Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
313 rules
Azure Audit Logs: Service Principal Removed via Remove service principal
Flags Azure audit log events where a service principal is removed from Entra ID.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium236Free2021-09-03Azure Audit Logs: Owner Removed From Application or Service Principal
Alerts on Azure audit log activity indicating an owner was removed from an application or service principal.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium163Free2021-09-03Azure Audit Logs: Device No Longer Managed or Compliant
Alerts on Azure device audits indicating the device is no longer managed or compliant.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium175Free2021-09-03Azure Audit Logs: Application Deletion (Delete/Hard Delete) Detected
Flags Azure audit events where an application (or administrative unit) is deleted, including hard deletes.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium102Free2021-09-03Azure Activity Logs: Device or Device Configuration Modified or Deleted
Flags Azure audit events indicating device or device configuration updates or deletions.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium81Free2021-09-03Azure Audit Logs: Service Principal Created via Add service principal
Alerts on Azure audit log events that add a new service principal.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium121Free2021-09-02Azure Network Firewall Policy Modified or Deleted via Activity Logs
Alerts on Azure Activity Log operations that modify or delete Network Firewall Policies.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium279Free2021-09-02Google Workspace: Admin audit events where strong authentication is allowed without enforcement (MFA disabled)
Alerts on Google Workspace admin changes that set strong authentication/MFA enforcement to false.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium492Free2021-08-26Google Workspace Admin: Application Removed from Domain
Flags Google Workspace domain events indicating an application was removed, including allowlist/whitelist removal.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium123Free2021-08-26Azure AD Hybrid Health AD FS Service Deletion via Azure Activity Logs
Flags Azure AD Hybrid Health AD FS service deletions from Azure Activity Logs under the Administrative category.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamAzureactivitylogsMedium151Free2021-08-26Azure Activity Logs: AD Hybrid Health AD FS server instance create/update
Alerts on Administrative Azure Activity Log events adding/updating AD Hybrid Health AD FS service member servers.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamAzureactivitylogsMedium1910Free2021-08-26Google Workspace Admin: Detect Role Privilege Deletion (REMOVE_PRIVILEGE)
Triggers on Google Workspace role privilege removal events (REMOVE_PRIVILEGE) in Admin audit logs.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium102Free2021-08-24Google Workspace Admin Role Modified or Deleted via admin.googleapis.com Audit Events
Identifies Google Workspace role updates, renames, or deletions from admin.googleapis.com audit events.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium279Free2021-08-24M365 Threat Management: Suspicious OAuth App File Downloads from SharePoint or OneDrive
Alerts on unusual bulk file downloads by a Microsoft 365 OAuth app from SharePoint or OneDrive.
Austin Songer @austinsonger, Huntrule TeamM365threat_managementMedium303Free2021-08-23Microsoft 365 Cloud Apps: Successful login from a risky IP address
Alerts on successful sanctioned-app logons from risky IP addresses reported in M365 SecurityComplianceCenter.
Austin Songer @austinsonger, Huntrule TeamM365threat_managementMedium92Free2021-08-23