Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
67 rules
Azure Sign-In: Successful single-factor atRisk logins from non-registered devices
Alerts on at-risk successful Azure sign-ins from devices with missing trust type when MFA isn’t required.
sigmaCloudhigh2023-01-10Azure sign-in logs: Detect AzureHound discovery tool via default User-Agent
Flags successful Azure sign-ins where the User-Agent contains "azurehound", indicating AzureHound discovery.
sigmaCloudhigh2022-11-27Azure AD Account Created and Deleted Shortly After Creation (Audit Logs)
Identifies successful Azure user creation and deletion in quick succession, consistent with short-lived account activity.
sigmaCloudhigh2022-08-11Azure Entra Audit Logs: Temporary Access Pass Method Added to an Account
Flags admin registration of a temporary access pass method in Azure audit logs for user accounts.
sigmaCloudhigh2022-08-10Azure Entra PIM Role Setting Changes in Audit Logs
Alerts on Azure PIM role setting update events recorded in audit logs.
sigmaCloudhigh2022-08-09Azure PIM Alert Setting Disabled (Audit Log Message Detection)
Flags Azure audit log events where PIM alerts are disabled (message: "Disable PIM Alert").
sigmaCloudhigh2022-08-09Azure PIM Approval or Denial Recorded in Audit Logs
Flags Azure PIM elevation requests that are approved or denied in audit logs for investigation.
sigmaCloudhigh2022-08-09Azure Audit Logs: User Added to Privileged Eligibility Role
Alerts on Azure audit log events indicating a user was added as an eligible or permanent member to a privileged role.
sigmaCloudhigh2022-08-06Azure Audit Logs: Removal of Privileged Role Eligible Members
Flags Azure audit log events indicating bulk removal of eligible members from privileged roles.
sigmaCloudhigh2022-08-05Azure Audit Logs: Admin-initiated App Role Assignments and Privileged Delegated Permissions
Alerts on Azure audit events where an admin grants app roles to a service principal, enabling privileged application access.
sigmaCloudhigh2022-07-28Azure audit logs: Delegated highly privileged permissions granted for all users
Alerts on Azure audit log events where delegated permissions are granted to all users.
sigmaCloudhigh2022-07-28Azure Audit Logs: App Granted Microsoft Graph/Exchange/SharePoint/Azure AD Permissions
Alerts on Azure AD audit log entries where an app/service principal is granted delegated or app-role permissions to Microsoft services.
sigmaCloudhigh2022-07-10Azure AD Sign-ins from Non-Compliant Devices
Alert on Entra ID sign-ins originating from devices flagged as non-compliant.
sigmaCloudhigh2022-06-28Azure Audit Logs: User Added to Global or Device Administrator Roles
Alerts when Azure AD role-management events add users to Global or Device Administrator roles.
sigmaCloudhigh2022-06-28Azure AD/Entra Audit Logs: Device Registration Policy Changes
Alerts on Azure audit log events that set or modify the device registration policy.
sigmaCloudhigh2022-06-28Azure AD Sign-ins Using Legacy Authentication Client Applications
Alerts on Azure sign-ins using legacy protocol client apps (IMAP/POP3/SMTP/EWS/ActiveSync), which may indicate risky authentication usage.
sigmaCloudhigh2022-06-17Azure Audit Logs: Application URI Configuration Changes (AppAddress)
Alerts on Azure audit log events indicating an application URI (AppAddress) was modified.
sigmaCloudhigh2022-06-02Azure Audit Logs: Application AppID URI Updates via App or Service Principal Changes
Alerts on Azure audit log entries indicating updates to an application or service principal AppID URI configuration.
sigmaCloudhigh2022-06-02Azure Sign-in Logs: Conditional Access Blocked Sign-in Failures (ResultType 53003)
Alerts on Azure sign-ins blocked by Conditional Access when requirements are not met.
sigmaCloudhigh2022-06-01Azure AuditLogs: Privileged role assignment to user access admin
Flags Azure AuditLogs events where a user is assigned to User Access Administrator, enabling full subscription management.
sigmaCloudhigh2021-11-26