Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
314 rules
GCP Kubernetes audit events: Admission webhook configuration creates/updates
Flags GCP Kubernetes audit events indicating mutating/validating admission webhook configuration create/patch/replace activity.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium131Free2021-11-25Azure Activity Logs: Kubernetes AdmissionRegistration webhook configuration writes
Flags Azure activity log events writing Kubernetes admission webhook configurations (mutating or validating), indicating potential cluster request interception.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium152Free2021-11-25GCP Kubernetes CronJob or Job Creation via gcp.audit
Flags GCP audit events where Kubernetes batch Job/CronJob API methods indicate CronJob or Job execution setup.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium181Free2021-11-22Azure Activity Logs: Kubernetes CronJob or Job Write Operations
Detects Azure Activity Log write operations for Kubernetes CronJobs and Jobs that can schedule container workloads.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium162Free2021-11-22GCP Cloud SQL Database Modified or Deleted via Audit API
Alerts on Cloud SQL instance create/delete and user update/delete events in GCP audit logs.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium183Free2021-10-15Azure Sign-in Logs: Conditional Access Blocks User Token Issuance (ResultType 53003)
Flags Azure sign-in attempts blocked by Conditional Access due to token issuance denial.
AlertIQ, Huntrule TeamAzuresigninlogsMedium4210Free2021-10-10Azure Sign-in Log MFA Interrupted via Strong Auth Failures
Identifies Azure sign-ins that fail during strong/MFA authentication, suggesting blocked credential attempts.
AlertIQ, Huntrule TeamAzuresigninlogsMedium235Free2021-10-10Azure AD Sign-in Attempts to Disabled Accounts
Alerts on Azure AD sign-in attempts that fail because the target account is disabled.
AlertIQ, Huntrule TeamAzuresigninlogsMedium343Free2021-10-10Azure AD Sign-In Logs: Account Locked After Too Many Failed Password/User ID Attempts
Flags Azure sign-in events where accounts are locked due to excessive failed logons from wrong user ID or password.
AlertIQ, Huntrule TeamAzuresigninlogsMedium308Free2021-10-10Azure Audit Logs: User registered security info (authentication method change)
Flags Azure AD audit events where a user registers new authentication security info.
AlertIQ, Huntrule TeamAzureauditlogsMedium113Free2021-10-10Azure AD Audit Logs: User Added to Administrator Role
Flags Azure AD audit events where a user is added to an Admin/Administrator role.
Raphaël CALVET, @MetallicHack, Huntrule TeamAzureauditlogsMedium103Free2021-10-04AWS Glue Dev Endpoint Lifecycle Events (Create/Update/Delete) via CloudTrail
Flags Glue Create/Update/DeleteDevEndpoint API activity in CloudTrail that may indicate suspicious development endpoint management.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow151Free2021-10-03AWS CloudTrail: Lambda Function Updated with New Layer Attached
Flags CloudTrail UpdateFunctionConfiguration calls that attach Lambda layers to an existing function.
Austin Songer, Huntrule TeamAwscloudtrailLow142Free2021-09-23AWS CloudTrail Alert for Suspicious SAML Role Assumption and SAML Provider Updates
Flags CloudTrail activity involving SAML provider updates plus SAML role assumptions in AWS, which can enable backdoor access.
Austin Songer, Huntrule TeamAwscloudtrailMedium325Free2021-09-22Azure Activity Logs: New CloudShell Created via Microsoft.Portal Consoles Write
Alerts on Azure portal activity indicating a Cloud Shell console was created.
Austin Songer, Huntrule TeamAzureactivitylogsMedium451Free2021-09-21