via-proxy</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-application-sign-on-policy-modified-or-deleted-via-okta</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-google-workspace-application-access-level-via-google-workspace-admin</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-aws-new-lambda-layer-attached-via-cloudtrail</loc>
    <lastmod>2026-01-24T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-delete-all-scheduled-tasks-via-process-creation</loc>
    <lastmod>2026-01-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-curl-exe-via-process-creation</loc>
    <lastmod>2026-01-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-access-utility-simple-help-execution-via-process-creation</loc>
    <lastmod>2026-01-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-base64-encoded-powershell-command-detected-via-process-creation</loc>
    <lastmod>2026-01-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-firewall-rule-deleted-through-netsh-exe-via-process-creation</loc>
    <lastmod>2026-01-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-syncappvpublishingserver-execute-arbitrary-powershell-code-via-process-creation</loc>
    <lastmod>2026-01-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-finger-exe-via-process-creation</loc>
    <lastmod>2026-01-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-silence-eda-via-ps-script</loc>
    <lastmod>2026-01-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-suspicious-lnk-double-extension-file-via-file-event</loc>
    <lastmod>2026-01-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-for-anonfiles-com-domain-dns-client-via-dns-client</loc>
    <lastmod>2026-01-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-triple-cross-ebpf-rootkit-default-persistence-via-file-event</loc>
    <lastmod>2026-01-23T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-uac-secure-desktop-prompt-via-registry-set</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-maxmpxct-registry-value-changed-via-registry-set</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-wmi-backdoor-exchange-transport-agent-via-process-creation</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pua-nimgrab-execution-via-process-creation</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-sysmon-driver-unloaded-through-fltmc-exe-via-process-creation</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-dumping-attempt-through-werfault-via-process-access</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-time-travel-debugging-utility-use-image-via-image-load</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-crash-dump-created-by-operating-system-via-system</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-transferring-files-with-credential-data-through-network-shares-via-security</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-codeintegrity-revoked-kernel-driver-loaded-via-codeintegrity-operational</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-local-system-accounts-enumeration-linux-via-process-creation</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-base64-encoded-shebang-in-cli-via-process-creation</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-country-via-riskdetection</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-users-added-to-global-or-device-admin-roles-via-auditlogs</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-kubernetes-service-account-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-rdp-new-connection-attempt-via-application</loc>
    <lastmod>2026-01-22T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ie-change-domain-zone-via-registry-set</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-where-via-process-creation</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-utilities-via-computerdefaults-via-process-creation</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-creation-via-sysnative-folder-via-process-creation</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-data-exfiltration-behavior-through-commandline-utilities-via-process-creation</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/shell32-dll-execution-in-suspicious-directory-via-process-creation</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-capture-credentials-with-rpcping-exe-via-process-creation</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-recon-behavior-via-get-localgroupmember-cmdlet-via-process-creation</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-lazagne-execution-via-process-creation</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privilege-escalation-via-symlink-between-osk-and-cmd-via-process-creation</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-cobaltstrike-bof-injection-pattern-via-process-access</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/remote-thread-creation-in-unusual-target-image-via-create-remote-thread</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-backup-catalog-via-application</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-script-located-in-potentially-suspicious-directory-via-process-creation</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-appid-uri-configuration-changes-via-auditlogs</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-mssql-login-attempt-via-windows-authentication-via-application</loc>
    <lastmod>2026-01-21T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-function-execution-security-warning-disabled-in-excel-registry-via-registry-set</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-amsi-com-server-hijacking-via-registry-set</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-termination-attempt-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-windows-script-components-file-execution-by-taef-via-process-creation</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-desktop-background-change-via-reg-exe-via-process-creation</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-base64-encoded-powershell-keywords-in-command-lines-via-process-creation</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mpclient-dll-sideloading-through-defender-binaries-via-process-creation</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-computer-password-change-through-ksetup-exe-via-process-creation</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-automated-collection-command-powershell-via-ps-script</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/hacktool-potential-cobaltstrike-process-injection-via-create-remote-thread</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-applocker-prevented-application-or-script-from-running-via-applocker</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-java-payload-strings-via-webserver</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-cobaltstrike-malleable-profile-patterns-proxy-via-proxy</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-transferring-files-with-credential-data-through-network-shares-zeek-via-smb-files</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-cisco-ldp-authentication-failures-via-ldp</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-clear-or-disable-kernel-ring-buffer-logs-through-syslog-syscall-via-auditd</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-security-threat-detected-via-okta</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-owner-removed-from-application-or-service-principal-via-auditlogs</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-key-pair-import-behavior-via-cloudtrail</loc>
