Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
45 rules
Malicious Windows Webshell Strings (via webserver)
highThis rule detects common commands used in Windows webshells
sigmaWebPaid2026-05-01Malicious JNDIExploit Pattern (via webserver)
highThis rule detects exploitation attempt using the JNDI-Exploit-Kit
sigmaWebPaid2026-04-12Suspicious Windows Strings In URI (via webserver)
highThis rule detects anomalous Windows strings in URI which could indicate possible exfiltration or webshell communication
sigmaWebPaid2026-04-06Suspicious SQL Injection Strings In URI (via webserver)
highThis rule detects potential SQL injection attempts via GET requests in access logs.
sigmaWebPaid2026-04-05Suspicious Execution of F5 BIG-IP iControl Rest API Command - Proxy (via proxy)
mediumThis rule detects POST requests to the F5 BIG-IP iControl Rest API "bash" endpoint, which enables the execution of commands on the BIG-IP
sigmaWeb2026-03-26Malicious Exploit Framework User Agent (via proxy)
highThis rule detects anomalous user agent strings used by exploit / pentest frameworks like Metasploit in proxy logs
sigmaWebPaid2026-03-19Download From Suspicious TLD - Blacklist (via proxy)
lowThis rule detects download of certain file types from hosts in anomalous TLDs
sigmaWeb2026-03-19Suspicious Windows WebDAV User Agent (via proxy)
highThis rule detects WebDav DownloadCradle
sigmaWebPaid2026-03-12Possible Hello-World Scraper Botnet Behavior (via proxy)
mediumThis rule detects network traffic potentially linked with a scraper botnet variant that uses the "Hello-World/1.0" user-agent string.
sigmaWeb2026-03-06Suspicious Server Side Template Injection Strings (via webserver)
highThis rule detects SSTI attempts sent via GET requests in access logs
sigmaWebPaid2026-02-19Suspicious HTTP Request With Empty User Agent (via proxy)
mediumThis rule detects a potentially anomalous empty user agent strings in proxy log. Could potentially indicate an uncommon request method.
sigmaWeb2026-02-19Suspicious User Agent (via proxy)
highThis rule detects anomalous malformed user agent strings in proxy logs
sigmaWebPaid2026-02-13Execution of Suspicious External WebDAV (via proxy)
highThis rule detects executables launched from external WebDAV shares using the WebDAV Explorer integration, frequently seen in initial access campaigns.
sigmaWebPaid2026-02-11Suspicious Windows PowerShell User Agent (via proxy)
mediumThis rule detects Windows PowerShell Web Access
sigmaWeb2026-02-08Suspicious Nginx Core Dump (via nginx)
highThis rule detects a core dump of a crashing Nginx worker process, which could be a signal of a serious problem or exploitation attempts.
sigmaWebPaid2026-02-07Bitsadmin to Unusual IP Server Address (via proxy)
highThis rule detects Bitsadmin connections to IP addresses instead of FQDN names
sigmaWebPaid2026-02-01Suspicious Base64 Encoded User-Agent (via proxy)
mediumThis rule detects anomalous encoded User-Agent strings, as seen used by some malware.
sigmaWeb2026-01-24Suspicious Java Payload Strings (via webserver)
highThis rule detects possible Java payloads in web access logs
sigmaWebPaid2026-01-20Malicious HackTool - CobaltStrike Malleable Profile Patterns - Proxy (via proxy)
highThis rule detects cobalt strike malleable profiles patterns (URI, User-Agents, Methods).
sigmaWebPaid2026-01-20Suspicious PwnDrp Access (via proxy)
criticalThis rule detects downloads from PwnDrp web servers developed for red team testing and most likely also used for criminal behavior
sigmaWebPaid2026-01-19