Proxy HTTP GET to /api/Core/Command Init/Restart indicative of possible C2

Flags proxy HTTP GET requests to C2-like command initialization/restart endpoints based on URI suffixes.

FreeReviewedSigma · Medium · v5
Category
proxy
Author
X__Junior (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-01-15
Updated
2026-07-31

What it detects

This rule flags proxy-observed HTTP GET requests whose request URI ends with /api/Core/Command/Init or /api/Core/Command/Restart. Such endpoint-specific polling or command initialization/restart behavior can indicate command-and-control or remote tasking. Detection relies on proxy telemetry capturing HTTP method and full request URI.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.