    <lastmod>2026-01-20T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/macro-enabled-in-a-potentially-suspicious-document-via-registry-set</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-sticky-key-like-backdoor-use-registry-via-registry-event</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-disk-and-volume-recon-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-browser-data-stealing-via-process-creation</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-plink-via-process-creation</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-renamed-netsupport-rat-via-process-creation</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-regsvr32-http-ftp-pattern-via-process-creation</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/pua-netcat-suspicious-execution-via-process-creation</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-password-spraying-attempt-via-dsacls-exe-via-process-creation</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-web-access-deployment-psscript-via-ps-script</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-manipulation-of-user-computer-or-group-security-principals-across-ad-via-ps-script</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-codeintegrity-unmet-signing-level-requirements-by-file-under-validation-via-codeintegrity-operational</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-lsass-process-crashed-application-via-application</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-pwndrp-access-via-proxy</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-commands-to-clear-or-remove-the-syslog-builtin-via-linux</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/anomalous-user-behavior-via-riskdetection</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-azure-keyvault-secrets-modified-or-deleted-via-activitylogs</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-aws-iam-backdoor-users-keys-via-cloudtrail</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-outdated-dependency-or-vulnerability-alert-via-audit</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-user-login-failure-through-ssh-via-audit</loc>
    <lastmod>2026-01-19T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-default-rdp-port-changed-to-non-standard-port-via-registry-set</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bypass-uac-via-event-viewer-via-registry-set</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-narrator-s-feedback-hub-persistence-via-registry-event</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-msconfig-token-change-process-via-process-creation</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-injection-or-execution-via-tracker-exe-via-process-creation</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-chromium-browser-instance-executed-with-custom-extension-suspicious-parent-via-process-creation</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-powershell-commandlets-scriptblock-via-ps-script</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-clip-launcher-powershell-via-ps-script</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/microsoft-sync-center-suspicious-network-connections-via-network-connection</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-write-to-webapps-root-directory-via-file-event</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-office-macro-file-creation-via-file-event</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hidden-executable-in-ntfs-alternate-data-stream-via-create-stream-hash</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cobalt-strike-dns-beaconing-dns-client-via-dns-client</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-telegram-api-access-via-proxy</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kubernetes-admission-controller-change-via-audit</loc>
    <lastmod>2026-01-18T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-registry-persistence-attempt-through-dbgmanageddebugger-via-registry-set</loc>
    <lastmod>2026-01-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-insecure-download-source-to-winget-via-process-creation</loc>
    <lastmod>2026-01-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dll-execution-through-rasautou-exe-via-process-creation</loc>
    <lastmod>2026-01-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-handlekatz-lsass-dumper-execution-via-process-creation</loc>
    <lastmod>2026-01-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-download-upload-behavior-via-type-command-via-process-creation</loc>
    <lastmod>2026-01-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/clfs-sys-loaded-by-process-located-in-a-possible-suspicious-location-via-image-load</loc>
    <lastmod>2026-01-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-server-enumeration-through-ldap-query-via-dns-query</loc>
    <lastmod>2026-01-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-keylogging-with-pam-d-via-auditd</loc>
    <lastmod>2026-01-17T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-environment-variable-has-been-registered-via-registry-set</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-credential-dumping-attempt-via-new-networkprovider-reg-via-registry-set</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-paexec-escalation-to-local-system-via-process-creation</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-through-workfolders-exe-via-process-creation</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-regsvr32-http-ip-pattern-via-process-creation</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-execution-of-regasm-regsvcs-from-unusual-location-via-process-creation</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabled-ie-security-features-via-process-creation</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-uacme-akagi-execution-via-process-creation</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-dll-or-csproj-code-execution-through-dotnet-exe-via-process-creation</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-script-with-file-hostname-resolving-capabilities-via-ps-script</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobaltstrike-named-pipe-pattern-regex-via-pipe-created</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-microsoft-office-startup-folder-via-file-event</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-omigod-scx-runasprovider-executeshellcommand-via-process-creation</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remove-scheduled-cron-task-job-via-process-creation</loc>
