Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Windows Proxy Activity Using Microsoft-WebDAV-MiniRedir GET User-Agent
Alerts on proxy HTTP GET requests using the Microsoft-WebDAV-MiniRedir/ User-Agent prefix associated with file download behavior.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh50Free2018-04-06Proxy Downloads of Executables and Documents from Suspicious Dynamic DNS Domains
Alerts when proxy traffic downloads common executable or document payload types from a curated list of dynamic DNS hostnames.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyMedium413Free2017-11-08Proxy downloads of executable and document files from suspicious TLDs (blacklisted domains)
Alerts when proxy users download common malware and lure file types from hosts using suspicious TLDs.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyLow375Free2017-11-07Proxy Web Requests for Flash Player Installer from Unofficial Locations
Flags proxy downloads for Flash Player installer paths when the request host is not ending in .adobe.com.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh113Free2017-10-25Suspicious Malformed User-Agent Strings in Proxy Logs
Flags proxy requests whose User-Agent headers are malformed or match suspicious automation/tooling patterns, excluding known Adobe/Acrobat traffic.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh125Free2017-07-08Suspicious Malware User-Agent Strings in Proxy Logs
Alerts on proxy traffic with user-agent values and substrings commonly seen in malware communications.
Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebproxyHigh81Free2017-07-08Proxy logs: Detect suspicious hack tool user agents from known scanning and SQLi tools
Alerts on proxy requests with User-Agent values commonly used by scanners and hack tools, indicating automated probing or exploitation attempts.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh103Free2017-07-08Proxy logs: suspicious exploit framework User-Agent strings
High-severity match on proxy User-Agent strings commonly seen in exploit/pentest frameworks.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh142Free2017-07-08Proxy HTTP Requests with Empty User-Agent Header
Flags proxy HTTP traffic with an empty User-Agent header, which may indicate automation or unusual client behavior.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyMedium71Free2017-07-08Windows PowerShell Web Access User-Agent Containing "WindowsPowerShell/" (Proxy Logs)
Alerts when proxy traffic shows a User-Agent containing "WindowsPowerShell/", consistent with PowerShell web access.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyMedium131Free2017-03-13Proxy: Block Suspicious Executable Downloads from Non-Trusted Top-Level Domains
Finds proxy traffic requesting executable or script/doc payloads from hosts with suspicious TLDs not in the whitelist.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyLow62Free2017-03-13Apache worker crash logs with "Segmentation Fault" exit signal
Alerts on Apache error log lines showing a worker process crashed with an exit signal Segmentation Fault.
Florian Roth (Nextron Systems), Huntrule TeamWebapacheHigh325Free2017-02-28Windows Webshell Command Strings in Webserver GET Requests
Identifies GET requests with URL-encoded Windows command strings consistent with webshell behavior.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebwebserverHigh151Free2017-02-19