Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Suspicious BunnyLoader C2 Gate Endpoint Communication (via proxy)
This rule detects HTTP requests to a gate.php endpoint, the command and control resource BunnyLoader polls to register infected hosts and pull tasking on a short heartbeat interval. This gate path is a common malware beacon convention, so requests to it warrant review for loader command and control traffic.
HuntRule TeamWebproxyMedium102Premium2026-05-09Possible Palo Alto PAN-OS Authentication Bypass via PHP Path Confusion js.map Suffix (via webserver)
This rule detects the path confusion technique in Palo Alto PAN-OS CVE-2024-0012 where a request appends a js.map suffix after a php script to bypass the authentication check on management endpoints. The mixed php and js.map path is not produced by normal clients.
HuntRule TeamWebwebserverHigh181Premium2026-05-09Suspicious Metabase Setup Token Disclosure via Session Properties Endpoint (CVE-2023-38646) (via webserver)
This rule detects requests to the unauthenticated Metabase session properties endpoint that leaks the setup token. This maps to the reconnaissance stage of CVE-2023-38646 where the token is harvested to enable the H2 JDBC injection. Repeated or external access to this endpoint may indicate an attacker preparing pre-auth code execution.
HuntRule TeamWebwebserverLow363Premium2026-05-08Possible Sitecore Path Traversal via ValidateXHtml PAGESTATE Injection
This rule detects requests to the Sitecore EditHtml.ValidateXHtml handler carrying a __PAGESTATE parameter with directory traversal sequences, matching the order-of-operations bug that Assetnote leveraged to reach RCE in Sitecore 8.x to 10.x. The traversal in the page-state value leaks server paths and enables the subsequent exploitation chain. Early detection of this handler abuse exposes reconnaissance before code execution.
HuntRule TeamWebwebserverHigh338Premium2026-05-06Malicious BadIIS SEO Poisoning C2 Request via Web Server (via webserver)
This rule detects HTTP requests to the hardcoded BadIIS command-and-control endpoint used by the Operation Rewrite SEO poisoning campaign. The BadIIS native IIS module intercepts requests and communicates with attacker infrastructure through this fixed URI path. Detecting these requests exposes a compromised IIS server acting as a malicious proxy for SEO fraud and traffic redirection.
HuntRule TeamWebwebserverHigh399Premium2026-05-06Possible Kentico Xperience Staging Sync Authentication Bypass via SyncServer Endpoint (via webserver)
This rule detects requests to the Kentico Xperience staging synchronization web service which is abused in the pre-auth RCE chain to upload objects after a password digest authentication bypass. Access to this SOAP endpoint from untrusted sources should be reviewed.
HuntRule TeamWebwebserverMedium451Premium2026-05-06Malicious Jamf Pro SSRF Targeting Cloud Metadata via imageUrl (via webserver)
This rule detects requests to the Jamf Pro eduFeatureSettingsTest endpoint whose imageUrl parameter references the cloud instance metadata address 169.254.169.254. This is the full-read SSRF CVE-2021-39303 and CVE-2021-40809 aimed at stealing AWS instance credentials from the metadata service. Detecting it surfaces active theft of cloud IAM credentials through the vulnerable server.
HuntRule TeamWebwebserverCritical113Premium2026-05-05Suspicious Watering Hole Exfiltration to Fake wp-includes Endpoint via SilentSelfie
This rule detects HTTP POST requests to the path /wp-includes/ms-menu.php, a fake WordPress endpoint used by the SilentSelfie watering hole campaign to receive stolen geolocation, WebRTC IP and webcam selfie data from visitors of compromised Kurdish websites. The ms-menu.php filename does not exist in genuine WordPress installations. Traffic to it indicates victim data exfiltration.
HuntRule TeamWebproxyHigh322Premium2026-05-05Possible Progress WhatsUp Gold SSRF via core render baseUrl (via webserver)
This rule detects PUT requests to the Progress WhatsUp Gold NmConsole core render API, abused as a server-side request forgery primitive through its baseUrl parameter. Attackers chained this SSRF to reach internal services and escalate impact on WhatsUp Gold deployments. Detecting it surfaces attempts to pivot into internal infrastructure via the monitoring server.
HuntRule TeamWebwebserverMedium322Premium2026-05-05Suspicious SharePoint ToolPane Endpoint Request via ToolShell (via webserver)
This rule detects HTTP requests to the SharePoint ToolPane.aspx endpoint carrying the DisplayMode Edit parameter, the exploitation vector for ToolShell (CVE-2025-53770). Attackers send crafted requests to this endpoint to bypass authentication and achieve remote code execution. Requests to this endpoint with an edit display mode are a strong indicator of exploitation attempts.
HuntRule TeamWebwebserverHigh254Premium2026-05-04Suspicious Telegram Bot API C2 Beaconing (via network)
This rule detects outbound HTTP requests to the Telegram bot API using sendPhoto and sendDocument methods which the CoralRaider actor abuses for command and control and exfiltration of stolen social media data. Abusing a legitimate messaging platform lets attackers hide C2 inside allowed web traffic and defeat domain reputation controls.
HuntRule TeamWebproxyMedium71Premium2026-05-04Suspicious Hello-World Scraper Botnet User-Agent in Web Requests
This rule detects inbound web requests carrying the User-Agent string Hello-World/1.0, a hardcoded identifier used by a scraper botnet concentrated in Taiwan that issues evenly distributed GET floods across ports 80 through 85. Surfacing this fingerprint reveals automated reconnaissance and scraping activity that often precedes targeted follow-on abuse.
HuntRule TeamWebwebserverMedium307Premium2026-05-03Possible PowerShell Empire Default User-Agent In HTTP Traffic
This rule detects outbound HTTP traffic carrying the default user-agent string shipped with the PowerShell Empire C2 framework. In the WithSecure C2 and Exfiltration Lab 1 the Empire agent beacons out with an unmodified Mozilla compatible MSIE user-agent that is characteristic of the framework default profile. Attackers rely on this static header for their staging and command channel unless an operator customizes it.
HuntRule TeamWebproxyLow51Premium2026-05-02Proxy HTTP GET traffic using Hello-World/1.0 user-agent (possible scraper botnet)
Flags proxy GET requests using the Hello-World/1.0 user-agent, which may indicate automated scraping.
Joseph A. M., Huntrule TeamWebproxyMedium194Free2025-08-02Proxy WebDAV MiniRedir Drives Execution from External Shares
Alert on external WebDAV MiniRedir GET requests for executable-like file extensions that may lead to execution.
Ahmed Farouk, Huntrule TeamWebproxyHigh213Free2024-05-10