    <lastmod>2026-01-16T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dumpstack-log-defender-evasion-via-process-creation</loc>
    <lastmod>2026-01-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regsvr32-execution-from-remote-share-via-process-creation</loc>
    <lastmod>2026-01-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-arbitrary-command-execution-via-msdt-exe-via-process-creation</loc>
    <lastmod>2026-01-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-access-to-browser-login-data-via-ps-script</loc>
    <lastmod>2026-01-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-api-token-revoked-via-okta</loc>
    <lastmod>2026-01-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-changes-to-pim-settings-via-auditlogs</loc>
    <lastmod>2026-01-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-added-to-an-administrator-s-azure-ad-role-via-auditlogs</loc>
    <lastmod>2026-01-15T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-defender-service-registry-via-registry-set</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-whoami-exe-execution-from-privileged-process-via-process-creation</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-patterns-ntds-dit-exfil-via-process-creation</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-command-patterns-in-scheduled-task-creation-via-process-creation</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-remote-desktop-connection-initiated-through-mstsc-exe-via-process-creation</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-arbitrary-file-download-through-gfxdownloadwrapper-exe-via-process-creation</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-high-integritylevel-conhost-legacy-option-via-process-creation</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/psscriptpolicytest-creation-by-unusual-process-via-file-event</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iso-or-image-mount-indicator-in-recent-files-via-file-event</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-mimikatz-kirbi-file-creation-via-file-event</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-appx-deployment-unsigned-package-deployment-via-appxdeployment-server</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-mssql-server-failed-logon-via-application</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-history-file-removal-via-process-creation</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-decode-base64-encoded-text-via-process-creation</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-creation-of-new-aws-lambda-function-url-configuration-via-cloudtrail</loc>
    <lastmod>2026-01-14T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-event-viewer-events-asp-via-registry-set</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-sigverif-exe-child-process-via-process-creation</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-base64-encoded-iex-cmdlet-via-process-creation</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-printbrm-zip-creation-of-extraction-via-process-creation</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-logged-on-user-password-change-through-ksetup-exe-via-process-creation</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-windows-kernel-debugger-via-process-creation</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-browser-execution-in-headless-mode-via-process-creation</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vulnerable-hacksys-extreme-vulnerable-driver-load-via-driver-load</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-to-visual-studio-code-tunnels-domain-via-dns-query</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-network-access-suspicious-desktop-ini-action-via-security</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-ruler-via-security</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-a-member-was-added-to-a-security-enabled-global-group-via-security</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-certificate-request-export-to-exchange-webserver-via-msexchange-management</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-security-software-enumeration-macos-via-process-creation</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/jamf-mdm-possible-suspicious-child-process-via-process-creation</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-linux-shell-pipe-to-shell-via-process-creation</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-user-access-blocked-by-azure-conditional-access-via-signinlogs</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-ip-address-sign-in-suspicious-via-riskdetection</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-registry-recon-via-application</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-global-ssh-settings-changed-via-audit</loc>
    <lastmod>2026-01-13T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-as-a-service-in-registry-via-registry-set</loc>
    <lastmod>2026-01-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-restrictedadminmode-registry-value-manipulation-via-registry-set</loc>
    <lastmod>2026-01-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-service-manipulation-via-process-creation</loc>
    <lastmod>2026-01-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-commandline-obfuscation-via-unicode-characters-from-suspicious-image-via-process-creation</loc>
    <lastmod>2026-01-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-privilege-escalation-through-weak-service-permissions-via-process-creation</loc>
    <lastmod>2026-01-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-execution-from-internet-hosted-webdav-share-via-process-creation</loc>
    <lastmod>2026-01-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-download-from-file-sharing-websites-file-stream-via-create-stream-hash</loc>
