<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Sigma Rule Library — recently updated rules</title><description>The most recently added or modified community-maintained Sigma detection rules, mirrored from the SigmaHQ repository.</description><link>https://cerez23.github.io/</link><language>en</language><item><title>Linux Webshell Indicators</title><link>https://cerez23.github.io/sigma-rule-library/rules/818f7b24-0fba-4c49-a073-8b755573b9c7/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/818f7b24-0fba-4c49-a073-8b755573b9c7/</guid><description>Detects suspicious sub processes of web server processes (severity: high)</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate></item><item><title>PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy</title><link>https://cerez23.github.io/sigma-rule-library/rules/f14b1e99-5e53-4598-98dc-6f20ad7b35e0/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/f14b1e99-5e53-4598-98dc-6f20ad7b35e0/</guid><description>Detects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local. (severity: low)</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate></item><item><title>New User Account Creation Attempt Via ADSI</title><link>https://cerez23.github.io/sigma-rule-library/rules/e50d5d26-0cf6-4045-b82b-13c0a4e316be/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/e50d5d26-0cf6-4045-b82b-13c0a4e316be/</guid><description>Detects an attempt to create a new user account via ADSI (Active Directory Service Interfaces) using either the WinNT or LDAP provider. This is an uncommon method to create user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands such as &quot;net user&quot;, &quot;New-LocalUser&quot; or &quot;New-ADUser&quot;. (severity: medium)</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate></item><item><title>New User Account Creation Attempt Via ADSI in CommandLine</title><link>https://cerez23.github.io/sigma-rule-library/rules/7c9fed65-039a-4055-8c23-fa763d94aff6/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/7c9fed65-039a-4055-8c23-fa763d94aff6/</guid><description>Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands such as &quot;net user&quot;, &quot;New-LocalUser&quot; or &quot;New-ADUser&quot;. (severity: medium)</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Potentially Suspicious Mofcomp Execution</title><link>https://cerez23.github.io/sigma-rule-library/rules/1dd05363-104e-4b4a-b963-196a534b03a1/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/1dd05363-104e-4b4a-b963-196a534b03a1/</guid><description>Detects execution of the &quot;mofcomp&quot; utility as a child of a suspicious shell or script running utility or by having a suspicious path in the commandline. The &quot;mofcomp&quot; utility parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository. Attackers abuse this utility to install malicious MOF scripts (severity: high)</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Uncommon New Firewall Rule Added In Windows Firewall Exception List</title><link>https://cerez23.github.io/sigma-rule-library/rules/cde0a575-7d3d-4a49-9817-b8004a7bf105/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/cde0a575-7d3d-4a49-9817-b8004a7bf105/</guid><description>Detects when a rule has been added to the Windows Firewall exception list (severity: medium)</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Active Directory Replication from Non Machine Account - DcSync Indicator</title><link>https://cerez23.github.io/sigma-rule-library/rules/17d619c1-e020-4347-957e-1d1207455c93/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/17d619c1-e020-4347-957e-1d1207455c93/</guid><description>Detects potential abuse of Active Directory Replication Service (ADRS) from a non machine account to request credentials. (severity: medium)</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>ADCS - Certighost Ghost Machine Account Creation</title><link>https://cerez23.github.io/sigma-rule-library/rules/fa0bac5f-d170-4a91-9780-1ad71dc1f49e/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/fa0bac5f-d170-4a91-9780-1ad71dc1f49e/</guid><description>Detects the creation of a machine account whose name starts with &apos;GHOST&apos;, which is the naming convention used by the CVE-2026-54121 (Certighost) exploit tooling. The public proof-of-concept for Certighost creates a temporary machine account with a name of the form GHOST&lt;random&gt;$ before enrolling for a DC certificate via the cdc chase path. The attacker-controlled machine account is used as the requester identity in the certificate request; the cdc attribute then redirects the CA to a rogue host that returns a forged Domain Controller identity. The resulting certificate carries the DC&apos;s SID and DNS name, enabling full PKINIT authentication as the targeted DC followed