Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Suspicious Ivanti Connect Secure License Keys-Status Command Injection Request (via webserver)
This rule detects HTTP requests to the Ivanti Connect Secure /api/v1/license/keys-status/ endpoint that embed a shell command separator followed by an interpreter reference. Actors chained a semicolon and python invocation onto this path to achieve command injection and drop reverse shells. Requests to this endpoint carrying inline command syntax indicate active exploitation.
HuntRule TeamWebwebserverHigh246Premium2026-07-02Malicious Apache Camel Exec Header Injection
This rule detects HTTP requests containing Apache Camel exec-command headers used to bypass the header filter in CVE-2025-27636 and CVE-2025-29891. Attackers inject CamelExecCommandExecutable and CamelExecCommandArgs headers to run arbitrary commands on vulnerable Camel routes. Presence of these headers in inbound traffic indicates exploitation attempts.
HuntRule TeamWebwebserverHigh122Premium2026-07-01Suspicious DEEPPOST Data Exfiltration URI Pattern via BrazenBamboo
This rule detects HTTP requests to the /api/third/file/upload/ endpoint used by the BrazenBamboo DEEPPOST exfiltration tool to upload stolen files. DEEPPOST posted collected data to attacker infrastructure over a fixed API path. Detecting this URI reveals active data theft from compromised hosts.
HuntRule TeamWebproxyMedium112Premium2026-07-01Malicious TBK DVR Command Injection Exploitation via RondoDox (via webserver)
This rule detects RondoDox botnet exploitation of the TBK DVR command injection flaw CVE-2024-3721 by requesting the device.rsp endpoint with the distinctive S_O_S_T_R_E_A_MAX command marker. This request injects operating system commands to drop the loader. The pattern is unique to the exploit.
HuntRule TeamWebwebserverHigh289Premium2026-06-30Malicious Credential Harvesting Request via All-in-1 PHP Endpoint (via proxy)
This rule detects HTTP requests to an All-in-1.php endpoint carrying user and password query parameters characteristic of the GTFire phishing scheme credential harvesting kit. GTFire lures victims through translate.goog and web.app redirect hops before submitting stolen credentials via crafted GET parameters. Surfacing this traffic reveals active phishing credential theft against organization users.
HuntRule TeamWebproxyHigh328Premium2026-06-29Malicious OysterLoader C2 Beacon Using WordPressAgent User Agent
This rule detects outbound web requests carrying the distinctive WordPressAgent FingerPrint user agent used by OysterLoader. The loader beacons to its command server with this hardcoded agent and reaches encrypted endpoints. A non browser user agent of this exact form is a high confidence network indicator of OysterLoader activity.
HuntRule TeamWebproxyHigh231Premium2026-06-28Suspicious Tycoon 2FA Credential Exfiltration Fields
This rule detects HTTP requests carrying the Tycoon 2FA exfiltration parameters bltdip, bltdref, bltdua and bltddata. These custom field names package the stolen victim context and session data sent back to the phishing kit, uniquely marking AiTM credential theft.
HuntRule TeamWebproxyMedium112Premium2026-06-28Possible MOVEit Transfer SQL Injection via X-siLock-SessVar Header
This rule detects requests to the MOVEit Transfer guestaccess endpoint carrying an X-siLock-SessVar header with SQL injection syntax, matching the header-driven SQLi documented by Assetnote for CVE-2023-34362. Attackers set session variables through this header to inject into backend queries and stage remote code execution. The endpoint and header combination indicates targeted injection rather than benign guest access.
HuntRule TeamWebwebserverMedium111Premium2026-06-28MintsLoader Stage-Two C2 Beacon via htr.php Key and Campaign Parameters (via proxy)
This rule detects MintsLoader stage-two command-and-control beacons that request the htr.php endpoint with key, host id, and campaign parameters against DGA-generated domains. Adversaries leverage this structured request to fetch the next-stage payload keyed to the infected host, making the endpoint-and-parameter combination a strong C2 indicator.
HuntRule TeamWebproxyHigh52Premium2026-06-27Suspicious Hardcoded Legacy Chrome User-Agent from Sparkling Pisces Tooling (via proxy)
This rule detects HTTP requests carrying the hardcoded legacy user-agent string Chrome/31.0.1650.57 embedded in Sparkling Pisces malware. Traffic from this obsolete browser version is anomalous on modern networks and can reveal the keylogger or backdoor beaconing out.
HuntRule TeamWebproxyMedium52Premium2026-06-26Suspicious Vidar Second-Stage Download via Structured index.zip Dropzone Paths (via proxy)
This rule detects HTTP requests for index.zip archives under file-type-segmented dropzone paths such as /pe/, /dll/, /py/, /ps/ and /bat/, the second-stage retrieval pattern used by an access-code-gated DocuSign-themed delivery chain that dropped the Vidar information stealer as analyzed by Joe Sandbox. Adversaries organize payload dropzones by artifact type behind an access gate, so requests matching this structured path layout indicate retrieval of a staged payload.
HuntRule TeamWebproxyMedium61Premium2026-06-26Suspicious DeadLock Ransomware C2 Proxy Request to prrq.php Endpoint (via proxy)
This rule detects HTTP requests to the /prrq.php proxy endpoint used by DeadLock ransomware to reach C2 proxy servers whose addresses are rotated through Polygon smart contracts per Group-IB. Adversaries route control and ransom-negotiation traffic through these proxy PHP endpoints, so requests to this path signal DeadLock C2 activity.
HuntRule TeamWebproxyMedium192Premium2026-06-26Malicious Cobalt Strike C2 Beaconing via REST URI Paths and Legacy MSIE User-Agent (via proxy)
This rule detects HTTP command-and-control beaconing that combines the /rest/funcStatus and /rest/policy/3/ URI paths with a legacy MSIE 7.0 .NET CLR User-Agent, a Malleable C2 profile used by a multi-stage Cobalt Strike loader analyzed by Joe Sandbox. Adversaries craft these profiles to blend beacon traffic into ordinary web requests, making the combined URI and User-Agent pattern a reliable signal of an active beacon before hands-on-keyboard activity.
HuntRule TeamWebproxyHigh375Premium2026-06-26Possible Adversary-in-the-Middle Proxy Login via Crafted URL Parameters
This rule detects HTTP requests carrying the qrc and login_hint URL parameters used by an adversary-in-the-middle proxy that relays victims to a spoofed Outlook login page. This tradecraft was observed in an HTML smuggling campaign that harvested Microsoft 365 credentials and session tokens. AiTM session theft bypasses multi-factor authentication and enables account takeover.
HuntRule TeamWebproxyMedium142Premium2026-06-26Malicious File Upload to SAP NetWeaver Metadata Uploader Endpoint
This rule detects HTTP POST requests to the SAP NetWeaver Visual Composer metadatauploader endpoint exploited in CVE-2025-31324. Threat actors abuse this unauthenticated upload flaw to drop JSP web shells and achieve remote code execution on internet-facing SAP servers. Detecting these uploads catches initial access before web shell deployment.
HuntRule TeamWebwebserverHigh122Premium2026-06-25