Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,742 rules
Suspicious Executable or Script Written to Windows Fonts Directory by FishMonger
This rule detects creation of batch, executable or DLL files inside the Windows Fonts directory, a hiding location used by the FishMonger group when staging SprySOCKS loader scripts such as klelam00007.bat. The Fonts folder normally holds only font resources, so script and binary drops there indicate masquerading and artifact concealment. Detecting this anomalous write path is important because it surfaces staged payloads placed in a trusted system location.
HuntRule TeamWindowsfile_eventMedium10Premium2026-09-23Suspicious FrostyNeighbor WinDataScope JavaScript Dropper Artifact
This rule detects creation of the FrostyNeighbor dropper artifacts under an AppData WinDataScope folder, specifically Update.js and WinUpdate.reg. These files are staged by the JavaScript dropper to seed later stages and registry persistence, so their appearance in this path indicates an active infection.
HuntRule TeamWindowsfile_eventHigh80Premium2026-09-23Suspicious PlushDaemon EdgeStepper Configuration File Creation
This rule detects creation of the EdgeStepper configuration file bioset.conf under etc, the encrypted settings store dropped by PlushDaemon on compromised routers. The filename masquerades as a legitimate system component while holding the AES-CBC keyed C2 configuration, so its appearance indicates implant deployment.
HuntRule TeamLinuxfile_eventMedium130Premium2026-09-23Malicious Secure Boot Bypass Files Dropped to EFI Partition
This rule detects creation of the cloak.dat or reloader.efi files used by HybridPetya to exploit CVE-2024-7344 and bypass UEFI Secure Boot. Writing these bootkit components onto the EFI system partition indicates an attempt to load unsigned code during boot and achieve stealthy pre-OS persistence.
HuntRule TeamWindowsfile_eventHigh110Premium2026-09-23Malicious Windows Boot Manager Backup Created by UEFI Bootkit
This rule detects creation of a bootmgfw.efi.old file on the EFI system partition, an artifact left when HybridPetya backs up the legitimate Windows Boot Manager before overwriting it with a malicious bootkit. Preserving the original boot manager under a .old name while hijacking the boot chain indicates pre-OS persistence and boot process tampering.
HuntRule TeamWindowsfile_eventHigh50Premium2026-09-23Malicious Startup LNK Dropped by WinRAR via CVE-2025-8088 Path Traversal
This rule detects the WinRAR process writing a shortcut (.lnk) file into a user or common Startup folder, behavior produced when RomCom and others exploit the CVE-2025-8088 alternate data stream path traversal flaw to gain persistence. Archive tools should not place shortcuts into autostart locations, so this write indicates exploitation and persistence installation.
HuntRule TeamWindowsfile_eventHigh90Premium2026-09-23Suspicious ToolShell Webshell Written to SharePoint Layouts Directory
This rule detects creation of the ToolShell webshell files spinstall0.aspx or ghostfile-prefixed .aspx files used by multiple threat actors after exploiting the SharePoint ToolShell vulnerability chain. These named ASPX payloads dropped onto a SharePoint server provide persistent remote command execution and are strong indicators of compromise.
HuntRule TeamWindowsfile_eventHigh50Premium2026-09-23Suspicious Whisper Backdoor Log File in Windows Temp
This rule detects creation of a file named WindowsEventLogs.txt in C:\Windows\Temp, the hardcoded log location written by the Whisper backdoor used by the BladedFeline group. The filename masquerades as legitimate event log data while actually storing attacker command output and activity records.
HuntRule TeamWindowsfile_eventHigh90Premium2026-09-23Suspicious Webshell Deployment in DNN DesktopModules Directory
This rule detects creation of ASP.NET handler (.ashx) files inside the DotNetNuke DesktopModules directory, a webshell staging location used by the FamousSparrow group for initial access and persistence on IIS servers. Web-facing handler files written into CMS module folders commonly represent server-side backdoors enabling remote command execution.
HuntRule TeamWindowsfile_eventHigh60Premium2026-09-23Suspicious Renamed GRUB Bootloader grubx64-real Creation via File System
This rule detects creation of grubx64-real.efi under the EFI system partition, the artifact Bootkitty produces by displacing the genuine GRUB bootloader so its malicious bootloader can chainload the real one after patching the kernel. A grubx64-real.efi file indicates that the boot chain has been hijacked by a UEFI bootkit.
HuntRule TeamLinuxfile_eventHigh70Premium2026-09-23Suspicious FireWood Autostart Desktop Entry gnome-control Creation via File System
This rule detects creation of an autostart desktop entry named gnome-control.desktop, the persistence mechanism of the FireWood backdoor associated with the WolfsBane intrusion set. The name imitates the GNOME Control Center to appear legitimate while relaunching the implant at login. This indicates XDG autostart persistence on a compromised Linux desktop.
HuntRule TeamLinuxfile_eventHigh100Premium2026-09-23Suspicious Masquerading systemd Unit display-managerd Creation via File System
This rule detects creation of a systemd unit file named display-managerd.service, a masquerading name WolfsBane uses to persist by imitating the legitimate display-manager service. The trailing d makes it resemble a normal daemon unit while providing boot persistence for the backdoor. This indicates systemd service persistence by the Gelsemium Linux implant.
HuntRule TeamLinuxfile_eventHigh60Premium2026-09-23Suspicious CloudScout hxkz_zip Exfiltration Archive Creation via File System
This rule detects creation of files with the .hxkz_zip extension, the custom archive format CloudScout produces to stage stolen browser cookies and cloud session data before exfiltration. This extension is unique to the tooling and is not produced by legitimate software. Its presence indicates collection of session tokens for cloud-service hijacking.
HuntRule TeamWindowsfile_eventHigh60Premium2026-09-23Suspicious HotPage Driver Drop under ShieldNetWork Directory via File System
This rule detects file creation under C:\Windows\ShieldNetWork\, the fixed directory where the HotPage installer drops its encrypted, randomly named vulnerable driver. The ShieldNetWork path is a distinctive artifact of this signed ad-injecting driver campaign. Its appearance indicates staging of a BYOVD component intended to run privileged browser injection code.
HuntRule TeamWindowsfile_eventHigh70Premium2026-09-23Suspicious Lunar Backdoor State File Creation via File System
This rule detects the creation of Lunar backdoor state and configuration files with the distinctive names perfconfm.dat, content.tpl, and outlk.share. These artifacts are dropped by the LunarMail and LunarWeb implants used against European diplomatic missions. Their presence indicates active espionage tooling and stager persistence on the host.
HuntRule TeamWindowsfile_eventHigh50Premium2026-09-23