Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Malicious XE Group thump.aspx Webshell Interaction via File Directory Parameters (via webserver)
This rule detects requests to the XE Group .thump.aspx webshell that carry the file-listing and file-read parameters the operator uses to browse and exfiltrate server files. The hidden-prefixed ASPX name combined with these directory parameters distinguishes webshell tasking from normal application traffic.
HuntRule TeamWebwebserverHigh62Premium2026-06-04Possible Pre-Auth SSRF via VMware Workspace One UEM BlobHandler CVE-2021-22054
This rule detects HTTP requests to the VMware Workspace One UEM BlobHandler.ashx endpoint carrying a Url parameter. CVE-2021-22054 is a pre-authentication server-side request forgery reached through this handler with an encrypted Url payload as detailed by Assetnote, letting attackers pivot to internal services and cloud metadata.
HuntRule TeamWebwebserverHigh1810Premium2026-06-02Suspicious Khmer Shadow C2 Beacon with Malformed Chrome User-Agent (via proxy)
This rule detects outbound requests carrying the malformed Chrome 131 on Windows 10 user-agent string used by the Khmer Shadow implant to blend its C2 traffic. Adversaries craft this non-standard agent value that does not match any real browser build. The exact malformed string provides a low-noise channel indicator for this espionage cluster.
HuntRule TeamWebproxyMedium224Premium2026-06-02Suspicious Telegram Bot API Command and Control Communication (via proxy)
This rule detects outbound web requests to the Telegram Bot API endpoint on api.telegram.org that include a bot path, a command and control channel HookSpoofer stealer abuses to exfiltrate stolen data. The stealer posts harvested credentials and files to a hardcoded bot token. Because Telegram is also used legitimately this indicator is low confidence and best correlated with host stealer activity.
HuntRule TeamWebproxyLow448Premium2026-05-31Suspicious RedHook Android RAT WebSocket Device Channel (via proxy)
This rule detects WebSocket connections to the RedHook Android RAT device channel identified by the ws/device path with the misspelled menberId parameter. The RAT maintains a real-time control socket to the operator using this distinctive URI. Detecting it flags a live command-and-control session from an infected device.
HuntRule TeamWebproxyHigh93Premium2026-05-31ScreenConnect SetupWizard Authentication Bypass Path Traversal (CVE-2024-1709)
This rule detects web requests to the ScreenConnect SetupWizard.aspx endpoint followed by an extra trailing path segment, the request shape that triggers the CVE-2024-1709 authentication bypass. Huntress observed this pattern used to reach the setup wizard on already configured servers and create attacker administrator accounts. A trailing path after SetupWizard.aspx is not produced by normal setup flows and indicates exploitation.
HuntRule TeamWebwebserverHigh337Premium2026-05-30Suspicious C2 Beacon via cpp-httplib User Agent
This rule detects outbound HTTP requests carrying the cpp-httplib user agent, matching the Potemkin loader command-and-control channel observed with the test_agent identifier. The loader is built on the cpp-httplib library and this user agent rarely appears in legitimate enterprise browsing. Its presence in proxy or web telemetry indicates loader check-in and tasking.
HuntRule TeamWebproxyHigh306Premium2026-05-30Malicious Zloader C2 Communication Over HTTP
This rule detects HTTP requests to the Zloader command-and-control gate path milagrecf.php observed in the attempted attack against Intel 471. The fixed PHP gate receives beacons from the loader after the malicious Excel 4.0 macro executes. The hardcoded C2 path identifies compromised hosts contacting the operator regardless of the C2 host.
HuntRule TeamWebproxyHigh153Premium2026-05-30Possible Nagios XI Unauthenticated Terminal Web Shell Access
This rule detects access to the Nagios XI terminal endpoint which exposes an interactive web shell, an access path abused to gain unauthenticated command execution on the appliance. Requests to this terminal path from unexpected sources indicate probing or exploitation of the web shell functionality.
HuntRule TeamWebwebserverMedium407Premium2026-05-27Possible FortiGate RCE via Chunked hostcheck_validate Request (CVE-2024-21762)
This rule detects POST requests to the FortiGate SSL VPN hostcheck_validate endpoint using Transfer-Encoding chunked, matching the out-of-bounds write exploited in CVE-2024-21762 as analyzed by Assetnote. The exploit relies on a malformed chunked body with a zero-length terminator and excess trailer lines to corrupt memory and reach code execution. Detecting chunked requests to this specific endpoint surfaces attempts against the vulnerable parser.
HuntRule TeamWebwebserverHigh41Premium2026-05-25Possible VMware Workspace ONE SSRF via instanceHealth hostName At-Injection (via webserver)
This rule detects requests to the SAAS REST instanceHealth endpoint whose hostName or path parameters contain an at-sign injection redirecting the server-side request to an attacker host. This is the post-auth SSRF CVE-2021-22056 used to leak administrative JWT Authorization tokens from internal cluster instances. Detecting it surfaces token theft and internal request forgery against the vulnerable appliance.
HuntRule TeamWebwebserverHigh91Premium2026-05-24Malicious Koi Loader C2 Check-in via Index PHP Beacon (via proxy)
This rule detects Koi Loader command-and-control beacons to an index.php endpoint carrying the campaign-specific subid=px8eIkut parameter used for host registration. This structured query pattern accompanies the pipe-delimited 101|GUID|VoYGkc5R check-in marker. Detecting it surfaces active Koi Loader C2 that precedes Koi Stealer deployment and credential exfiltration.
HuntRule TeamWebproxyHigh112Premium2026-05-24Possible NetHealth Implant C2 Beacon URI Pattern
This rule detects outbound HTTP requests matching the structured C2 beacon paths used by the Rapid Breach implant, including the resutato.com tap.php stager and the st.php beacon carrying computer and user name query parameters. These fixed URI patterns indicate command-and-control communication with the attacker infrastructure.
HuntRule TeamWebproxyHigh173Premium2026-05-23Suspicious AiTM Phishing Kit Session Validation Endpoint via Proxy
This rule detects web requests to reverse-proxy adversary-in-the-middle phishing kit endpoints, specifically the check_response handler carrying a session_id parameter alongside kit paths such as api/login, 2fa, sms and tap. It is associated with the Operation Fake KickOff campaign that abused recruiters and SaaS services to harvest corporate credentials and relay multi-factor authentication tokens. Detecting these structured kit paths surfaces live credential and MFA session theft.
HuntRule TeamWebproxyHigh241Premium2026-05-22Malicious Ivanti EPMM Exploitation via appstore fob Endpoint (via webserver)
This rule detects requests to the Ivanti EPMM exploit endpoints under the appstore and aftstore fob paths, the access pattern used to trigger CVE-2026-1281 and CVE-2026-1340. Hitting these routes drives unauthenticated code paths that lead to JSP webshell deployment and reverse shells.
HuntRule TeamWebwebserverHigh162Premium2026-05-22