Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
59 rules
Suspicious Credential Exfiltration to webhook.site (via dns_query)
This rule detects DNS resolution of webhook.site, the request-catcher service abused by the Shai-Hulud npm worm to exfiltrate stolen .npmrc, cloud and SSH tokens. Enterprise hosts rarely need this testing service, so a lookup from a build or developer machine is a strong exfiltration signal.
HuntRule TeamNetworkdns_queryMedium131Premium2026-08-23Suspicious Outbound Connection to InvisibleFerret C2 Ports 1224 and 1245
This rule detects outbound TCP connections to the uncommon ports 1224 and 1245 used by the InvisibleFerret and BeaverTail command and control servers in the North Korean job-hunter campaigns per Unit 42. These fixed high ports carry the actor heartbeat and tasking traffic which is rare for legitimate applications and flags an infected host.
HuntRule TeamNetworknetwork_connectionLow51Premium2026-08-15Malicious Mini Shai-Hulud TanStack C2 git-tanstack and getsession (via dns_query)
This rule detects DNS lookups for the git-tanstack.com payload host and getsession.org session channels used by the Mini Shai-Hulud TanStack npm compromise to fetch its Bun payload and exfiltrate stolen tokens. A resolution indicates the preinstall dropper has executed on a developer or CI host.
HuntRule TeamNetworkdns_queryHigh133Premium2026-08-10Suspicious FinCounter DNS Tunneling Query via dns_query
This rule detects DNS queries whose leftmost label begins with the counter prefix used by the FinCounter DNS tunneling toolkit. Unit 42 catalogued this fixed prefix as a distinctive encoding marker of FinCounter command-and-control over DNS, so repeated queries of this shape from a host suggest a covert DNS tunnel.
HuntRule TeamNetworkdns_queryLow297Premium2026-07-24Malicious DNS Query To ClickFix Infostealer C2 Domain
This rule detects DNS resolution of apposx.com, the fake Cloudflare verification and staging domain used in the ClickFix infostealer campaign. The domain fronts the social-engineering lure that leads macOS users to install the Odyssey and ACR stealers. Alerting on the hardcoded C2 domain surfaces hosts that reached the delivery infrastructure regardless of the payload used.
HuntRule TeamNetworkdns_queryHigh176Premium2026-07-24Suspicious Exploitation Callback to Dnslog Service (via dns_query)
This rule detects DNS lookups for the dnslog.store out of band interaction service, which attackers query to confirm successful exploitation and command injection during mass vulnerability scanning. Enterprise hosts have no legitimate reason to resolve this canary domain, so such queries indicate reconnaissance or validated exploitation of an internet facing device.
HuntRule TeamNetworkdns_queryMedium123Premium2026-07-13Malicious Project CAV3RN DNS Configuration Recovery via cloudlanecdn.com (via dns_query)
This rule detects DNS queries to encoded subdomains of cloudlanecdn.com, a channel used by the Project CAV3RN espionage framework to recover configuration data from DNS AAAA records. The encoded label structure and attacker-controlled domain indicate covert command-and-control and data-encoding activity that should not appear in normal traffic.
HuntRule TeamNetworkdns_queryHigh424Premium2026-07-02Malicious dnscat2 DNS Tunneling C2 Traffic
This rule detects DNS queries containing the dnscat marker string used by the dnscat2 tunneling tool. It maps to command-and-control and data exfiltration over DNS where an operator encodes traffic in oversized MX and TXT lookups to evade network controls. Detecting the dnscat pattern surfaces DNS-based C2 beaconing.
HuntRule TeamNetworkdns_queryHigh412Premium2026-06-21Malicious DNS Query To FvncBot Android Banking Trojan C2
This rule detects DNS resolution of naleymilva.it.com, the command-and-control domain of the FvncBot Android banking trojan targeting Poland. Infected devices resolve this domain to register and receive operator commands over HTTP and WebSocket. Alerting on the hardcoded C2 domain identifies devices beaconing to the trojan infrastructure.
HuntRule TeamNetworkdns_queryHigh202Premium2026-06-12Malicious PeerBlight Command and Control Beacon to qtss.cc Domain
This rule detects DNS resolution of the qtss.cc domain, the ZinFoq command and control infrastructure contacted by the PeerBlight Linux backdoor for beaconing. Resolution of this domain indicates an infected host reaching out to attacker-controlled C2. The domain is a known PeerBlight indicator and has no legitimate business use.
HuntRule TeamNetworkdns_queryHigh275Premium2026-05-27Suspicious DNS-over-HTTPS C2 via Wildcard DNS Services
This rule detects DNS resolution of sslip.io and nip.io wildcard DNS domains that encode an IP address in the hostname, matching BRICKSTORM DNS-over-HTTPS command-and-control on appliances and hypervisors. Espionage operators use these services to dynamically map beacon traffic to attacker infrastructure while blending with legitimate DNS.
HuntRule TeamNetworkdns_queryMedium63Premium2026-05-10Cisco Network Device 802.1X (dot1x) Disabled via port-control Force-Authorized
Alerts on Cisco configuration changes that disable 802.1X on a port (force-authorized or no dot1x port-control).
Luc Génaux, Huntrule TeamCiscoaaaMedium585Free2026-04-28FortiGate SSL VPN Settings Edited
Flags FortiGate VPN SSL settings being edited, which may indicate changes to SSL VPN access or authentication configuration.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium182Free2025-11-01FortiGate User Group Modified via Edit Event
Alerts on FortiGate user group edits that can change access permissions, including VPN-related group membership.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium173Free2025-11-01FortiGate: Addition of VPN SSL Web Portal via Event Logs
Detects FortiGate configuration events where a VPN SSL web portal is added.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamFortigateeventMedium436Free2025-11-01