by DCSync. A machine account creation event (4741) where TargetUserName starts with &apos;GHOST&apos; and ends with &apos;$&apos; is a high-fidelity indicator of this attack tool&apos;s execution. Legitimate environments very rarely provision machine accounts with this prefix. (severity: high)</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Suspicious Machine Account Replication - DcSync Indicator</title><link>https://cerez23.github.io/sigma-rule-library/rules/611eab06-a145-4dfa-a295-3ccc5c20f59a/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/611eab06-a145-4dfa-a295-3ccc5c20f59a/</guid><description>Detects suspicious Active Directory Replication Service (ADRS) requests originating from a machine account (SubjectUserName ending in &apos;$&apos;) rather than a legitimate Domain Controller. Under normal operation, only Domain Controllers initiate replication requests carrying the DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account credentials — for example by abusing certificate-based authentication (PKINIT) to impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost), where a temporary machine account is created to request a DC certificate and then used to perform DCSync — they can dump all domain credential material including the krbtgt hash. (severity: medium)</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Certificate Services Outbound SMB or LDAP Connection</title><link>https://cerez23.github.io/sigma-rule-library/rules/2a9e4f17-6c3b-4d8a-e1f0-b57c2d94a631/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/2a9e4f17-6c3b-4d8a-e1f0-b57c2d94a631/</guid><description>Detects the Windows Certificate Services process (certsrv.exe) initiating an outbound network connection on port 445 (SMB) or 389 (LDAP) to a non-DC host. This behaviour is inherently suspicious: under normal operation the CA resolves subject identities via local RPC against the domain and never initiates outbound SMB or LDAP connections to arbitrary hosts. Any such connection indicates the CA is being coerced into performing a remote identity lookup against an attacker-controlled host. The most direct known trigger is the CA chase fallback (EDITF_ENABLECHASECLIENTDC) where a requester-supplied &apos;cdc&apos; attribute causes the CA to open SMB and LDAP to a specified address. CVE-2026-54121 (Certighost) exploits this path to redirect the CA to rogue LSA and LDAP services that return a DC&apos;s identity, resulting in a forged DC certificate. This rule is not limited to Certighost — any future vulnerability or misconfiguration that causes certsrv.exe to make outbound SMB or LDAP connections is covered. (severity: high)</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>DC Machine Account Network Logon from Non-DC Source IP</title><link>https://cerez23.github.io/sigma-rule-library/rules/b2e4a719-3c8f-4d1b-a507-f83c2d56e901/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/b2e4a719-3c8f-4d1b-a507-f83c2d56e901/</guid><description>Detects a Domain Controller machine account authenticating from a source IP that is not a known Domain Controller. DC machine accounts should only authenticate locally or from other DCs during replication operations. Any logon event for a DC account from a workstation or non-DC host is anomalous and indicates one of the following: - Silver Ticket: attacker forged a Kerberos TGS for a DC machine account without requesting a TGT - Pass-the-Ticket: attacker is replaying a captured DC machine account TGS from a non-DC host - Overpass-the-Hash: attacker converted a stolen DC machine account hash into a Kerberos ticket and is authenticating from a non-DC host - Exploitation of certain vulnerabilities such as CVE-2026-54121 (Certighost): attacker obtained a DC certificate via ADCS CDC-chase abuse, authenticates via PKINIT as the DC from their own host, then performs DCSync (severity: critical)</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>DC Machine Account TGS Request from Non-DC Source IP</title><link>https://cerez23.github.io/sigma-rule-library/rules/e3f7c841-2a9d-4b5e-c018-d94b3e67f012/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/e3f7c841-2a9d-4b5e-c018-d94b3e67f012/</guid><description>Detects a Kerberos service ticket request (Event 4769) targeting a Domain Controller machine account&apos;s service (e.g. DRSUAPI) originating from an IP address that is not a known Domain Controller. Service tickets for DC machine accounts should only be requested by other DCs during legitimate replication operations. An attacker with a valid TGT (obtained via PKINIT, overpass-the-hash, or stolen TGT) targeting a DC machine account&apos;s service from a workstation IP indicates preparation for DCSync or impersonation of a DC. Unlike Silver Ticket attacks (which forge the TGS and bypass this