Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Proxy Detection: Cobalt Strike Malleable C2 Profile HTTP URI/User-Agent/Method Patterns
Flags proxy HTTP requests whose URI, method, User-Agent, host, and cookie fragments match known Cobalt Strike malleable profile patterns.
Markus Neis, Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh3610Free2024-02-15F5 BIG-IP iControl REST Webserver POST to /mgmt/tm/util/bash Command Execution
Alerts on webserver POST requests to the BIG-IP iControl REST bash execution endpoint (/mgmt/tm/util/bash).
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule TeamWebwebserverMedium217Free2023-11-08F5 BIG-IP iControl REST API Bash Endpoint Command Execution via Proxy POST
Alerts on POST requests to the BIG-IP iControl REST /mgmt/tm/util/bash endpoint that can execute shell commands.
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule TeamWebproxyMedium92Free2023-11-08Proxy User-Agent starts with Base64-like prefixes associated with encoded client strings
Identifies proxy requests with User-Agent values starting with known Base64-encoded prefixes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebproxyMedium234Free2023-05-04Suspicious Proxy Requests to IPFS URLs Containing Email Address
Alerts when proxy request URIs target IPFS and include an email address.
Gavin Knapp, Huntrule TeamWebproxyLow193Free2023-03-16Detect rclone CLI Activity via Proxy User-Agent Prefix
Flags proxy traffic with a user agent beginning with rclone/v, indicating rclone usage through the proxy.
Janantha Marasinghe, Huntrule TeamWebproxyMedium194Free2022-10-18PUA Tool Update Check to /checkupdate.php (Advanced IP/Port Scanner) via Proxy
Identifies proxy HTTP requests to /checkupdate.php from Advanced IP/Port Scanner with expected update-check query parameters.
Axel Olsson, Huntrule TeamWebproxyMedium143Free2022-08-14Webserver User-Agent Identifies Known Recon and Scanning Tool Strings
Alerts on web requests with User-Agent values containing known recon/scanner tool identifiers.
Nasreddine Bencherchali (Nextron Systems), Tim Shelton, Huntrule TeamWebwebserverMedium103Free2022-07-19Proxy Log User-Agent Ending with '=' Suggesting Base64 Encoding
Alerts on proxy requests with User-Agent values ending in '=' that may indicate Base64-encoded content.
Florian Roth (Nextron Systems), Brian Ingram (update), Huntrule TeamWebproxyMedium102Free2022-07-08Web Server GET Requests Containing SSTI Payload Strings (Server-Side Template Injection)
Flags GET requests containing SSTI probe strings in web access logs when the response is not 404.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebwebserverHigh172Free2022-06-14Microsoft BITS Proxy Requests to Uncommon Server IP Hosts
Identifies Microsoft BITS proxy connections where the destination host ends with a single-digit, indicating uncommon IP-style addressing.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh93Free2022-06-10Webserver: Suspicious Windows Path Strings in URI Query
Alerts when a web URI query contains encoded or plain Windows path strings indicative of possible exfiltration or webshell behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebwebserverHigh111Free2022-06-06Java Payload Indicators in Web Server Logs
Alerts when web access logs contain Java payload-like strings indicating possible injection or runtime execution attempts.
frack113, Harjot Singh, "@cyb3rjy0t" (update), Huntrule TeamWebwebserverHigh142Free2022-06-04Webserver JNDI-Exploit-Kit Exploitation Indicators via Known Payload Paths
Flags webserver requests whose URL paths match known JNDI-Exploit-Kit exploit, deserialization, and memshell pattern strings.
Florian Roth (Nextron Systems), Huntrule TeamWebwebserverHigh162Free2021-12-12Webserver: Successful IIS shortname fuzzing scan using "~1" parameter
Alerts on successful IIS probing requests containing ~1 and ending with a.aspx using GET/OPTIONS.
frack113, Huntrule TeamWebwebserverMedium172Free2021-10-06