Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

Cleartext FTP upload of an archive or database dump

Matches the FTP store commands — STOR, STOU and APPE — that push a file from the monitored network out to a server, restricted to arguments naming an archive, backup or database-export extension, which is the staged-collection shape MITRE's AN0423 describes moving over an unencrypted protocol. Zeek's ftp.log is chosen over the endpoint sources in the brief because it records the direction and the file name of the transfer, which the Windows process and connection events do not; the corpus already covers the endpoint side of this family in T1048 (port-based) and T1048.002 (encrypted egress). MITRE's DataTransferSizeThreshold knob is the analytic's real discriminator and Sigma has no numeric comparison, so this rule fires on one upload rather than on volume. FTPS and SFTP sessions never produce these command records at all, so absence of matches is not evidence that nothing left the estate. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0149, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full description

The detection

The 3 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: Cleartext FTP upload of an archive or database dumpid: 662112ba-1b10-4195-9792-a2a1046d9d58status: experimentaldescription: |  Matches the FTP store commands — STOR, STOU and APPE — that push a file from  the monitored network out to a server, restricted to arguments naming an  archive, backup or database-export extension, which is the staged-collection  shape MITRE's AN0423 describes moving over an unencrypted protocol. Zeek's  ftp.log is chosen over the endpoint sources in the brief because it records  the direction and the file name of the transfer, which the Windows process and  connection events do not; the corpus already covers the endpoint side of this  family in T1048 (port-based) and T1048.002 (encrypted egress). MITRE's  DataTransferSizeThreshold knob is the analytic's real discriminator and Sigma  has no numeric comparison, so this rule fires on one upload rather than on  volume. FTPS and SFTP sessions never produce these command records at all, so  absence of matches is not evidence that nothing left the estate.  UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0149, not hand-written and not tested by its author. Any lab result is on this rule's own page.references:  - https://attack.mitre.org/techniques/T1048/003  - https://attack.mitre.org/detectionstrategies/DET0149author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.exfiltration  - attack.t1048.003logsource:  product: zeek  service: ftpdetection:  selection_upload:    command:      - 'STOR'      - 'STOU'      - 'APPE'  selection_payload:    arg|endswith:      - '.zip'      - '.rar'      - '.7z'      - '.tar'      - '.gz'      - '.tgz'      - '.cab'      - '.bak'      - '.sql'      - '.dmp'      - '.pst'      - '.csv'  condition: selection_upload and selection_payloadfalsepositives:  - "Sanctioned partner and EDI transfers. Estates that still exchange files with suppliers over plain FTP will match on every scheduled push, and the archive extensions selected here are exactly what those jobs carry. This is MITRE's ProcessBaseline thinking applied at the network layer — pin the allowed client, server and directory triple rather than shortening the extension list."  - "Backup and reporting jobs writing .bak, .sql or .csv to an internal FTP drop, which is business-normal in older estates and indistinguishable from staged exfiltration on the command and file name alone."  - "Appliance and network-device configuration exports, which are still commonly shipped to an FTP or TFTP collector as an archive during maintenance windows."  - "Developer and build tooling publishing release artefacts to a legacy FTP-backed distribution host."level: medium

Splunk · SPL

Run this as a search.

index=* ((command="STOR" OR command="STOU" OR command="APPE") AND (arg="*.zip" OR arg="*.rar" OR arg="*.7z" OR arg="*.tar" OR arg="*.gz" OR arg="*.tgz" OR arg="*.cab" OR arg="*.bak" OR arg="*.sql" OR arg="*.dmp" OR arg="*.pst" OR arg="*.csv"))

Elastic · ES|QL

Run this as a search.

FROM logs-*| WHERE ((TO_LOWER(command) == "stor" OR TO_LOWER(command) == "stou" OR TO_LOWER(command) == "appe") AND (TO_LOWER(arg) LIKE "*.zip" OR TO_LOWER(arg) LIKE "*.rar" OR TO_LOWER(arg) LIKE "*.7z" OR TO_LOWER(arg) LIKE "*.tar" OR TO_LOWER(arg) LIKE "*.gz" OR TO_LOWER(arg) LIKE "*.tgz" OR TO_LOWER(arg) LIKE "*.cab" OR TO_LOWER(arg) LIKE "*.bak" OR TO_LOWER(arg) LIKE "*.sql" OR TO_LOWER(arg) LIKE "*.dmp" OR TO_LOWER(arg) LIKE "*.pst" OR TO_LOWER(arg) LIKE "*.csv"))

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,zeek,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <rule id="100000" level="7">    <!-- Set <if_sid> to the decoder/base rule for zeek so this only evaluates relevant events. -->    <field name="command" type="pcre2">(?i)(^STOR$|^STOU$|^APPE$)</field>    <field name="arg" type="pcre2">(?i)(\.zip$|\.rar$|\.7z$|\.tar$|\.gz$|\.tgz$|\.cab$|\.bak$|\.sql$|\.dmp$|\.pst$|\.csv$)</field>    <description>Cleartext FTP upload of an archive or database dump</description>    <mitre>      <id>T1048.003</id>    </mitre>  </rule></group>

Sentinel · KQL

Run this as a search.

Sentinel cannot express this construct. No Sentinel table is modelled for this logsource ({"product":"zeek","service":"ftp"}), so there is nothing honest to query. Pick a logsource this translator maps, or write the KQL by hand. The Sigma source is on the first tab, unchanged.

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.