Detection Rules

Sigma Rules, by Threat

Filter to the vendor, campaign, or CVE you're worried about and get the rule that detects it, not a firehose of everything we've ever matched. Copy the YAML and convert to your SIEM's query language with sigma-cli. The companion to Prevention & Mitigation: this answers what tells you it's already happening.

16 rules

mediumfortigate / eventMONDAY INTEL DROP · WEEKLY BRIEF

FortiGate - New VPN SSL Web Portal Added

Detects the addition of a VPN SSL Web Portal on a Fortinet FortiGate Firewall. This behavior was observed in pair with modification of VPN SSL settings.

Matched threat: FortiBleed Hits 430K Firewalls: 4 Threats to Prioritize This Week

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
mediumfortigate / eventMONDAY INTEL DROP · WEEKLY BRIEF

FortiGate - VPN SSL Settings Modified

Detects the modification of VPN SSL Settings (for example, the modification of authentication rules). This behavior was observed in pair with the addition of a VPN SSL Web Portal.

Matched threat: FortiBleed Hits 430K Firewalls: 4 Threats to Prioritize This Week

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
highprocess_creation (windows)MONDAY INTEL DROP · WEEKLY BRIEF

Microsoft IIS Connection Strings Decryption

Detects use of aspnet_regiis to decrypt Microsoft IIS connection strings. An attacker with Microsoft IIS web server access via a webshell or alike can decrypt and dump any hardcoded connection strings, such as the MSSQL service account password using aspnet_regiis command.

Matched threat: FortiBleed Hits 430K Firewalls: 4 Threats to Prioritize This Week

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
highapplication (opencanary)KNOW YOUR ENEMY · APT PROFILECVE-2018-0171

OpenCanary - SNMP OID Request

Detects instances where an SNMP service on an OpenCanary node has had an OID request.

Matched threat: FSB Center 16: 13 Nations Warn of Russia's Static Tundra Router Espionage Campaign

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
mediumcisco / aaaKNOW YOUR ENEMY · APT PROFILECVE-2018-0171

Cisco Dot1x Disabled

Detects the manual disablement of IEEE 802.1X (dot1x) on a Cisco network device interface. Disabling dot1x bypasses Network Access Control (NAC) mechanisms, potentially allowing unauthorized devices to gain access to the internal network. This activity is a common technique used by attackers or malicious insiders to establish persistence or perform lateral movement via rogue devices.

Matched threat: FSB Center 16: 13 Nations Warn of Russia's Static Tundra Router Espionage Campaign

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
mediumwindows / ldapAI WEAPONIZED · OFFENSIVE AI

Potential Active Directory Reconnaissance/Enumeration Via LDAP

Detects potential Active Directory enumeration via LDAP

Matched threat: AI-Generated 'Vibe-Coded' Malware Caught Mapping Active Directory in Live Attack

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
lowps_script (windows)AI WEAPONIZED · OFFENSIVE AI

AD Groups Or Users Enumeration Using PowerShell - ScriptBlock

Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.

Matched threat: AI-Generated 'Vibe-Coded' Malware Caught Mapping Active Directory in Live Attack

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
highprocess_creation (windows)AI WEAPONIZED · OFFENSIVE AI

PUA - Rclone Execution

Detects execution of RClone utility for exfiltration as used by various ransomware strains like REvil, Conti, FiveHands, and others. The same behavioral pattern applies to s5cmd, AzCopy, and other cloud CLI tools used for unauthorized data staging.

Matched threat: AI-Generated 'Vibe-Coded' Malware Caught Mapping Active Directory in Live Attack

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
highfile_event (windows)CLOSE THIS GAP · EXPOSURE ADVISORYCVE-2026-56155

Suspicious File Write to SharePoint Layouts Directory

Detects suspicious file writes to SharePoint layouts directory which could indicate webshell activity or post-exploitation. This behavior has been observed in the exploitation of SharePoint vulnerabilities such as CVE-2025-49704, CVE-2025-49706 or CVE-2025-53770.

Matched threat: Microsoft Patch Tuesday July 2026: 2 Zero-Days Exploited in Attacks, 570 Flaws Fixed

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
highprocess_creation (windows)CLOSE THIS GAP · EXPOSURE ADVISORYCVE-2026-56155

Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators

Detects potential exploitation of CVE-2025-53770 by identifying indicators such as suspicious command lines discovered in Post-Exploitation activities. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.

Matched threat: Microsoft Patch Tuesday July 2026: 2 Zero-Days Exploited in Attacks, 570 Flaws Fixed

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
highokta / oktaYOUR EXPOSURE TODAY · DATA BREACH

Okta FastPass Phishing Detection

Detects when Okta FastPass prevents a known phishing site.

Matched threat: Aflac Japan Data Breach Exposes 4.38 Million Customers: Bank Accounts and PII Stolen

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
highokta / oktaYOUR EXPOSURE TODAY · DATA BREACH

Okta User Session Start Via An Anonymising Proxy Service

Detects when an Okta user session starts where the user is behind an anonymising proxy service.

Matched threat: Aflac Japan Data Breach Exposes 4.38 Million Customers: Bank Accounts and PII Stolen

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
highokta / oktaYOUR EXPOSURE TODAY · DATA BREACH

Okta Suspicious Activity Reported by End-user

Detects when an Okta end-user reports activity by their account as being potentially suspicious.

Matched threat: Aflac Japan Data Breach Exposes 4.38 Million Customers: Bank Accounts and PII Stolen

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
highprocess_creation (linux)ACTIVE CAMPAIGN · SONICWALLCVE-2026-15409

Linux Webshell Indicators

Detects suspicious sub processes of web server processes

Matched threat: SonicWall SMA1000 Zero-Days CVE-2026-15409 Actively Exploited: Patch Before July 17

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
highprocess_creation (linux)ACTIVE CAMPAIGN · SONICWALLCVE-2026-15409

Potential Netcat Reverse Shell Execution

Detects execution of netcat with the "-e" flag followed by common shells. This could be a sign of a potential reverse shell setup.

Matched threat: SonicWall SMA1000 Zero-Days CVE-2026-15409 Actively Exploited: Patch Before July 17

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub
highwebserverACTIVE CAMPAIGN · SONICWALLCVE-2026-15409

Webshell ReGeorg Detection Via Web Logs

Certain strings in the uri_query field when combined with null referer and null user agent can indicate activity associated with the webshell ReGeorg.

Matched threat: SonicWall SMA1000 Zero-Days CVE-2026-15409 Actively Exploited: Patch Before July 17

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Source: SigmaHQ, Detection Rule License 1.1View on GitHub

Rules are from the SigmaHQ community repository, licensed under the Detection Rule License 1.1, matched to threat-specific editorial coverage (active campaigns, CVEs, APT profiles, exposure advisories) — scanning the 250 most recent threat posts with a matched rule. Always review false positive notes before enabling a rule in production.