Detection Rules
Sigma Rules, by Threat
Filter to the vendor, campaign, or CVE you're worried about and get the rule that detects it, not a firehose of everything we've ever matched. Copy the YAML and convert to your SIEM's query language with sigma-cli. The companion to Prevention & Mitigation: this answers what tells you it's already happening.
16 rules
FortiGate - New VPN SSL Web Portal Added
Detects the addition of a VPN SSL Web Portal on a Fortinet FortiGate Firewall. This behavior was observed in pair with modification of VPN SSL settings.
Matched threat: FortiBleed Hits 430K Firewalls: 4 Threats to Prioritize This Week
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
FortiGate - VPN SSL Settings Modified
Detects the modification of VPN SSL Settings (for example, the modification of authentication rules). This behavior was observed in pair with the addition of a VPN SSL Web Portal.
Matched threat: FortiBleed Hits 430K Firewalls: 4 Threats to Prioritize This Week
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Microsoft IIS Connection Strings Decryption
Detects use of aspnet_regiis to decrypt Microsoft IIS connection strings. An attacker with Microsoft IIS web server access via a webshell or alike can decrypt and dump any hardcoded connection strings, such as the MSSQL service account password using aspnet_regiis command.
Matched threat: FortiBleed Hits 430K Firewalls: 4 Threats to Prioritize This Week
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
OpenCanary - SNMP OID Request
Detects instances where an SNMP service on an OpenCanary node has had an OID request.
Matched threat: FSB Center 16: 13 Nations Warn of Russia's Static Tundra Router Espionage Campaign
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Cisco Dot1x Disabled
Detects the manual disablement of IEEE 802.1X (dot1x) on a Cisco network device interface. Disabling dot1x bypasses Network Access Control (NAC) mechanisms, potentially allowing unauthorized devices to gain access to the internal network. This activity is a common technique used by attackers or malicious insiders to establish persistence or perform lateral movement via rogue devices.
Matched threat: FSB Center 16: 13 Nations Warn of Russia's Static Tundra Router Espionage Campaign
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Potential Active Directory Reconnaissance/Enumeration Via LDAP
Detects potential Active Directory enumeration via LDAP
Matched threat: AI-Generated 'Vibe-Coded' Malware Caught Mapping Active Directory in Live Attack
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
AD Groups Or Users Enumeration Using PowerShell - ScriptBlock
Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
Matched threat: AI-Generated 'Vibe-Coded' Malware Caught Mapping Active Directory in Live Attack
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
PUA - Rclone Execution
Detects execution of RClone utility for exfiltration as used by various ransomware strains like REvil, Conti, FiveHands, and others. The same behavioral pattern applies to s5cmd, AzCopy, and other cloud CLI tools used for unauthorized data staging.
Matched threat: AI-Generated 'Vibe-Coded' Malware Caught Mapping Active Directory in Live Attack
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Suspicious File Write to SharePoint Layouts Directory
Detects suspicious file writes to SharePoint layouts directory which could indicate webshell activity or post-exploitation. This behavior has been observed in the exploitation of SharePoint vulnerabilities such as CVE-2025-49704, CVE-2025-49706 or CVE-2025-53770.
Matched threat: Microsoft Patch Tuesday July 2026: 2 Zero-Days Exploited in Attacks, 570 Flaws Fixed
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators
Detects potential exploitation of CVE-2025-53770 by identifying indicators such as suspicious command lines discovered in Post-Exploitation activities. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
Matched threat: Microsoft Patch Tuesday July 2026: 2 Zero-Days Exploited in Attacks, 570 Flaws Fixed
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Okta FastPass Phishing Detection
Detects when Okta FastPass prevents a known phishing site.
Matched threat: Aflac Japan Data Breach Exposes 4.38 Million Customers: Bank Accounts and PII Stolen
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Okta User Session Start Via An Anonymising Proxy Service
Detects when an Okta user session starts where the user is behind an anonymising proxy service.
Matched threat: Aflac Japan Data Breach Exposes 4.38 Million Customers: Bank Accounts and PII Stolen
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Okta Suspicious Activity Reported by End-user
Detects when an Okta end-user reports activity by their account as being potentially suspicious.
Matched threat: Aflac Japan Data Breach Exposes 4.38 Million Customers: Bank Accounts and PII Stolen
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Linux Webshell Indicators
Detects suspicious sub processes of web server processes
Matched threat: SonicWall SMA1000 Zero-Days CVE-2026-15409 Actively Exploited: Patch Before July 17
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Potential Netcat Reverse Shell Execution
Detects execution of netcat with the "-e" flag followed by common shells. This could be a sign of a potential reverse shell setup.
Matched threat: SonicWall SMA1000 Zero-Days CVE-2026-15409 Actively Exploited: Patch Before July 17
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Webshell ReGeorg Detection Via Web Logs
Certain strings in the uri_query field when combined with null referer and null user agent can indicate activity associated with the webshell ReGeorg.
Matched threat: SonicWall SMA1000 Zero-Days CVE-2026-15409 Actively Exploited: Patch Before July 17
Subscribe to unlock this Sigma rule
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Rules are from the SigmaHQ community repository, licensed under the Detection Rule License 1.1, matched to threat-specific editorial coverage (active campaigns, CVEs, APT profiles, exposure advisories) — scanning the 250 most recent threat posts with a matched rule. Always review false positive notes before enabling a rule in production.