Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Suspicious PHP Stream Wrapper in Query-String CLI Argument
This rule detects HTTP requests combining injected CLI option syntax in the query string with remote PHP stream wrappers such as ftp, phar, or php filter, matching the Craft CMS argv injection to remote code execution chain documented by Assetnote. Attackers use these wrappers to load remote templates or configuration and pivot to code execution. The pairing of a leading double-dash option with a wrapper scheme strongly indicates exploitation rather than benign parameters.
HuntRule TeamWebwebserverMedium122Premium2026-08-24Possible IcedID C2 Communication via HTTP Parameters (via proxy)
This rule detects HTTP requests carrying the analytics mimicking parameter set combined with the __io token used by IcedID command and control traffic. The malware disguises beacons as web analytics requests to blend into normal browsing traffic while relaying host data.
HuntRule TeamWebproxyMedium383Premium2026-08-21Malicious OilRig Solar and Mango C2 URI Pattern via Proxy (via proxy)
This rule detects outbound HTTP requests matching the Solar and Mango command-and-control URI pattern used by OilRig, where template.aspx is queried with the rt=d and sun= parameters. This structured URI encodes tasking and exfiltration for the group's downloaders and marks active C2 traffic.
HuntRule TeamWebproxyHigh166Premium2026-08-21Possible Log4Shell JNDI Exploitation Attempt in Web Request
This rule detects Log4Shell (CVE-2021-44228) exploitation strings such as JNDI LDAP/RMI/DNS lookups and Log4j lookup obfuscation appearing in web request URIs and User-Agent headers. Attackers embed these expressions to force vulnerable Log4j2 loggers into resolving attacker-controlled JNDI references, leading to remote code execution.
HuntRule TeamWebwebserverHigh278Premium2026-08-20Malicious Keenadu Android Backdoor C2 Registration and Task Polling URIs
This rule detects HTTP requests to the command-and-control URI paths used by the Keenadu Android backdoor including its client registration and task polling endpoints. Kaspersky tied these structured paths to Keenadu infrastructure linking several major Android botnets. Traffic matching these endpoints indicates an infected device beaconing to its operator to receive tasking and exfiltrate data.
HuntRule TeamWebproxyMedium215Premium2026-08-20Possible Sitecore Experience Platform Pre-Auth RCE via TypeConfuseDelegate Gadget (via webserver)
This rule detects POST requests to the Sitecore Reporting Report.ashx handler carrying a parameters XML body with NetDataContractSerializer and TypeConfuseDelegate gadget markers. This is the pre-auth deserialization RCE CVE-2021-42237 that reaches Process.Start on the server. Detecting it exposes code-execution attempts against internet-facing Sitecore Experience Platform instances.
HuntRule TeamWebwebserverHigh4210Premium2026-08-19Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
This rule detects HTTP requests to the sneakylog license verification endpoint used by the Sneaky 2FA Phishing-as-a-Service platform. Each deployed phishing kit calls the api key path on the operator infrastructure to validate its license before serving the AiTM page. Observing this callback identifies hosts interacting with the Sneaky 2FA kit infrastructure.
HuntRule TeamWebproxyLow218Premium2026-08-19Suspicious PAN-OS Exploit User-Agent for CVE-2024-0012
This rule detects HTTP requests carrying the malformed User-Agent string used in exploitation of PAN-OS CVE-2024-0012 and CVE-2024-9474. This behavior matches Operation Lunar Peek where attackers chained authentication bypass and privilege escalation against management interfaces. The distinctive rv 11.0 token differs from legitimate browsers and provides a reliable signature for exploit traffic against exposed firewalls.
HuntRule TeamWebwebserverMedium296Premium2026-08-18Possible ITG05 Headlace Staging via Mocky and Mockbin Services (via proxy)
This rule detects ITG05 Headlace retrieving staged payloads from the mocky and mockbin request-mocking services used as disposable command-and-control. Requests to these API-mocking hosts from enterprise endpoints are unusual and warrant review. The services return next-stage scripts to the infection chain.
HuntRule TeamWebproxyMedium51Premium2026-08-17Suspicious Nimbus Manticore Agent Polling Endpoints over HTTP (via proxy)
This rule detects HTTP requests to the /agent/init, /agent/poll, and /agent/result endpoints used by the Nimbus Manticore native implant to register, poll for tasking, and return results from Azure-hosted command-and-control infrastructure. Adversaries leverage these structured routes to operate the beacon while blending into web traffic, making detection valuable for exposing active command-and-control.
HuntRule TeamWebproxyMedium289Premium2026-08-15Suspicious HTTP POST to Local AI Malware Exfil Endpoint (via proxy)
This rule detects HTTP POST requests to the /crypto-data endpoint used by AI-assisted malware to transmit collected cryptocurrency and victim data. The specific exfiltration path combined with the POST method reflects the malware sending stolen data to its collection service.
HuntRule TeamWebproxyLow121Premium2026-08-14Malicious wp2shell Batch Endpoint Exploitation (via webserver)
This rule detects POST requests to the WordPress batch REST endpoint that return HTTP 207 multi-status, matching in-the-wild exploitation of wp2shell for CVE-2026-63030 and CVE-2026-60137. Attackers chain requests through the batch route to reach vulnerable handlers and drop a web shell. The 207 response to the batch route is characteristic of this exploitation.
HuntRule TeamWebwebserverHigh71Premium2026-08-13Suspicious Typosquatted Apple User-Agent Beaconing from Ivanti Implant (via proxy)
This rule detects HTTP requests bearing a typosquatted Apple user-agent string that substitutes look-alike characters for the letter l. Implants deployed against Ivanti Connect Secure used App1e and AppIe user-agents during their dormancy and beaconing. A user-agent forging the Apple brand with homoglyphs is a distinctive command-and-control fingerprint.
HuntRule TeamWebproxyMedium421Premium2026-08-12Possible AntSword Webshell Access on Ivanti EPMM 403.jsp
This rule detects HTTP POST requests to the 403.jsp resource on Ivanti EPMM carrying the AntSword webshell parameter k. It is tied to a Java webshell appended to the legitimate 403.jsp error page during EPMM exploitation to provide operators remote command execution. Detecting these requests reveals interaction with the deployed webshell.
HuntRule TeamWebwebserverMedium116Premium2026-08-11WezRat Command and Control HTTP URI Pattern
This rule detects HTTP requests matching the WezRat command and control URI scheme including the distinctive wez Agent InsMch endpoint. The backdoor tasks and reads data through these fixed URI paths while spoofing a firefox user agent. Detecting the URI pattern reveals active command and control traffic.
HuntRule TeamWebproxyHigh309Premium2026-08-11