Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,063 rules
Possible DotCMS Path Traversal Webshell Upload via content API CVE-2022-26352
This rule detects POST requests to the DotCMS /api/content/ endpoint whose multipart filename contains directory-traversal sequences and a JSP extension. CVE-2022-26352 is an arbitrary file upload that drops a JSP webshell into the Tomcat webroot as documented by Assetnote, giving attackers remote code execution.
HuntRule TeamWebwebserverMedium60Premium2026-09-08Suspicious Avaya Aura ACS Path Traversal to Admin Login via Semicolon Bypass (via webserver)
This rule detects requests to the Avaya Aura ACS admin login path that use a semicolon path-segment traversal such as /acs/..;/admin/public/login.jsp to bypass access controls, seen alongside a reflected XSS via the error parameter. This pattern was used to reach protected admin functionality on the appliance. Detecting it surfaces access-control bypass attempts against Avaya Aura Device Services.
HuntRule TeamWebwebserverMedium10Premium2026-09-08Possible Avaya Aura Device Services WebDAV PHP Webshell Upload via PhoneBackup (via webserver)
This rule detects WebDAV PUT requests writing a PHP file into the Avaya Aura Device Services PhoneBackup directory, optionally with the User-Agent AVAYA seen in the exploit. This is the RCE path where an attacker uploads a PHP webshell and then requests it for command execution. Detecting it surfaces webshell deployment against Avaya Aura Device Services.
HuntRule TeamWebwebserverHigh70Premium2026-09-07Possible Aspera Faspex Pre-Auth RCE via YAML Deserialization in package_relay (via webserver)
This rule detects POST requests to the Aspera Faspex package_relay relay_package endpoint, the injection point for a pre-auth RCE where the external_emails field carries a serialized YAML payload deserialized by YAML.load. Attackers abuse this Ruby on Rails unsafe deserialization to execute arbitrary commands. Detecting it surfaces exploitation attempts against internet-facing Faspex servers.
HuntRule TeamWebwebserverHigh50Premium2026-09-07Malicious Dynamicweb Unauthenticated Administrator Creation via Setup Default.aspx (via webserver)
This rule detects requests to the Dynamicweb Access Setup Default.aspx page invoking the createadministrator action with adminusername and adminpassword parameters. This logic flaw in Dynamicweb 9.5.0 through 9.12.7 lets an unauthenticated attacker create an administrator account and then upload an ASPX webshell for RCE. Detecting it surfaces account creation abuse leading to full server compromise.
HuntRule TeamWebwebserverCritical10Premium2026-09-07Possible DotCMS Arbitrary File Upload and JSP Webshell Drop via api content (via webserver)
This rule detects multipart POST or PUT requests to the DotCMS content API whose filename carries path traversal sequences aimed at the webapps ROOT html directory. This is the 0day exploitation path that drops a .jsp webshell outside the intended upload location for remote code execution. Detecting it surfaces webshell installation against internet-facing DotCMS instances.
HuntRule TeamWebwebserverHigh40Premium2026-09-07Possible PHP Webshell Access After Malicious ZIP Upload (via webserver)
This rule detects requests to a PHP file named workdone.php served from a work directory, the webshell dropped by extracting a malicious ZIP into /www/work/ during the Mozilla AWS code-execution research. Access to this out-of-place PHP file indicates a planted webshell being used for remote command execution. Detecting it surfaces post-exploitation control of the compromised host.
HuntRule TeamWebwebserverHigh90Premium2026-09-07Suspicious Fastly Client IP Header Spoofed to Localhost (via webserver)
This rule detects inbound requests where the Fastly client IP header is set to a loopback address such as 127.0.0.1, a spoofing technique used to bypass IP-based access controls on Fastly-fronted applications. During the Mozilla AWS research this trust in the client-supplied header let an attacker reach protected functionality. Detecting it surfaces attempts to forge trusted-source access to internal endpoints.
