Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Malicious Arkanix Stealer C2 Communication via Custom User-Agent
This rule detects outbound HTTP traffic carrying the hardcoded User-Agent string used by the Arkanix C++ and Python infostealer. Kaspersky observed Arkanix identifying itself to its panel with the ArkanixStealer client string while requesting stealer and hidden VNC modules. This distinctive agent is a reliable indicator of an infected host communicating with the stealer backend to receive payloads and exfiltrate credentials.
HuntRule TeamWebproxyHigh102Premium2026-08-10Malicious Cobalt Strike Malleable C2 URI Beacon via Proxy
This rule detects HTTP requests to the Cobalt Strike malleable profile URI /1/events/com.amazon.csm.csa.prod observed in the Nitrogen 2.0 campaign. This fixed path masquerades as Amazon telemetry to blend with normal traffic. Detecting it identifies beaconing to Cobalt Strike infrastructure.
HuntRule TeamWebproxyHigh3810Premium2026-08-10Suspicious Access to MOVEit Transfer Internal machine2 Endpoint
This rule detects HTTP access to the MOVEit Transfer machine2.aspx endpoint, which Assetnote identified during patch diffing as an internal-only interface reachable through SSRF in CVE-2023-34362. External or unexpected requests to this endpoint indicate an attacker has pivoted past the intended trust boundary. Because legitimate clients should not reach machine2 directly, such access is a strong exploitation signal.
HuntRule TeamWebwebserverMedium103Premium2026-08-09Possible Access-Code Validation Beacon to Malware Delivery C2 (via proxy)
This rule detects HTTP requests to an /api/submit endpoint carrying a code parameter, the access-code validation call made by a DocuSign-themed loader before it retrieves its second stage in a Vidar delivery chain analyzed by Joe Sandbox. Adversaries gate payload delivery behind server-side code validation to evade sandboxes and analysts, so this submit-with-code request pattern surfaces the loader contacting its delivery infrastructure.
HuntRule TeamWebproxyLow367Premium2026-08-08Possible FortiOS Authentication Bypass via local_access_token on WebSocket CLI Endpoint (via webserver)
This rule detects exploitation of FortiOS and FortiProxy CVE-2024-55591 where an unauthenticated request to the Node.js websocket CLI endpoint supplies a local_access_token to bypass session validation and gain super_admin access. The combination of the ws cli path and the token parameter is not seen in normal administration.
HuntRule TeamWebwebserverHigh132Premium2026-08-05Suspicious Go HTTP Client User Agent via Proxy
This rule detects outbound web requests carrying the default Go HTTP client user agent, which Peach Sandstorm used from Azure infrastructure during password spray attacks against target tenants. The user agent is a weak but useful signal that can highlight automated credential-guessing traffic when correlated with failed authentication.
HuntRule TeamWebproxyLow62Premium2026-08-05Malicious Mirage Kitten C2 Communication via Keyboard-Walk URIs (via proxy)
This rule detects HTTP requests to the distinctive keyboard-walk URI paths used by Mirage Kitten malware for command-and-control against Middle East and Africa targets. These fixed, non-dictionary URI stems are strong C2 indicators and their presence in web traffic points to active beaconing from a compromised host.
HuntRule TeamWebproxyHigh161Premium2026-08-05Possible VMware Workspace ONE Access Authentication Bypass via Embedded Auth Broker Callback (CVE-2022-22972) (via webserver)
This rule detects POST requests to the Workspace ONE Access embedded auth broker callback endpoint used in the CVE-2022-22972 host header authentication bypass. This maps to exploitation where an attacker supplies a crafted Host header to trick the internal auth broker into issuing a valid session. Successful abuse grants unauthenticated administrative access to the appliance.
HuntRule TeamWebwebserverMedium62Premium2026-08-04Malicious Stealth Soldier C2 User-Agent (via proxy)
This rule detects outbound web requests carrying the hardcoded Stealth Soldier user-agent string used by the Stealth Soldier backdoor in espionage attacks across North Africa. This static, tool-specific user-agent is a distinctive command-and-control fingerprint that legitimate clients do not present.
HuntRule TeamWebproxyHigh191Premium2026-08-04Suspicious Rogue WordPress REST Route morning/v1 (via webserver)
This rule detects requests to a rogue REST route morning/v1 registered by the wp2shell web shell to execute commands via a base64 parameter passed to passthru. Access to this attacker-defined route indicates an active web shell on the WordPress host. The specific route name is characteristic of this implant.
HuntRule TeamWebwebserverHigh163Premium2026-08-04Malicious LummaC2 Stealer C2 Endpoint Beacon via Proxy
This rule detects HTTP requests to the LummaC2 command-and-control endpoints /c2conf and /c2sock used by version 4.0 of the stealer. These fixed URI paths handle configuration retrieval and data exfiltration. Detecting them identifies infected hosts communicating with LummaC2 infrastructure.
HuntRule TeamWebproxyHigh116Premium2026-08-02Possible Local File Inclusion Path Traversal Targeting CentreStack Web.config
This rule detects web requests to the CentreStack storage handler containing directory traversal sequences that reference Web.config, matching the local file inclusion exploitation of Gladinet CentreStack and Triofox. Attackers read Web.config to steal machine keys and secrets enabling deserialization attacks. Successful traversal to configuration files precedes full remote code execution and warrants investigation.
HuntRule TeamWebwebserverHigh103Premium2026-08-02Possible Atlassian Confluence CVE-2023-22518 Setup-Restore Exploitation via Webserver (via webserver)
This rule detects unauthenticated HTTP POST requests to the Confluence setup-restore endpoints used to exploit the improper authorization vulnerability CVE-2023-22518. It is associated with attacks against Atlassian Confluence Data Center and Server that abuse the restore functionality to import a malicious ZIP. Successful exploitation lets an attacker reset the instance and create administrative access, so this activity should be triaged as a potential compromise.
HuntRule TeamWebwebserverHigh397Premium2026-08-01Suspicious Phishing URL with Unrendered Template Placeholder (via proxy)
This rule detects web requests whose URL path contains the unrendered phishing-kit template placeholder sf_rand_string_lowercase6, a literal artifact left in links from a large refresh-header phishing campaign. The presence of this build-time placeholder in a live URL is a strong indicator of the credential-harvesting kit and its automatic redirect landing pages.
HuntRule TeamWebproxyHigh82Premium2026-08-01Suspicious Tomcat Manager WAR Deployment via HTTP PUT by UNC6201
This rule detects an HTTP PUT to the Tomcat manager text deploy endpoint with update set to true which UNC6201 used to upload a WAR web shell after abusing default manager credentials. Attackers deploy the GRIMBOLT backdoor as a running web application to gain root on Dell RecoverPoint appliances.
HuntRule TeamWebwebserverHigh2310Premium2026-08-01