    <lastmod>2026-01-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-use-rundll32-system-via-system</loc>
    <lastmod>2026-01-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-new-or-renamed-user-account-with-character-via-security</loc>
    <lastmod>2026-01-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-auditd-via-auditd</loc>
    <lastmod>2026-01-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-overwriting-the-file-with-dev-zero-or-null-via-auditd</loc>
    <lastmod>2026-01-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-azure-kubernetes-pods-via-activitylogs</loc>
    <lastmod>2026-01-12T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-detected-windows-software-enumeration-via-process-creation</loc>
    <lastmod>2026-01-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-changing-existing-service-imagepath-value-through-reg-exe-via-process-creation</loc>
    <lastmod>2026-01-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-operator-bloopers-cobalt-strike-modules-via-process-creation</loc>
    <lastmod>2026-01-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-application-whitelisting-bypass-through-dnx-exe-via-process-creation</loc>
    <lastmod>2026-01-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/file-download-through-bitsadmin-to-a-suspicious-target-folder-via-process-creation</loc>
    <lastmod>2026-01-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-through-stdin-powershell-via-ps-script</loc>
    <lastmod>2026-01-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-traffic-to-ngrok-tunneling-service-linux-via-network-connection</loc>
    <lastmod>2026-01-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-duo-successful-mfa-authentication-through-bypass-code-via-duo</loc>
    <lastmod>2026-01-11T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-printer-driver-empty-manufacturer-via-registry-set</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disabling-of-windows-hypervisor-enforced-code-integrity-via-registry-set</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-non-existing-file-via-process-creation</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execution-of-visual-studio-nodejstools-pressanykey-renamed-via-process-creation</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-plink-port-forwarding-via-process-creation</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-nslookup-powershell-download-cradle-processcreation-via-process-creation</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-indirect-command-execution-by-program-compatibility-wizard-via-process-creation</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-encoded-to-base64-through-certutil-exe-uncommon-extension-via-process-creation</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-indirect-inline-command-execution-through-bash-exe-via-process-creation</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-netcat-the-powershell-version-via-ps-classic-start</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-edputil-dll-sideloading-via-image-load</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-disabling-of-windows-defender-malware-and-pua-scanning-via-windefend</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-active-directory-user-backdoors-via-security</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-openssh-server-listening-on-socket-via-openssh</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-successful-iis-shortname-fuzzing-scan-via-webserver</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-microsoft-office-child-process-macos-via-process-creation</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-process-execution-from-shared-memory-directory-via-process-creation</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-okta-password-in-alternateid-field-via-okta</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-okta-mfa-reset-or-deactivated-via-okta</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-guest-user-invited-by-non-approved-inviters-via-auditlogs</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-antivirus-ransomware-signature-via-antivirus</loc>
    <lastmod>2026-01-10T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-whoami-exe-execution-with-output-option-via-process-creation</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-virtualbox-driver-deployment-or-starting-of-vms-via-process-creation</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-covenant-powershell-launcher-via-process-creation</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-fsutil-drive-enumeration-via-process-creation</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-filesystem-load-attempt-by-format-com-via-process-creation</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/conhost-spawned-by-unusual-parent-process-via-process-creation</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/creation-of-malicious-named-pipe-via-pipe-created</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dll-sideloading-through-jsschhlp-via-image-load</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-abusing-winsat-path-parsing-file-via-file-event</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-request-by-quickassist-exe-via-dns-query</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remcom-service-deployment-via-system</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-new-bits-job-created-through-bitsadmin-via-bits-client</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/dump-ntds-dit-to-suspicious-location-via-application</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-python-one-liners-with-base64-decoding-linux-via-process-creation</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ca-policy-removed-by-non-approved-actor-via-auditlogs</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-granting-of-permissions-to-an-account-via-activitylogs</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-bitbucket-full-data-export-triggered-via-audit</loc>