event), this rule catches attacks that go through the KDC legitimately. This rule requires %dc_machine_accounts% and %dc_ip_addresses% to be populated with all known DC machine account names and DC IP addresses respectively. (severity: high)</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>DC Machine Account TGT Request from Non-DC Source IP</title><link>https://cerez23.github.io/sigma-rule-library/rules/9c5d2b84-1f7e-4a3c-d6b8-e04f9a17c523/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/9c5d2b84-1f7e-4a3c-d6b8-e04f9a17c523/</guid><description>Detects a Kerberos TGT request (Event 4768) for a known Domain Controller machine account originating from an IP address that is not a known Domain Controller. DC machine accounts should only request TGTs from their own IP. Any TGT request for a DC account from a workstation or non-DC host is anomalous and indicates one of the following: - PKINIT abuse (CVE-2026-54121 / Certighost): attacker authenticating as a DC via a forged certificate from their workstation - Overpass-the-Hash: attacker converting a stolen DC machine account NTLM hash into a Kerberos TGT - Pass-the-Hash (RC4): attacker using the DC machine account hash directly with Kerberos (severity: high)</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Access To Windows DPAPI Master Keys By Uncommon Applications</title><link>https://cerez23.github.io/sigma-rule-library/rules/46612ae6-86be-4802-bc07-39b59feb1309/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/46612ae6-86be-4802-bc07-39b59feb1309/</guid><description>Detects file access requests to the the Windows Data Protection API Master keys by an uncommon application. This can be a sign of credential stealing. Example case would be usage of mimikatz &quot;dpapi::masterkey&quot; function (severity: medium)</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Credential Manager Access By Uncommon Applications</title><link>https://cerez23.github.io/sigma-rule-library/rules/407aecb1-e762-4acf-8c7b-d087bcff3bb6/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/407aecb1-e762-4acf-8c7b-d087bcff3bb6/</guid><description>Detects suspicious processes based on name and location that access the windows credential manager and vault. Which can be a sign of credential stealing. Example case would be usage of mimikatz &quot;dpapi::cred&quot; function (severity: medium)</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Files With System Process Name In Unsuspected Locations</title><link>https://cerez23.github.io/sigma-rule-library/rules/d5866ddf-ce8f-4aea-b28e-d96485a20d3d/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/d5866ddf-ce8f-4aea-b28e-d96485a20d3d/</guid><description>Detects the creation of an executable with a system process name in folders other than the system ones (System32, SysWOW64, etc.). It is highly recommended to perform an initial baseline before using this rule in production. (severity: medium)</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Load Of RstrtMgr.DLL By An Uncommon Process</title><link>https://cerez23.github.io/sigma-rule-library/rules/3669afd2-9891-4534-a626-e5cf03810a61/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/3669afd2-9891-4534-a626-e5cf03810a61/</guid><description>Detects the load of RstrtMgr DLL (Restart Manager) by an uncommon process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them (e.g. Conti ransomware, Cactus ransomware). It has also recently been seen used by the BiBi wiper for Windows. It could also be used for anti-analysis purposes by shut downing specific processes. (severity: low)</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Msiexec Quiet Installation</title><link>https://cerez23.github.io/sigma-rule-library/rules/79a87aa6-e4bd-42fc-a5bb-5e6fbdcd62f5/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/79a87aa6-e4bd-42fc-a5bb-5e6fbdcd62f5/</guid><description>Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi) (severity: medium)</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>PowerShell Core DLL Loaded By Non PowerShell Process</title><link>https://cerez23.github.io/sigma-rule-library/rules/092bc4b9-3d1d-43b4-a6b4-8c8acd83522f/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/092bc4b9-3d1d-43b4-a6b4-8c8acd83522f/</guid><description>Detects loading of essential DLLs used by PowerShell by non-PowerShell process. Detects behavior similar to meterpreter&apos;s &quot;load powershell&quot; extension. (severity: medium)</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>PSScriptPolicyTest Creation By Uncommon Process</title><link>https://cerez23.github.io/sigma-rule-library/rules/1027d292-dd87-4a1a-8701-2abe04d7783c/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/1027d292-dd87-4a1a-8701-2abe04d7783c/</guid><description>Detects the creation of