Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
225 rules
Suspicious App Granted Microsoft Permissions (via auditlogs)
highThis rule detects when an application is granted delegated or app role permissions for Microsoft Graph, Exchange, Sharepoint, or Azure AD
sigmaCloudPaid2026-06-25Suspicious Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted (via activitylogs)
mediumThis rule detects the creation or patching of potential hostile RoleBinding/ClusterRoleBinding.
sigmaCloud2026-06-25Suspicious Behavior From Anonymous IP Address (via riskdetection)
highThis rule detects that users were active from an IP address that has been identified as an anonymous proxy IP address.
sigmaCloudPaid2026-06-22Suspicious Google Cloud Kubernetes Secrets Modified or Deleted (via gcp.audit)
mediumThis rule detects when the Secrets are Modified or Deleted.
sigmaCloud2026-06-21Suspicious Disabling of PIM Alert Setting Changes To (via auditlogs)
highThis rule detects when PIM alerts are set to disabled.
sigmaCloudPaid2026-06-21Suspicious Removal of AWS VPC Flow Logs (via cloudtrail)
highThis rule detects the deletion of one or more VPC Flow Logs in AWS Elastic Compute Cloud (EC2) through the DeleteFlowLogs API call. Adversaries may delete flow logs to evade detection or remove evidence of network activity, hindering forensic investigations and visibility into hostile operations.
sigmaCloudPaid2026-06-21Possible Azure Container Registry Created or Deleted (via activitylogs)
lowThis rule detects when a Container Registry is created or deleted.
sigmaCloud2026-06-20Suspicious Changes to Device Registration Policy (via auditlogs)
highThis rule detects changes to the device registration policy.
sigmaCloudPaid2026-06-19Suspicious Roles Are Not Being Used (via pim)
highThis rule detects when a user has been assigned a privilege role and are not using that role.
sigmaCloudPaid2026-06-16Suspicious Azure Firewall Rule Configuration Modified or Deleted (via activitylogs)
mediumThis rule detects when a Firewall Rule Configuration is Modified or Deleted.
sigmaCloud2026-06-16Suspicious Removal of AWS Bedrock Guardrail (via cloudtrail)
mediumThis rule detects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove model safety controls and enable unsafe or unauthorized model responses.
sigmaCloud2026-06-15Suspicious Sign-ins from Non-Compliant Devices (via signinlogs)
highThis rule detects sign-ins where the device was non-compliant.
sigmaCloudPaid2026-06-14Suspicious Google Workspace Out Of Domain Email Forwarding (via google_workspace.login)
mediumThis rule detects automatic email forwarding to external domains in Google Workspace, which may indicate data leakage or misuse.
sigmaCloud2026-06-13Suspicious AWS Identity Center Identity Provider Change (via cloudtrail)
highThis rule detects a change in the AWS Identity Center (FKA AWS SSO) identity provider. A change in identity provider enables an adversary to establish persistent access or escalate privileges via user impersonation.
sigmaCloudPaid2026-06-12Suspicious Device Registration or Join Without MFA (via signinlogs)
mediumThis rule detects device registration or join events where MFA was not performed.
sigmaCloud2026-06-07Suspicious AWS IAM S3Browser User or AccessKey Creation (via cloudtrail)
highThis rule detects S3 Browser utility creating IAM User or AccessKey.
sigmaCloudPaid2026-06-07Suspicious Stale Accounts In A Privileged Role (via pim)
highThis rule detects when an account hasn't signed in during the past n number of days.
sigmaCloudPaid2026-06-06Suspicious Google Cloud VPN Tunnel Modified or Deleted (via gcp.audit)
mediumThis rule detects when a VPN Tunnel Modified or Deleted in Google Cloud.
sigmaCloud2026-06-05Suspicious Azure AD Account Credential Leaked (via riskdetection)
highThis rule detects suggests that the user's valid credentials have been leaked.
sigmaCloudPaid2026-06-05Suspicious AWS IAM S3Browser Templated S3 Bucket Policy Creation (via cloudtrail)
highThis rule detects S3 browser utility creating Inline IAM policy containing default S3 bucket name placeholder value of "<YOUR-BUCKET-NAME>".
sigmaCloudPaid2026-06-05