Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
100 rules
Suspicious IAM Policy Attachment Granting AdministratorAccess
This rule detects an AttachUserPolicy call that attaches the AWS managed AdministratorAccess policy to an IAM user. After compromising an EC2 instance and stealing IMDS credentials the attacker created a rogue IAM user and granted it full administrator rights for persistence and privilege escalation. Sudden attachment of AdministratorAccess to a user is high-signal for cloud account takeover.
HuntRule TeamAwscloudtrailHigh444Premium2026-05-11Malicious Active Directory Federated Trust Added (via office365)
This rule detects scenarios where an federated trust is added by an attacker.
HuntRule TeamAzureoffice365High93Premium2026-05-11Suspicious High-Privilege Microsoft Graph Application Role Grant via Azure Audit (via azure)
This rule detects the assignment of high-privilege Microsoft Graph application roles such as AppRoleAssignment.ReadWrite.All, Directory.ReadWrite.All, or RoleManagement.ReadWrite.Directory to a service principal, an escalation path into Azure highlighted by Red Canary. Granting these permissions lets an app rewrite directory roles and grant itself further access, making it a powerful and stealthy persistence mechanism that should be tightly controlled.
HuntRule TeamAzureauditlogsHigh135Premium2026-05-03AWS CloudTrail GuardDuty Detector Deleted or Disabled via UpdateDetector
Identifies successful GuardDuty detector deletion or disablement from CloudTrail, reducing GuardDuty monitoring coverage.
suktech24, Huntrule TeamAwscloudtrailHigh2010Free2025-11-27AWS CloudTrail Detects EC2 DeleteFlowLogs API Calls
Flags successful EC2 DeleteFlowLogs API calls in CloudTrail indicating VPC Flow Logs were removed.
Ivan Saakov, Huntrule TeamAwscloudtrailHigh182Free2025-10-19AWS KMS Imported Key Material Import or Deletion via CloudTrail
Detects AWS KMS imported key material events in CloudTrail, including import and deletion of imported key material.
toopricey, Huntrule TeamAwscloudtrailHigh143Free2025-10-18M365 Audit: Successful Intune Company Portal login via Cmsi
Flags successful Company Portal (Intune) logins via Cmsi audit events that may indicate Conditional Access bypass attempts.
Josh Nickels, Marius Rothenbücher, Huntrule TeamM365auditHigh422Free2025-01-08AWS CloudTrail: RDS Cluster Modification or Deletion (ModifyDBCluster/DeleteDBCluster)
Detects CloudTrail ModifyDBCluster or DeleteDBCluster actions on AWS RDS clusters.
Ivan Saakov, Huntrule TeamAwscloudtrailHigh212Free2024-12-06Azure AD Audit: Update User Risk and MFA Registration Policy
Flags Azure AD audit events showing updates to user risk and MFA registration policy.
Harjot Singh (@cyb3rjy0t), Huntrule TeamAzureauditlogsHigh152Free2024-08-13AWS CloudTrail SSM SendCommand Successful Execution for Instance
Identifies successful AWS SSM SendCommand executions recorded in CloudTrail.
jamesc-grafana, Huntrule TeamAwscloudtrailHigh247Free2024-07-11AWS CloudTrail: Instance Profile Role Assumed Actions Outside SSM RegisterManagedInstance
Identifies CloudTrail activity from assumed-role instance identities when it is not part of SSM RegisterManagedInstance.
jamesc-grafana, Huntrule TeamAwscloudtrailHigh123Free2024-07-11AWS CloudTrail: AWS Identity Center Identity Provider Configuration Changes
Detects CloudTrail identity center events that associate or change the external identity provider configuration.
Michael McIntyre @wtfender, Huntrule TeamAwscloudtrailHigh122Free2023-09-27Microsoft 365 Audit: Disabling Strong Authentication (MFA)
Flags Microsoft 365 audit events indicating MFA/strong authentication was disabled.
Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule), Huntrule TeamM365auditHigh386Free2023-09-18Azure Entra PIM Alerts: Too Many Global Administrators Assigned to Tenant
Alerts when Azure PIM reports an overabundance of Global Administrator role assignments in a tenant.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh103Free2023-09-14Azure AD PIM Redundant Assignment Alert When Privileged Role Not Used
Alerts on Azure PIM redundant privileged role assignments where the assigned role appears unused.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh303Free2023-09-14