Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Possible Citrix NetScaler CVE-2023-4966 Session Token Disclosure
This rule detects HTTP requests to the OpenID configuration discovery endpoints on Citrix NetScaler that are abused by CVE-2023-4966 to disclose session memory and steal valid session tokens. When paired with an abnormally large Host header these requests indicate exploitation attempts against an exposed NetScaler appliance for session hijacking.
HuntRule TeamWebwebserverMedium111Premium2026-06-25Suspicious CTF-Framed Vulnerability Scanner User Agent via Webserver
This rule detects HTTP User-Agents matching the CTF and CVE-hunt framing that attackers use while jailbreaking LLM services and mass-scanning for vulnerabilities. These agents self-identify with capture-the-flag and CVE-scanner labels as part of automated probing. Their presence indicates reconnaissance against internet-facing AI applications.
HuntRule TeamWebwebserverMedium238Premium2026-06-25Possible Mamba 2FA AiTM Phishing URL Pattern
This rule detects HTTP requests matching the Mamba 2FA adversary in the middle phishing URL structure of a single letter path segment m, n or o followed by a query string carrying a Base64 encoded victim token. Mamba 2FA relays Microsoft 365 credentials and session cookies through this pattern to bypass multifactor authentication. Because the pattern is broad it should be corroborated with the known relay domains before action.
HuntRule TeamWebproxyLow354Premium2026-06-24Suspicious Data Exfiltration to Telegram Bot API sendDocument (via proxy)
This rule detects HTTP requests to the Telegram Bot API sendDocument endpoint, the exfiltration channel used by 0bj3ctivityStealer to upload harvested credentials and wallet data as documents to an attacker-controlled bot. Adversaries leverage Telegram as a resilient exfiltration service that blends with legitimate traffic, making detection of bot document uploads useful for exposing data theft.
HuntRule TeamWebproxyMedium123Premium2026-06-24CastleLoader Stager HTTP Beacon via Misspelled GoogeBot User-Agent (via proxy)
This rule detects outbound HTTP requests carrying the misspelled GoogeBot user-agent used by the CastleLoader stager to retrieve follow-on TAG-150 payloads while masquerading as a search-engine crawler. Adversaries leverage crawler-like user-agents to blend malicious downloads into ordinary web traffic, making this distinctive typo a reliable delivery-stage indicator.
HuntRule TeamWebproxyHigh191Premium2026-06-23Suspicious SSRF Probe for Cloud Instance Metadata Service
This rule detects HTTP requests attempting to reach the cloud instance metadata service link local address through a url parameter. Attackers abuse server side request forgery to pull IAM security credentials from the metadata endpoint of a misconfigured public facing application.
HuntRule TeamWebwebserverHigh102Premium2026-06-23IDAT Loader Delivery via Compromised WordPress wpstream youtube.min.js (via proxy)
This rule detects HTTP requests to the wpstream plugin youtube.min.js path used by the UAC-0184 IDAT Loader campaign to stage its steganographic payload from a compromised WordPress site. Adversaries leverage a legitimate-looking script path on a hijacked site to blend delivery traffic with normal content requests, making early detection critical for catching the intrusion at the delivery stage before Remcos RAT is deployed.
HuntRule TeamWebproxyMedium133Premium2026-06-23Suspicious HTTP Beacon Using Rare MyIE User Agent (via proxy)
This rule detects outbound HTTP traffic carrying the uncommon MyIE user agent string used by the MemFun implant in a suspected China-based espionage operation against military targets in Southeast Asia. The hardcoded user agent identifies the malware's beaconing channel, so matching traffic to external hosts indicates active command and control.
HuntRule TeamWebproxyMedium287Premium2026-06-22Suspicious Error 524 Decoy Smishing Phishing Endpoint Access (via proxy)
This rule detects access to the single-page phishing endpoints used by the Error 524 decoy smishing campaign, including getApp application-id lookups and WebSocket uuid exfiltration paths. The campaign hides credential and card data theft behind fake Cloudflare Error 524 pages. Detecting these URIs reveals victims interacting with the phishing infrastructure.
HuntRule TeamWebproxyMedium92Premium2026-06-22Possible FortiWeb Authentication Bypass via Path Traversal to fwbcgi (via webserver)
This rule detects HTTP requests to the FortiWeb management CMDB admin API that traverse into the internal fwbcgi CGI handler. This request pattern corresponds to CVE-2025-64446 which lets unauthenticated attackers create administrator accounts. Legitimate API clients do not reach cgi-bin through path traversal.
HuntRule TeamWebwebserverHigh112Premium2026-06-22Malicious Lazarus ScoringMathTea WordPress C2 URL Path
This rule detects HTTP requests to the compromised WordPress command-and-control path used by the ScoringMathTea RAT in the Lazarus UAV-sector campaign. The RAT beacons to a theme functions file at inc/functions/function-hand.php, and this structured path is a durable network indicator of the malicious channel.
HuntRule TeamWebproxyHigh102Premium2026-06-22Possible F5 iControl REST Remote Code Execution via Util Bash Endpoint
This rule detects POST requests to the F5 iControl REST util bash endpoint which grants arbitrary command execution when reached after the SSRF authentication bypass of CVE-2021-22986 documented by NCC Group. Access to this endpoint by an unauthenticated actor indicates full appliance compromise.
HuntRule TeamWebwebserverHigh132Premium2026-06-21Suspicious 0ktapus Phishing Kit Credential Post Path Access
This rule detects web requests to the /login/email and /login/identifier endpoints combined with the Poll.js resource which are DOM and URL fingerprints of the 0ktapus phishing kit that impersonates Okta and single sign-on portals. This is important because these paths are hardcoded artifacts of the kit used to harvest credentials and multi-factor codes so their presence in proxy logs indicates a user interacting with a 0ktapus phishing site.
HuntRule TeamWebproxyMedium269Premium2026-06-21Malicious Tycoon 2FA AiTM Phishing WebSocket Channel
This rule detects the Tycoon 2FA phishing kit opening its adversary-in-the-middle relay over the fixed /web6socket/socket.io WebSocket endpoint. This path is unique to the kit and identifies a victim connecting to the AiTM proxy used to steal session cookies.
HuntRule TeamWebproxyHigh101Premium2026-06-20Suspicious Malware Delivery via Discord CDN Attachment
This rule detects downloads of archive and executable payloads from the Discord content delivery network attachments path which criminal actors abuse to host and distribute malware. Because Discord is a widely trusted service this channel is frequently used to bypass reputation based controls for staging second stage payloads.
HuntRule TeamWebproxyMedium362Premium2026-06-19