Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
313 rules
Suspicious MURKY PANDA Mail Permission Grant to Service Principal (via azure)
This rule detects an application role assignment being granted to a service principal in Microsoft Entra ID. MURKY PANDA assigned Microsoft Graph mail permissions to compromised service principals to read victim mailboxes over a trusted application identity. Newly granted high-privilege app roles warrant review.
HuntRule TeamAzureauditlogsMedium00Premium2026-09-12Suspicious MURKY PANDA Credential Addition to Entra ID Service Principal (via azure)
This rule detects credentials being added to an existing Microsoft Entra ID service principal. MURKY PANDA injected new secrets into legitimate service principals to establish stealthy cross-tenant cloud persistence. Unexpected credential additions to application identities can indicate abuse of trusted relationships.
HuntRule TeamAzureauditlogsMedium30Premium2026-09-12Suspicious Inbox Rule Creation With Forwarding or Deletion via M365 Exchange
This rule detects the creation or modification of a mailbox inbox rule that forwards, redirects, or deletes messages within Microsoft 365 Exchange, matching the mail-exfiltration tradecraft of the ARToken EvilTokens affiliate panel reported by Cisco Talos. After token theft the operators plant inbox rules to silently siphon or hide victim mail. This behavior signals attacker persistence and collection inside a compromised tenant.
HuntRule TeamM365exchangeMedium30Premium2026-09-10Suspicious Google Cloud Function Create or Update Triggering Build
This rule detects creation or modification of a Google Cloud Function which automatically triggers a build using the default Cloud Build service account. Talos observed this serverless attack vector where an actor deploys a malicious function to execute attacker code during the build and inherit the over-privileged build service account, so unexpected function writes warrant review as a privilege-escalation foothold.
HuntRule TeamGcpgcp.auditLow40Premium2026-09-10Malicious Assignment of a Privileged Azure AD Role (via auditlogs)
This rule detects an account being added to a privileged Azure AD directory role such as Global Administrator or Privileged Role Administrator, an account-manipulation technique used to escalate and entrench control of a tenant. Privileged role assignment is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting this operation surfaces privilege escalation in the identity plane.
HuntRule TeamAzureauditlogsHigh30Premium2026-09-05Suspicious Email-Hiding Inbox Rule Creation (via exchange)
This rule detects creation of a mailbox rule that automatically deletes messages or moves them to obscure folders such as RSS Feeds or Junk, a defense-evasion behavior adversaries use to hide security alerts and their own correspondence after account compromise. Email-hiding rules feature in the Red Canary Threat Detection Report as a post-compromise persistence and evasion tactic in business email compromise. Detecting these rules surfaces attacker efforts to stay unnoticed.
HuntRule TeamM365exchangeMedium10Premium2026-09-05Malicious Mailbox Audit Bypass Association in Exchange Online (via exchange)
This rule detects an account being added to the mailbox audit bypass list, which stops Exchange from logging that account's mailbox actions, a defense-evasion technique used to hide mailbox access and rule creation. Mailbox audit bypass is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting this operation surfaces an attacker suppressing mailbox telemetry.
HuntRule TeamM365exchangeHigh10Premium2026-09-05Suspicious IAM Access Key Creation for Persistence (via cloudtrail)
This rule detects creation of a new IAM access key, a cloud account-manipulation technique attackers use to establish durable programmatic access to an AWS account after compromising a principal. Adding access keys for persistence is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting the CreateAccessKey call surfaces a potential backdoor credential being minted.
HuntRule TeamAwscloudtrailMedium30Premium2026-09-05Malicious OAuth Application Granted Full Mailbox and EWS Permissions (via m365)
This rule detects OAuth application permission grants for high privilege mailbox scopes such as full_access_as_app EWS.AccessAsUser.All and ApplicationImpersonation. Midnight Blizzard granted these permissions to attacker-controlled applications to access mailboxes across the tenant.
HuntRule TeamM365auditHigh41Premium2026-08-25Suspicious Compute Disk IAM Policy Modification Granting Owner Role via GCP Audit
This rule detects v1.compute.disks.setIamPolicy operations that modify the IAM policy on a Compute Engine disk. Adversaries bind privileged roles such as roles/owner to an external principal to share a disk out of the victim project for data exfiltration. Granting broad access to a disk resource enables theft of the data stored on it without directly reading the volume.
HuntRule TeamGcpgcp.auditMedium417Premium2026-08-23Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
This rule detects Microsoft 365 sign-in events blocked by Conditional Access after a valid password was supplied, which can indicate credential stuffing or password spraying against accounts protected only by MFA. Huntress observed adversaries validating stolen credentials from VPN, Tor, and proxy sources before attempting session takeover. A spike of these blocks from anomalous geographies surfaces pre-MFA account compromise that would otherwise be silent.
HuntRule TeamAzuresigninlogsMedium346Premium2026-08-20Malicious Office 365 Email Rule Breach - On Behalf (via office365)
This rule detects attempt to hide emails in order to perform phishing attacks by replacing, for example, financial information from the original email with another email containing attacker's financial information. This technique may also be used to avoid specific email notification to be received by end users in case, for example, of an ongoing breach.
HuntRule TeamAzureoffice365High71Premium2026-08-20Suspicious IAM AdministratorAccess Policy Attachment via CloudTrail (via cloudtrail)
This rule detects the Shai Hulud privilege escalation in AWS where a freshly created IAM user is granted the AdministratorAccess managed policy through an AttachUserPolicy call. Attaching full administrator rights to a user is a high impact action that is rare in normal operations. It followed the creation of a cloudops-monitor identity.
HuntRule TeamAwscloudtrailMedium121Premium2026-08-19Suspicious AWS Administrator Policy Attachment via CloudTrail (via aws)
This rule detects the attachment of the administrator access managed policy to an IAM user in CloudTrail. During the intrusion the attacker created a backdoor admin user and attached administrator access to retain full control of the account. Administrator policy attachments should be reconciled against approved access change requests.
HuntRule TeamAwscloudtrailMedium112Premium2026-08-18Suspicious AWS SSO Account Role Enumeration via ListAccountRoles (via cloudtrail)
This rule detects the AWS SSO ListAccountRoles call, the reconnaissance step Red Canary noted adversaries performing after obtaining a cached SSO access token to enumerate assignable roles. A burst of ListAccountRoles from an unfamiliar source can indicate an actor mapping available roles before assuming credentials.
HuntRule TeamAwscloudtrailLow424Premium2026-08-16