Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
40 rules
Suspicious Telegram Bot API C2 Beaconing (via network)
This rule detects outbound HTTP requests to the Telegram bot API using sendPhoto and sendDocument methods which the CoralRaider actor abuses for command and control and exfiltration of stolen social media data. Abusing a legitimate messaging platform lets attackers hide C2 inside allowed web traffic and defeat domain reputation controls.
HuntRule TeamWebproxyMedium81Premium2026-05-04Proxy Traffic to Operation Triangulation Domains Indicative of C2 Beaconing
Alerts on proxy requests to specific suspect C2-related domains by host substring match.
Florian Roth (Nextron Systems), Huntrule Team—proxyHigh162Free2023-06-01Suspicious DNS Queries to Operation Triangulation-Like Domains for C2 Beaconing
Detects DNS queries to known Operation Triangulation-related domains that may indicate C2 beaconing.
Florian Roth (Nextron Systems), Huntrule Team—dnsHigh91Free2023-06-01Proxy Beaconing to 3CX-Related Domains Indicating Possible Compromise
Flags proxy requests to 3CX-related domains that may indicate C2 beaconing behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyHigh3810Free2023-03-29Windows 3CXDesktopApp.exe Beaconing to Suspicious 3CX-Related Domains (Netcon)
Potential Compromised 3CXDesktopApp Beaconing Activity - Netcon
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh189Free2023-03-29Windows DNS: Detect potential beaconing to domains associated with 3CXDesktopApp compromise
Potential Compromised 3CXDesktopApp Beaconing Activity - DNS
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns_queryHigh235Free2023-03-29Windows DNS Client: Cobalt Strike DNS Beaconing Patterns via Suspicious Query Names
Alerts when Windows DNS client logs show Event ID 3008 DNS queries matching Cobalt Strike beacon patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientCritical4410Free2023-01-16Suspicious DNS Query Patterns for Cobalt Strike Beacons on Windows (Sysmon)
Alerts on Windows Sysmon DNS queries with QueryName patterns consistent with Cobalt Strike DNS beaconing.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdns_queryCritical173Free2021-11-09Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowssecurityHigh123Free2021-05-26Cobalt Strike-style DNS Beaconing Queries (DNS)
Flags DNS queries with Cobalt Strike-style stage subdomain patterns used for covert beaconing.
Florian Roth (Nextron Systems), Huntrule TeamNetworkdnsCritical81Free2018-05-10