Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Web Path Traversal Exploitation Attempts via Encoded Traversal in URL Query
Alerts on web requests with URL query path traversal patterns targeting /etc/ and other sensitive filesystem paths.
Subhash Popuri (@pbssubhash), Florian Roth (Nextron Systems), Thurein Oo, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebwebserverMedium111Free2021-09-25Webserver GET requests containing XSS-related payload strings
Finds likely XSS injection attempts in webserver GET requests by matching script, tag, and JS payload strings while excluding 404s.
Saw Win Naung, Nasreddine Bencherchali, Huntrule TeamWebwebserverHigh358Free2021-08-15BabyShark HackTool Proxy C2 URL Pattern via momyshark?key=
Alerts on proxy URIs containing the BabyShark agent default "momyshark?key=" query pattern.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyCritical123Free2021-06-09Nginx service core dump after worker crash (signal 6)
Flags Nginx worker crashes that end with signal 6 core dumps, which may indicate serious issues or exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWebnginxHigh192Free2021-05-31Webserver logs: Webshell ReGeorg indicators in POST URI query with null Referer/User-Agent
Flags HTTP POST requests with null referer/user-agent and ReGeorg-like URI query parameters in web logs.
Cian Heasley, Huntrule TeamWebwebserverHigh161Free2020-08-04Empire C2 Proxy Requests with Specific User-Agent and POSTed PHP URIs
Flags proxy HTTP POSTs using an Empire-like user agent to specific admin/login PHP endpoints.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh355Free2020-07-13Proxy Downloads Containing /pwndrop/ (PwnDrp Web Server)
Alerts on proxy requests to URIs containing '/pwndrop/', consistent with PwnDrp-style web delivery.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyCritical122Free2020-04-15Detect Potential SQL Injection Payloads in GET URIs via Webserver Access Logs
Flags HTTP GET URIs containing SQL injection indicator strings in webserver access logs, excluding 404 responses.
Saw Win Naung, Nasreddine Bencherchali (Nextron Systems), Thurein Oo (Yoma Bank), Huntrule TeamWebwebserverHigh162Free2020-02-22Proxy access to raw paste endpoints on paste.ee and Pastebin-style services
Alerts on proxy requests for raw paste service URLs that can be used to stage or fetch malicious payloads.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh131Free2019-12-05Suspicious APT User-Agent Strings in Proxy Logs
Alerts when proxy requests contain known APT-style user agent strings indicating likely malicious client behavior.
Florian Roth (Nextron Systems), Markus Neis, Huntrule TeamWebproxyHigh152Free2019-11-12Suspicious Crypto Miner User Agents in Proxy Logs
Flags proxy requests with User-Agent prefixes tied to XMRig or CCMiner crypto miners.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh267Free2019-10-21Webserver URL Enumeration for Exposed .git Paths via GET Keyword
Alerts when web requests include .git/ in the URL, suggesting source code enumeration against version control paths.
James Ahearn, Huntrule TeamWebwebserverMedium102Free2019-06-08Microsoft BITS Proxy Activity to Uncommon Top-Level Domains
Flags Microsoft BITS-initiated proxy requests to domains using uncommon TLDs.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWebproxyHigh209Free2019-03-07Apache thread assertion error in error.log
Flags Apache error log entries that include a pthread thread-priority assertion failure message.
Florian Roth (Nextron Systems), Huntrule TeamWebapacheMedium375Free2019-01-22Suspicious Telegram API proxy access without Telegram User-Agent
Alerts on api.telegram.org requests where the User-Agent lacks common Telegram bot identifiers.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyMedium72Free2018-06-05