Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,064 rules
Possible SSRF to AWS Metadata via Workspace One UEM BlobHandler CVE-2021-22054
This rule detects HTTP requests to the VMware Workspace One UEM Catalog or AirWatch BlobHandler.ashx endpoint that reference the AWS instance metadata service. Assetnote documented CVE-2021-22054 as a pre-auth server-side request forgery through this handler, letting attackers reach 169.254.169.254 and harvest cloud credentials.
HuntRule TeamWebwebserverHigh90Premium2026-09-07Possible SSRF via VMware Workspace One Access instanceHealth CVE-2021-22056
This rule detects HTTP requests to the VMware Workspace One Access instanceHealth REST endpoint that inject an at-sign into the hostName parameter. CVE-2021-22056 abuses this health-check path for server-side request forgery as detailed by Assetnote, which can leak an admin JWT and reach internal services.
HuntRule TeamWebwebserverHigh40Premium2026-09-07Possible WatchGuard Pre-Auth RCE via agent login XML-RPC CVE-2022-26318
This rule detects POST requests to the WatchGuard /agent/login endpoint that carry an XML-RPC agent.login method call. CVE-2022-26318 is a pre-authentication buffer overflow reached through an oversized gzip-encoded XML methodCall to this endpoint as shown by Assetnote, enabling remote code execution on the firewall.
HuntRule TeamWebwebserverMedium60Premium2026-09-07Possible Yellowfin BI Authentication Bypass via StoryBody Endpoint
This rule detects HTTP requests to the Yellowfin BI /StoryBody.i4 endpoint carrying the identity parameters abused for authentication bypass. Assetnote exploited hardcoded keys and this endpoint with ipPerson and ipOrg parameters to forge sessions, a first step toward JNDI-injection remote code execution.
HuntRule TeamWebwebserverHigh40Premium2026-09-07Possible Oracle Opera CGI Webshell Command Execution via operabin
This rule detects HTTP requests to CGI scripts under the Oracle Opera /operabin/ path that pass a cmd parameter. Following a FileReceiver webshell drop described by Assetnote, attackers invoke the planted CGI script with a cmd argument to run operating system commands on the Opera host.
HuntRule TeamWebwebserverHigh80Premium2026-09-07Possible Pre-Auth Webshell Upload via Oracle Opera FileReceiver Servlet
This rule detects HTTP requests to the Oracle Opera FileReceiver servlet used to drop a CGI webshell into the operabin cgi-bin directory. Assetnote research chains an order-of-operations bug to reach pre-auth remote code execution via this servlet, which attackers use to plant a webshell for persistent command execution.
HuntRule TeamWebwebserverMedium30Premium2026-09-07Possible Reflected XSS via cPanel cpanelwebcall Endpoint CVE-2023-29489
This rule detects HTTP requests to the cPanel /cpanelwebcall/ path that contain reflected cross-site scripting payload markers. CVE-2023-29489 allows unauthenticated reflected XSS on cPanel management ports as documented by Assetnote, which attackers use to hijack sessions and pivot into hosting infrastructure.
HuntRule TeamWebwebserverMedium30Premium2026-09-07Possible SSRF via Gatsby _gatsby File Proxy Endpoint
This rule detects HTTP requests to the Gatsby /_gatsby/file remote file proxy carrying an absolute URL or a cloud metadata target. Assetnote research showed this static site generator proxy can be coerced into server-side request forgery against internal services and the cloud metadata endpoint.
HuntRule TeamWebwebserverMedium50Premium2026-09-07Possible SSRF to Cloud Metadata via Nuxt _ipx Image Proxy
This rule detects HTTP requests to the Nuxt/Next _ipx image optimization proxy that reference the cloud instance metadata service. Static site generators expose _ipx as an open image proxy that can be abused for server-side request forgery as shown in Assetnote research, allowing an attacker to reach 169.254.169.254 and steal cloud credentials.
HuntRule TeamWebwebserverHigh30Premium2026-09-07Malicious IIS Worker Spawning nslookup via WS_FTP Deserialization
This rule detects the IIS worker process w3wp.exe spawning cmd.exe to run nslookup, matching the out-of-band verification step in the WS_FTP Ad Hoc deserialization exploit for CVE-2023-40044 shown by Assetnote. A web worker executing shell commands that resolve attacker-controlled hostnames indicates code execution through the vulnerable HTTP module. Such a process chain from IIS is rarely legitimate and points to active exploitation.
HuntRule TeamWindowsprocess_creationHigh120Premium2026-09-07Suspicious Connection to Local Zoom Opener Webserver Launch Endpoint (via network_connection)
This rule detects traffic to the local ZoomOpener helper webserver launch endpoint on loopback port 19421. This maps to the Zoom drive-by RCE chain where a webpage sends a crafted launch request to the hidden local server. An attacker leverages this to trigger silent installation and code execution on the victim host.
HuntRule TeamWebproxyLow40Premium2026-09-07Possible JSP Webshell Dropped in Tomcat Webroot by DotCMS Exploit CVE-2022-26352
This rule detects creation of a JSP file inside the DotCMS Tomcat webroot dojo static directory. Exploitation of CVE-2022-26352 writes a JSP webshell such as ROOT/html/js/dojo/a.jsp via path traversal as shown by Assetnote, so a JSP appearing in this static asset path indicates a planted webshell.
HuntRule TeamWindowsfile_eventHigh30Premium2026-09-07Suspicious PlugX Persistence via CanonPrinter Run Key (via registry_set)
This rule detects creation of a CurrentVersion Run registry value named CanonPrinter that points to a sideloading executable in a user AppData Roaming directory. UNC6384 used this Run key to persist the Canon binary that sideloads PlugX across reboots.
HuntRule TeamWindowsregistry_setHigh90Premium2026-09-07Suspicious Mass Windows Event Log Clearing via PowerShell (via ps_script)
This rule detects a PowerShell one-liner enumerating all event logs and clearing them through the EventLogSession GlobalSession ClearLog method. Qilin ransomware operators used this to wipe forensic evidence across every log on compromised hosts.
HuntRule TeamWindowsps_scriptHigh30Premium2026-09-07Malicious Fake Fortinet Patch Infostealer Execution (via process_creation)
This rule detects execution of a binary named FortiEndpoint_Patch.exe, the EKZ infostealer masqueraded as a Fortinet endpoint patch. It was delivered after FortiClient EMS exploitation to harvest browser credentials and cookies.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-07