Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
225 rules
Suspicious AWS Bedrock Guardrail Updated (via cloudtrail)
mediumThis rule detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken model safety controls and enable unsafe or unauthorized model responses.
sigmaCloud2026-06-05Suspicious Multifactor Authentication Denied (via signinlogs)
mediumThis rule detects user has indicated they haven't instigated the MFA prompt and could indicate an adversary has the password for the account.
sigmaCloud2026-06-04Suspicious Azure Kubernetes Network Policy Change (via activitylogs)
mediumThis rule detects when a Azure Kubernetes network policy is modified or deleted.
sigmaCloud2026-06-01Suspicious Google Full Network Traffic Packet Capture (via gcp.audit)
mediumThis rule detects potential full network packet capture in gcp. This feature can potentially be misused to read sensitive data from unencrypted internal traffic.
sigmaCloud2026-05-31Possible Google Cloud Storage Buckets Enumeration (via gcp.audit)
lowThis rule detects when storage bucket is enumerated in Google Cloud.
sigmaCloud2026-05-31Malicious AWS EC2 Disable EBS Encryption (via cloudtrail)
mediumThis rule detects disabling of default Amazon Elastic Block Store (EBS) encryption in the current region. Disabling default encryption does not change the encryption status of your existing volumes.
sigmaCloud2026-05-31Suspicious Added Credentials to Existing Application (via auditlogs)
highThis rule detects when a new credential is added to an existing application. Any additional credentials added outside of expected processes could be a hostile actor using those credentials.
sigmaCloudPaid2026-05-29Suspicious Disabling Multi Factor Authentication (via audit)
highThis rule detects disabling of Multi Factor Authentication.
sigmaCloudPaid2026-05-27Suspicious Azure Virtual Network Modified or Deleted (via activitylogs)
mediumThis rule detects when a Virtual Network is modified or deleted in Azure.
sigmaCloud2026-05-27Suspicious AWS S3 Bucket Versioning Disable (via cloudtrail)
mediumThis rule detects when S3 bucket versioning is disabled. Threat actors use this method during AWS ransomware incidents prior to deleting S3 objects.
sigmaCloud2026-05-27Suspicious Microsoft 365 - Impossible Travel Activity (via threat_management)
mediumThis rule detects when a Microsoft Cloud App Security reported a risky sign-in attempt due to a login linked with an impossible travel.
sigmaCloud2026-05-26Suspicious Applications That Are Via ROPC Authentication Flow (via signinlogs)
mediumThis rule detects resource owner password credentials (ROPC) should be avoided if at all possible as this requires the user to expose their current password credentials to the application directly. The application then uses those credentials to authenticate the user against the identity provider.
sigmaCloud2026-05-26Suspicious Use of Legacy Authentication Protocols (via signinlogs)
highThis rule detects when legacy authentication has been used on an account
sigmaCloudPaid2026-05-25Suspicious AWS SAML Provider Removal Behavior (via cloudtrail)
mediumThis rule detects the deletion of an AWS SAML provider, potentially suggesting hostile intent to disrupt administrative or security team access. An adversary can remove the SAML provider for the information security team or a team of system administrators, to make it difficult for them to work and investigate at the time of the attack and after it.
sigmaCloud2026-05-25Suspicious Azure Virtual Network Device Modified or Deleted (via activitylogs)
mediumThis rule detects when a virtual network device is being modified or deleted. This can be a network interface, network virtual appliance, virtual hub, or virtual router.
sigmaCloud2026-05-24Suspicious Azure Network Firewall Policy Modified or Deleted (via activitylogs)
mediumThis rule detects when a Firewall Policy is Modified or Deleted.
sigmaCloud2026-05-24Suspicious AWS EFS Fileshare Mount Modified or Deleted (via cloudtrail)
mediumThis rule detects when a EFS Fileshare Mount is modified or deleted. An adversary breaking any file system using the mount target that is being deleted, which might disrupt instances or applications using those mounts.
sigmaCloud2026-05-24Suspicious Inbox Forwarding Identity Protection (via riskdetection)
highThis rule detects suggests anomalous rules such as an inbox rule that forwards a copy of all emails to an external address
sigmaCloudPaid2026-05-21Suspicious Azure Application Gateway Modified or Deleted (via activitylogs)
mediumThis rule detects when a application gateway is modified or deleted.
sigmaCloud2026-05-17Suspicious GCP Break-glass Container Workload Deployed (via gcp.audit)
mediumThis rule detects the deployment of workloads that are deployed by using the break-glass flag to override Binary Authorization controls.
sigmaCloud2026-05-15