Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
53 rules
Possible Ivanti Connect Secure Webshell Access
This rule detects HTTP access to Ivanti Connect Secure API paths and CGI scripts associated with the WIREFIRE, LIGHTWIRE, and backdoored compcheckresult webshells dropped during the zero-day exploitation. Attackers use these implanted webshells for persistent remote command execution on the appliance. Requests to these specific endpoints indicate an already-compromised device.
HuntRule TeamWebwebserverHigh10Premium2026-09-14Suspicious SD-WAN Compromise JSP Webshell Access
This rule detects web requests to the JSP webshells dropped during the Cisco Catalyst SD-WAN exploitation, including the XenShell and named sysinit and vmurnp_ikp shells. Access to these attacker-planted JSP files gives operators command execution on the compromised appliance. Requests to these paths indicate webshell interaction following exploitation.
HuntRule TeamWebwebserverMedium30Premium2026-09-12Malicious AquaShell Webshell Access on Cisco Secure Email Gateway by UAT-9686
This rule detects HTTP POST requests to the AquaShell Python webshell planted at the euq_webui index.py endpoint on Cisco Secure Email appliances. UAT-9686 uses this unauthenticated webshell to execute arbitrary commands on compromised gateways. Requests to this appliance path indicate active exploitation and remote command execution.
HuntRule TeamWebwebserverHigh30Premium2026-09-12Possible Citrix ShareFile Unauthenticated Upload Path Traversal Webshell (CVE-2023-24489) (via webserver)
This rule detects unauthenticated POST requests to the ShareFile storage controller upload endpoints carrying a traversal uploadid and archive extraction flags. This maps to CVE-2023-24489 where a cryptographic flaw allows uploading and unzipping an ASPX webshell outside the intended directory. An attacker uses this to achieve remote code execution and persistence.
HuntRule TeamWebwebserverHigh260Premium2026-09-08Possible DotCMS Path Traversal Webshell Upload via content API CVE-2022-26352
This rule detects POST requests to the DotCMS /api/content/ endpoint whose multipart filename contains directory-traversal sequences and a JSP extension. CVE-2022-26352 is an arbitrary file upload that drops a JSP webshell into the Tomcat webroot as documented by Assetnote, giving attackers remote code execution.
HuntRule TeamWebwebserverMedium130Premium2026-09-08Possible Avaya Aura Device Services WebDAV PHP Webshell Upload via PhoneBackup (via webserver)
This rule detects WebDAV PUT requests writing a PHP file into the Avaya Aura Device Services PhoneBackup directory, optionally with the User-Agent AVAYA seen in the exploit. This is the RCE path where an attacker uploads a PHP webshell and then requests it for command execution. Detecting it surfaces webshell deployment against Avaya Aura Device Services.
HuntRule TeamWebwebserverHigh120Premium2026-09-07Possible DotCMS Arbitrary File Upload and JSP Webshell Drop via api content (via webserver)
This rule detects multipart POST or PUT requests to the DotCMS content API whose filename carries path traversal sequences aimed at the webapps ROOT html directory. This is the 0day exploitation path that drops a .jsp webshell outside the intended upload location for remote code execution. Detecting it surfaces webshell installation against internet-facing DotCMS instances.
HuntRule TeamWebwebserverHigh100Premium2026-09-07Possible PHP Webshell Access After Malicious ZIP Upload (via webserver)
This rule detects requests to a PHP file named workdone.php served from a work directory, the webshell dropped by extracting a malicious ZIP into /www/work/ during the Mozilla AWS code-execution research. Access to this out-of-place PHP file indicates a planted webshell being used for remote command execution. Detecting it surfaces post-exploitation control of the compromised host.
HuntRule TeamWebwebserverHigh150Premium2026-09-07Possible Oracle Opera CGI Webshell Command Execution via operabin
This rule detects HTTP requests to CGI scripts under the Oracle Opera /operabin/ path that pass a cmd parameter. Following a FileReceiver webshell drop described by Assetnote, attackers invoke the planted CGI script with a cmd argument to run operating system commands on the Opera host.
HuntRule TeamWebwebserverHigh110Premium2026-09-07Possible Pre-Auth Webshell Upload via Oracle Opera FileReceiver Servlet
This rule detects HTTP requests to the Oracle Opera FileReceiver servlet used to drop a CGI webshell into the operabin cgi-bin directory. Assetnote research chains an order-of-operations bug to reach pre-auth remote code execution via this servlet, which attackers use to plant a webshell for persistent command execution.
HuntRule TeamWebwebserverMedium50Premium2026-09-07Possible JSP Webshell Dropped in Tomcat Webroot by DotCMS Exploit CVE-2022-26352
This rule detects creation of a JSP file inside the DotCMS Tomcat webroot dojo static directory. Exploitation of CVE-2022-26352 writes a JSP webshell such as ROOT/html/js/dojo/a.jsp via path traversal as shown by Assetnote, so a JSP appearing in this static asset path indicates a planted webshell.
HuntRule TeamWindowsfile_eventHigh80Premium2026-09-07Malicious Houken PHP Webshell Written into Ivanti CSA Webroot via Shell Redirection (via process_creation)
This rule detects a shell dropping a PHP webshell into the Ivanti Cloud Service Appliance LANDesk broker webroot by echoing PHP code that invokes system() or eval() on request parameters, the initial-access behavior used by the Houken intrusion set after exploiting Ivanti CSA zero-days. Adversaries leverage this to obtain a persistent command channel on the appliance, making early detection critical for catching perimeter compromise before rootkit deployment and lateral movement.
HuntRule TeamLinuxprocess_creationHigh80Premium2026-09-02Malicious XE Group Webshell Upload via VeraCore UploadImage CVE-2024-57968 (via webserver)
This rule detects abuse of the VeraCore UploadImage handler to upload an ASP or ASPX webshell through the CVE-2024-57968 unrestricted-upload flaw exploited by XE Group. The request combines the PMA upload controller with a script-file filename parameter, reflecting the point at which the actor plants a persistent webshell on the server.
HuntRule TeamWebwebserverHigh120Premium2026-09-01Malicious alexantr File Manager Webshell Access after CraftCMS Compromise (via webserver)
This rule detects requests to a filemanager.php webshell with its upload and delete parameters, the open-source alexantr file manager dropped to the web root following CraftCMS CVE-2025-32432 exploitation. Adversaries use this webshell to browse, upload and remove files on the compromised server for hands-on-keyboard actions.
HuntRule TeamWebwebserverHigh80Premium2026-08-30Suspicious Timestomping of PHP Webshell in Ivanti CSA Webroot via touch (via process_creation)
This rule detects use of touch with an explicit date argument to backdate a PHP file inside the Ivanti Cloud Service Appliance LANDesk broker webroot, the timestomping behavior used by the Houken intrusion set to blend planted webshells with legitimate appliance files. Adversaries leverage timestamp manipulation to frustrate forensic triage, making this a strong signal of an attacker actively concealing webshell drops on the appliance.
HuntRule TeamLinuxprocess_creationMedium140Premium2026-08-29