Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
100 rules
Suspicious Entra Sign-In to OfficeHome with axios User Agent
This rule detects a successful Entra ID sign-in to the OfficeHome application where the user agent contains axios, an automation library used by the Tycoon 2FA adversary-in-the-middle platform. Tycoon 2FA relayed intercepted credentials and stolen session cookies through scripted axios clients to authenticate as the victim. A non-browser axios agent completing sign-in to OfficeHome indicates automated session token replay from an AiTM phishing kit.
HuntRule TeamAzuresigninlogsHigh81Premium2026-06-28Suspicious AWS CloudTrail Logging Disabled
This rule detects API calls that stop or delete AWS logging such as StopLogging, DeleteTrail and DeleteFlowLogs. Adversaries disable CloudTrail and VPC flow logs to blind defenders before carrying out further actions, a defense evasion step that should be rare and deliberate.
HuntRule TeamAwscloudtrailHigh121Premium2026-06-27Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs
This rule detects a delegated permission grant that targets an Entra agent blueprint access_agent scope, the consent step that lets an attacker-controlled app drive an assistive AI agent. Adversaries obtain delegated access to agents that can send mail and act on the user behalf, so a grant referencing access_agent indicates agent hijacking through illicit consent.
HuntRule TeamAzureauditlogsHigh437Premium2026-06-26Malicious S3 Object Encryption for Ransom via SSE-C
This rule detects an S3 PutObject call that supplies a customer provided encryption key using server side encryption with customer keys, the core primitive of the AWS S3 SSE-C ransom scenario emulated by Elastic. By overwriting objects with a key only the attacker holds the adversary makes bucket data unrecoverable to the owner and demands payment. SSE-C on writes is uncommon in most environments and can indicate destructive ransom activity.
HuntRule TeamAwscloudtrailHigh226Premium2026-06-17Suspicious OAuth Application Registration with Localhost Reply URL via Azure AD
This rule detects registration or update of an Azure AD OAuth application whose reply or redirect URL points to an anomalous localhost loopback endpoint such as http://localhost:7823/access/. This behavior was observed in OAuth application attacks researched by Huntress where adversaries register illicit applications to harvest tokens. Attackers abuse consented OAuth apps to maintain persistent access to cloud mailboxes and data, so anomalous reply URLs are a strong early indicator of illicit app registration.
HuntRule TeamAzureauditlogsHigh405Premium2026-06-12Malicious Azure Deletion of Resource Locks and Immutability Policies
This rule detects deletion of Azure resource locks and blob immutability policies, an anti-recovery step preceding storage ransomware. Removing locks and immutability protections strips the guardrails that would otherwise prevent an actor from overwriting or destroying blob data. A burst of these delete operations on storage resources indicates preparation for data destruction or ransom.
HuntRule TeamAzureactivitylogsHigh132Premium2026-06-09Malicious S3 Object Encryption with Customer Provided Key via CopyObject
This rule detects S3 CopyObject or PutObject API calls that supply a customer provided SSE-C encryption key which is the technique used in the CopyObjection intrusion to encrypt a victim S3 bucket for ransom. Because the attacker holds the key AWS cannot recover the data making this a destructive extortion action. Detecting SSE-C on bulk object operations surfaces ransomware activity in cloud storage.
HuntRule TeamAwscloudtrailHigh62Premium2026-06-03Suspicious Boto3 Kali Linux User Agent in AWS CloudTrail Reconnaissance (via cloudtrail)
This rule detects AWS CloudTrail activity from the specific Boto3 1.42.73 build running on Kali Linux that TeamPCP used to enumerate IAM EC2 Lambda and Secrets Manager resources after stealing credentials. The pairing of this SDK version with a Kali offensive distribution user agent is a strong indicator of hands-on-keyboard cloud reconnaissance with stolen keys.
HuntRule TeamAwscloudtrailHigh4310Premium2026-05-23Suspicious AWS IAM User Creation Using Support Impersonation Name
This rule detects the creation of an AWS IAM user named aws_support which the TeamTNT Doppelganger campaign creates and grants administrative permissions to in order to establish a persistent privileged foothold disguised as a legitimate AWS support account.
HuntRule TeamAwscloudtrailHigh83Premium2026-05-20Suspicious IAM CreateLoginProfile For Root User via AWS AssumeRoot Abuse
This rule detects an IAM CreateLoginProfile event that establishes console access for the root user which follows abuse of STS AssumeRoot to plant durable access in a member account. Adversaries create a root login profile to convert temporary root credentials into persistent account takeover.
HuntRule TeamAwscloudtrailHigh281Premium2026-05-20Malicious Directory Enumeration With Recon Tooling User Agent via Azure AD Graph
This rule detects Azure AD Graph requests carrying user agents belonging to known enumeration frameworks such as AzureHound BloodHound and AADInternals as described in Elastic research on AAD Graph activity logs. These tool signatures against the legacy Graph service indicate active directory reconnaissance for privilege escalation paths.
HuntRule TeamAzureazureactivityHigh122Premium2026-05-19Suspicious Entra Device Code Authentication with Office Client and Automated User Agent
This rule detects Entra ID sign-ins using the device code authentication flow against the Microsoft Office client application from an automated python-requests user agent, matching the Kali365 device code phishing ecosystem. Adversaries phish device codes to obtain refresh tokens for the well-known Office client and replay them programmatically to access mailboxes. Device code flow paired with a scripted user agent is a strong indicator of token theft and mailbox compromise.
HuntRule TeamAzuresigninlogsHigh122Premium2026-05-18Suspicious AWS IAM Privilege Escalation via AttachUserPolicy of Administrator Policy
This rule detects an IAM AttachUserPolicy call that attaches an administrator managed policy to a user, a technique used by operators of exposed IAM keys tracked by Unit 42 to escalate privileges before launching cryptojacking instances. Attackers abuse leaked long-term keys to grant themselves full control of the account which enables large scale resource abuse.
HuntRule TeamAwscloudtrailHigh123Premium2026-05-17Malicious EKS Access Policy Association Granting Cluster Admin
This rule detects CloudTrail AssociateAccessPolicy events that attach the AmazonEKSClusterAdminPolicy or AmazonEKSAdminPolicy to an EKS access entry. Wiz Research showed this new access management API can be abused to grant an attacker principal cluster administrator rights, so unexpected admin grants should be treated as potential privilege escalation.
HuntRule TeamAwscloudtrailHigh164Premium2026-05-15Malicious Office 365 Email Forwarding Rule to External Domain (via office365)
This rule detects creates a forwarding rules to a non company email in order to collect information.
HuntRule TeamAzureoffice365High244Premium2026-05-14