Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
225 rules
Rare Subscription-level Operations In Azure (via activitylogs)
mediumThis rule detects IPs from which users grant access to other users on azure resources and alerts when a previously unseen source IP address is used.
sigmaCloud2026-02-12Suspicious AWS Config Disabling Channel/Recorder (via cloudtrail)
highThis rule detects AWS Config Service disabling
sigmaCloudPaid2026-02-12Suspicious Removal of Google Workspace Application (via google_workspace.admin)
mediumThis rule detects when an an application is removed from Google Workspace.
sigmaCloud2026-02-11Suspicious Roles Activation Doesn't Require MFA (via pim)
highThis rule detects when a privilege role can be activated without performing mfa.
sigmaCloudPaid2026-02-11Suspicious User Added To Privilege Role (via auditlogs)
highThis rule detects when a user is added to a privileged role.
sigmaCloudPaid2026-02-10Possible AWS ElastiCache Security Group Modified or Deleted (via cloudtrail)
lowThis rule detects when an ElastiCache security group has been modified or deleted.
sigmaCloud2026-02-10Suspicious AWS EFS Fileshare Modified or Deleted (via cloudtrail)
mediumThis rule detects when a EFS Fileshare is modified or deleted. You can't delete a file system that is in use. If the file system has any mount targets, the adversary must first delete them, so deletion of a mount will occur before deletion of a fileshare.
sigmaCloud2026-02-09Suspicious AWS Successful Console Login Without MFA (via cloudtrail)
mediumThis rule detects successful AWS console logins that were performed without Multi-Factor Authentication (MFA). This alert can be leveraged to identify potential unauthorized access attempts, as logging in without MFA can indicate compromised credentials or misconfigured security settings.
sigmaCloud2026-02-08Possible Azure Kubernetes Cluster Created or Deleted (via activitylogs)
lowThis rule detects when a Azure Kubernetes Cluster is created or deleted.
sigmaCloud2026-02-07AWS Suspicious SAML Behavior (via cloudtrail)
mediumThis rule detects when anomalous SAML behavior has occurred in AWS. An adversary could gain backdoor access via SAML.
sigmaCloud2026-02-07Suspicious Restore Public AWS RDS Instance (via cloudtrail)
highThis rule detects the recovery of a new public database instance from a snapshot. It may be a part of data exfiltration.
sigmaCloudPaid2026-02-07Suspicious Azure Device No Longer Managed or Compliant (via auditlogs)
mediumThis rule detects when a device in azure is no longer managed or compliant
sigmaCloud2026-02-05Suspicious Change or Removal of an AWS RDS Cluster (via cloudtrail)
highThis rule detects modifications to an RDS cluster or its deletion, which may indicate potential data exfiltration attempts, unauthorized access, or exposure of sensitive information.
sigmaCloudPaid2026-02-01Suspicious Removal of Google Workspace Role Privilege (via google_workspace.admin)
mediumThis rule detects when an a role privilege is deleted in Google Workspace.
sigmaCloud2026-01-31Suspicious Google Cloud Re-identifies Sensitive Information (via gcp.audit)
mediumThis rule detects when sensitive information is re-identified in google Cloud.
sigmaCloud2026-01-29Possible AWS STS AssumeRole Misuse (via cloudtrail)
lowThis rule detects the anomalous use of AssumeRole. Adversaries could move laterally and escalate privileges.
sigmaCloud2026-01-29Suspicious Azure AD Threat Intelligence (via riskdetection)
highThis rule detects suggests user behavior that is unusual for the user or consistent with known attack patterns.
sigmaCloudPaid2026-01-27Suspicious AWS KMS Imported Key Material Use (via cloudtrail)
highThis rule detects the import or deletion of key material in AWS KMS, that can be used as part of ransomware attacks. This behavior is uncommon and provides a high certainty signal.
sigmaCloudPaid2026-01-25Suspicious Change of Google Workspace Application Access Level (via google_workspace.admin)
mediumThis rule detects when an access level is changed for a Google workspace application. An access level is part of BeyondCorp Enterprise which is Google Workspace's way of enforcing Zero Trust model. An adversary would be able to remove access levels to gain easier access to Google workspace resources.
sigmaCloud2026-01-24Possible AWS New Lambda Layer Attached (via cloudtrail)
lowThis rule detects when a user attached a Lambda layer to an existing Lambda function. A hostile Lambda layer could execute arbitrary code in the context of the function's IAM role. This would give an adversary access to resources that the function has access to.
sigmaCloud2026-01-24