Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
313 rules
Suspicious AWS CloudTrail Logging Disabled
This rule detects API calls that stop or delete AWS logging such as StopLogging, DeleteTrail and DeleteFlowLogs. Adversaries disable CloudTrail and VPC flow logs to blind defenders before carrying out further actions, a defense evasion step that should be rare and deliberate.
HuntRule TeamAwscloudtrailHigh111Premium2026-06-27Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs
This rule detects a delegated permission grant that targets an Entra agent blueprint access_agent scope, the consent step that lets an attacker-controlled app drive an assistive AI agent. Adversaries obtain delegated access to agents that can send mail and act on the user behalf, so a grant referencing access_agent indicates agent hijacking through illicit consent.
HuntRule TeamAzureauditlogsHigh427Premium2026-06-26Suspicious Entra Sign-In Interrupt With High Aggregated Risk via AiTM DNS Hijacking (via azure)
This rule surfaces Microsoft Entra sign-ins carrying a high aggregated risk score alongside interrupt or success result codes, the pattern seen when SOHO router DNS hijacking redirects victims through an adversary-in-the-middle proxy that replays authentication. Adversaries use the hijacked DNS to intercept credentials and tokens, so high-risk sign-ins clustered with these result codes warrant investigation for token theft and mailbox access.
HuntRule TeamAzuresigninlogsMedium334Premium2026-06-26Suspicious GCP Log Sink Tampering for Defense Evasion (via gcp)
This rule detects Google Cloud audit-log operations that update, disable, or delete logging sinks and buckets, a defense-evasion tactic used to blind visibility during cloud attacks. Adversaries suppress log export so their subsequent actions are not recorded.
HuntRule TeamGcpgcp.auditMedium376Premium2026-06-25Malicious S3 Object Encryption for Ransom via SSE-C
This rule detects an S3 PutObject call that supplies a customer provided encryption key using server side encryption with customer keys, the core primitive of the AWS S3 SSE-C ransom scenario emulated by Elastic. By overwriting objects with a key only the attacker holds the adversary makes bucket data unrecoverable to the owner and demands payment. SSE-C on writes is uncommon in most environments and can indicate destructive ransom activity.
HuntRule TeamAwscloudtrailHigh206Premium2026-06-17Suspicious UNC3944 Rogue Federated Identity Provider Added to Entra Tenant (via azure)
This rule detects Azure AD/Entra directory operations that configure or modify domain federation settings, which adds or alters a trusted identity provider. UNC3944 abused hybrid identity by registering a rogue federated IdP to forge SAML tokens and impersonate any user in the tenant. Unexpected federation trust changes are a high-value indicator of a Golden SAML style backdoor.
HuntRule TeamAzureauditlogsMedium93Premium2026-06-13Suspicious AWS STS Session Token and Role Chaining Abuse via CloudTrail (via aws)
This rule surfaces AWS STS GetSessionToken and AssumeRole activity that adversaries abuse to mint temporary credentials and chain roles for lateral movement, as detailed in Red Canary's analysis of AWS cloud account abuse. Because these APIs are also used legitimately, alerts should be correlated with the calling identity and source to spot role chaining that escalates access across the environment.
HuntRule TeamAwscloudtrailLow41Premium2026-06-13Suspicious OAuth Application Registration with Localhost Reply URL via Azure AD
This rule detects registration or update of an Azure AD OAuth application whose reply or redirect URL points to an anomalous localhost loopback endpoint such as http://localhost:7823/access/. This behavior was observed in OAuth application attacks researched by Huntress where adversaries register illicit applications to harvest tokens. Attackers abuse consented OAuth apps to maintain persistent access to cloud mailboxes and data, so anomalous reply URLs are a strong early indicator of illicit app registration.
HuntRule TeamAzureauditlogsHigh395Premium2026-06-12Possible Rogue Device Registration in Entra ID After Device Code Phishing
This rule detects registration of a new device in Entra ID which commonly follows successful device-code phishing. In the Dangerous Invitations campaign the Russian actor registered attacker-controlled devices to obtain durable access after luring targets with spoofed European security event invitations. Adding a rogue device is a stealthy persistence mechanism that can bypass conditional access and sustain access to the tenant.
HuntRule TeamAzureauditlogsMedium419Premium2026-06-11Suspicious Bedrock AgentCore Runtime Invocation on Wildcard Resources (via aws)
This rule detects Bedrock AgentCore code interpreter and agent runtime invocations that, in the Agent God Mode scenario, are abused through wildcard IAM permissions to execute code across agent boundaries. Invocation of these runtimes by unexpected principals can indicate exploitation of excessive privileges for arbitrary execution in the AI environment.
HuntRule TeamAwscloudtrailLow265Premium2026-06-10Suspicious AWS SAML Provider Enumeration for Federation Recon (via cloudtrail)
This rule detects enumeration of configured SAML identity providers through the IAM ListSAMLProviders call, a discovery step Muddled Libra performs to understand federation and plan cross tenant identity abuse. Because this API is rarely called in day to day operations, its use by an interactive or unfamiliar principal points to adversary reconnaissance of the trust configuration.
HuntRule TeamAwscloudtrailMedium364Premium2026-06-10Malicious Azure Deletion of Resource Locks and Immutability Policies
This rule detects deletion of Azure resource locks and blob immutability policies, an anti-recovery step preceding storage ransomware. Removing locks and immutability protections strips the guardrails that would otherwise prevent an actor from overwriting or destroying blob data. A burst of these delete operations on storage resources indicates preparation for data destruction or ransom.
HuntRule TeamAzureactivitylogsHigh132Premium2026-06-09Suspicious SNS Email Subscription for Data Exfiltration
This rule detects an SNS Subscribe call using the email protocol, an exfiltration setup step in the AWS SNS abuse scenario researched by Elastic. Attackers subscribe an external email address to a topic then publish stolen credentials or data to it over a trusted AWS channel. Email subscriptions created by unexpected principals should be reviewed for data theft.
HuntRule TeamAwscloudtrailMedium338Premium2026-06-09Suspicious Teams Message Soft Delete by Agent Identity via M365 Audit
This rule detects soft deletion of Teams channel messages, the cleanup step observed when a compromised Entra agent identity posts internal phishing links and then removes the evidence. Adversaries delete their own messages to hide internal spearphishing and slow investigation, so agent-driven message deletions in Teams warrant correlation with preceding message-send activity.
HuntRule TeamM365auditMedium345Premium2026-06-09Malicious Storm-0558 Forged Token Sign-In from MSA Consumer Tenant (via azure signinlogs)
This rule detects Entra ID sign-ins whose home tenant is the Microsoft consumer MSA tenant 9188040d-6c67-4c5b-b112-36a304b66dad, the issuer Storm-0558 impersonated with a stolen MSA signing key to forge OpenID v2.0 tokens against Exchange Online and other organizational resources. Tokens minted for enterprise access from this consumer issuer indicate forged-credential authentication and should be treated as identity compromise.
HuntRule TeamAzuresigninlogsMedium102Premium2026-06-08