Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
314 rules
Azure AD User Login Risk: Impossible Travel from Distant Locations
Flags Azure Entra risk events tagged as impossibleTravel indicating implausible geographic sign-in travel within a short time.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh91Free2023-09-03Azure Entra ID Identity Protection Unlikely Travel Risk Events
Alerts on unlikelyTravel risk events tied to geographically distant sign-ins and potential deviation from user travel history.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh162Free2023-09-03Azure RiskDetection flags riskyIPAddress from anonymous proxy IP addresses
Alerts when Azure reports user activity linked to a risky anonymous proxy IP address.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh2410Free2023-09-03Azure Entra ID anomalous user activity risk event
Alerts on Azure AD risk events indicating anomalous user activity via riskEventType=anomalousUserActivity.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh121Free2023-09-03Azure Entra ID Riskdetection: Anonymous IP Address sign-in risk events
Detects Azure sign-in risk events labeled as anonymized/anonymous IP addresses.
Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh82Free2023-08-22Azure risk detection: anomalousToken risk events
Flags Azure Entra ID risk events indicating anomalous token lifetime or use from unfamiliar locations.
Mark Morowczynski '@markmorow', Huntrule TeamAzureriskdetectionHigh122Free2023-08-07AWS CloudTrail: S3 Browser Creates IAM User or Access Key
Alerts on CloudTrail IAM CreateUser/CreateAccessKey actions initiated by a "S3 Browser" user agent.
daniel.bohannon@permiso.io (@danielhbohannon), Huntrule TeamAwscloudtrailHigh131Free2023-05-17AWS CloudTrail: S3 Browser creates inline IAM policy with default bucket placeholder
Detects S3 Browser–initiated IAM PutUserPolicy requests that include a templated S3 bucket placeholder in the inline policy.
daniel.bohannon@permiso.io (@danielhbohannon), Huntrule TeamAwscloudtrailHigh123Free2023-05-17AWS CloudTrail: S3 Browser creating IAM LoginProfiles after querying GetLoginProfile
Flags CloudTrail IAM GetLoginProfile and CreateLoginProfile activity initiated by an S3 Browser user agent.
daniel.bohannon@permiso.io (@danielhbohannon), Huntrule TeamAwscloudtrailHigh481Free2023-05-17Azure Sign-in Success with Legacy Client User-Agent Indicators (MFA Bypass Suspicion)
Alerts on successful Azure sign-ins using legacy client user-agent markers that may indicate MFA bypass attempts.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamAzuresigninlogsHigh172Free2023-03-20Azure Sign-In: Successful single-factor atRisk logins from non-registered devices
Alerts on at-risk successful Azure sign-ins from devices with missing trust type when MFA isn’t required.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamAzuresigninlogsHigh90Free2023-01-10AWS CloudTrail: Potential S3 Bucket Enumeration via ListBuckets by Non-AssumedRole
Identifies S3 ListBuckets calls in CloudTrail that are not from assumed-role identities, which may indicate bucket discovery activity.
Christopher Peacock @securepeacock, SCYTHE @scythe_io, Huntrule TeamAwscloudtrailLow142Free2023-01-06AWS SES Identity Deleted via CloudTrail DeleteIdentity Event
Flags CloudTrail events showing an SES identity was deleted using the DeleteIdentity API.
Janantha Marasinghe, Huntrule TeamAwscloudtrailMedium296Free2022-12-13Azure sign-in logs: Detect AzureHound discovery tool via default User-Agent
Flags successful Azure sign-ins where the User-Agent contains "azurehound", indicating AzureHound discovery.
Janantha Marasinghe, Huntrule TeamAzuresigninlogsHigh81Free2022-11-27Microsoft 365 Threat Management: PST Export via New-ComplianceSearchAction -Export
Flags M365 SecurityComplianceCenter activity that includes New-ComplianceSearchAction with -Export for PST content.
Nikita Khalimonenkov, Huntrule TeamM365threat_managementMedium163Free2022-11-17