Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
225 rules
Suspicious Creation of Azure New CloudShell (via activitylogs)
mediumThis rule detects when a new cloudshell is created inside of Azure portal.
sigmaCloud2026-07-28Suspicious Ingress/Egress Security Group Change (via cloudtrail)
mediumThis rule detects when an account makes changes to the ingress or egress rules of a security group. This can indicate that an adversary is attempting to open up new attack vectors in the account, that they are trying to exfiltrate data over the network, or that they are trying to enable machines in that VPC/Subnet to contact a C&C server.
sigmaCloud2026-07-28Suspicious App Assigned To Azure RBAC/Microsoft Entra Role (via auditlogs)
mediumThis rule detects when an app is assigned Azure AD roles, such as global administrator, or Azure RBAC roles, such as subscription owner.
sigmaCloud2026-07-27Suspicious Change of AWS User Login Profile Was (via cloudtrail)
highThis rule detects behavior when someone is changing passwords on behalf of other users. An adversary with the "iam:UpdateLoginProfile" permission on other users can change the password used to login to the AWS console on any user that already has a login profile setup.
sigmaCloudPaid2026-07-27Suspicious AWS RDS Master Password Change (via cloudtrail)
mediumThis rule detects the change of database master password. It may be a part of data exfiltration.
sigmaCloud2026-07-27Suspicious Browser Behavior (via riskdetection)
highThis rule detects suggests anomalous behavior based on anomalous sign-in behavior across multiple tenants from different countries in the same browser
sigmaCloudPaid2026-07-26Suspicious New CA Policy by Non-approved Actor (via auditlogs)
mediumThis rule detects conditional access changes.
sigmaCloud2026-07-22Suspicious Azure Point-to-site VPN Modified or Deleted (via activitylogs)
mediumThis rule detects when a Point-to-site VPN is Modified or Deleted.
sigmaCloud2026-07-21Suspicious Google Workspace User Granted Admin Privileges (via google_workspace.admin)
mediumThis rule detects when an Google Workspace user is granted admin privileges.
sigmaCloud2026-07-20Suspicious Inbox Manipulation Rules (via riskdetection)
highThis rule detects anomalous rules that delete or move messages or folders are set on a user's inbox.
sigmaCloudPaid2026-07-20Suspicious Added Owner To Application (via auditlogs)
mediumThis rule detects when a new owner is added to an application. This gives that account privileges to make modifications and configuration changes to the application.
sigmaCloud2026-07-19Suspicious Azure Active Directory Hybrid Health AD FS New Server (via activitylogs)
mediumThis rule detects this detection uses azureactivity logs (Administrative category) to identify the creation or update of a server instance in an Azure AD Hybrid health AD FS service. A threat actor can create a new AD Health ADFS service and create a fake server instance to spoof AD FS signing logs. There is no need to compromise an on-prem AD FS server. This can be done programmatically via HTTP requests to Azure.
sigmaCloud2026-07-19Suspicious Login Behavior Classified By Google (via google_workspace.login)
mediumThis rule detects Google Workspace login behavior that's classified as anomalous by Google.
sigmaCloud2026-07-17Suspicious Multifactor Authentication Interrupted (via signinlogs)
mediumThis rule detects user login with multifactor authentication failures, which might be an indication an adversary has the password for the account but can't pass the MFA challenge.
sigmaCloud2026-07-14Suspicious AWS CloudTrail Important Change (via cloudtrail)
mediumThis rule detects disabling, deleting and updating of a Trail
sigmaCloud2026-07-14Suspicious Privileged Account Creation (via auditlogs)
mediumThis rule detects when a new admin is created.
sigmaCloud2026-07-13Suspicious PIM Approvals And Deny Elevation (via auditlogs)
highThis rule detects when a PIM elevation is approved or denied. Outside of normal operations should be investigated.
sigmaCloudPaid2026-07-13Suspicious Account Created And Deleted Within A Close Time Frame (via auditlogs)
highThis rule detects when an account was created and deleted in a short period of time.
sigmaCloudPaid2026-07-12Suspicious New Federated Domain Added (via audit)
mediumThis rule detects the addition of a new Federated Domain.
sigmaCloud2026-07-11Suspicious Too Many Global Admins (via pim)
highThis rule detects an event where there are there are too many accounts assigned the Global Administrator role.
sigmaCloudPaid2026-07-11