Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
45 rules
Suspicious Raw Paste Service Access (via proxy)
highThis rule detects direct access to raw pastes in different paste services frequently used by malware in their second stages to download hostile code in encrypted or encoded form
sigmaWebPaid2026-07-27Malicious HackTool - BabyShark Agent Default URL Pattern (via proxy)
criticalThis rule detects Baby Shark C2 Framework default communication patterns
sigmaWebPaid2026-07-10Suspicious APT User Agent (via proxy)
highThis rule detects anomalous user agent strings used in APT malware in proxy logs
sigmaWebPaid2026-07-03Possible Base64 Encoded User-Agent (via proxy)
mediumThis rule detects User Agent strings that end with an equal sign, that can be a sign of base64 encoding.
sigmaWeb2026-06-30Malicious Malware User Agent (via proxy)
highThis rule detects anomalous user agent strings used by malware in proxy logs
sigmaWebPaid2026-06-19Possible Source Code Enumeration Detection by Keyword (via webserver)
mediumThis rule detects source code enumeration that use GET requests by keyword searches in URL strings
sigmaWeb2026-06-18Malicious Webshell ReGeorg Detection Through Web Logs (via webserver)
highThis rule detects certain strings in the uri_query field when combined with null referer and null user agent can indicate behavior linked with the webshell ReGeorg.
sigmaWebPaid2026-06-01Suspicious Rclone Behavior through Proxy (via proxy)
mediumThis rule detects the use of rclone, a command-line program to manage files on cloud storage, via its default user-agent string
sigmaWeb2026-05-31Download From Suspicious TLD - Whitelist (via proxy)
lowThis rule detects executable downloads from anomalous remote systems
sigmaWeb2026-05-31Suspicious Execution of F5 BIG-IP iControl Rest API Command - Webserver (via webserver)
mediumThis rule detects POST requests to the F5 BIG-IP iControl Rest API "bash" endpoint, which enables the execution of commands on the BIG-IP
sigmaWeb2026-05-29Flash Player Update from Suspicious Location (via proxy)
highThis rule detects a flashplayer update from an unofficial location
sigmaWebPaid2026-05-26Suspicious Cross Site Scripting Strings (via webserver)
highThis rule detects XSS attempts injected via GET requests in access logs
sigmaWebPaid2026-05-23Suspicious PUA - Advanced IP/Port Scanner Update Check (via proxy)
mediumThis rule detects the update check performed by Advanced IP/Port Scanner utilities.
sigmaWeb2026-05-20Malicious HackTool - Empire UserAgent URI Combo (via proxy)
highThis rule detects user agent and URI paths used by empire agents
sigmaWebPaid2026-05-17Suspicious Apache Segmentation Fault (via apache)
highThis rule detects a segmentation fault error message caused by a crashing apache worker process
sigmaWebPaid2026-05-12Bitsadmin to Unusual TLD (via proxy)
highThis rule detects Bitsadmin connections to domains with uncommon TLDs
sigmaWebPaid2026-05-09Suspicious User-Agents Related To Recon Utilities (via webserver)
mediumThis rule detects known anomalous (default) user-agents related to scanning/recon tools
sigmaWeb2026-05-05Malicious Path Traversal Exploitation Attempts (via webserver)
mediumThis rule detects path traversal exploitation attempts
sigmaWeb2026-05-04Suspicious Network Traffic With IPFS (via proxy)
lowThis rule detects connections to interplanetary file system (IPFS) containing a user's email address which mirrors behaviours observed in recent phishing campaigns abusing IPFS to host credential harvesting webpages.
sigmaWeb2026-05-03Suspicious Hack Utility User Agent (via proxy)
highThis rule detects anomalous user agent strings user by hack tools in proxy logs
sigmaWebPaid2026-05-02