Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Possible SSRF via Gatsby _gatsby File Proxy Endpoint
This rule detects HTTP requests to the Gatsby /_gatsby/file remote file proxy carrying an absolute URL or a cloud metadata target. Assetnote research showed this static site generator proxy can be coerced into server-side request forgery against internal services and the cloud metadata endpoint.
HuntRule TeamWebwebserverMedium50Premium2026-09-07Possible SSRF to Cloud Metadata via Nuxt _ipx Image Proxy
This rule detects HTTP requests to the Nuxt/Next _ipx image optimization proxy that reference the cloud instance metadata service. Static site generators expose _ipx as an open image proxy that can be abused for server-side request forgery as shown in Assetnote research, allowing an attacker to reach 169.254.169.254 and steal cloud credentials.
HuntRule TeamWebwebserverHigh30Premium2026-09-07Suspicious Connection to Local Zoom Opener Webserver Launch Endpoint (via network_connection)
This rule detects traffic to the local ZoomOpener helper webserver launch endpoint on loopback port 19421. This maps to the Zoom drive-by RCE chain where a webpage sends a crafted launch request to the hidden local server. An attacker leverages this to trigger silent installation and code execution on the victim host.
HuntRule TeamWebproxyLow60Premium2026-09-07Malicious CastleLoader C2 Communication via Hardcoded User-Agent
This rule detects outbound HTTP requests using the hardcoded non-standard User-Agent token associated with CastleLoader C2 check-ins. The loader beacons to its server with this fixed string before receiving tasks.
HuntRule TeamWebproxyHigh20Premium2026-09-06Malicious XE Group Webshell Upload via VeraCore UploadImage CVE-2024-57968 (via webserver)
This rule detects abuse of the VeraCore UploadImage handler to upload an ASP or ASPX webshell through the CVE-2024-57968 unrestricted-upload flaw exploited by XE Group. The request combines the PMA upload controller with a script-file filename parameter, reflecting the point at which the actor plants a persistent webshell on the server.
HuntRule TeamWebwebserverHigh120Premium2026-09-01Malicious PHP Code Injection in URL via CraftCMS CVE-2025-32432 Exploitation (via webserver)
This rule detects inline PHP code appearing in a request URL, the code-injection technique used after CraftCMS CVE-2025-32432 exploitation to write a file manager webshell to the web root via file_put_contents and file_get_contents. Adversaries embed PHP tags and file functions in the request so the vulnerable application stores and executes attacker-controlled code.
HuntRule TeamWebwebserverHigh80Premium2026-09-01Suspicious Cobalt Strike Loader C2 Traffic via Forged MSIE yie9 User-Agent (via proxy)
This rule detects command-and-control traffic using the forged Internet Explorer 9 user-agent carrying the yie9 token observed with the Cobalt Strike PowerShell loader across Chinese and Russian infrastructure. Adversaries leverage a spoofed legacy browser user-agent to blend beacon traffic into normal web requests.
HuntRule TeamWebproxyMedium80Premium2026-08-30GateDoor Command-and-Control via gateway REST Endpoints (via proxy)
This rule detects outbound HTTP requests to the Django REST command-and-control endpoints used by GateDoor and RustDoor, including gateway register, gateway report and gateway future_task for device registration and command polling. Matching these fixed URI paths in proxy logs can reveal an infected host beaconing to the backdoor infrastructure.
HuntRule TeamWebproxyMedium50Premium2026-08-30Malicious alexantr File Manager Webshell Access after CraftCMS Compromise (via webserver)
This rule detects requests to a filemanager.php webshell with its upload and delete parameters, the open-source alexantr file manager dropped to the web root following CraftCMS CVE-2025-32432 exploitation. Adversaries use this webshell to browse, upload and remove files on the compromised server for hands-on-keyboard actions.
HuntRule TeamWebwebserverHigh80Premium2026-08-30PATCHCORD Beacon C2 Tasking via api.jsp clientId Poll (via proxy)
This rule detects the PATCHCORD implant polling its command channel with the hardcoded Beacon user-agent and the api.jsp clientId tasking URI observed in the Afghan telecom intrusion set. Adversaries use this fixed user-agent and endpoint to fetch operator commands over HTTP. The distinctive agent string and URI make this beacon reliably separable from normal web traffic.
HuntRule TeamWebproxyHigh80Premium2026-08-29Suspicious Cisco ASA WebVPN Login Scanning with Spoofed Chrome User-Agent
This rule detects inbound requests to Cisco ASA web login endpoints /+CSCOE+/logon.html and /+webvpn+/index.html that carry the single spoofed browser identifier Chrome/102.0.5005.63 used across a coordinated scanning botnet. The activity mapped a surge of 25,000 IPs probing Cisco ASA devices, frequently a precursor to a newly disclosed vulnerability being weaponized for initial access.
HuntRule TeamWebwebserverMedium375Premium2026-08-28SilentMare Loader C2 Beacon via Custom GatewayClient User-Agent (via proxy)
This rule detects outbound HTTP requests carrying the hardcoded GatewayClient and Metrics User-Agent strings used by the SilentMare and HollowMare trojan families distributed through Google Search ads. These custom agents identify updater check-ins that pull AES-encrypted .NET payloads from attacker infrastructure, making them a reliable network fingerprint for the loader stage.
HuntRule TeamWebproxyMedium161Premium2026-08-27Possible C2 Beacon with Fixed Authorization URI Parameter via proxy
This rule detects outbound web requests to index.php carrying the fixed authorization=1 query parameter used by the DGA based command-and-control of the pirated-media miner campaign. The constant URI structure across randomized domains is a reliable protocol fingerprint. Catching the beacon URI reveals active C2 traffic that domain blocklists miss.
HuntRule TeamWebproxyMedium122Premium2026-08-26Possible React Server Components Exploitation via Next-Action Header
This rule detects inbound web requests carrying a Next-Action server action header together with crafted action parameter markers, the request shape used to trigger CVE-2025-55182 in React Server Components. Exploitation abuses the server action deserialization path to reach arbitrary command execution. Requests bearing this header alongside the action index syntax against a Next.js application warrant investigation for RCE attempts.
HuntRule TeamWebwebserverMedium121Premium2026-08-25Possible Super SSRF via Jira Server nativemobile batch CVE-2022-26135
This rule detects POST requests to the Jira Server /rest/nativemobile/1.0/batch endpoint used to perform blind server-side request forgery. CVE-2022-26135 abuses this batch API with an attacker-controlled location value as shown by Assetnote, allowing requests to arbitrary internal hosts and cloud metadata.
HuntRule TeamWebwebserverMedium151Premium2026-08-25