    <lastmod>2026-01-09T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-add-debugger-entry-to-aedebug-for-persistence-via-registry-set</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-of-path-to-screensaver-binary-via-registry-event</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-use-of-w32tm-as-timer-via-process-creation</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-process-execution-proxy-through-cl-invocation-ps1-via-process-creation</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-msiexec-masquerading-via-process-creation</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-powershell-obfuscation-via-alias-cmdlets-via-ps-script</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-rundll-launcher-powershell-module-via-ps-module</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-alternate-powershell-hosts-pipe-via-pipe-created</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-safetykatz-dump-indicator-via-file-event</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-iis-webserver-access-logs-via-file-delete</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-password-dumper-remote-thread-in-lsass-via-create-remote-thread</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-mssql-xpcmdshell-suspicious-via-application</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/download-from-suspicious-dyndns-hosts-via-proxy</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-space-after-filename-macos-via-process-creation</loc>
    <lastmod>2026-01-08T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-winlogon-notify-key-logon-persistence-via-registry-set</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-servicedll-hijack-via-registry-set</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-service-startup-type-change-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-remote-desktop-tunneling-via-process-creation</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/schtasks-from-suspicious-folders-via-process-creation</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-arbitrary-command-execution-through-ftp-exe-via-process-creation</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-greedy-file-removal-via-del-via-process-creation</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-invoke-obfuscation-compress-obfuscation-powershell-via-ps-script</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deployment-of-teamviewer-desktop-via-file-event</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/service-deployment-with-suspicious-folder-pattern-via-system</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-scripts-installed-as-services-via-system</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-vulnerable-netlogon-secure-channel-connection-allowed-via-system</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dhcp-server-error-failed-loading-the-callout-dll-via-system</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-hybridconnectionmanager-service-running-via-microsoft-servicebus-client</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-dns-query-indicating-kerberos-coercion-through-dns-object-spn-spoofing-network-via-dns</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-data-compressed-via-auditd</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-uri-configuration-changes-via-auditlogs</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-aws-iam-s3browser-loginprofile-creation-via-cloudtrail</loc>
    <lastmod>2026-01-07T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/new-run-key-pointing-to-suspicious-folder-via-registry-set</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-attempt-through-existing-service-manipulation-via-process-creation</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-download-and-execution-cradles-via-process-creation</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-openwith-exe-executes-specified-binary-via-process-creation</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-execute-files-with-msdeploy-exe-via-process-creation</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ie4uinit-lolbin-use-from-invalid-path-via-process-creation</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-iis-url-globalrules-rewrite-through-appcmd-via-process-creation</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-deleted-data-overwritten-through-cipher-exe-via-process-creation</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ssl-connection-via-ps-script</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-active-directory-enumeration-via-ad-module-psmodule-via-ps-module</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-network-connection-to-notion-api-via-network-connection</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/adsi-cache-file-creation-by-unusual-utility-via-file-event</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-failed-event-log-clear-through-wmi-nteventlogfile-cleareventlog-via-wmi</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-base64-decoded-from-images-via-process-creation</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-disk-image-mounting-through-hdiutil-macos-via-process-creation</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-openssh-daemon-error-via-sshd</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-google-workspace-government-attack-warning-via-google-workspace-login</loc>
    <lastmod>2026-01-06T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-application-removed-through-wmic-exe-via-process-creation</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-defender-disabled-through-systemsettingsadminflows-exe-via-process-creation</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/process-execution-from-a-potentially-suspicious-folder-via-process-creation</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-crypto-mining-behavior-via-process-creation</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-file-download-from-file-sharing-domain-through-powershell-exe-via-process-creation</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-defender-exclusion-via-process-creation</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-crackmapexec-execution-patterns-via-process-creation</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-credential-dumping-attempt-through-svchost-via-process-access</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-deleted-mounted-share-via-ps-script</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-suspicious-powershell-keywords-via-ps-script</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-in-memory-execution-via-reflection-assembly-via-ps-script</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-created-in-outlook-temporary-directory-via-file-event</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-hacktool-powerup-write-hijack-dll-via-file-event</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-logon-with-explicit-credentials-via-security</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-apache-threading-error-via-apache</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-macos-emond-launch-daemon-via-file-event</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-flush-iptables-ufw-chain-via-process-creation</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-crontab-enumeration-via-process-creation</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/aws-console-getsignintoken-possible-misuse-via-cloudtrail</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-remote-server-service-misuse-via-application</loc>
