Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
313 rules
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
This rule detects non-interactive Microsoft 365 sign-ins using the BAV2ROPC legacy authentication client. In the Railway PaaS token replay campaign, operators used BAV2ROPC to silently refresh stolen tokens and access mailboxes without triggering interactive MFA, so this client string on sign-ins indicates likely token abuse and legacy protocol exploitation.
HuntRule TeamM365signinlogsHigh82Premium2026-07-19Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)
This rule detects Entra ID operations that add cross-tenant partners, invite external users, or create access packages, overlooked entry points into Microsoft Azure that adversaries abuse for persistence per Red Canary. These identity changes can silently grant outside principals durable access to a tenant, so unexpected occurrences should be validated against approved administrative activity.
HuntRule TeamAzureauditlogsMedium132Premium2026-07-19Suspicious AWS Long-Term Access Key Creation for Persistence via CloudTrail (via aws)
This rule detects the creation of a long-term IAM access key, which adversaries generate as a backup AKIA credential to maintain persistent access to a compromised AWS account per Red Canary. Key creation for a user other than the caller, or immediately following STS token abuse, is a strong indicator that an attacker is establishing durable persistence.
HuntRule TeamAwscloudtrailLow133Premium2026-07-16Suspicious STS AssumeRole With Exfil Session Name via CloudTrail (via cloudtrail)
This rule detects the Shai Hulud actor assuming high privilege roles using session names that begin with exfil such as exfil, exfil10 and exfil12 to run Systems Manager commands and read data. Operator chosen session names that reveal exfiltration intent are a strong hunting signal. These sessions preceded Redshift data theft.
HuntRule TeamAwscloudtrailHigh142Premium2026-07-15Suspicious AWS SAML Identity Provider Creation
This rule detects creation of a SAML identity provider through the IAM CreateSAMLProvider call. Adversaries register a rogue federation provider to establish durable authenticated access to the account, a persistence and account manipulation technique highlighted by Sekoia AWS detection guidance.
HuntRule TeamAwscloudtrailMedium73Premium2026-07-10AWS Bedrock Guardrail Updated via UpdateGuardrail API
Alerts on CloudTrail-reported Amazon Bedrock guardrail updates, which may signal attempts to weaken safety controls.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamAwscloudtrailMedium241Free2026-07-10AWS Bedrock Guardrail Deletion via CloudTrail DeleteGuardrail API
Alerts on CloudTrail DeleteGuardrail events indicating an AWS Bedrock guardrail was removed.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamAwscloudtrailMedium203Free2026-07-10Suspicious Entra Agent Service Principal Sign-In With PowerShell User Agent via Sign-In Logs
This rule detects a service principal sign-in using a PowerShell user agent against Entra Agent ID identities, a pattern of automated credential misuse where an attacker authenticates as an AI agent through scripted Graph calls. Because assigned agents normally authenticate through their own runtime rather than interactive PowerShell tooling, this user agent on service principal sign-ins indicates hands-on-keyboard abuse of agent credentials.
HuntRule TeamAzuresigninlogsMedium371Premium2026-07-09Suspicious Entra ID Auth Broker Sign-In With Node.js User Agent via Tycoon 2FA
This rule detects Entra ID sign ins against the Microsoft Authentication Broker application from Node.js based clients such as axios undici and node-fetch as characteristic of Tycoon 2FA adversary in the middle attacks in Elastic research. Automated Node runtimes replaying stolen tokens through the Auth Broker indicate token theft and primary refresh token abuse rather than genuine user interaction.
HuntRule TeamAzuresigninlogsHigh93Premium2026-07-09Suspicious Inbox Rule Moving Mail to Junk for Concealment (via m365)
This rule detects creation or modification of a mailbox inbox rule that moves incoming messages to the junk email folder. Threat actors created such rules to hide fraud notifications and security alerts from the victim while automating financially driven attacks.
HuntRule TeamM365exchangeMedium62Premium2026-07-08Suspicious AWS Organizations and Account Discovery via aws (via cloudtrail)
This rule detects AWS Organizations and account enumeration API calls that map the blast radius of compromised access keys. Unit 42 observed this cloud service discovery during the SugarCRM incident where stolen credentials were used to survey the target environment before resource abuse, so alerting is warranted when these calls come from unexpected principals.
HuntRule TeamAwscloudtrailLow73Premium2026-07-06Suspicious AWS Console Login Without MFA
This rule detects a successful AWS Management Console sign-in where additionalEventData.MFAUsed is No, indicating interactive access with only a password or root credentials and no second factor. Adversaries who compromise console credentials rely on non-MFA logins to gain hands-on-keyboard access, a pattern GuardDuty also flags as IAMUser ConsoleLoginSuccess. This is important because non-MFA console logins are a primary indicator of account takeover.
HuntRule TeamAwscloudtrailMedium151Premium2026-07-04Suspicious Spoofed Inbound Email With Failed Authentication and Anonymous Internal Sender (via m365)
This rule detects inbound messages that fail SPF, DKIM, and composite authentication yet are marked as internal organization senders while authenticating anonymously. This combination reflects the routing and misconfiguration abuse used by phishing actors to spoof trusted internal domains and bypass tenant protections. Detecting the mismatch between claimed internal origin and failed authentication surfaces domain-spoofing phishing that would otherwise appear trustworthy to recipients.
HuntRule TeamM365exchangeMedium361Premium2026-07-02Suspicious Cloud Sign-In From an Anonymizer or High-Risk Session (via signinlogs)
This rule detects an Entra ID sign-in flagged with an anonymized IP address or a high real-time risk level, indicating access through Tor or a VPN anonymizer or from a session Microsoft's risk engine deems likely compromised. Compromise of cloud accounts is the most prevalent technique in the Red Canary Threat Detection Report. Detecting anonymized and high-risk sign-ins surfaces suspicious identity access at the authentication boundary.
HuntRule TeamAzuresigninlogsMedium101Premium2026-06-29Suspicious Entra Sign-In to OfficeHome with axios User Agent
This rule detects a successful Entra ID sign-in to the OfficeHome application where the user agent contains axios, an automation library used by the Tycoon 2FA adversary-in-the-middle platform. Tycoon 2FA relayed intercepted credentials and stolen session cookies through scripted axios clients to authenticate as the victim. A non-browser axios agent completing sign-in to OfficeHome indicates automated session token replay from an AiTM phishing kit.
HuntRule TeamAzuresigninlogsHigh61Premium2026-06-28