Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
40 rules
Malicious HarborWatch RAT Command and Control Beacon by User Agent (via proxy)
This rule detects outbound HTTP requests carrying the HarborWatchAgent user agent string used by the custom monitoring RAT delivered through a fake Amazon ClickFix lure. This hardcoded agent value is specific to the malware and should not appear in normal traffic.
HuntRule TeamWebproxyHigh30Premium2026-09-12Suspicious UAT-10608 Credential Harvesting C2 Beacon via HTTP
This rule detects outbound HTTP requests carrying the UAT-10608 command-and-control beacon layout where the URI encodes the victim host, the harvesting phase and a campaign identifier as h, l and id parameters. This structured query pattern is used by the credential harvesting operation to report progress and exfiltrate results over HTTP. Matching traffic indicates an actively beaconing compromised host.
HuntRule TeamWebproxyMedium70Premium2026-09-12Possible PS1Bot C2 Beacon With Drive Serial URI Pattern (via proxy)
This rule detects HTTP GET requests whose URI query contains the PS1Bot command-and-control marker k=result used to exfiltrate results keyed by the victim drive serial number. This structured URI pattern identifies PS1Bot beaconing to its command-and-control server. Detection of this traffic reveals active command-and-control and data exfiltration.
HuntRule TeamWebproxyMedium00Premium2026-09-12Suspicious WarmCookie C2 Beacon With Fixed Firefox User-Agent
This rule detects web traffic carrying the hardcoded Firefox 115.0 User-Agent string used by WarmCookie. WarmCookie beaconed to its command-and-control servers with a fixed Mozilla Firefox 115.0 User-Agent regardless of the host browser. A single static outdated User-Agent applied to all C2 requests is an application-layer protocol indicator that stands out from real browser diversity.
HuntRule TeamWebproxyMedium10Premium2026-09-12PATCHCORD Beacon C2 Tasking via api.jsp clientId Poll (via proxy)
This rule detects the PATCHCORD implant polling its command channel with the hardcoded Beacon user-agent and the api.jsp clientId tasking URI observed in the Afghan telecom intrusion set. Adversaries use this fixed user-agent and endpoint to fetch operator commands over HTTP. The distinctive agent string and URI make this beacon reliably separable from normal web traffic.
HuntRule TeamWebproxyHigh80Premium2026-08-29SilentMare Loader C2 Beacon via Custom GatewayClient User-Agent (via proxy)
This rule detects outbound HTTP requests carrying the hardcoded GatewayClient and Metrics User-Agent strings used by the SilentMare and HollowMare trojan families distributed through Google Search ads. These custom agents identify updater check-ins that pull AES-encrypted .NET payloads from attacker infrastructure, making them a reliable network fingerprint for the loader stage.
HuntRule TeamWebproxyMedium161Premium2026-08-27Possible C2 Beacon with Fixed Authorization URI Parameter via proxy
This rule detects outbound web requests to index.php carrying the fixed authorization=1 query parameter used by the DGA based command-and-control of the pirated-media miner campaign. The constant URI structure across randomized domains is a reliable protocol fingerprint. Catching the beacon URI reveals active C2 traffic that domain blocklists miss.
HuntRule TeamWebproxyMedium152Premium2026-08-26Possible Cryptomining Beacon to c3pool Mining Domain
This rule detects DNS lookups for the c3pool mining pool domain used by the cryptominer dropped after SSTI exploitation in this research. Enterprise systems have no reason to resolve public mining pool infrastructure. Detecting the query surfaces resource hijacking following the web compromise.
HuntRule TeamLinuxdns_queryMedium326Premium2026-08-23Suspicious Typosquatted Apple User-Agent Beaconing from Ivanti Implant (via proxy)
This rule detects HTTP requests bearing a typosquatted Apple user-agent string that substitutes look-alike characters for the letter l. Implants deployed against Ivanti Connect Secure used App1e and AppIe user-agents during their dormancy and beaconing. A user-agent forging the Apple brand with homoglyphs is a distinctive command-and-control fingerprint.
HuntRule TeamWebproxyMedium421Premium2026-08-12Malicious Cobalt Strike Malleable C2 URI Beacon via Proxy
This rule detects HTTP requests to the Cobalt Strike malleable profile URI /1/events/com.amazon.csm.csa.prod observed in the Nitrogen 2.0 campaign. This fixed path masquerades as Amazon telemetry to blend with normal traffic. Detecting it identifies beaconing to Cobalt Strike infrastructure.
HuntRule TeamWebproxyHigh3810Premium2026-08-10Possible Access-Code Validation Beacon to Malware Delivery C2 (via proxy)
This rule detects HTTP requests to an /api/submit endpoint carrying a code parameter, the access-code validation call made by a DocuSign-themed loader before it retrieves its second stage in a Vidar delivery chain analyzed by Joe Sandbox. Adversaries gate payload delivery behind server-side code validation to evade sandboxes and analysts, so this submit-with-code request pattern surfaces the loader contacting its delivery infrastructure.
HuntRule TeamWebproxyLow367Premium2026-08-08Malicious LummaC2 Stealer C2 Endpoint Beacon via Proxy
This rule detects HTTP requests to the LummaC2 command-and-control endpoints /c2conf and /c2sock used by version 4.0 of the stealer. These fixed URI paths handle configuration retrieval and data exfiltration. Detecting them identifies infected hosts communicating with LummaC2 infrastructure.
HuntRule TeamWebproxyHigh126Premium2026-08-02Suspicious SD-WAN Compromise Nim Implant C2 Beacon
This rule detects HTTP requests to the Nim implant endpoints observed in the ongoing Cisco Catalyst SD-WAN exploitation, where the backdoor uses fixed URI paths for handshake and exfiltration. The dedicated /api/v1/handshake and /exfiltrate routes reveal the implant control channel used after webshell deployment. Matching traffic indicates an active Nim implant beaconing from a compromised appliance.
HuntRule TeamWebproxyMedium383Premium2026-07-22ValleyRat Beacon Sideloading via NtHandleCallback Loading log.dll (via image_load)
This rule detects the NtHandleCallback.exe process loading log.dll from its working directory, the DLL sideloading pair used to launch the ValleyRat beacon in the Silver Fox campaign. Adversaries leverage a masqueraded executable and a co-located malicious DLL to run the beacon under a benign-looking process, making detection valuable for surfacing command-and-control staging.
HuntRule TeamWindowsimage_loadHigh202Premium2026-07-16Malicious GachiLoader C2 Beacon via X-Secret gachifamily Header
This rule detects HTTP traffic carrying the custom header value gachifamily or the GachiLoader C2 URI patterns /log and /richfamily, structural markers of the malware's command-and-control channel. These fixed protocol artifacts identify GachiLoader beaconing and tasking regardless of the C2 host in use.
HuntRule TeamWebproxyHigh2710Premium2026-07-16