the &quot;PSScriptPolicyTest&quot; PowerShell script by an uncommon process. This file is usually generated by Microsoft Powershell to test against Applocker. (severity: medium)</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Suspicious WSMAN Provider Image Loads</title><link>https://cerez23.github.io/sigma-rule-library/rules/ad1f4bb9-8dfb-4765-adb6-2a7cfb6c0f94/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/ad1f4bb9-8dfb-4765-adb6-2a7cfb6c0f94/</guid><description>Detects signs of potential use of the WSMAN provider from uncommon processes locally and remote execution. (severity: medium)</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>System File Execution Location Anomaly</title><link>https://cerez23.github.io/sigma-rule-library/rules/e4a6b256-3e47-40fc-89d2-7a477edd6915/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/e4a6b256-3e47-40fc-89d2-7a477edd6915/</guid><description>Detects the execution of a Windows system binary that is usually located in the system folder from an uncommon location. (severity: high)</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>ADCS - Certighost CDC Chase Certificate Request (CVE-2026-54121)</title><link>https://cerez23.github.io/sigma-rule-library/rules/c4a1f389-2e6b-4d9a-8f0c-b73e5a12d947/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/c4a1f389-2e6b-4d9a-8f0c-b73e5a12d947/</guid><description>Detects Active Directory Certificate Services (ADCS) certificate requests that include the &apos;cdc&apos; (Client DC) request attribute pointing to a domain or IP that is not a known Domain Controller. &apos;cdc&apos; is an optional MS-WCCE enrollment attribute designed for cross-domain/cross-forest scenarios where a client in a child domain tells the CA which DC to contact for identity lookups when the CA cannot reach that domain directly. Legitimate values are DC hostnames or IPs that resolve to a real Domain Controller computer object in AD with the SERVER_TRUST_ACCOUNT (0x2000) userAccountControl bit set. In an attack, the attacker sets cdc to a domain or IP they control so the CA connects to their rogue SMB and LDAP services instead of a real DC. The rogue server returns a forged DC identity which the pre-patch CA accepts without validation. A malicious event looks like: Requester: DOMAIN\GHOST&lt;random&gt;$ Attributes: cdc:&lt;attacker_ip&gt; rmd:&lt;target_dc_fqdn&gt; SubjectAlternativeName: DNS Name=&lt;target_dc_fqdn&gt; CVE-2026-54121 (Certighost) is the known exploit for this path. The July 2026 patch added _ValidateChaseTargetIsDC which rejects cdc values that do not resolve to a legitimate DC object in Active Directory before following the chase. (severity: high)</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>ADCS - Certighost Certificate Issued via CDC Chase (CVE-2026-54121)</title><link>https://cerez23.github.io/sigma-rule-library/rules/8b7e2c54-1f93-4a6d-b8e0-3c9d7f25a168/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/8b7e2c54-1f93-4a6d-b8e0-3c9d7f25a168/</guid><description>Detects successful issuance of an ADCS certificate where the request attributes include &apos;cdc&apos; (Client DC) or &apos;rmd&apos; (Remote Domain) pointing to a non-DC domain or IP, confirming the CA&apos;s chase fallback path was taken against an attacker-controlled target. &apos;cdc&apos; directs the CA to an address for identity lookup; &apos;rmd&apos; specifies the principal to look up there. In an attack (CVE-2026-54121, Certighost), cdc points to a rogue host that returns a forged DC identity. A successfully issued certificate at this stage means the attacker has obtained a cert carrying a Domain Controller&apos;s SID and DNS identity, enabling PKINIT authentication as that DC followed by DCSync replication. (severity: high)</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Network Communication With Crypto Mining Pool</title><link>https://cerez23.github.io/sigma-rule-library/rules/fa5b1358-b040-4403-9868-15f7d9ab6329/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/fa5b1358-b040-4403-9868-15f7d9ab6329/</guid><description>Detects initiated network connections to crypto mining pools. It indicates that the system is likely infected with a crypto miner malware or is being used for crypto mining. (severity: high)</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>DNS Query to External Service Interaction Domains</title><link>https://cerez23.github.io/sigma-rule-library/rules/aff715fa-4dd5-497a-8db3-910bea555566/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/aff715fa-4dd5-497a-8db3-910bea555566/</guid><description>Detects DNS queries to well-known out-of-band application security testing (OAST) and callback domains. These services (e.g. Burp Collaborator, interactsh, canarytokens, dnslog.cn) are used by security researchers and