Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
225 rules
Suspicious New Country (via riskdetection)
highThis rule detects sign-ins from new countries. The detection considers past behavior locations to determine new and infrequent locations.
sigmaCloudPaid2026-01-22Suspicious Users Added to Global or Device Admin Roles (via auditlogs)
highThis rule detects users added to device admin roles.
sigmaCloudPaid2026-01-22Suspicious Azure Kubernetes Service Account Modified or Deleted (via activitylogs)
mediumThis rule detects when a service account is modified or deleted.
sigmaCloud2026-01-22Suspicious Application AppID Uri Configuration Changes (via auditlogs)
highThis rule detects when a configuration change is made to an applications AppID URI.
sigmaCloudPaid2026-01-21Suspicious Azure Owner Removed From Application or Service Principal (via auditlogs)
mediumThis rule detects when a owner is was removed from a application or service principal in Azure.
sigmaCloud2026-01-20Suspicious AWS Key Pair Import Behavior (via cloudtrail)
mediumThis rule detects the import of SSH key pairs into AWS EC2, which may indicate an adversary attempting to gain unauthorized access to instances. This behavior could lead to initial access, persistence, or privilege escalation, potentially compromising sensitive data and operations.
sigmaCloud2026-01-20Anomalous User Behavior (via riskdetection)
highThis rule detects suggests that there are anomalous patterns of behavior like anomalous changes to the directory.
sigmaCloudPaid2026-01-19Suspicious Azure Keyvault Secrets Modified or Deleted (via activitylogs)
mediumThis rule detects when secrets are modified or deleted in Azure.
sigmaCloud2026-01-19Malicious AWS IAM Backdoor Users Keys (via cloudtrail)
mediumThis rule detects AWS API key creation for a user by another user. Backdoored users can be leveraged to obtain persistence in the AWS environment. Also with this alert, you can detect a flow of AWS keys in your org.
sigmaCloud2026-01-19Suspicious Changes To PIM Settings (via auditlogs)
highThis rule detects when changes are made to PIM roles
sigmaCloudPaid2026-01-15Suspicious User Added to an Administrator's Azure AD Role (via auditlogs)
mediumThis rule detects user Added to an Administrator's Azure AD Role
sigmaCloud2026-01-15Suspicious Creation of New AWS Lambda Function URL Configuration (via cloudtrail)
mediumThis rule detects when a user generates a Lambda function URL configuration, which could be used to expose the function to the internet and potentially enable unauthorized access to the function's IAM role for AWS API calls. This could give an adversary access to the privileges linked with the Lambda service role that is attached to that function.
sigmaCloud2026-01-14Suspicious User Access Blocked by Azure Conditional Access (via signinlogs)
mediumThis rule detects access has been blocked by Conditional Access policies. The access policy does not enable token issuance which might be sights≈ of unauthorizeed login to valid accounts.
sigmaCloud2026-01-13Malicious IP Address Sign-In Suspicious (via riskdetection)
highThis rule detects suggests sign-in from a hostile IP address known to be hostile at time of sign-in.
sigmaCloudPaid2026-01-13Suspicious Removal of Azure Kubernetes Pods (via activitylogs)
mediumThis rule detects the deletion of Azure Kubernetes Pods.
sigmaCloud2026-01-12Suspicious Guest User Invited By Non Approved Inviters (via auditlogs)
mediumThis rule detects when a user that doesn't have permissions to invite a guest user attempts to invite one.
sigmaCloud2026-01-10Suspicious CA Policy Removed by Non Approved Actor (via auditlogs)
mediumThis rule detects conditional access changes where non approved actor removed CA Policy.
sigmaCloud2026-01-09Suspicious Granting Of Permissions To An Account (via activitylogs)
mediumThis rule detects IPs from which users grant access to other users on azure resources and alerts when a previously unseen source IP address is used.
sigmaCloud2026-01-09Suspicious Application URI Configuration Changes (via auditlogs)
highThis rule detects when a configuration change is made to an applications URI. URIs for domain names that no longer exist (dangling URIs), not using HTTPS, wildcards at the end of the domain, URIs that are no unique to that app, or URIs that point to domains you do not control should be investigated.
sigmaCloudPaid2026-01-07Suspicious AWS IAM S3Browser LoginProfile Creation (via cloudtrail)
highThis rule detects S3 Browser utility performing reconnaissance looking for existing IAM Users without a LoginProfile defined then (when found) creating a LoginProfile.
sigmaCloudPaid2026-01-07