Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,288 rules
Possible Sitecore Pre-Auth RCE via Report.ashx Insecure Deserialization (via webserver)
This rule detects POST requests to the Sitecore Reporting Report.ashx handler carrying serialized .NET gadget markers such as NetDataContractSerializer, DelegateSerializationHolder or System.Diagnostics.Process. This is the exploitation pattern for the Sitecore pre-auth insecure deserialization RCE CVE-2021-42237, where a crafted XML payload triggers process execution on the server. Detecting it exposes attempts to gain code execution on internet-facing Sitecore instances.
HuntRule TeamWebwebserverHigh60Premium2026-09-07Possible Jamf Pro SSRF Exploitation via eduFeatureSettingsTest imageUrl (via webserver)
This rule detects requests to the Jamf Pro eduFeatureSettingsTest AJAX endpoint carrying the imageUrl parameter together with the ACTION_AJAX_REQUEST_PHOTO action. This pattern was used to exploit the Jamf Pro full-read SSRF tracked as CVE-2021-39303 and CVE-2021-40809, letting an attacker coerce the server into fetching arbitrary internal URLs and returning their contents. Detecting it surfaces attempts to reach internal services or cloud metadata through the vulnerable server.
HuntRule TeamWebwebserverHigh80Premium2026-09-07Possible WebSphere Portal SSRF via Proxy Servlet targeting Cloud Metadata (CVE-2021-27748) (via webserver)
This rule detects requests to the IBM WebSphere Portal proxy servlets combined with an internal or cloud metadata IP target in the URI. This maps to CVE-2021-27748 where the ajax/docpicker proxy endpoints are abused for server-side request forgery. An attacker leverages this to reach internal services and the 169.254.169.254 metadata endpoint to steal cloud credentials.
HuntRule TeamWebwebserverHigh190Premium2026-09-07Possible SSRF to AWS Metadata via Workspace One UEM BlobHandler CVE-2021-22054
This rule detects HTTP requests to the VMware Workspace One UEM Catalog or AirWatch BlobHandler.ashx endpoint that reference the AWS instance metadata service. Assetnote documented CVE-2021-22054 as a pre-auth server-side request forgery through this handler, letting attackers reach 169.254.169.254 and harvest cloud credentials.
HuntRule TeamWebwebserverHigh140Premium2026-09-07Possible SSRF via VMware Workspace One Access instanceHealth CVE-2021-22056
This rule detects HTTP requests to the VMware Workspace One Access instanceHealth REST endpoint that inject an at-sign into the hostName parameter. CVE-2021-22056 abuses this health-check path for server-side request forgery as detailed by Assetnote, which can leak an admin JWT and reach internal services.
HuntRule TeamWebwebserverHigh100Premium2026-09-07Possible Yellowfin BI Authentication Bypass via StoryBody Endpoint
This rule detects HTTP requests to the Yellowfin BI /StoryBody.i4 endpoint carrying the identity parameters abused for authentication bypass. Assetnote exploited hardcoded keys and this endpoint with ipPerson and ipOrg parameters to forge sessions, a first step toward JNDI-injection remote code execution.
HuntRule TeamWebwebserverHigh60Premium2026-09-07Possible Oracle Opera CGI Webshell Command Execution via operabin
This rule detects HTTP requests to CGI scripts under the Oracle Opera /operabin/ path that pass a cmd parameter. Following a FileReceiver webshell drop described by Assetnote, attackers invoke the planted CGI script with a cmd argument to run operating system commands on the Opera host.
HuntRule TeamWebwebserverHigh130Premium2026-09-07Possible SSRF to Cloud Metadata via Nuxt _ipx Image Proxy
This rule detects HTTP requests to the Nuxt/Next _ipx image optimization proxy that reference the cloud instance metadata service. Static site generators expose _ipx as an open image proxy that can be abused for server-side request forgery as shown in Assetnote research, allowing an attacker to reach 169.254.169.254 and steal cloud credentials.
HuntRule TeamWebwebserverHigh70Premium2026-09-07Malicious IIS Worker Spawning nslookup via WS_FTP Deserialization
This rule detects the IIS worker process w3wp.exe spawning cmd.exe to run nslookup, matching the out-of-band verification step in the WS_FTP Ad Hoc deserialization exploit for CVE-2023-40044 shown by Assetnote. A web worker executing shell commands that resolve attacker-controlled hostnames indicates code execution through the vulnerable HTTP module. Such a process chain from IIS is rarely legitimate and points to active exploitation.
HuntRule TeamWindowsprocess_creationHigh200Premium2026-09-07Possible JSP Webshell Dropped in Tomcat Webroot by DotCMS Exploit CVE-2022-26352
This rule detects creation of a JSP file inside the DotCMS Tomcat webroot dojo static directory. Exploitation of CVE-2022-26352 writes a JSP webshell such as ROOT/html/js/dojo/a.jsp via path traversal as shown by Assetnote, so a JSP appearing in this static asset path indicates a planted webshell.
HuntRule TeamWindowsfile_eventHigh90Premium2026-09-07Suspicious PlugX Persistence via CanonPrinter Run Key (via registry_set)
This rule detects creation of a CurrentVersion Run registry value named CanonPrinter that points to a sideloading executable in a user AppData Roaming directory. UNC6384 used this Run key to persist the Canon binary that sideloads PlugX across reboots.
HuntRule TeamWindowsregistry_setHigh170Premium2026-09-07Suspicious Mass Windows Event Log Clearing via PowerShell (via ps_script)
This rule detects a PowerShell one-liner enumerating all event logs and clearing them through the EventLogSession GlobalSession ClearLog method. Qilin ransomware operators used this to wipe forensic evidence across every log on compromised hosts.
HuntRule TeamWindowsps_scriptHigh120Premium2026-09-07Malicious Fake Fortinet Patch Infostealer Execution (via process_creation)
This rule detects execution of a binary named FortiEndpoint_Patch.exe, the EKZ infostealer masqueraded as a Fortinet endpoint patch. It was delivered after FortiClient EMS exploitation to harvest browser credentials and cookies.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-07Suspicious BeyondTrust Bomgar Process Spawning Remote Access Client (via process_creation)
This rule detects a BeyondTrust Bomgar process spawning a renamed SimpleHelp remote access binary. Operators abused the CVE-2026-1731 command-execution flaw to deploy SimpleHelp under the SYSTEM account as a secondary remote access foothold.
HuntRule TeamWindowsprocess_creationHigh90Premium2026-09-07Malicious NTDS Extraction via ntdsutil IFM (via process_creation)
This rule detects use of ntdsutil to create an Install From Media copy of the Active Directory database. Qilin ransomware operators ran ntdsutil with the ifm create full arguments to extract the NTDS database and registry hives for offline credential harvesting.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-07