THE HUNTER’S LEDGER
Hunting Detections
Sigma, YARA & Suricata Rules
Detection logic from original research, mapped to MITRE ATT&CK. Free to use in your environment under CC BY-NC 4.0.
Subscribe β€” live Suricata rule feed

Every published detection here, consolidated into one auto-updating Suricata ruleset β€” point your sensor at it and pull on your own schedule. Free under CC BY-NC 4.0.

suricata-update add-source hunters-ledger https://the-hunters-ledger.com/feeds/suricata/hunters-ledger.rules
HIGH · Jun 2026
Detection Rules β€” Multi-Actor AI-Agent Framework Abuse (8 Operators)
AI Abuse Multi-Family Threat Open Dir
MED · Jun 2026
Detection Rules β€” Flask C2 & MSSQL CLR Backdoor on a Windows Post-Exploitation Staging Host
Post-Ex Priv Esc C2 Open Dir
MED · May 2026
Detection Rules β€” Korean Claude Code + OpenClaw Operator (221.150.15.104)
AI Abuse Persistence Open Dir
HIGH · May 2026
Detection Rules β€” Rovodev AI-Co-Authored Mirai Variant + Matrix C2 (87.106.143.220)
AI Abuse C2 Botnet Open Dir
HIGH · May 2026
Detection Rules β€” GHOST Cryptojacker Kit β€” Vova75Rus Supply Chain (77.110.96.200)
Cryptominer Rootkit Toolkit Open Dir
CRITICAL · May 2026
Detection Rules β€” Turkish ARPA AI-Augmented Observability Compromise (209.38.205.158)
AI Abuse Exfil Cred Theft Open Dir
CRITICAL · May 2026
Detection Rules β€” Russian Gemini CLI Credential Mill (213.165.51.115)
AI Abuse Cred Theft C2 Open Dir
HIGH · May 2026
Detection Rules β€” CVE-2026-41940 cPanel Harvester Toolkit (216.126.227.49)
CVE Exploit Cred Theft Phishing Open Dir
HIGH · May 2026
Detection Rules β€” Inkognito Russian VPN/Phishing Operator (INK VPN / INK Lens)
Phishing Fraud VPN Abuse Cred Theft
HIGH · May 2026
Detection Rules β€” BellaMain Turkish PhaaS Panel (79.137.192.3)
PhaaS Phishing Cred Theft Open Dir
CRITICAL · May 2026
Detection Rules β€” Multi-Cluster Open Directory 79.137.192.3 (Rhadamanthys MaaS / BellaMain / Inkognito)
MaaS Stealer Loader Open Dir
HIGH · May 2026
Detection Rules β€” HijackLoader / Penguish / Rugmi to AsyncRAT Multi-Vector Phishing Campaign
Loader RAT MaaS Open Dir
HIGH · Apr 2026
Detection Rules β€” AdaptixC2 Open Directory Exposure (45.130.148.125)
C2 Toolkit Open Dir Multi-Family
HIGH · Apr 2026
Detection Rules β€” Chaos Ransomware (TorBrowserTor) Multi-Stage Loader (94.103.1.13)
Ransomware Loader Evasion Open Dir
HIGH · Apr 2026
Detection Rules β€” ShinyHunters Data Leak Site (91.215.85.22)
Exfil Cred Theft Open Dir Threat
HIGH · Apr 2026
Detection Rules β€” OpenStrike Expanded Toolkit β€” 106 New Files (2026-04-08)
Toolkit C2 Injection Open Dir
HIGH · Apr 2026
Detection Rules β€” OpenStrike Beacon Toolkit (172.105.0.126)
Toolkit C2 Open Dir Evasion
HIGH · Apr 2026
Detection Rules β€” Shadow RAT & XWorm Open Directory Campaign
RAT MaaS C2 Multi-Family
HIGH · Apr 2026
Detection Rules β€” Open Directory at 193.56.255.154 β€” XiebroC2 v3.1 & Covenant C2
C2 Multi-Family Open Dir Injection
HIGH · Mar 2026
Detection Rules β€” ZeroTrace Multi-Family MaaS Operation (74.0.42.25)
MaaS C2 Open Dir Multi-Family
MED · Mar 2026
