Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
100 rules
Malicious GCP Service Account Backdoor via serviceAccountTokenCreator Grant
This rule detects a google.iam.admin.v1.SetIAMPolicy admin activity event that grants the roles/iam.serviceAccountTokenCreator role, allowing a principal to mint access tokens for a targeted service account. Adversaries use this binding to backdoor a service account and later impersonate it through GenerateAccessToken, keeping durable privileged access. This matters because the grant converts any controlled identity into a lasting path to the service account privileges.
HuntRule TeamGcpgcp.auditHigh10Premium2026-09-15Malicious Azure Elevate Access to User Access Administrator
This rule detects the Microsoft.Authorization/elevateAccess/action operation, which assigns the calling Global Administrator the User Access Administrator role across all Azure subscriptions in the tenant. Adversaries who compromise a Global Administrator use elevateAccess to break out of Entra ID into the Azure resource plane and take control of every subscription. This is important because it is a high-impact privilege escalation that exposes all cloud resources.
HuntRule TeamAzureactivitylogsHigh10Premium2026-09-14Possible Azure Storage Ransomware via Customer-Managed Key Encryption
This rule detects Azure Activity operations that rewrite storage account encryption to attacker-controlled key material, a hijack path for blob storage ransomware. Writing an encryption scope or setting the account key source to Key Vault lets an actor re-encrypt blobs under a key they hold and then deny the victim access. These control-plane encryption changes on production storage accounts warrant urgent review.
HuntRule TeamAzureactivitylogsHigh20Premium2026-09-14Malicious Assignment of a Privileged Azure AD Role (via auditlogs)
This rule detects an account being added to a privileged Azure AD directory role such as Global Administrator or Privileged Role Administrator, an account-manipulation technique used to escalate and entrench control of a tenant. Privileged role assignment is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting this operation surfaces privilege escalation in the identity plane.
HuntRule TeamAzureauditlogsHigh30Premium2026-09-05Malicious Mailbox Audit Bypass Association in Exchange Online (via exchange)
This rule detects an account being added to the mailbox audit bypass list, which stops Exchange from logging that account's mailbox actions, a defense-evasion technique used to hide mailbox access and rule creation. Mailbox audit bypass is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting this operation surfaces an attacker suppressing mailbox telemetry.
HuntRule TeamM365exchangeHigh10Premium2026-09-05Malicious OAuth Application Granted Full Mailbox and EWS Permissions (via m365)
This rule detects OAuth application permission grants for high privilege mailbox scopes such as full_access_as_app EWS.AccessAsUser.All and ApplicationImpersonation. Midnight Blizzard granted these permissions to attacker-controlled applications to access mailboxes across the tenant.
HuntRule TeamM365auditHigh51Premium2026-08-25Malicious Office 365 Email Rule Breach - On Behalf (via office365)
This rule detects attempt to hide emails in order to perform phishing attacks by replacing, for example, financial information from the original email with another email containing attacker's financial information. This technique may also be used to avoid specific email notification to be received by end users in case, for example, of an ongoing breach.
HuntRule TeamAzureoffice365High71Premium2026-08-20Suspicious AWS Inline Policy Granting Full S3 Access
This rule detects a PutUserPolicy call that attaches an inline IAM policy granting s3 wildcard permissions to a user. It maps to privilege escalation observed in S3 attack chains where an operator self-grants full bucket access before collection. Detecting it exposes IAM policy tampering aimed at cloud data theft.
HuntRule TeamAwscloudtrailHigh386Premium2026-08-10Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
This rule detects creation or modification of Exchange Online inbox rules that filter messages from myworkday.com and delete or move them to obscure folders. This behavior is associated with payroll pirate campaigns against US universities where attackers hide Workday payroll and direct deposit change notifications from compromised victims. Concealing these alerts lets attackers reroute salary payments without the victim noticing, making early detection critical.
HuntRule TeamM365exchangeHigh162Premium2026-08-04Malicious Mailbox Forwarding Rule Creation (via exchange)
This rule detects creation or modification of a mailbox rule that auto-forwards or redirects mail to an external address, a collection-and-exfiltration technique adversaries use after compromising an account to silently siphon correspondence. Malicious email rules are a recurring identity threat in the Red Canary Threat Detection Report, often following business email compromise. Detecting forwarding-rule creation surfaces data theft that victims rarely notice.
HuntRule TeamM365exchangeHigh153Premium2026-07-30Malicious Credential Added to an Azure AD Application (via auditlogs)
This rule detects a password or key credential being added to an Azure AD application or service principal, an account-manipulation technique that grants an attacker persistent, app-based access to a tenant. Adding application credentials is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting this operation surfaces a stealthy tenant backdoor being created.
HuntRule TeamAzureauditlogsHigh102Premium2026-07-29Suspicious EC2 Serial Console SSH Public Key Push (via cloudtrail)
This rule detects the SendSerialConsoleSSHPublicKey call used to push an SSH key to an instance serial console, an uncommon access path adversaries leverage to reach hosts that block normal network SSH. Legitimate serial console use is rare, so this event strongly suggests an attacker seeking out of band interactive access to a cloud instance.
HuntRule TeamAwscloudtrailHigh133Premium2026-07-23Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
This rule detects non-interactive Microsoft 365 sign-ins using the BAV2ROPC legacy authentication client. In the Railway PaaS token replay campaign, operators used BAV2ROPC to silently refresh stolen tokens and access mailboxes without triggering interactive MFA, so this client string on sign-ins indicates likely token abuse and legacy protocol exploitation.
HuntRule TeamM365signinlogsHigh82Premium2026-07-19Suspicious STS AssumeRole With Exfil Session Name via CloudTrail (via cloudtrail)
This rule detects the Shai Hulud actor assuming high privilege roles using session names that begin with exfil such as exfil, exfil10 and exfil12 to run Systems Manager commands and read data. Operator chosen session names that reveal exfiltration intent are a strong hunting signal. These sessions preceded Redshift data theft.
HuntRule TeamAwscloudtrailHigh142Premium2026-07-15Suspicious Entra ID Auth Broker Sign-In With Node.js User Agent via Tycoon 2FA
This rule detects Entra ID sign ins against the Microsoft Authentication Broker application from Node.js based clients such as axios undici and node-fetch as characteristic of Tycoon 2FA adversary in the middle attacks in Elastic research. Automated Node runtimes replaying stolen tokens through the Auth Broker indicate token theft and primary refresh token abuse rather than genuine user interaction.
HuntRule TeamAzuresigninlogsHigh103Premium2026-07-09