attackers alike to confirm blind vulnerabilities such as SSRF, XXE, blind RCE, and Log4Shell-style injections, where the exploit payload triggers an external DNS lookup to a controlled domain. A detection indicates that a host on your network resolved one of these domains, which may mean: (1) an attacker is actively probing or exploiting a vulnerable service and using the callback to confirm code execution or data exfiltration, (2) a security scanner (e.g. Nuclei, Gobies) is running against internal targets. Investigate the source host, the full DNS query string (the unique subdomain prefix encodes the callback session), and any concurrent outbound connections or process activity to determine intent. (severity: high)</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Potentially Suspicious Explicit Credential Local Logon</title><link>https://cerez23.github.io/sigma-rule-library/rules/e3c6d245-7b8f-4e2a-c17f-a9d0e5b38f62/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/e3c6d245-7b8f-4e2a-c17f-a9d0e5b38f62/</guid><description>Detects potentially suspicious explicit credential logon events where the user is trying to logon with explicit credentials (username and password) that are different from the current user context. It might indicate an attacker attempting to escalate privileges after obtaining credentials for a different user account. (severity: medium)</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Potentially Suspicious Image Load of Offreg.dll</title><link>https://cerez23.github.io/sigma-rule-library/rules/c9e5f013-4a6f-4d8c-9b0e-f7a4c3d26e95/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/c9e5f013-4a6f-4d8c-9b0e-f7a4c3d26e95/</guid><description>Detects potentially suspicious loading of the Offline Registry Library (offreg.dll). Offreg.dll enables direct read/write access to offline registry hives without invoking the Windows Registry API, bypassing its associated audit logging and telemetry. Attackers may abuse this to stealthily modify registry hives while evading detection mechanisms that rely on standard registry event logs. (severity: medium)</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Registry Hive File Staged Outside Standard User Profile Path</title><link>https://cerez23.github.io/sigma-rule-library/rules/a7f3c891-2e4d-4b6a-9f8c-d5e2a1b04c73/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/a7f3c891-2e4d-4b6a-9f8c-d5e2a1b04c73/</guid><description>Detects the creation of a registry hive file (UsrClass.dat or NTUSER.DAT) outside of the standard user profile path. These files generally contain various user-specific registry settings and are typically located in the user&apos;s profile directory. Staging these files outside of the standard path can be indicative of an attacker attempting to manipulate user registry settings for persistence, privilege escalation, or dump user registry hives for credential harvesting. (severity: high)</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Suspicious Cross-User Process Spawn</title><link>https://cerez23.github.io/sigma-rule-library/rules/d2b7a134-9c3e-4f8a-b56d-e0c1f8a29b47/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/d2b7a134-9c3e-4f8a-b56d-e0c1f8a29b47/</guid><description>Detects suspicious spawning of a process under a different user context than the parent process. Processes such as notepad.exe, calculator etc. are generally spawned under the same user context and also they are often targeted as sacrificial process or decoy process to check successful privilege escalation. (severity: medium)</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Sysmon Configuration Error</title><link>https://cerez23.github.io/sigma-rule-library/rules/815cd91b-7dbc-4247-841a-d7dd1392b0a8/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/815cd91b-7dbc-4247-841a-d7dd1392b0a8/</guid><description>Detects when an adversary is trying to hide it&apos;s action from Sysmon logging based on error messages (severity: high)</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Rundll32 UNC Path Execution</title><link>https://cerez23.github.io/sigma-rule-library/rules/5cdb711b-5740-4fb2-ba88-f7945027afac/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/5cdb711b-5740-4fb2-ba88-f7945027afac/</guid><description>Detects rundll32 execution where the DLL is located on a remote location (share). Threat actors can abuse the rundll32.exe binary to execute remote DLLs from a UNC pathh. (severity: high)</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item><item><title>WordPress Wp2shell Exploitation Tool User-Agent</title><link>https://cerez23.github.io/sigma-rule-library/rules/a7c4e2f9-1b38-4d5c-9e72-3f4a5b6c7d8e/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/a7c4e2f9-1b38-4d5c-9e72-3f4a5b6c7d8e/</guid><description>Detects the hardcoded &quot;wp2shell&quot; User-Agent string used by the wp2shell PoC tool during all phases of CVE-2026-63030 and CVE-2026-60137 exploitation. (severity: high)</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate></item><item><title>WordPress Wp2shell REST Batch Endpoint Exploitation</title><link>https://cerez23.github.io/sigma-rule-library/rules/b8d5f301-2c49-4e6d-af83-4a5b6c7d8e9f/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/b8d5f301-2c49-4e6d-af83-4a5b6c7d8e9f/</guid><description>Detects exploitation attempts against the WordPress REST batch endpoint (CVE-2026-63030, CVE-2026-60137) using the wp2shell PoC tool. The tool sends POST requests to the batch endpoint via the ?rest_route=/batch/v1 query parameter, covering all attack phases from initial probe through SQL injection and pre-auth admin creation. A 207 response confirms the endpoint is active on the target. (severity: medium)</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate></item><item><title>WordPress Wp2shell Webshell Plugin Access</title><link>https://cerez23.github.io/sigma-rule-library/rules/c9e6f412-3d50-4f7e-bf94-5b6c7d8e9f0a/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/c9e6f412-3d50-4f7e-bf94-5b6c7d8e9f0a/</guid><description>Detects post-exploitation access to the wp2shell webshell plugin dropped after successful exploitation of CVE-2026-63030 and CVE-2026-60137. After the pre-auth SQLi-to-admin bridge is established, the attacker can upload a malicious plugin (wp2shell) to the target WordPress instance. At this phase, the attacker accesses the webshell for command execution and persistence. (severity: critical)</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Webshell Detection With Command Line Keywords</title><link>https://cerez23.github.io/sigma-rule-library/rules/bed2a484-9348-4143-8a8a-b801c979301c/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/bed2a484-9348-4143-8a8a-b801c979301c/</guid><description>Detects certain command line parameters often used during reconnaissance activity via web shells (severity: high)</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AWS Bedrock Guardrail Deleted</title><link>https://cerez23.github.io/sigma-rule-library/rules/59b70e4d-dd17-44a9-b740-acf07ae3eb6a/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/59b70e4d-dd17-44a9-b740-acf07ae3eb6a/</guid><description>Detects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove model safety controls and allow unsafe or unauthorized model responses. (severity: medium)</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AWS Bedrock Guardrail Updated</title><link>https://cerez23.github.io/sigma-rule-library/rules/1c722651-254a-4b04-a9f4-99b62a2d0a1f/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/1c722651-254a-4b04-a9f4-99b62a2d0a1f/</guid><description>Detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken model safety controls and allow unsafe or unauthorized model responses. (severity: medium)</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Potential System DLL Sideloading From Non System Locations</title><link>https://cerez23.github.io/sigma-rule-library/rules/4fc0deee-0057-4998-ab31-d24e46e0aba4/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/4fc0deee-0057-4998-ab31-d24e46e0aba4/</guid><description>Detects DLL sideloading of DLLs usually located in system locations (System32, SysWOW64, etc.). (severity: high)</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Local System Accounts Discovery - MacOs</title><link>https://cerez23.github.io/sigma-rule-library/rules/ddf36b67-e872-4507-ab2e-46bda21b842c/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/ddf36b67-e872-4507-ab2e-46bda21b842c/</guid><description>Detects enumeration of local system accounts on MacOS systems. This can be used by attackers to identify accounts for lateral movement or privilege escalation. (severity: low)</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Execution Of Non-Existing File</title><link>https://cerez23.github.io/sigma-rule-library/rules/71158e3f-df67-472b-930e-7d287acaa3e1/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/71158e3f-df67-472b-930e-7d287acaa3e1/</guid><description>Detects process creation events where the Image field lacks an absolute path, which occurs when the backing file no longer exists on disk at the time of logging - commonly caused by Process Ghosting or other unorthodox process creation techniques. (severity: high)</description><pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog</title><link>https://cerez23.github.io/sigma-rule-library/rules/d4f1a2b3-7c8e-4d5f-b6a9-1e0c2d3f4e5b/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/d4f1a2b3-7c8e-4d5f-b6a9-1e0c2d3f4e5b/</guid><description>Detects failed attempts to clear Windows event logs via the WMI NTEventLogFile