Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Suspicious Cloudflare Workers Brand-Impersonation Phishing Domains via Proxy
This rule detects proxy requests to Cloudflare Workers subdomains that impersonate document and cloud storage brands such as docviewer, onedrive, and adobe, matching the phishing lure infrastructure of the ARToken EvilTokens campaign reported by Cisco Talos. Attackers host credential and device-code capture pages on ephemeral workers.dev subdomains. Detecting these brand-mimicking hosts flags users being funneled into the phishing panel.
HuntRule TeamWebproxyMedium00Premium2026-09-12Malicious BadIIS C2 Communication via lwxatisme User-Agent
This rule detects HTTP traffic carrying the User-Agent string lwxatisme, a fixed marker used by the commodity BadIIS ecosystem tracked by Talos to authenticate to its C2. The BadIIS native IIS module keys off this hardcoded agent to gate operator commands. Presence of this User-Agent indicates a BadIIS-infected server communicating with its controller.
HuntRule TeamWebproxyHigh00Premium2026-09-12Suspicious UAT-10608 Credential Harvesting C2 Beacon via HTTP
This rule detects outbound HTTP requests carrying the UAT-10608 command-and-control beacon layout where the URI encodes the victim host, the harvesting phase and a campaign identifier as h, l and id parameters. This structured query pattern is used by the credential harvesting operation to report progress and exfiltrate results over HTTP. Matching traffic indicates an actively beaconing compromised host.
HuntRule TeamWebproxyMedium00Premium2026-09-12Possible PS1Bot C2 Beacon With Drive Serial URI Pattern (via proxy)
This rule detects HTTP GET requests whose URI query contains the PS1Bot command-and-control marker k=result used to exfiltrate results keyed by the victim drive serial number. This structured URI pattern identifies PS1Bot beaconing to its command-and-control server. Detection of this traffic reveals active command-and-control and data exfiltration.
HuntRule TeamWebproxyMedium00Premium2026-09-12Suspicious WarmCookie C2 Beacon With Fixed Firefox User-Agent
This rule detects web traffic carrying the hardcoded Firefox 115.0 User-Agent string used by WarmCookie. WarmCookie beaconed to its command-and-control servers with a fixed Mozilla Firefox 115.0 User-Agent regardless of the host browser. A single static outdated User-Agent applied to all C2 requests is an application-layer protocol indicator that stands out from real browser diversity.
HuntRule TeamWebproxyMedium00Premium2026-09-12Malicious GhostLocker2 C2 Communication via HTTP POST (via proxy)
This rule detects HTTP POST requests to the GhostLocker2 command-and-control endpoints /addInfection and /incrementLaunch used by GhostSec ransomware. These beacons report new infections and launch counts to the operator panel and indicate active ransomware deployment.
HuntRule TeamWebproxyHigh00Premium2026-09-12Malicious RemusStealer Credential Exfiltration to pics TLD C2
This rule detects HTTP POST requests to hosts under the .pics top-level domain whose body carries access_token and step parameters, the exfiltration pattern of RemusStealer distributed by this ecosystem. This structured upload to an uncommon TLD signals active credential and session-token theft.
HuntRule TeamWebproxyHigh40Premium2026-09-09Malicious NSIS_InetLoad User-Agent C2 Traffic in Malware Distribution Ecosystem
This rule detects outbound HTTP requests carrying the User-Agent NSIS_InetLoad (Mozilla), a fixed string emitted by NSIS-based downloaders in this malware distribution ecosystem when fetching second-stage payloads. This unusual agent is a reliable network indicator of the loader stage.
HuntRule TeamWebproxyHigh110Premium2026-09-09Possible React2Shell CVE-2025-55182 Prototype Pollution Exploitation
This rule detects web requests carrying prototype pollution markers that reach Node.js command execution primitives. This is the exploitation pattern for CVE-2025-55182 also known as React2Shell against public facing Node.js and React applications.
HuntRule TeamWebwebserverHigh20Premium2026-09-08Possible Next.js Middleware Auth Bypass via X-Middleware-Subrequest Header (CVE-2025-29927)
This rule detects HTTP requests carrying the X-Middleware-Subrequest header, which Next.js internally uses to prevent middleware recursion and which attackers forge to bypass middleware-based authentication in CVE-2025-29927 as analyzed by Assetnote. A client-supplied value for this header causes the framework to skip auth middleware and return protected content. Because legitimate external clients never send this internal header, its presence strongly indicates an exploitation attempt.
HuntRule TeamWebwebserverHigh80Premium2026-09-08Possible Ivanti Pulse Connect Secure Command Injection via License Keys-Status Endpoint (via webserver)
This rule detects requests to the Pulse Connect Secure license keys-status API node parameter carrying shell metacharacters. This maps to the command injection flaw where the node name is passed unsanitized into a shell context. An attacker uses this to execute arbitrary operating system commands on the appliance.
HuntRule TeamWebwebserverMedium190Premium2026-09-08Possible Ivanti Pulse Connect Secure Auth Bypass via TOTP Backup Code Path Traversal (via webserver)
This rule detects requests to the Pulse Connect Secure TOTP user backup code API containing directory traversal sequences. This maps to the authentication bypass where traversal from the totp endpoint reaches restricted admin and system functions. An attacker uses this to bypass authentication and pivot toward remote code execution.
HuntRule TeamWebwebserverHigh190Premium2026-09-08Possible Citrix ShareFile Unauthenticated Upload Path Traversal Webshell (CVE-2023-24489) (via webserver)
This rule detects unauthenticated POST requests to the ShareFile storage controller upload endpoints carrying a traversal uploadid and archive extraction flags. This maps to CVE-2023-24489 where a cryptographic flaw allows uploading and unzipping an ASPX webshell outside the intended directory. An attacker uses this to achieve remote code execution and persistence.
HuntRule TeamWebwebserverHigh230Premium2026-09-08Suspicious Citrix StoreFront SAML Test Endpoint Access for XSS (CVE-2023-5914) (via webserver)
This rule detects POST requests to the Citrix StoreFront SAML test authentication endpoint associated with CVE-2023-5914. This maps to abuse of the SamlTest handler where a crafted SAMLResponse reflects into a cross-site scripting payload. An attacker leverages this to execute script in an administrator context.
HuntRule TeamWebwebserverMedium50Premium2026-09-08Possible Citrix Bleed Session Token Leak via OpenID Configuration Endpoint (CVE-2023-4966) (via webserver)
This rule detects requests to the NetScaler OpenID configuration discovery endpoint used to trigger CVE-2023-4966 memory disclosure. This maps to Citrix Bleed where an oversized Host header causes the appliance to leak adjacent memory containing session tokens. An attacker replays the leaked NSC_AAAC cookie to hijack authenticated sessions.
HuntRule TeamWebwebserverMedium100Premium2026-09-08