Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
40 rules
Possible Hive0051 GammaLoad C2 Beacon via Crafted User-Agent (via proxy)
This rule detects the distinctive User-Agent string used by Hive0051 GammaLoad implants for victim profiling during command-and-control. The agent appends a host token followed by an eight-character uppercase hex identifier and a keyword delimited by repeated semicolons and slash-dot sequences. This structure does not occur in standard browser traffic.
HuntRule TeamWebproxyMedium418Premium2026-07-12Suspicious UPDTAE Backdoor Reverse Shell HTTP Beacon via Quad7 Operators
This rule detects HTTP requests carrying the hardcoded User-Agent value IOT together with POST requests to the /iot/post URI, the reverse shell beaconing pattern of the UPDTAE backdoor deployed by the Quad7 operators. The implant polls its C2 roughly every thirty seconds using this fixed header and path. The unusual static User-Agent and endpoint make this a reliable network indicator.
HuntRule TeamWebproxyHigh216Premium2026-07-07Malicious OysterLoader C2 Beacon Using WordPressAgent User Agent
This rule detects outbound web requests carrying the distinctive WordPressAgent FingerPrint user agent used by OysterLoader. The loader beacons to its command server with this hardcoded agent and reaches encrypted endpoints. A non browser user agent of this exact form is a high confidence network indicator of OysterLoader activity.
HuntRule TeamWebproxyHigh231Premium2026-06-28MintsLoader Stage-Two C2 Beacon via htr.php Key and Campaign Parameters (via proxy)
This rule detects MintsLoader stage-two command-and-control beacons that request the htr.php endpoint with key, host id, and campaign parameters against DGA-generated domains. Adversaries leverage this structured request to fetch the next-stage payload keyed to the infected host, making the endpoint-and-parameter combination a strong C2 indicator.
HuntRule TeamWebproxyHigh52Premium2026-06-27Malicious Cobalt Strike C2 Beaconing via REST URI Paths and Legacy MSIE User-Agent (via proxy)
This rule detects HTTP command-and-control beaconing that combines the /rest/funcStatus and /rest/policy/3/ URI paths with a legacy MSIE 7.0 .NET CLR User-Agent, a Malleable C2 profile used by a multi-stage Cobalt Strike loader analyzed by Joe Sandbox. Adversaries craft these profiles to blend beacon traffic into ordinary web requests, making the combined URI and User-Agent pattern a reliable signal of an active beacon before hands-on-keyboard activity.
HuntRule TeamWebproxyHigh375Premium2026-06-26CastleLoader Stager HTTP Beacon via Misspelled GoogeBot User-Agent (via proxy)
This rule detects outbound HTTP requests carrying the misspelled GoogeBot user-agent used by the CastleLoader stager to retrieve follow-on TAG-150 payloads while masquerading as a search-engine crawler. Adversaries leverage crawler-like user-agents to blend malicious downloads into ordinary web traffic, making this distinctive typo a reliable delivery-stage indicator.
HuntRule TeamWebproxyHigh191Premium2026-06-23Suspicious HTTP Beacon Using Rare MyIE User Agent (via proxy)
This rule detects outbound HTTP traffic carrying the uncommon MyIE user agent string used by the MemFun implant in a suspected China-based espionage operation against military targets in Southeast Asia. The hardcoded user agent identifies the malware's beaconing channel, so matching traffic to external hosts indicates active command and control.
HuntRule TeamWebproxyMedium287Premium2026-06-22Malicious CR4T C2 Beacon via TroubleShooter User-Agent (via proxy)
This rule detects outbound HTTP requests carrying the distinctive TroubleShooter User-Agent string which the CR4T implant of the DuneQuixote campaign uses when communicating with its command-and-control server.
HuntRule TeamWebproxyHigh339Premium2026-06-06Suspicious Khmer Shadow C2 Beacon with Malformed Chrome User-Agent (via proxy)
This rule detects outbound requests carrying the malformed Chrome 131 on Windows 10 user-agent string used by the Khmer Shadow implant to blend its C2 traffic. Adversaries craft this non-standard agent value that does not match any real browser build. The exact malformed string provides a low-noise channel indicator for this espionage cluster.
HuntRule TeamWebproxyMedium224Premium2026-06-02Suspicious C2 Beacon via cpp-httplib User Agent
This rule detects outbound HTTP requests carrying the cpp-httplib user agent, matching the Potemkin loader command-and-control channel observed with the test_agent identifier. The loader is built on the cpp-httplib library and this user agent rarely appears in legitimate enterprise browsing. Its presence in proxy or web telemetry indicates loader check-in and tasking.
HuntRule TeamWebproxyHigh316Premium2026-05-30Malicious PeerBlight Command and Control Beacon to qtss.cc Domain
This rule detects DNS resolution of the qtss.cc domain, the ZinFoq command and control infrastructure contacted by the PeerBlight Linux backdoor for beaconing. Resolution of this domain indicates an infected host reaching out to attacker-controlled C2. The domain is a known PeerBlight indicator and has no legitimate business use.
HuntRule TeamNetworkdns_queryHigh285Premium2026-05-27Malicious Koi Loader C2 Check-in via Index PHP Beacon (via proxy)
This rule detects Koi Loader command-and-control beacons to an index.php endpoint carrying the campaign-specific subid=px8eIkut parameter used for host registration. This structured query pattern accompanies the pipe-delimited 101|GUID|VoYGkc5R check-in marker. Detecting it surfaces active Koi Loader C2 that precedes Koi Stealer deployment and credential exfiltration.
HuntRule TeamWebproxyHigh152Premium2026-05-24Possible NetHealth Implant C2 Beacon URI Pattern
This rule detects outbound HTTP requests matching the structured C2 beacon paths used by the Rapid Breach implant, including the resutato.com tap.php stager and the st.php beacon carrying computer and user name query parameters. These fixed URI patterns indicate command-and-control communication with the attacker infrastructure.
HuntRule TeamWebproxyHigh203Premium2026-05-23Malicious SSLoad Downloader C2 Beacon via Custom SSLoad User-Agent (via proxy)
This rule detects outbound HTTP traffic carrying the hardcoded SSLoad User-Agent used by the SSLoad downloader when it registers a fingerprinted host and beacons for tasks to its command-and-control server. This bespoke agent string is not produced by legitimate software and identifies the downloader stage of the intrusion on the wire.
HuntRule TeamWebproxyHigh71Premium2026-05-11Malicious TeamPCP Trivy C2 Beacon to ICP Canister and Cloudflare Tunnel (via dns_query)
This rule detects DNS resolution of the Internet Computer canister fallback host the Cloudflare tunnel and the aquasecurtiy typosquat domain used as command-and-control by the TeamPCP implant embedded in the compromised Trivy v0.69.4 release. These hosts serve payloads and receive exfiltrated credentials so a lookup indicates an infected build or developer host beaconing out.
HuntRule TeamLinuxdns_queryHigh191Premium2026-05-05