Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
53 rules
DNS TXT Answer with Possible Execution Strings (via dns)
highThis rule detects strings used in command execution in DNS TXT Answer
sigmaNetworkPaid2026-06-12Suspicious Access to Sensitive File Extensions - Zeek (via smb_files)
mediumThis rule detects known sensitive file extensions via Zeek
sigmaNetwork2026-06-03Suspicious Cisco Disabling Logging (via aaa)
highThis rule detects turn off logging locally or remote
sigmaNetworkPaid2026-05-26Suspicious Default Cobalt Strike Certificate (via x509)
highThis rule detects the presence of default Cobalt Strike certificate in the HTTPS traffic
sigmaNetworkPaid2026-05-22Suspicious Disabling of Cisco Dot1x (via aaa)
mediumThis rule detects the manual disablement of IEEE 802.1X (dot1x) on a Cisco network device interface. Disabling dot1x bypasses Network Access Control (NAC) mechanisms, potentially allowing unauthorized devices to gain access to the internal network. This behavior is a common method used by adversaries or hostile insiders to establish persistence or perform lateral movement via rogue devices.
sigmaNetwork2026-05-20Possible Cisco Stage Data (via aaa)
lowThis rule detects various protocols maybe used to put data on the device for exfil or infil
sigmaNetwork2026-05-17Execution of Suspicious PsExec - Zeek (via smb_files)
highThis rule detects execution of psexec or paexec with renamed service name, this rule helps to filter out the noise if psexec is used for legit purposes or if adversary uses a different psexec client other than sysinternal one
sigmaNetworkPaid2026-05-16Suspicious Cisco Sniffing (via aaa)
mediumThis rule detects show when a monitor or a span/rspan is setup or modified
sigmaNetwork2026-05-12Possible Cisco Enumeration (via aaa)
lowThis rule detects information about network devices that is not stored in config files
sigmaNetwork2026-04-20Suspicious MITRE BZAR Indicators for Persistence (via dce_rpc)
mediumThis rule detects windows DCE-RPC functions which indicate a persistence methods on the remote system. All credit for the Zeek mapping of the anomalous endpoint/operation field goes to MITRE.
sigmaNetwork2026-04-10Suspicious DNS Z Flag Bit Set (via dns)
mediumThis rule detects the DNS Z flag is bit within the DNS protocol header that is, per the IETF design, meant to be used reserved (unused). Although recently it has been used in DNSSec, the value being set to anything other than 0 should be rare. Otherwise if it is set to non 0 and DNSSec is being used, then excluding the legitimate domains is low effort and high reward. Determine if multiple of these files were accessed in a short period of time to further enhance the possibility of seeing if this was a one off or the possibility of larger sensitive file gathering. This Sigma query is designed to accompany the Corelight Threat Hunting Guide, that can be found here: https://www3.corelight.com/corelights-introductory-guide-to-threat-hunting-with-zeek-bro-logs'
sigmaNetwork2026-03-31Possible Cisco BGP Authentication Failures (via bgp)
lowThis rule detects BGP failures which may be indicative of brute force attacks to manipulate routing
sigmaNetwork2026-03-23Suspicious Kerberos Network Traffic RC4 Ticket Encryption (via kerberos)
mediumThis rule detects kerberos TGS request using RC4 encryption which may be indicative of kerberoasting
sigmaNetwork2026-03-22Suspicious DNS TOR Proxies (via dns)
mediumThis rule detects IPs performing DNS lookups linked with common Tor proxies.
sigmaNetwork2026-03-22Possible DNS Query to External Service Interaction Domains (via dns)
highThis rule detects DNS queries to well-known out-of-band application security testing (OAST) and callback domains. These services (e.g. Burp Collaborator, interactsh, canarytokens, dnslog.cn) are used by security researchers and adversaries alike to confirm blind vulnerabilities such as SSRF, XXE, blind RCE, and Log4Shell-style injections, where the exploit payload triggers an external DNS lookup to a controlled domain. A detection suggests that a host on your network resolved one of these domains, which may mean: (1) an adversary is actively probing or exploiting a vulnerable service and using the callback to confirm code execution or data exfiltration, (2) a security scanner (e.g. Nuclei, Gobies) is running against internal targets. Investigate the source host, the full DNS query string (the unique subdomain prefix encodes the callback session), and any concurrent outbound connections or process behavior to determine intent.
sigmaNetworkPaid2026-03-22Possible Juniper BGP Missing MD5 (via bgp)
lowThis rule detects juniper BGP missing MD5 digest. Which may be indicative of brute force attacks to manipulate routing.
sigmaNetwork2026-03-17Possible WebDav Put Request (via http)
lowThis rule detects a General detection for WebDav user-agent being used to PUT files on a WebDav network share. This could be an indicator of exfiltration.
sigmaNetwork2026-03-15Suspicious Remote Task Creation through ATSVC Named Pipe - Zeek (via smb_files)
mediumThis rule detects remote task creation via at.exe or API interacting with ATSVC namedpipe
sigmaNetwork2026-03-10Possible Huawei BGP Authentication Failures (via bgp)
lowThis rule detects BGP failures which may be indicative of brute force attacks to manipulate routing.
sigmaNetwork2026-03-05Suspicious Cisco Local Accounts (via aaa)
highThis rule detects local accounts being created or modified as well as remote authentication configurations
sigmaNetworkPaid2026-03-05