Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Suspicious BumbleBee C2 URI Pattern (via proxy)
This rule detects outbound web requests to the BumbleBee command-and-control URI paths such as get_load, gate and gates. These fixed endpoint names are used by the loader to fetch tasks and payloads. Matching this beacon pattern surfaces infected hosts communicating with attacker infrastructure for tasking and payload delivery.
HuntRule TeamWebproxyMedium81Premium2026-06-19Malicious Cloud Metadata Credential SSRF via HTTP (via proxy)
This rule detects HTTP requests to the cloud instance metadata IAM security credentials path on Linux hosts. Attackers exploiting the LMDeploy server side request forgery vulnerability coerced the inference engine into fetching temporary IAM credentials from the metadata service. Requests reaching the metadata credentials endpoint from an application server indicate credential theft through SSRF.
HuntRule TeamWebproxyHigh72Premium2026-06-18Malicious Discord RAT Module Download from GitHub via Proxy
This rule detects retrieval of Discord RAT plugin modules hosted on the public Discord-RAT-2.0 GitHub repository. The malware dynamically downloads and reflectively loads capability modules such as credential theft, webcam capture, and token stealers from this raw content path.
HuntRule TeamWebproxyHigh131Premium2026-06-18Suspicious PHP Webshell Access under WordPress Cache Directory
This rule detects HTTP requests to a PHP file located in the WordPress wp-content cache directory. Legitimate WordPress caching stores static HTML and never executable PHP, so a PHP file served from this path indicates a dropped webshell used for post exploitation command execution.
HuntRule TeamWebwebserverHigh426Premium2026-06-15SharePoint spinstall Webshell Deployment after ToolShell Exploitation (via webserver)
This rule detects requests to spinstall or related aspx webshells dropped after ToolShell exploitation of SharePoint CVE-2025-53770, which extract the ValidationKey and DecryptionKey machine key material from the server. Adversaries retrieve these keys to forge authentication and regain access even after patching.
HuntRule TeamWebwebserverHigh103Premium2026-06-13Download of Fake Messaging App Update APK
This rule detects proxy or web download requests for APK files masquerading as updates for popular messaging and social apps. Arid Viper distributed Android spyware as fake update packages such as whatsapp-update.apk, messenger-update.apk, google-play-update.apk and instagram-update.apk. These update-themed APK names impersonate trusted applications to trick users into sideloading spyware.
HuntRule TeamWebproxyMedium407Premium2026-06-11Malicious SharePoint spinstall Web Shell Access Leaking Machine Keys
This rule detects web requests to the spinstall web shell dropped during on-premises SharePoint exploitation. Microsoft observed spinstall0.aspx and its variants deployed to leak the server MachineKey via GET requests. Retrieval of the ASP.NET machine key enables forged payloads and full compromise, so any access to this web shell is a critical finding.
HuntRule TeamWebwebserverCritical142Premium2026-06-11Suspicious Access to SonicWall SMA JSP Webshell
This rule detects HTTP requests to JSP webshells planted on a compromised SonicWall SMA appliance. In the 0-day exploitation the actor placed error.jsp and errorDialog.jsp under the workplace directory and proxied them to a local listener to execute commands. Access to these attacker-planted endpoints indicates active webshell interaction and hands-on-keyboard control of the appliance.
HuntRule TeamWebwebserverHigh81Premium2026-06-09Possible MOVEit Transfer Exploitation via MOVEitISAPI action m2 and X-siLock Headers
This rule detects requests to MOVEitISAPI.dll with action=m2 that also carry X-siLock control headers, matching the MOVEit Transfer RCE chain analyzed by Assetnote for CVE-2023-34362. The X-siLock headers drive internal session-variable manipulation used in the SQL injection to RCE path. Detecting this handler and header pairing surfaces active exploitation of the MOVEit ISAPI extension.
HuntRule TeamWebwebserverHigh132Premium2026-06-09Possible Yellowfin BI JWT Forgery via refresh-tokens Endpoint
This rule detects HTTP requests to the Yellowfin BI /api/refresh-tokens endpoint associated with forged JWT abuse. Assetnote used hardcoded signing keys to mint tokens against this API before triggering JNDI-injection remote code execution, so anomalous access here can indicate exploitation.
HuntRule TeamWebwebserverMedium145Premium2026-06-08TAG-144 Payload Staging via MyCustomAgent User-Agent (via proxy)
This rule detects HTTP requests using the hardcoded MyCustomAgent/1.0 user-agent that the TAG-144 loader sets when pulling staged payloads from paste services via ServerXMLHTTP. Adversaries leverage a fixed non-browser user-agent to fetch second-stage code, making this distinctive string a reliable delivery-stage indicator.
HuntRule TeamWebproxyHigh92Premium2026-06-07Possible Path Traversal Local File Inclusion Against Exposed Cloud Function (via webserver)
This rule detects web requests containing directory traversal sequences targeting sensitive Unix files such as etc/passwd, matching the local file inclusion probes sent to exposed Cloud Function endpoints. Adversaries use these payloads to read arbitrary files and enumerate a container before escalating to remote code execution, so traversal attempts against run.app services should be reviewed.
HuntRule TeamWebwebserverLow323Premium2026-06-07Possible Citrix NetScaler SAML Endpoint Abuse for Pre-Auth RCE (CVE-2023-3519) (via webserver)
This rule detects requests to the NetScaler SAML processing endpoints associated with CVE-2023-3519 exploitation. This maps to abuse of the SAML login and artifact endpoints where crafted assertions trigger the memory corruption vulnerability. An attacker leverages these unauthenticated endpoints to achieve remote code execution on the gateway.
HuntRule TeamWebwebserverMedium438Premium2026-06-07Malicious CR4T C2 Beacon via TroubleShooter User-Agent (via proxy)
This rule detects outbound HTTP requests carrying the distinctive TroubleShooter User-Agent string which the CR4T implant of the DuneQuixote campaign uses when communicating with its command-and-control server.
HuntRule TeamWebproxyHigh339Premium2026-06-06Suspicious FakeBat Fake Browser Update Stats and Download Endpoints (via proxy)
This rule detects requests to the FakeBat distribution endpoints get_stats.php and the misspelled dwnl_standart.php used by fake browser update pages to track victims and serve the MSIX payload. The typo-laden download path is a distinctive campaign artifact hosted on doggygangers[.]com. This surfaces drive-by delivery of FakeBat leading to LummaC2.
HuntRule TeamWebproxyMedium316Premium2026-06-05