Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
53 rules
Malicious JSP Webshell Deployment in Ivanti EPMM Tomcat (via file_event)
This rule detects creation of JSP files under the Ivanti EPMM Tomcat mifs webapps directory, where exploitation of CVE-2026-1281 and CVE-2026-1340 plants webshells such as 401.jsp and 403.jsp. A webshell in this application path gives attackers persistent authenticated command execution on the appliance.
HuntRule TeamLinuxfile_eventHigh132Premium2026-08-28Malicious WordPress Webshell session-manager PHP in mu-plugins
This rule detects creation of a session-manager.php file inside the WordPress must use plugins directory. ErrTraffic deploys this file as a persistent server side backdoor on compromised WordPress installations. A PHP file named session-manager.php dropped into mu-plugins is characteristic of this web shell and rarely legitimate.
HuntRule TeamLinuxfile_eventHigh411Premium2026-08-15Possible AntSword Webshell Access on Ivanti EPMM 403.jsp
This rule detects HTTP POST requests to the 403.jsp resource on Ivanti EPMM carrying the AntSword webshell parameter k. It is tied to a Java webshell appended to the legitimate 403.jsp error page during EPMM exploitation to provide operators remote command execution. Detecting these requests reveals interaction with the deployed webshell.
HuntRule TeamWebwebserverMedium116Premium2026-08-11Malicious JSP Webshell Written to SAP NetWeaver Servlet Directory
This rule detects creation of JSP webshell files with names observed in exploitation of the SAP NetWeaver CVE-2025-31324 file upload vulnerability inside servlet_jsp working directories. Adversaries drop these webshells to gain persistent remote command execution on the compromised application server. Detecting the file write surfaces web shell installation immediately after exploitation.
HuntRule TeamWindowsfile_eventHigh111Premium2026-08-08Malicious Webshell Written to Citrix NetScaler VPN Theme Directory (via file_event)
This rule detects the post-exploitation stage of Citrix NetScaler CVE-2026-8452 where a php webshell is dropped into the vpn theme directory after a pre-auth heap overflow. A php file in this template directory indicates appliance compromise.
HuntRule TeamLinuxfile_eventHigh111Premium2026-07-23Suspicious PHP Webshell File Creation Linked to BeyondTrust Exploitation (via file_event)
This rule detects creation of PHP webshell files named aws.php and file_save.php observed after exploitation of BeyondTrust CVE-2026-1731. These webshells provide persistent remote command execution on the compromised host, so their appearance on a web-accessible path indicates an established foothold.
HuntRule TeamWindowsfile_eventMedium269Premium2026-07-22WordPress wp2shell Plugin Webshell Access via wp-content/plugins URL Path
Alert on HTTP requests targeting the wp2shell WordPress plugin path used for webshell execution/persistence.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverCritical323Free2026-07-19Malicious SharePoint spinstall0 Webshell Dropped in LAYOUTS
This rule detects the spinstall0.aspx file being written into the SharePoint LAYOUTS directory. Attackers exploiting the ToolShell chain drop this ASPX webshell to steal machine keys and maintain access. Creation of spinstall0.aspx in LAYOUTS is a definitive post-exploitation indicator.
HuntRule TeamWindowsfile_eventCritical132Premium2026-07-11Suspicious ASPX Webshell Written to IIS inetsrv Directory via file_event
This rule detects an fd.aspx file being written under the IIS inetsrv directory, matching the webshell dropped by the hacktivist actors for server access. Web-facing script files appearing in the IIS binaries path are a hallmark of server-side webshell deployment. This supports persistence and remote command execution on internet-facing hosts.
HuntRule TeamWindowsfile_eventHigh91Premium2026-07-03Suspicious SharePoint Webshell File Creation in LAYOUTS Directory via ToolShell (via file_event)
This rule detects creation of known ToolShell webshell and key harvester aspx files inside the SharePoint LAYOUTS directory. These filenames are associated with post exploitation of CVE-2025-53770 and related SharePoint flaws.
HuntRule TeamWindowsfile_eventHigh378Premium2026-06-16Suspicious PHP Webshell Access under WordPress Cache Directory
This rule detects HTTP requests to a PHP file located in the WordPress wp-content cache directory. Legitimate WordPress caching stores static HTML and never executable PHP, so a PHP file served from this path indicates a dropped webshell used for post exploitation command execution.
HuntRule TeamWebwebserverHigh436Premium2026-06-15SharePoint spinstall Webshell Deployment after ToolShell Exploitation (via webserver)
This rule detects requests to spinstall or related aspx webshells dropped after ToolShell exploitation of SharePoint CVE-2025-53770, which extract the ValidationKey and DecryptionKey machine key material from the server. Adversaries retrieve these keys to forge authentication and regain access even after patching.
HuntRule TeamWebwebserverHigh123Premium2026-06-13Suspicious Webshell Written To F5 TMUI Web Directory
This rule detects creation of a PHP or JSP file within the F5 BIG-IP xui web directory tree which is where operators dropped webshells after TMUI exploitation as described in NCC Group RIFT F5 TMUI intelligence. Adversaries plant these webshells to maintain persistent remote command execution on the appliance so any script file appearing in these image and script paths is highly suspicious.
HuntRule TeamLinuxfile_eventHigh132Premium2026-06-09Suspicious Access to SonicWall SMA JSP Webshell
This rule detects HTTP requests to JSP webshells planted on a compromised SonicWall SMA appliance. In the 0-day exploitation the actor placed error.jsp and errorDialog.jsp under the workplace directory and proxied them to a local listener to execute commands. Access to these attacker-planted endpoints indicates active webshell interaction and hands-on-keyboard control of the appliance.
HuntRule TeamWebwebserverHigh81Premium2026-06-09Malicious XE Group thump.aspx Webshell Interaction via File Directory Parameters (via webserver)
This rule detects requests to the XE Group .thump.aspx webshell that carry the file-listing and file-read parameters the operator uses to browse and exfiltrate server files. The hidden-prefixed ASPX name combined with these directory parameters distinguishes webshell tasking from normal application traffic.
HuntRule TeamWebwebserverHigh72Premium2026-06-04