Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
53 rules
Exchange WebShell Creation
These commands were used to create a WebShell by exploiting ProxyShell vulnerabilities
HuntRule TeamWindowsprocess_creationMedium142Premium2026-05-30Malicious spinstall0.aspx Webshell Written to SharePoint Layouts
This rule detects creation of the spinstall0.aspx webshell within the SharePoint LAYOUTS directory, the payload dropped by ToolShell exploitation to harvest machine key material. An aspx file written into the SharePoint application layouts path is a strong indicator of webshell installation.
HuntRule TeamWindowsfile_eventHigh491Premium2026-05-23Possible Citrix NetScaler Webshell Deployment under VPN Theme Directory (CVE-2023-3519) (via webserver)
This rule detects requests to PHP files located under the NetScaler VPN theme directory. This maps to post-exploitation of CVE-2023-3519 where attackers write a PHP webshell to /var/vpn/theme after the buffer overflow. Access to a PHP resource in this static theme path indicates a deployed webshell used for persistent remote command execution.
HuntRule TeamWebwebserverHigh403Premium2026-05-20Suspicious JSP Webshell Written to SAP irj work Directory (via file_event)
This rule detects JSP files being written under the SAP servlet_jsp irj work directory, the deployment location where CVE-2025-31324 exploitation dropped webshells such as forwardsap.jsp and helper.jsp. New JSP files appearing in this runtime path indicate server software component abuse. This is a reliable webshell persistence signal.
HuntRule TeamWindowsfile_eventHigh82Premium2026-05-15Malicious PHP Webshell Dropped in PAN-OS Unauthenticated Web Root
This rule detects a PHP file being written under the PAN-OS management web root path /var/appweb/htdocs/unauth/ which Wiz observed attackers using to drop webshells while exploiting CVE-2024-0012 and CVE-2024-9474 in the wild. This is important because the unauth directory should never contain attacker PHP scripts so a new PHP file there is a high confidence indicator of authentication bypass followed by webshell installation on the firewall.
HuntRule TeamLinuxfile_eventHigh141Premium2026-05-06Windows Process: Commvault qoperation.exe JSP Webroot Path Traversal Webshell Drop
Alerts on qoperation.exe commands that use -file to write a .jsp into a webroot path, consistent with a webshell drop.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2025-10-20SAP NetViewer Webshell Command Execution via JSP cmd Parameter
Alerts on SAP NetViewer JSP requests likely used as webshells to execute system commands via cmd-style query parameters.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverHigh317Free2025-05-14Windows File Events: SAP NetWeaver Directory Webshell File Creation (.jsp/.java/.class)
Flags Windows file creation of JSP/Java/Class under SAP NetWeaver servlet_jsp work/root paths that may indicate webshell persistence.
Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventMedium163Free2025-04-28Linux File Events: Webshell-like JSP/Java/Class Creation in SAP NetWeaver Directories
Alerts on Linux file creation of .jsp/.java/.class under SAP NetWeaver IRJ servlet paths that may indicate webshell deployment.
Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxfile_eventMedium393Free2025-04-28Windows Process Creation: China Chopper Webshell Command Pattern via W3WP
Flags w3wp.exe-launched commands matching China Chopper webshell execution patterns in Windows process creation logs.
Florian Roth (Nextron Systems), MSTI (query), Huntrule TeamWindowsprocess_creationHigh281Free2022-10-01Webserver: Suspicious Windows Path Strings in URI Query
Alerts when a web URI query contains encoded or plain Windows path strings indicative of possible exfiltration or webshell behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebwebserverHigh111Free2022-06-06Linux Process Creation Webshell Tooling: Web Server Child Processes Running System Commands
Detects web server processes spawning Linux command-line tools commonly used for host discovery or persistence.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh203Free2021-10-15Webserver URI Detects DEWMODE Webshell Access Attempts
Identifies webserver requests with DEWMODE webshell-specific URI query parameter patterns.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh142Free2021-02-22Detect SolarWinds SUPERNOVA Webshell URL Access on Webservers (logoimagehandler.ashx)
Identifies webserver traffic consistent with SUPERNOVA webshell access targeting logoimagehandler.ashx with a clazz query parameter.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical354Free2020-12-17Webserver logs: Webshell ReGeorg indicators in POST URI query with null Referer/User-Agent
Flags HTTP POST requests with null referer/user-agent and ReGeorg-like URI query parameters in web logs.
Cian Heasley, Huntrule TeamWebwebserverHigh161Free2020-08-04