Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Suspicious Oversized Numeric X-Forwarded-For Header Targeting Ivanti Connect Secure (via proxy)
This rule detects the network signature of Ivanti Connect Secure CVE-2025-22457 where an extremely long X-Forwarded-For header consisting only of digits and periods is used to overflow a stack buffer in the web process. Legitimate proxy chains do not produce headers of this length.
HuntRule TeamWebproxyLow3410Premium2026-07-31Malicious Exploitation of Confluence setup-restore Endpoint
This rule detects POST requests to the Confluence setup-restore action, the endpoint abused in CVE-2023-22518 to reset the instance and gain administrative control before Cerber ransomware deployment. Requests to this administrative restore endpoint from untrusted sources indicate active exploitation of the vulnerability.
HuntRule TeamWebwebserverHigh3010Premium2026-07-31FortiOS WebSocket CLI Authentication Bypass via Node.js Exploit Tooling (via webserver)
This rule detects requests to the FortiOS websocket CLI endpoints ws cli open and ws newcli open originating from a Node.js user-agent, matching the KeyPlug-linked exploit tooling for CVE-2024-23108 and CVE-2024-23109. Adversaries leverage these websocket CLI paths to bypass authentication and reach the Fortinet command interface.
HuntRule TeamWebwebserverHigh51Premium2026-07-31AsyncRAT C2 Check-in via Structured Verify Query Parameters (via proxy)
This rule detects AsyncRAT command-and-control check-ins carrying the structured verify query parameters observed in the ScreenConnect campaign, including the verify host, Support and Guest markers. Adversaries leverage these fixed request parameters to register infected hosts with the controller over web traffic.
HuntRule TeamWebproxyHigh133Premium2026-07-29CraftCMS Yii Object Injection via generate-transform Endpoint (via webserver)
This rule detects requests to the CraftCMS asset generate-transform endpoint carrying Yii gadget class markers, the object-injection primitive exploited in CVE-2025-32432 to reach PhpManager and execute attacker code from a session file. Adversaries send crafted class references such as FnStream and PhpManager to trigger unauthenticated remote code execution.
HuntRule TeamWebwebserverHigh81Premium2026-07-29Possible SharePoint ToolShell Exploitation via ToolPane Edit POST With Spoofed Referer (CVE-2025-53770)
This rule detects a POST to the SharePoint ToolPane page in edit display mode with a Referer spoofing SignOut.aspx, the exploitation request of the ToolShell CVE-2025-53770 and CVE-2025-53771 chain. It matters because this unauthenticated request is the entry point for deserialization based remote code execution.
HuntRule TeamWebwebserverHigh224Premium2026-07-29Possible Atlassian Confluence CVE-2023-22515 Setup Recovery Exploitation via Webserver (via webserver)
This rule detects HTTP requests that re-enable the Confluence setup workflow by toggling setupComplete to false and then hitting the setup administrator and finish-setup actions, matching exploitation of the broken access control flaw CVE-2023-22515. It is associated with attacks against internet-facing Atlassian Confluence servers to create rogue administrator accounts. Because these endpoints should never be reachable on a configured instance, this pattern strongly indicates active exploitation.
HuntRule TeamWebwebserverHigh292Premium2026-07-28Malicious WordPress REST Batch UNION SQL Injection Attempt
This rule detects requests that carry a UNION based SQL injection in the author_exclude parameter used by the WordPress core CVE-2026-63030 exploitation. The payload chains the author_exclude parameter with UNION and SELECT keywords to extract data through the REST batch endpoint.
HuntRule TeamWebwebserverHigh155Premium2026-07-28Suspicious Larva-24009 C2 Command and Exfiltration URI Patterns (via proxy)
This rule detects outbound HTTP requests to the Larva-24009 C2 endpoints used for command retrieval, persistence script delivery, and screenshot exfiltration. These specific PHP endpoint paths under a Res directory are unique to this campaign infrastructure.
—WebproxyHigh103Premium2026-07-27Suspicious SD-WAN Compromise Nim Implant C2 Beacon
This rule detects HTTP requests to the Nim implant endpoints observed in the ongoing Cisco Catalyst SD-WAN exploitation, where the backdoor uses fixed URI paths for handshake and exfiltration. The dedicated /api/v1/handshake and /exfiltrate routes reveal the implant control channel used after webshell deployment. Matching traffic indicates an active Nim implant beaconing from a compromised appliance.
HuntRule TeamWebproxyMedium363Premium2026-07-22Suspicious Stealth Soldier C2 Request URI (via proxy)
This rule detects HTTP POST requests to the Server Request endpoint used by the Stealth Soldier backdoor for command-and-control. The fixed URI path combined with the POST method is a structured C2 pattern that helps surface backdoor beaconing in web proxy telemetry.
HuntRule TeamWebproxyMedium157Premium2026-07-21Possible Ivanti EPMM CVE-2025-4428 Exploitation via format Parameter (via webserver)
This rule detects requests to the Ivanti EPMM api v2 endpoint carrying a format parameter that invokes runtime code execution, the exploitation pattern for CVE-2025-4428. Attackers embedded Java Runtime.exec calls in this parameter to achieve remote command execution. Such requests against the mifs api are a strong exploitation indicator.
HuntRule TeamWebwebserverHigh73Premium2026-07-20Suspicious Peach Sandstorm Password Spray via go-http-client User Agent (via proxy)
This rule detects inbound authentication traffic carrying the default Go HTTP library user agent go-http-client. Peach Sandstorm used this user agent while conducting password spray attacks against enterprise sign-in endpoints for initial access.
HuntRule TeamWebproxyMedium81Premium2026-07-20Suspicious InvisibleFerret C2 Endpoints over Port 1224 (via proxy)
This rule detects HTTP requests to the InvisibleFerret command and control server that exposes payload, browser, clipboard and key exfiltration endpoints over TCP port 1224. The Lazarus backdoor cycles through fixed URI paths such as payload, brow, mclip and keys on this port. The pairing of the non-standard port with these named resources reveals the backdoor traffic.
HuntRule TeamWebproxyHigh63Premium2026-07-19Possible SysAid On-Premise Command Injection via API.jsp javaLocation Parameter (via webserver)
This rule detects exploitation of SysAid On-Premise CVE-2024-36394 where a request to the API settings endpoint supplies a javaLocation parameter with newline encoded operating system commands to achieve execution. The javaLocation parameter combined with the API.jsp endpoint is a strong exploitation signal.
HuntRule TeamWebwebserverMedium121Premium2026-07-17