Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
313 rules
Microsoft 365 Impossible Travel Sign-ins Reported as Successful
Alerts on successful Microsoft 365 “Impossible travel activity” events in SecurityComplianceCenter telemetry.
Austin Songer @austinsonger, Huntrule TeamM365threat_managementMedium224Free2020-07-06Azure Activity Logs: Alert on First-Time Source IP for Subscription-Level Rare Operations
Alerts when specified Azure subscription operations occur from a new, previously unseen source IP.
sawwinnnaung, Huntrule TeamAzureactivitylogsMedium142Free2020-05-07Azure Activity Logs: Granting Role Assignments from New Source IPs
Alerts on Azure role assignment permission grants when they originate from a new source IP in Activity Logs.
sawwinnnaung, Huntrule TeamAzureactivitylogsMedium359Free2020-05-07Azure Activity Logs: High Rate of VM Creations or Deployment Writes
Flags Azure activity log events showing VM creation or deployment write operations occurring at an anomalously high volume.
sawwinnnaung, Huntrule TeamAzureactivitylogsMedium153Free2020-05-07AWS CloudTrail EC2 CreateInstanceExportTask Failure
Flags failed EC2 VM export task creation events in AWS CloudTrail to surface potential instance data extraction attempts.
Diogo Braz, Huntrule TeamAwscloudtrailLow101Free2020-04-16AWS CloudTrail: RestoreDBInstanceFromDBSnapshot Creates Public RDS Instance
Detects RDS restores from snapshots that result in a publicly accessible database instance in AWS CloudTrail.
faloker, Huntrule TeamAwscloudtrailHigh461Free2020-02-12AWS CloudTrail RDS ModifyDBInstance Master User Password Change
Flags AWS RDS ModifyDBInstance events that include a master user password change.
faloker, Huntrule TeamAwscloudtrailMedium132Free2020-02-12AWS CloudTrail CreateAccessKey by Another IAM User (Backdoor Key Creation)
Identifies AWS access key creation where the requester is different from the access key’s target user.
faloker, Huntrule TeamAwscloudtrailMedium2410Free2020-02-12AWS EC2 ModifyInstanceAttribute userData Startup Script Change
Detects CloudTrail EC2 userData startup script changes made via ModifyInstanceAttribute.
faloker, Huntrule TeamAwscloudtrailHigh81Free2020-02-12AWS GuardDuty CreateIPSet Trusted IP Set Changes (CloudTrail)
Alerts on CloudTrail GuardDuty CreateIPSet events that add or update trusted IP address sets.
faloker, Huntrule TeamAwscloudtrailHigh102Free2020-02-11AWS CloudTrail: Root User Credential Usage (UserIdentity.type=Root)
Alerts on CloudTrail activity performed by AWS account root credentials.
vitaliy0x1, Huntrule TeamAwscloudtrailMedium123Free2020-01-21AWS CloudTrail: AWS Config Delivery Channel/Recorder Disabled
Identifies CloudTrail actions that delete AWS Config delivery channels or stop the configuration recorder.
vitaliy0x1, Huntrule TeamAwscloudtrailHigh112Free2020-01-21AWS CloudTrail Trail Stop/Update/Delete Activity
Detects CloudTrail stop, update, or delete actions that can impair logging and audit visibility.
vitaliy0x1, Huntrule TeamAwscloudtrailMedium2410Free2020-01-21