Detection Rules β€” Sliver C2 Toolchain with ScareCrow Loader (45.94.31.220)
C2 Loader Go Evasion
HIGH · Feb 2026
Detection Rules β€” Webserver Compromise Kit (91.236.230.250)
Toolkit Priv Esc RCE .NET
CRITICAL · Feb 2026
Detection Rules β€” Remcos RAT OpenDirectory Campaign
RAT Cred Theft Persistence Evasion
HIGH · Feb 2026
Detection Rules β€” NsMiner: Multi-Stage Cryptojacking Operation
Cryptominer Dropper Persistence Evasion
MED · Jan 2026
Detection Rules β€” Arsenal-237: agent.exe (PoetRAT)
RAT C2
MED · Jan 2026
Detection Rules β€” Arsenal-237: agent_xworm.exe (XWorm RAT v6)
RAT C2
MED · Jan 2026
Detection Rules β€” Arsenal-237: agent_xworm_v2.exe (XWorm RAT v2.4.0)
RAT C2
MED · Jan 2026
Detection Rules β€” Arsenal-237: FleetAgentAdvanced.exe
Dropper Persistence
MED · Jan 2026
Detection Rules β€” Arsenal-237: FleetAgentFUD.exe
Dropper Evasion
MED · Jan 2026
Detection Rules β€” Arsenal-237: uac_test.exe
Priv Esc Evasion
CRITICAL · Jan 2026
Detection Rules β€” Arsenal-237: enc/dec Ransomware Family
Ransomware Rust
CRITICAL · Jan 2026
Detection Rules β€” Arsenal-237 New Files: killer.dll (BYOVD Process Termination)
BYOVD Evasion
CRITICAL · Jan 2026
Detection Rules β€” Arsenal-237 New Files: killer_crowdstrike.dll (CrowdStrike-Specific Termination)
Evasion BYOVD
CRITICAL · Jan 2026
Detection Rules β€” Arsenal-237 New Files: lpe.exe (Privilege Escalation)
Priv Esc
CRITICAL · Jan 2026
Detection Rules β€” Arsenal-237 New Files: BdApiUtil64.sys (Vulnerable Baidu Driver)
BYOVD Priv Esc
CRITICAL · Jan 2026
Detection Rules β€” Arsenal-237 New Files: rootkit.dll (Kernel-Mode Rootkit)
Rootkit Evasion
CRITICAL · Jan 2026
Detection Rules β€” Arsenal-237 New Files: nethost.dll (DLL Hijacking Persistence)
DLL Hijack Persistence
CRITICAL · Jan 2026
Detection Rules β€” Arsenal-237 New Files: chromelevator.exe (Browser Credential Theft)
Cred Theft .NET
CRITICAL · Jan 2026
Detection Rules β€” Arsenal-237 New Files: enc_c2.exe (Rust Ransomware with Tor C2)
Ransomware C2 Rust
CRITICAL · Jan 2026
Detection Rules β€” Arsenal-237 New Files: dec_fixed.exe (Ransomware Decryptor)
Ransomware Rust
CRITICAL · Jan 2026
Detection Rules β€” Arsenal-237 New Files: new_enc.exe (Human-Operated Rust Ransomware)
Ransomware Rust
CRITICAL · Jan 2026
Detection Rules β€” Arsenal-237 New Files: full_test_enc.exe (Advanced Rust Ransomware)
Ransomware Rust
HIGH · Dec 2025
Detection Rules β€” Dual-RAT Analysis: Pulsar RAT vs. NjRAT/XWorm
RAT Injection .NET Cred Theft
CRITICAL · Dec 2025
Detection Rules β€” PULSAR RAT (server.exe) β€” Technical Analysis & Business Risk Assessment
RAT Cred Theft Evasion .NET
MED · Nov 2025
Detection Rules β€” Hybrid Loader/Stealer Ecosystem Masquerading as Sogou
Loader Stealer Cred Theft Evasion
MED · Nov 2025
Detection Rules β€” Houselet.exe β€” The Go-Based Loader Masquerading as PlayStation Remote Play
Loader Stealer Go Injection
MED · Oct 2025
Detection Rules β€” AdvancedRouterScanner
Scanner Python Exploitation
HIGH · Oct 2025
Detection Rules β€” From Webshells to The Cloud
Webshell PHP Exfil C2
MED · Oct 2025
Detection Rules β€” Quasar + XWorm + PowerShell
RAT Loader PowerShell Evasion