Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
225 rules
Suspicious Google Workspace Government Attack Warning (via google_workspace.login)
mediumThis rule detects a login attempt in Google Workspace flagged as a potential attack by a government-backed threat actor
sigmaCloud2026-01-06AWS Console GetSigninToken Possible Misuse (via cloudtrail)
mediumThis rule detects potentially anomalous events involving "GetSigninToken". An adversary using the "aws_consoler" tool can abuse this console API to create temporary federated credential that help obfuscate which AWS credential is compromised (the original access key) and enables the adversary to pivot from the AWS CLI to console sessions without the need for MFA using the new access key issued in this request.
sigmaCloud2026-01-05Suspicious Atypical Travel (via riskdetection)
highThis rule detects two sign-ins originating from geographically distant locations, where at least one of the locations may also be atypical for the user, given past behavior.
sigmaCloudPaid2026-01-03Anomalous Token (via riskdetection)
highThis rule detects suggests that there are abnormal characteristics in the token such as an unusual token lifetime or a token that is played from an unfamiliar location.
sigmaCloudPaid2026-01-03Suspicious Removal of AWS Bucket (via cloudtrail)
mediumThis rule detects the deletion of S3 buckets in AWS CloudTrail logs. Monitoring the deletion of S3 buckets is critical for security and data integrity, as it may indicate potential data loss or unauthorized access attempts.
sigmaCloud2026-01-02