Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
313 rules
Azure Key Vault Key Modified or Deleted via Activity Log Operations
Alerts on Azure Key Vault key create/update/import/recover/restore/backup/purge/delete activity from Activity Logs.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium113Free2021-08-16Azure Application Security Group Modified or Deleted via Activity Log Write/Delete
Flags Azure Activity Log events showing Application Security Group write (modify) or delete operations.
Austin Songer, Huntrule TeamAzureactivitylogsMedium163Free2021-08-16Azure Application Gateway Modified or Deleted via Activity Logs
Alerts on Azure Activity Log operations that modify or delete Application Gateway resources.
Austin Songer, Huntrule TeamAzureactivitylogsMedium262Free2021-08-16AWS EKS Cluster CreateCluster or DeleteCluster Events (CloudTrail)
Alerts on CloudTrail API activity indicating an EKS cluster was created or deleted.
Austin Songer, Huntrule TeamAwscloudtrailLow356Free2021-08-16Google Cloud Audit: DNS Managed Zone Modified or Deleted
Flags Google Cloud DNS Managed Zone delete, update, and patch events from audit logs.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium3910Free2021-08-15Google Cloud DLP Re-identifies Sensitive Data via projects.content.reidentify
Detects Google Cloud DLP re-identification activity using projects.content.reidentify in audit logs.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium81Free2021-08-15AWS EFS Mount Target Modified or Deleted via CloudTrail
Detects CloudTrail-reported deletion of an AWS EFS mount target that can break dependent instances or applications.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailMedium92Free2021-08-15AWS EFS Filesystem Modified or Deleted via CloudTrail
Alert on AWS EFS file system deletion activity observed in CloudTrail via DeleteFileSystem events.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailMedium286Free2021-08-15GCP Audit: Service Account Modified via IAM Patch/Create/Update/Enable/Undelete
Flags GCP audit events indicating service account create, update, enable, undelete, or patch operations.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium1710Free2021-08-14Google Cloud: Service Account Disabled or Deleted via IAM Audit Events
Identifies GCP IAM audit events where service accounts are disabled or deleted via serviceAccounts.disable/delete.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium163Free2021-08-14GCP Audit: Storage Bucket Modified or Deleted via Storage API
Alert on GCP audit events indicating storage bucket insert, update, patch, or delete actions.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium458Free2021-08-14GCP Audit Alerts for Google Cloud Storage Bucket Enumeration via Listing APIs
Triggers on GCP audit events indicating Storage bucket listing (storage.buckets.list or listChannels).
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditLow133Free2021-08-14GCP Audit: Full Network Packet Capture via Compute PacketMirrorings API
Alerts on GCP Compute PacketMirrorings API calls that may enable full network packet capture.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium122Free2021-08-13GCP Audit: Firewall Rule Insert, Update, Patch, or Delete
Flags GCP audit events where firewall rules are inserted, updated, patched, or deleted.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium394Free2021-08-13GCP Kubernetes Engine audit logs: Secrets created, updated, patched, or deleted
Alerts on GCP Kubernetes audit events showing Secrets being updated, patched, or deleted via Kubernetes API calls.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium237Free2021-08-09