Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
313 rules
Azure Activity Logs: Kubernetes Network Policy Write/Delete Changes
Alerts on Azure Activity Log events that modify or remove Kubernetes network policies for connected clusters.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium92Free2021-08-07Azure Activity Logs: Azure Kubernetes Connected Cluster Created or Deleted
Alerts on Azure Activity Log operations that write or delete Kubernetes Connected Clusters.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsLow153Free2021-08-07Azure Activity Logs: Container Registry Created or Deleted
Flags Azure Activity Log events where an Azure Container Registry is created (write) or deleted.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsLow352Free2021-08-07Azure Activity Logs: Kubernetes Pod Deletion via Connected Clusters API
Flags Azure Activity Log events indicating Kubernetes pods were deleted for connected clusters.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium93Free2021-07-24Azure Kubernetes Events Deleted via Activity Logs
Identifies Azure Activity Log entries where Kubernetes event records are deleted for connected clusters.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium4710Free2021-07-24AWS CloudTrail: IAMUser STS GetSessionToken Use
Alerts on CloudTrail STS GetSessionToken calls made by IAM users, indicating potential temporary credential misuse.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow111Free2021-07-24AWS CloudTrail: Suspicious STS AssumeRole sessions from Role-issued principals
Alert on CloudTrail AssumeRole events initiated from an already assumed role session.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow177Free2021-07-24AWS CloudTrail S3 Bucket/Replication Configuration Tampering via Management API Calls
Flags CloudTrail S3 management API actions that modify bucket protections or move/restore objects.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow191Free2021-07-24AWS ElastiCache Cache Security Group Modified or Deleted via CloudTrail
Flags CloudTrail activity indicating an ElastiCache security group was modified or deleted.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow377Free2021-07-24AWS CloudTrail: ElastiCache Cache Security Group Created
Flags CloudTrail events indicating a new ElastiCache cache security group was created.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow152Free2021-07-24AWS Route 53 Domain Transfer to Another Account via TransferDomainToAnotherAwsAccount
Alerts on Route 53 domain transfer requests in CloudTrail when a domain is moved to another AWS account.
Elastic, Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow171Free2021-07-22AWS Route 53 Domain Transfer Lock Disabled via CloudTrail
Alerts when Route 53 domain transfer protection is removed through DisableDomainTransferLock events in CloudTrail.
Elastic, Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow3910Free2021-07-22AWS EC2: DisableEbsEncryptionByDefault API call to turn off default EBS encryption
Flags when EC2 default EBS encryption is disabled for the current AWS region via CloudTrail.
Sittikorn S, Huntrule TeamAwscloudtrailMedium295Free2021-06-29AWS CloudTrail: Security Hub findings evasion via finding updates or deletions
Identifies Security Hub finding and insight modifications (update or delete) that may impair detection results.
Sittikorn S, Huntrule TeamAwscloudtrailHigh202Free2021-06-28AWS CloudTrail: EC2 Snapshot Attribute Permission Modified for Cross-Account Access
Alerts on CloudTrail ModifySnapshotAttribute events indicating EC2 snapshot permissions were changed for other-account access.
Darin Smith, Huntrule TeamAwscloudtrailMedium204Free2021-05-17