Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
313 rules
Suspicious AWS EC2 RunInstances of Large Compute-Optimized Instance for Cryptomining
This rule detects EC2 RunInstances launching oversized compute-optimized instance types such as c5a.24xlarge, matching the resource hijacking behavior of exposed IAM key operators tracked by Unit 42. Adversaries spin up high-core instances to maximize cryptomining throughput which drives sudden cloud spend and indicates account compromise.
HuntRule TeamAwscloudtrailMedium133Premium2026-08-15Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
This rule detects UpdateAccountSendingEnabled and VerifyEmailIdentity events against Amazon SES. Adversaries who compromise valid AWS credentials verify new sending identities and re-enable account sending so they can abuse SES to distribute spam or phishing from the victim account. Re-enabling sending and verifying new identities together is characteristic of SES abuse rather than normal onboarding.
HuntRule TeamAwscloudtrailMedium383Premium2026-08-15Possible Stolen AWS Credential Validation via STS GetCallerIdentity
This rule detects AWS STS GetCallerIdentity calls which the Hugging Face breach actor issued to validate stolen cloud credentials after harvesting secrets from a compromised AI agent environment. Identity self-checks are a common first move once keys are obtained. Because legitimate automation also calls this API, baseline expected principals and alert on unfamiliar or first-seen callers.
HuntRule TeamAwscloudtrailLow191Premium2026-08-13Suspicious AWS Inline Policy Granting Full S3 Access
This rule detects a PutUserPolicy call that attaches an inline IAM policy granting s3 wildcard permissions to a user. It maps to privilege escalation observed in S3 attack chains where an operator self-grants full bucket access before collection. Detecting it exposes IAM policy tampering aimed at cloud data theft.
HuntRule TeamAwscloudtrailHigh376Premium2026-08-10Suspicious AWS Federated Console Login From Programmatic Credentials
This rule detects an AWS Management Console sign-in performed by a federated user identity which indicates a session created from long-term or temporary programmatic credentials rather than an IAM user or SSO login. Wiz shows attackers exchange stolen keys for a federated console session to obfuscate their real identity and break session traceability. This matters because it lets an adversary operate interactively in the console while evading the account owner attribution normally provided by ConsoleLogin.
HuntRule TeamAwscloudtrailMedium93Premium2026-08-04Suspicious GCP Service Account Key Creation for Persistence (via gcp.audit)
This rule detects the CreateServiceAccountKey method in GCP audit logs, the persistence technique Red Canary described where a service account creates a new key for itself to survive key-deletion remediation. Because these tokens are not revokable, key creation where the requesting principal matches the target service account is a strong sign of an actor establishing durable access.
HuntRule TeamGcpgcp.auditMedium102Premium2026-08-04Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
This rule detects creation or modification of Exchange Online inbox rules that filter messages from myworkday.com and delete or move them to obscure folders. This behavior is associated with payroll pirate campaigns against US universities where attackers hide Workday payroll and direct deposit change notifications from compromised victims. Concealing these alerts lets attackers reroute salary payments without the victim noticing, making early detection critical.
HuntRule TeamM365exchangeHigh162Premium2026-08-04Suspicious Device Registration Following OAuth Token Theft
This rule detects Entra ID device registration and Primary Refresh Token acquisition activity consistent with the ROADtools tradecraft used after OAuth phishing. Registering an attacker-controlled device lets the adversary obtain a PRT and maintain durable access to the tenant beyond the stolen refresh token.
HuntRule TeamAzureauditlogsMedium113Premium2026-08-04Suspicious EBS Snapshot Shared With External Account via CloudTrail
This rule detects ModifySnapshotAttribute events that add CREATE_VOLUME_PERMISSION for a specific external AWS account, sharing an EBS snapshot outside the owner account. Adversaries share a snapshot they created with an attacker-controlled account so they can restore the volume elsewhere and exfiltrate its data. Externally sharing a snapshot bypasses direct data reads and is a known cloud exfiltration technique.
HuntRule TeamAwscloudtrailMedium191Premium2026-08-04Malicious Mailbox Forwarding Rule Creation (via exchange)
This rule detects creation or modification of a mailbox rule that auto-forwards or redirects mail to an external address, a collection-and-exfiltration technique adversaries use after compromising an account to silently siphon correspondence. Malicious email rules are a recurring identity threat in the Red Canary Threat Detection Report, often following business email compromise. Detecting forwarding-rule creation surfaces data theft that victims rarely notice.
HuntRule TeamM365exchangeHigh153Premium2026-07-30Suspicious Entra ID Device Code Flow Authentication
This rule detects Entra ID sign-ins performed through the OAuth device code flow which threat actors abuse in device code phishing campaigns to trick users into authorizing attacker-controlled sessions and obtain tokens for apps such as Azure AD PowerShell and the Microsoft Authentication Broker. Device code authentications with inconsistent user agent and location across a shared session are a hallmark of this phishing technique.
HuntRule TeamAzuresigninlogsMedium321Premium2026-07-29Malicious Credential Added to an Azure AD Application (via auditlogs)
This rule detects a password or key credential being added to an Azure AD application or service principal, an account-manipulation technique that grants an attacker persistent, app-based access to a tenant. Adding application credentials is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting this operation surfaces a stealthy tenant backdoor being created.
HuntRule TeamAzureauditlogsHigh102Premium2026-07-29Suspicious AWS Large GPU Instance Launch via CloudTrail (via aws)
This rule detects the launch of large accelerated GPU EC2 instances recorded in CloudTrail. The intrusion abused stolen administrator access to run expensive p4d GPU instances for resource hijacking. Sudden launches of high cost GPU instance types outside of sanctioned workloads can indicate cloud resource abuse.
HuntRule TeamAwscloudtrailMedium113Premium2026-07-25Suspicious EC2 Serial Console SSH Public Key Push (via cloudtrail)
This rule detects the SendSerialConsoleSSHPublicKey call used to push an SSH key to an instance serial console, an uncommon access path adversaries leverage to reach hosts that block normal network SSH. Legitimate serial console use is rare, so this event strongly suggests an attacker seeking out of band interactive access to a cloud instance.
HuntRule TeamAwscloudtrailHigh133Premium2026-07-23Uncommon Security Info Registration Following AiTM Session Theft (via azure)
This rule detects a user registering new security info in Entra ID, the persistence step attackers take after adversary-in-the-middle session theft to enroll their own MFA method on a compromised account. Adversaries register a controlled authenticator to retain access after the stolen session expires, making this a useful signal when correlated with anomalous or geo-infeasible sign-ins from the same account.
HuntRule TeamAzureauditlogsMedium207Premium2026-07-22