Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
314 rules
Azure AD Account Disabled or Blocked Login Attempt Failures (Sign-in Logs)
Alerts when Azure sign-in attempts fail because the target account is disabled or blocked.
Yochana Henderson, '@Yochana-H', Huntrule TeamAzuresigninlogsMedium425Free2022-06-17AWS ECS Task Definition Commands Query AWS Container Credentials Endpoint
Alerts on ECS Describe/Register/Run activity when task container commands reference the container credential endpoint URI.
Darin Smith, Huntrule TeamAwscloudtrailMedium112Free2022-06-07Azure Audit Logs: Application URI Configuration Changes (AppAddress)
Alerts on Azure audit log events indicating an application URI (AppAddress) was modified.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzureauditlogsHigh151Free2022-06-02Azure AD: Application Owner Added via Audit Log Message
Detects when an application owner is added in Azure audit logs, granting additional permissions to modify app configuration.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzureauditlogsMedium218Free2022-06-02Azure Audit Logs: Application AppID URI Updates via App or Service Principal Changes
Alerts on Azure audit log entries indicating updates to an application or service principal AppID URI configuration.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzureauditlogsHigh101Free2022-06-02Azure Sign-in Logs: Conditional Access Blocked Sign-in Failures (ResultType 53003)
Alerts on Azure sign-ins blocked by Conditional Access when requirements are not met.
Yochana Henderson, '@Yochana-H', Huntrule TeamAzuresigninlogsHigh100Free2022-06-01Azure AD Sign-in Logs: Detect ROPC Authentication Flow Use in Application Sign-ins
Flags Azure AD sign-ins where the message indicates an application is using the ROPC authentication flow.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzuresigninlogsMedium122Free2022-06-01Azure Sign-in Logs: OAuth Device Code Flow Usage Detected
Alerts on Azure sign-in events showing "Device Code" usage by applications outside expected input-constrained device contexts.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzuresigninlogsMedium316Free2022-06-01Azure Sign-in Logs: MFA Denied Based on Authentication Requirement
Flags Azure sign-ins requiring MFA where the status indicates "MFA Denied."
AlertIQ, Huntrule TeamAzuresigninlogsMedium113Free2022-03-24Microsoft 365 eDiscovery PST Export or Search Started Success Alert
Alerts on successful eDiscovery search/export activity that produces PST files in Microsoft 365.
Sorina Ionescu, Huntrule TeamM365threat_managementMedium336Free2022-02-08M365 Exchange Add-FederatedDomain Success: New Federated Domain Created
Alerts on successful Exchange addition of a new federated domain via Add-FederatedDomain.
Splunk Threat Research Team (original rule), '@ionsor (rule)', Huntrule TeamM365exchangeMedium122Free2022-02-08Azure Audit Logs: Successful Disable Strong Authentication Indicates MFA Disabled
Alerts on successful MFA disable actions in Azure audit logs that could weaken account authentication.
"@ionsor, Huntrule Team"AzureauditlogsMedium153Free2022-02-08Azure Sign-in Auth Interruption: DeviceAuthenticationRequired/Failed and External Security Challenge
Alerts on Azure sign-in authentication interruptions tied to device authentication and external security challenge failures.
Austin Songer @austinsonger, Huntrule TeamAzuresigninlogsMedium162Free2021-11-26Azure AuditLogs: Privileged role assignment to user access admin
Flags Azure AuditLogs events where a user is assigned to User Access Administrator, enabling full subscription management.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsHigh163Free2021-11-26Azure Activity Logs: Authorization ElevateAccess Grants Subscription-Level Management
Alerts on Azure Activity Log authorization elevation actions that can grant access to manage all subscriptions.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsHigh122Free2021-11-26