Log source category
proxy log source Sigma rules
56 Sigma detection rules in the library use the proxy log source. The proxy category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
HackTool - BabyShark Agent Default URL Pattern
criticalDetects Baby Shark C2 Framework default communication patterns
OWASSRF Exploitation Attempt Using Public POC - Proxy
criticalDetects exploitation attempt of the OWASSRF variant targeting exchange servers using publicly available POC. It uses the OWA endpoint to access the powershell backend endpoint
Potential CVE-2023-36884 Exploitation Pattern
criticalDetects a unique pattern seen being used by RomCom potentially exploiting CVE-2023-36884
PwnDrp Access
criticalDetects downloads from PwnDrp web servers developed for red team testing and most likely also used for criminal activity
Small Sieve Malware Potential C2 Communication
criticalDetects potential C2 communication related to Small Sieve malware
Ursnif Malware C2 URL Pattern
criticalDetects Ursnif C2 traffic.
APT User Agent
highDetects suspicious user agent strings used in APT malware in proxy logs
APT40 Dropbox Tool User Agent
highDetects suspicious user agent string of APT40 Dropbox tool
Bitsadmin to Uncommon IP Server Address
highDetects Bitsadmin connections to IP addresses instead of FQDN names
Bitsadmin to Uncommon TLD
highDetects Bitsadmin connections to domains with uncommon TLDs
Chafer Malware URL Pattern
highDetects HTTP request used by Chafer malware to receive data from its C2.
Cisco ASA Exploitation Activity - Proxy
highDetects suspicious requests to Cisco ASA WebVpn via proxy logs associated with CVE-2025-20333 and CVE-2025-20362 exploitation.
ComRAT Network Communication
highDetects Turla ComRAT network communication.
Crypto Miner User Agent
highDetects suspicious user agent strings used by crypto miners in proxy logs
CVE-2023-46747 Exploitation Activity - Proxy
highDetects exploitation activity of CVE-2023-46747 an unauthenticated remote code execution vulnerability in F5 BIG-IP.
CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
highDetects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs by looking for a very long host header string.
Devil Bait Potential C2 Communication Traffic
highDetects potential C2 communication related to Devil Bait malware
Exploit Framework User Agent
highDetects suspicious user agent strings used by exploit / pentest frameworks like Metasploit in proxy logs
Flash Player Update from Suspicious Location
highDetects a flashplayer update from an unofficial location
Goofy Guineapig Backdoor Potential C2 Communication
highDetects potential C2 communication related to Goofy Guineapig backdoor
Hack Tool User Agent
highDetects suspicious user agent strings user by hack tools in proxy logs
HackTool - CobaltStrike Malleable Profile Patterns - Proxy
highDetects cobalt strike malleable profiles patterns (URI, User-Agents, Methods).
HackTool - Empire UserAgent URI Combo
highDetects user agent and URI paths used by empire agents
Malware User Agent
highDetects suspicious user agent strings used by malware in proxy logs
Potential Compromised 3CXDesktopApp Beaconing Activity - Proxy
highDetects potential beaconing activity to domains related to 3CX 3CXDesktopApp compromise
Potential Compromised 3CXDesktopApp ICO C2 File Download
highDetects potential malicious .ICO files download from a compromised 3CXDesktopApp via web requests to the the malicious Github repository
Potential CVE-2023-36884 Exploitation - URL Marker
highDetects a unique URL marker seen being used by RomCom potentially exploiting CVE-2023-36884
Potential CVE-2023-36884 URL Request Pattern Traffic
highDetects a specific URL pattern containing a specific extension and parameters pointing to an IP address. This pattern was seen being used by RomCOM potentially exploiting CVE-2023-36884
Potential Information Disclosure CVE-2023-43261 Exploitation - Proxy
highDetects exploitation attempts of CVE-2023-43261 and information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 that allows attackers to access sensitive router components in proxy logs.
Potential Operation Triangulation C2 Beaconing Activity - Proxy
highDetects potential beaconing activity to domains used in 0day attacks on iOS devices and revealed by Kaspersky and the FSB
Potential OWASSRF Exploitation Attempt - Proxy
highDetects exploitation attempt of the OWASSRF variant targeting exchange servers It uses the OWA endpoint to access the powershell backend endpoint
Raw Paste Service Access
highDetects direct access to raw pastes in different paste services often used by malware in their second stages to download malicious code in encrypted or encoded form
Suspicious External WebDAV Execution
highDetects executables launched from external WebDAV shares using the WebDAV Explorer integration, commonly seen in initial access campaigns.
Suspicious User Agent
highDetects suspicious malformed user agent strings in proxy logs
Ursnif Malware Download URL Pattern
highDetects download of Ursnif malware done by dropper documents.
Windows WebDAV User Agent
highDetects WebDav DownloadCradle
.Class Extension URI Ending Request
mediumDetects requests to URI ending with the ".class" extension in proxy logs. This could rules can be used to hunt for potential downloads of Java classes as seen for example in Log4shell exploitation attacks against Log4j.
CVE-2023-1389 Potential Exploitation Attempt - Unauthenticated Command Injection In TP-Link Archer AX21
mediumDetects potential exploitation attempt of CVE-2023-1389 an Unauthenticated Command Injection in TP-Link Archer AX21.
CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy)
mediumDetects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
mediumDetects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs.
Download from Suspicious Dyndns Hosts
mediumDetects download of certain file types from hosts with dynamic DNS names (selected list)
F5 BIG-IP iControl Rest API Command Execution - Proxy
mediumDetects POST requests to the F5 BIG-IP iControl Rest API "bash" endpoint, which allows the execution of commands on the BIG-IP
HTTP Request With Empty User Agent
mediumDetects a potentially suspicious empty user agent strings in proxy log. Could potentially indicate an uncommon request method.
Potential Base64 Encoded User-Agent
mediumDetects User Agent strings that end with an equal sign, which can be a sign of base64 encoding.
Potential CVE-2023-36884 Exploitation - File Downloads
mediumDetects files seen being requested by RomCom while potentially exploiting CVE-2023-36884
Potential Hello-World Scraper Botnet Activity
mediumDetects network traffic potentially associated with a scraper botnet variant that uses the "Hello-World/1.0" user-agent string.
Potential Peach Sandstorm APT C2 Communication Activity
mediumDetects potential C2 communication activity related to Peach Sandstorm APT
PUA - Advanced IP/Port Scanner Update Check
mediumDetect the update check performed by Advanced IP/Port Scanner utilities.
Rclone Activity via Proxy
mediumDetects the use of rclone, a command-line program to manage files on cloud storage, via its default user-agent string
Suspicious Base64 Encoded User-Agent
mediumDetects suspicious encoded User-Agent strings, as seen used by some malware.
Telegram API Access
mediumDetects suspicious requests to Telegram API without the usual Telegram User-Agent
Windows PowerShell User Agent
mediumDetects Windows PowerShell Web Access
Download From Suspicious TLD - Blacklist
lowDetects download of certain file types from hosts in suspicious TLDs
Download From Suspicious TLD - Whitelist
lowDetects executable downloads from suspicious remote systems
EvilTokens PhaaS Kit Phishing Related Request - Proxy
lowDetects outbound web proxy requests to URLs matching the EvilTokens Phishing-as-a-Service (PhaaS) kit infrastructure. Specifically Cloudflare Workers and Railway.app domains used in OAuth device code authorization phishing attacks. This indicates a user has clicked a phishing link.
Suspicious Network Communication With IPFS
lowDetects connections to interplanetary file system (IPFS) containing a user's email address which mirrors behaviours observed in recent phishing campaigns leveraging IPFS to host credential harvesting webpages.