Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
225 rules
Suspicious Bitlocker Key Retrieval (via auditlogs)
mediumThis rule detects Bitlocker key retrieval.
sigmaCloud2026-07-11Suspicious Google Cloud DNS Zone Modified or Deleted (via gcp.audit)
mediumThis rule detects when a DNS Zone is modified or deleted in Google Cloud.
sigmaCloud2026-07-10Suspicious Azure VPN Connection Modified or Deleted (via activitylogs)
mediumThis rule detects when a VPN connection is modified or deleted.
sigmaCloud2026-07-10Suspicious Data Exfiltration to Unsanctioned Apps (via threat_management)
mediumThis rule detects when a Microsoft Cloud App Security reported when a user or IP address uses an app that is not sanctioned to perform a behavior that resembles an attempt to exfiltrate information from your organization.
sigmaCloud2026-07-09Suspicious Multi Factor Authentication Disabled For User Account (via auditlogs)
mediumThis rule detects changes to the "StrongAuthenticationRequirement" value, where the state is set to "0" or "Disabled". Threat actors were seen disabling multi factor authentication for users to maintain or achieve access to the account. Also see in SIM Swap attacks.
sigmaCloud2026-07-09Suspicious Delegated Permissions Granted For All Users (via auditlogs)
highThis rule detects when highly privileged delegated permissions are granted on behalf of all users
sigmaCloudPaid2026-07-08Suspicious Google Cloud Storage Buckets Modified or Deleted (via gcp.audit)
mediumThis rule detects when storage bucket is modified or deleted in Google Cloud.
sigmaCloud2026-07-06Suspicious Password Reset By User Account (via auditlogs)
mediumThis rule detects when a user has reset their password in Azure AD
sigmaCloud2026-07-05Suspicious Creation of Azure Suppression Rule (via activitylogs)
mediumThis rule detects when a suppression rule is created in Azure. Adversary's could attempt this to evade detection.
sigmaCloud2026-07-05Possible New Network ACL Entry Added (via cloudtrail)
lowThis rule detects that network ACL entries have been added to a route table which could indicate that new attack vectors have been opened up in the AWS account.
sigmaCloud2026-07-03Microsoft 365 - Unusual Volume of File Deletion (via threat_management)
mediumThis rule detects when a Microsoft Cloud App Security reported a user has deleted a unusual a large volume of files.
sigmaCloud2026-07-01Suspicious Removal of Azure Service Principal (via auditlogs)
mediumThis rule detects when a service principal was removed in Azure.
sigmaCloud2026-07-01Suspicious Creation of Azure Service Principal (via auditlogs)
mediumThis rule detects when a service principal is created in Azure.
sigmaCloud2026-07-01Suspicious AWS GuardDuty Detector Deleted Or Updated (via cloudtrail)
highThis rule detects successful deletion or disabling of an AWS GuardDuty detector, possibly by an adversary trying to avoid detection of its hostile activities. Upon deletion, GuardDuty stops monitoring the environment and all existing findings are lost. Verify with the user identity that this behavior is legitimate.
sigmaCloudPaid2026-07-01Possible PST Export Alert Via eDiscovery Alert (via threat_management)
mediumThis rule detects when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content
sigmaCloud2026-06-30Suspicious Disabling of Google Workspace MFA (via google_workspace.admin)
mediumThis rule detects when multi-factor authentication (MFA) is disabled.
sigmaCloud2026-06-30Suspicious Primary Refresh Token Access Attempt (via riskdetection)
highThis rule detects suggests access attempt to the PRT resource that can be leveraged to move laterally into an organization or perform credential theft
sigmaCloudPaid2026-06-30Suspicious Email Delivered In Microsoft 365 (via audit)
mediumThis rule detects instances where an email, identified as hostile or anomalous by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder. It might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.
sigmaCloud2026-06-29Malicious AWS EC2 Startup Shell Script Change (via cloudtrail)
highThis rule detects changes to the EC2 instance startup script. The shell script will be executed as root/SYSTEM every time the specific instances are booted up.
sigmaCloudPaid2026-06-29Suspicious Roles Assigned Outside PIM (via pim)
highThis rule detects when a privilege role assignment has taken place outside of PIM and may indicate an attack.
sigmaCloudPaid2026-06-28