    <lastmod>2026-01-05T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-uac-bypass-via-windows-media-player-registry-via-registry-set</loc>
    <lastmod>2026-01-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-odbc-driver-registered-via-registry-set</loc>
    <lastmod>2026-01-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-remote-squiblytwo-technique-via-process-creation</loc>
    <lastmod>2026-01-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-mailbox-export-to-share-via-process-creation</loc>
    <lastmod>2026-01-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-download-via-notepad-gup-utility-via-process-creation</loc>
    <lastmod>2026-01-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-driverquery-exe-via-process-creation</loc>
    <lastmod>2026-01-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-suspicious-addinutil-exe-commandline-via-process-creation</loc>
    <lastmod>2026-01-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-timestomp-via-ps-script</loc>
    <lastmod>2026-01-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-cobaltstrike-named-pipe-patterns-via-pipe-created</loc>
    <lastmod>2026-01-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-file-write-to-sharepoint-layouts-directory-via-file-event</loc>
    <lastmod>2026-01-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-octopus-scanner-malware-via-file-event</loc>
    <lastmod>2026-01-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-psexec-and-wmi-process-creations-block-via-windefend</loc>
    <lastmod>2026-01-04T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/windows-processes-suspicious-parent-directory-via-process-creation</loc>
    <lastmod>2026-01-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-enumeration-of-a-system-time-via-process-creation</loc>
    <lastmod>2026-01-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-change-default-file-association-to-executable-through-assoc-via-process-creation</loc>
    <lastmod>2026-01-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-webshell-creation-on-static-website-via-file-event</loc>
    <lastmod>2026-01-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/hacktool-possible-remote-credential-dumping-behavior-through-crackmapexec-or-impacket-secretsdump-via-file-event</loc>
    <lastmod>2026-01-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-cisco-denial-of-service-via-aaa</loc>
    <lastmod>2026-01-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-atypical-travel-via-riskdetection</loc>
    <lastmod>2026-01-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/anomalous-token-via-riskdetection</loc>
    <lastmod>2026-01-03T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-dllpathoverride-via-registry-set</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-outlook-security-settings-updated-registry-via-registry-set</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/malicious-folder-removed-from-exploit-guard-protectedfolders-list-registry-via-registry-delete</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-registry-enumeration-through-wmi-stdregprov-via-process-creation</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-persistence-through-vmwaretoolboxcmd-exe-vm-state-change-script-via-process-creation</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-nodejs-execution-of-javascript-file-via-process-creation</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-obfuscated-ordinal-call-through-rundll32-via-process-creation</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-regedit-as-trusted-installer-via-process-creation</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-computer-enumeration-and-export-through-get-adcomputer-cmdlet-via-process-creation</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-recon-behavior-through-nltest-exe-via-process-creation</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-windows-internet-hosted-webdav-share-mount-through-net-exe-via-process-creation</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/execution-of-possible-suspicious-mofcomp-via-process-creation</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-prefetch-file-via-file-delete</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/unusual-file-change-by-dns-exe-via-file-change</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-kerberos-manipulation-via-security</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-shell-execution-through-flock-linux-via-process-creation</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-removal-of-aws-bucket-via-cloudtrail</loc>
    <lastmod>2026-01-02T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-execution-of-pua-sysinternal-utility-registry-via-registry-set</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-ie-zonemap-setting-downgraded-to-mycomputer-zone-for-http-protocols-via-registry-set</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/potentially-suspicious-command-targeting-teams-sensitive-files-via-process-creation</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-powershell-encoded-command-patterns-via-process-creation</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-loading-of-dbgcore-dbghelp-dlls-from-unusual-location-via-image-load</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-dns-query-request-to-onelaunch-update-service-via-dns-query</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-important-scheduled-task-deleted-or-disabled-via-taskscheduler</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-scheduled-task-update-via-security</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-device-deployment-blocked-via-security</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-crypto-miner-user-agent-via-proxy</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-information-enumeration-via-system-profiler-via-process-creation</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-system-shutdown-reboot-linux-via-auditd</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/suspicious-opencanary-telnet-login-attempt-via-application</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://huntrule.com/rules/possible-kubernetes-unauthorized-or-unauthenticated-access-via-audit</loc>
    <lastmod>2026-01-01T00:00:00.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
</urlset>