HuntRule TeamWebwebserverMedium10Premium2026-09-07Possible Progress WhatsUp Gold Path Traversal and UNC Coercion via core API (via webserver)
This rule detects requests to the WhatsUp Gold AlarmCustomizer and WebContent core API endpoints that carry directory traversal sequences or UNC paths such as backslash-backslash host references and administrative shares. This pattern was used to read arbitrary files and coerce the server into authenticating to attacker SMB shares to capture NTLM credentials. Detecting it exposes file read and forced-authentication attacks against the monitoring server.
HuntRule TeamWebwebserverHigh170Premium2026-09-07Possible SolarWinds Web Help Desk Arbitrary HQL Evaluation via rawHQL (via webserver)
This rule detects POST requests to the SolarWinds Web Help Desk assetReport rawHQL endpoint, the injection point for the arbitrary HQL evaluation flaw CVE-2021-35232. Attackers submit attacker-controlled HQL queries to this endpoint, often reusing the hardcoded Basic credentials shipped with the product, to read or manipulate backend data. Detecting it surfaces exploitation of the vulnerable help desk instance.
HuntRule TeamWebwebserverHigh310Premium2026-09-07Possible Sitecore Pre-Auth RCE via Report.ashx Insecure Deserialization (via webserver)
This rule detects POST requests to the Sitecore Reporting Report.ashx handler carrying serialized .NET gadget markers such as NetDataContractSerializer, DelegateSerializationHolder or System.Diagnostics.Process. This is the exploitation pattern for the Sitecore pre-auth insecure deserialization RCE CVE-2021-42237, where a crafted XML payload triggers process execution on the server. Detecting it exposes attempts to gain code execution on internet-facing Sitecore instances.
HuntRule TeamWebwebserverHigh50Premium2026-09-07Possible Jamf Pro SSRF Exploitation via eduFeatureSettingsTest imageUrl (via webserver)
This rule detects requests to the Jamf Pro eduFeatureSettingsTest AJAX endpoint carrying the imageUrl parameter together with the ACTION_AJAX_REQUEST_PHOTO action. This pattern was used to exploit the Jamf Pro full-read SSRF tracked as CVE-2021-39303 and CVE-2021-40809, letting an attacker coerce the server into fetching arbitrary internal URLs and returning their contents. Detecting it surfaces attempts to reach internal services or cloud metadata through the vulnerable server.
HuntRule TeamWebwebserverHigh60Premium2026-09-07Possible WebSphere Portal SSRF via Proxy Servlet targeting Cloud Metadata (CVE-2021-27748) (via webserver)
This rule detects requests to the IBM WebSphere Portal proxy servlets combined with an internal or cloud metadata IP target in the URI. This maps to CVE-2021-27748 where the ajax/docpicker proxy endpoints are abused for server-side request forgery. An attacker leverages this to reach internal services and the 169.254.169.254 metadata endpoint to steal cloud credentials.
HuntRule TeamWebwebserverHigh160Premium2026-09-07Possible SSRF via WebSphere Portal docpicker internal_proxy CVE-2021-27748
This rule detects HTTP requests to the WebSphere Portal docpicker internal_proxy and wps proxy passthrough endpoints. CVE-2021-27748 exposes these proxy paths to server-side request forgery as described by Assetnote, which attackers use to reach internal-only services from the portal server.
HuntRule TeamWebwebserverMedium240Premium2026-09-07Possible SSRF to AWS Metadata via Workspace One UEM BlobHandler CVE-2021-22054
This rule detects HTTP requests to the VMware Workspace One UEM Catalog or AirWatch BlobHandler.ashx endpoint that reference the AWS instance metadata service. Assetnote documented CVE-2021-22054 as a pre-auth server-side request forgery through this handler, letting attackers reach 169.254.169.254 and harvest cloud credentials.
HuntRule TeamWebwebserverHigh90Premium2026-09-07