Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Suspicious AWS Console AiTM Phishing Kit API Endpoints
This rule detects requests to the AWS console phishing kit API endpoints that relay login attempts using its distinctive input_24 parameter. The adversary-in-the-middle kit proxies AWS console authentication through check, login, and auth routes to capture credentials in real time. Traffic to these kit endpoints carrying the input_24 field indicates victims interacting with the AWS console phishing infrastructure.
HuntRule TeamWebproxyHigh121Premium2026-05-21Suspicious Marimo Terminal WebSocket RCE Access via Webserver
This rule detects access to the marimo terminal WebSocket endpoint that an attacker abused for remote code execution as the initial pivot in an LLM-guided intrusion toward an internal database. The endpoint exposes an interactive shell over the notebook interface. Requests to this path from untrusted sources indicate attempted exploitation of the exposed marimo service.
HuntRule TeamWebwebserverMedium121Premium2026-05-20Possible Citrix NetScaler Webshell Deployment under VPN Theme Directory (CVE-2023-3519) (via webserver)
This rule detects requests to PHP files located under the NetScaler VPN theme directory. This maps to post-exploitation of CVE-2023-3519 where attackers write a PHP webshell to /var/vpn/theme after the buffer overflow. Access to a PHP resource in this static theme path indicates a deployed webshell used for persistent remote command execution.
HuntRule TeamWebwebserverHigh403Premium2026-05-20Possible Metabase Pre-Auth RCE via H2 JDBC Injection on Setup Validate (CVE-2023-38646) (via webserver)
This rule detects requests to the Metabase setup validate endpoint carrying an H2 JDBC connection string with a trace level directive referencing the application jar. This maps to CVE-2023-38646 where a leaked setup token allows unauthenticated H2 injection to write and execute code. An attacker uses this chain to achieve remote code execution before authentication.
HuntRule TeamWebwebserverHigh131Premium2026-05-19Suspicious Nmap Scripting Engine User-Agent in HTTP Requests (via webserver)
This rule detects HTTP requests carrying the Nmap Scripting Engine user-agent string, indicating automated NSE web probing against exposed services. Scanning activity of this kind precedes exploitation as adversaries enumerate service versions and vulnerabilities. Identifying the NSE user-agent surfaces active reconnaissance targeting internet-facing or ICS-adjacent web assets.
HuntRule TeamWebwebserverMedium74Premium2026-05-19Possible Log4Shell JNDI Injection in HTTP Request
This rule detects JNDI lookup strings in HTTP request URIs or fields, indicative of Log4Shell (CVE-2021-44228) exploitation attempts against Log4j. Attackers embed jndi:ldap, jndi:rmi, or jndi:dns references, often inside headers such as X-Api-Version, to force the vulnerable logger to fetch and execute a remote class.
HuntRule TeamWebwebserverHigh132Premium2026-05-18Mirai and Rondo Payload Retrieval via Known Loader Paths
This rule detects outbound web requests to loader paths used to distribute Mirai binaries and the Rondo cryptominer. These retrievals follow CVE-2025-55182 exploitation of IoT and smart home devices.
HuntRule TeamWebproxyHigh229Premium2026-05-17ZOHOMURK Non-Browser Zoho and IPFetcher User-Agents (via proxy)
This rule detects the hardcoded Zoho client and IPFetcher user-agent strings used by the ZOHOMURK implant when abusing Zoho WorkDrive and ipinfo.io during the Mustang Panda campaign. Adversaries reuse these non-browser agent strings for OAuth, folder enumeration and external IP discovery. Because legitimate Zoho software does not emit these exact tokens, the agents provide a reliable channel indicator.
HuntRule TeamWebproxyMedium112Premium2026-05-14Possible PAN-OS Auth Bypass via Double-Encoded Path Traversal to ztp_gate (CVE-2025-0108)
This rule detects requests to the PAN-OS unauth path that use double-encoded traversal sequences to reach authenticated PHP scripts such as ztp_gate.php, matching the Nginx and Apache path confusion auth bypass for CVE-2025-0108 documented by Assetnote. The double-encoded %252e segments defeat the X-pan-AuthCheck routing and expose privileged management endpoints. This encoded traversal against ztp_gate indicates an attempt to bypass authentication on the management interface.
HuntRule TeamWebwebserverHigh432Premium2026-05-14Suspicious HijackLoader Connectivity Check to Apache Incubator Logo (via proxy)
This rule detects HTTP requests to the Apache incubator default.png logo path that HijackLoader uses as an internet connectivity check before contacting its command and control server. This exact static resource request from non browser processes is uncommon.
HuntRule TeamWebproxyMedium145Premium2026-05-12Possible Citrix Session Recording SOAPAction Deserialization RCE (CVE-2023-6184) (via webserver)
This rule detects POST or M-POST requests to the Citrix Session Recording broker rem endpoints carrying a SOAPAction header. This maps to the .NET deserialization vulnerability where crafted SOAP requests to the RestApiStat and Player broker interfaces execute arbitrary code. An attacker uses this to gain remote code execution on the session recording server.
HuntRule TeamWebwebserverHigh187Premium2026-05-12Malicious SSLoad Downloader C2 Beacon via Custom SSLoad User-Agent (via proxy)
This rule detects outbound HTTP traffic carrying the hardcoded SSLoad User-Agent used by the SSLoad downloader when it registers a fingerprinted host and beacons for tasks to its command-and-control server. This bespoke agent string is not produced by legitimate software and identifies the downloader stage of the intrusion on the wire.
HuntRule TeamWebproxyHigh71Premium2026-05-11Possible Ivanti Connect Secure Path Traversal Exploitation
This rule detects HTTP requests to the Ivanti Connect Secure TOTP backup-code endpoint containing directory traversal sequences, the access pattern used to exploit the authentication bypass zero-day. Threat actors chain this traversal to reach restricted API paths and deploy webshells. Detecting these requests exposes active exploitation of the Ivanti appliance.
HuntRule TeamWebwebserverHigh201Premium2026-05-11Suspicious Chafer Backdoor HTTP C2 Communication via Proxy
This rule detects HTTP requests to the comm.aspx endpoint used by the Chafer backdoor for command-and-control communication. Observed in NCC Group research analyzing the Chafer backdoor beaconing to comm.aspx over HTTP. Identifying this request path helps detect infected hosts contacting Chafer C2 infrastructure.
HuntRule TeamWebproxyLow3010Premium2026-05-11Possible Origin Logger C2 Exfiltration via Hardcoded User Agent and Gate Endpoints via proxy
This rule detects Origin Logger keylogger command and control traffic that beacons with a hardcoded Firefox/99.0 user agent to /gate and /login exfiltration endpoints. Origin Logger is an AgentTesla derived stealer that harvests browser credentials and web session data. Correlating the fixed user agent with the exfil URI paths surfaces credential theft egress while suppressing benign Firefox browsing.
HuntRule TeamWebproxyHigh355Premium2026-05-09