Describe the behaviour you want to detect. SARA writes a starting Sigma rule with MITRE tags, false-positive guidance, and detection-engineering context. Anonymous, no account, best-effort generic detection.
VALIDT1552.001T1552.004T1211
Sigma rule
title: Potential CVE-2015-4495 Firefox PDF.js Arbitrary File Read
id: 402c1c7c-009a-48cd-b93e-6c371bf4e88a
status: experimental
description: |
Detects potential exploitation of CVE-2015-4495 (CISA KEV). A vulnerability in Mozilla Firefox's PDF.js component allows a remote attacker to read arbitrary local files via a crafted webpage.
This rule looks for Firefox accessing sensitive local files (like SSH keys, RDP files, or password vaults) which is highly abnormal for standard web browsing.
CVSS: 8.8 (High) | KEV Status: Listed.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2015-4495
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.mozilla.org/en-US/security/advisories/mfsa2015-78/
date: 2026-08-15
author: SARA Detection Engineering
tags:
- attack.t1552.001
- attack.t1552.004
- attack.t1211
logsource:
category: file_event
product: windows
detection:
selection_target:
Image|endswith:
- '\firefox.exe'
TargetFilename|contains:
- '\.ssh\'
- '\.aws\credentials'
- '\.rdp'
- '\.kdbx'
- '\.ppk'
- '\.vnc'
filter_downloads:
TargetFilename|contains:
- '\Downloads\'
- '\AppData\Local\Mozilla\Firefox\Profiles\'
- '\AppData\Roaming\Mozilla\Firefox\Profiles\'
condition: selection_target and not filter_downloads
falsepositives:
- Legitimate local HTML applications running in Firefox accessing local resources (highly discouraged in modern environments).
- Security browsers or extensions explicitly configured to read local files for analysis (e.g., sandbox checkers).
level: high
Sigma is the open, vendor-neutral format for log-based detections. One rule, written once, converts to Splunk SPL, Elastic ES|QL, KQL for Microsoft Sentinel, Sumo, Chronicle, QRadar, and more. Detection engineers love it for the same reason ATT&CK is the lingua franca for tactics — Sigma is the lingua franca for the queries that detect them.
GuideHow to use this tool
Describe the behaviour you want to detect in plain English. Be specific — "PowerShell encoded command spawned by an Office process" wins over "PowerShell abuse".
SARA writes a starting Sigma rule with the right logsource, fields, MITRE ATT&CK tags, and false-positive guidance.
Copy the YAML or convert to your target backend. Then tune the rule for your environment — the output is a starting point, not a tested artifact.
When to useWhen is the Sigma generator the right move?
Closing a coverage gap fast
You've got a fresh write-up of a TTP and need a starting detection in your stack today. Generate, tune, ship.
Onboarding a junior detection engineer
Pair-program with SARA: the generator produces the skeleton, the engineer learns by tuning, the team commits the result.
Translating between backends
You have a rule in one query language; describe it in English and get the Sigma version + conversions to every other backend.
Sanity-checking a hypothesis
Sketch a detection idea in 30 seconds before investing in a full DE sprint.
API
Want this in your SOAR or SIEM?
SARA Open ships an OpenAI-compatible API. Call POST /api/v1/sigma — Plain English in, valid Sigma YAML out, with MITRE tags and false-positive guidance.