ClearEventLog method. Event 5858 in the WMI-Activity operational log is an error event, meaning it is only generated when the WMI operation encounters an error (e.g. access denied, provider failure). It could be an indication of an attacker attempting to clear event logs via WMI, but failing due to insufficient privileges or other issues. Successful clearing operations will NOT produce this event; for those, correlate with Security event 1102 or System event 104. (severity: medium)</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Windows Defender Disabled Via SystemSettingsAdminFlows.EXE</title><link>https://cerez23.github.io/sigma-rule-library/rules/da92713f-ca2d-4fab-8320-098013d3f43a/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/da92713f-ca2d-4fab-8320-098013d3f43a/</guid><description>Detects the usage of SystemSettingsAdminFlows.exe to disable Windows Defender. SystemSettingsAdminFlows.exe is a legitimate Windows component used for administrative configuration tasks. However, attackers may abuse it to disable Windows Defender as part of their attack chain, especially in the context of ransomware or other malware campaigns. (severity: high)</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Amsi.DLL Load By Uncommon Process</title><link>https://cerez23.github.io/sigma-rule-library/rules/facd1549-e416-48e0-b8c4-41d7215eedc8/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/facd1549-e416-48e0-b8c4-41d7215eedc8/</guid><description>Detects loading of Amsi.dll by uncommon processes (severity: low)</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Antivirus - Relevant File Paths Alerts Signature</title><link>https://cerez23.github.io/sigma-rule-library/rules/c9a88268-0047-4824-ba6e-4d81ce0b907c/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/c9a88268-0047-4824-ba6e-4d81ce0b907c/</guid><description>Detects an Antivirus alert in a highly relevant file path or with a relevant file name. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place. (severity: high)</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Antivirus - Web Shell Detection Signature</title><link>https://cerez23.github.io/sigma-rule-library/rules/fdf135a2-9241-4f96-a114-bb404948f736/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/fdf135a2-9241-4f96-a114-bb404948f736/</guid><description>Detects a highly relevant Antivirus alert that reports a web shell. It&apos;s highly recommended to tune this rule to the specific strings used by your anti virus solution by downloading a big WebShell repository from e.g. github and checking the matches. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place. (severity: high)</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CredUI.DLL Loaded By Uncommon Process</title><link>https://cerez23.github.io/sigma-rule-library/rules/9ae01559-cf7e-4f8e-8e14-4c290a1b4784/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/9ae01559-cf7e-4f8e-8e14-4c290a1b4784/</guid><description>Detects loading of &quot;credui.dll&quot; and related DLLs by an uncommon process. Attackers might leverage this DLL for potential use of &quot;CredUIPromptForCredentials&quot; or &quot;CredUnPackAuthenticationBufferW&quot;. (severity: medium)</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item><item><title>HackTool - SysmonEnte Execution</title><link>https://cerez23.github.io/sigma-rule-library/rules/d29ada0f-af45-4f27-8f32-f7b77c3dbc4e/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/d29ada0f-af45-4f27-8f32-f7b77c3dbc4e/</guid><description>Detects the use of SysmonEnte, a tool to attack the integrity of Sysmon (severity: high)</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Permission Check Via Accesschk.EXE</title><link>https://cerez23.github.io/sigma-rule-library/rules/c625d754-6a3d-4f65-9c9a-536aea960d37/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/c625d754-6a3d-4f65-9c9a-536aea960d37/</guid><description>Detects the usage of the &quot;Accesschk&quot; utility, an access and privilege audit tool developed by SysInternal and often being abused by attacker to verify process privileges (severity: medium)</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Potential Credential Dumping Activity Via LSASS</title><link>https://cerez23.github.io/sigma-rule-library/rules/5ef9853e-4d0e-4a70-846f-a9ca37d876da/</link><guid isPermaLink="true">https://cerez23.github.io/sigma-rule-library/rules/5ef9853e-4d0e-4a70-846f-a9ca37d876da/</guid><description>Detects process access requests to the LSASS process with specific call trace calls and access masks. This behaviour is expressed by many credential dumping tools such as Mimikatz, NanoDump, Invoke-Mimikatz, Procdump and even the Taskmgr dumping feature. (severity: medium)</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item></channel></rss>