OpenCanary SIP Request on Honeypot Node

Alerts on OpenCanary logs showing SIP request activity on a configured SIP service.

FreeReviewedSigma · High · v5
Product
opencanary
Category
application
Author
Security Onion Solutions (SigmaHQ), DRL 1.1
Published
2024-03-08
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

Identifies when an OpenCanary node logs an SIP request event from its SIP service. Attackers may probe or interact with exposed services to enumerate reachability and attempt protocol-level interactions. The rule relies on OpenCanary application telemetry identifying SIP request records by log type.

Related detections5 linkedT1123 — drag to rearrange
Linux Audio Capture via arecord and ecasound (auditd execve and memfd_create)
Windows Registry Changes Indicating Suspicious Camera/Microphone Capability Access
Windows processes accessing microphone and webcam via CapabilityAccessManager ConsentStore
Windows Process Creation: SoundRecorder audio capture using /FILE
Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice
OpenCanary SIP Request on Honeypot Node
Pivot detection · T1123 · 5 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.