Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
100 rules
Azure PIM Role Activation Without MFA Alert (noMfaOnRoleActivationAlertIncident)
Alerts when Azure PIM signals role activation occurred without MFA.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh408Free2023-09-14Azure AD PIM Role Activations Too Frequent for Same User
Alerts when Azure PIM logs sequential activation renewals for the same role by the same user.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh151Free2023-09-14Azure PIM Alert: Privileged Role Assigned Outside PIM
Detects Azure PIM risk events indicating privileged role assignments were made outside PIM.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh194Free2023-09-14Azure PIM Invalid License Alert Incident
Alerts when Azure PIM reports an invalid or missing license condition for the organization.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh272Free2023-09-14Azure PIM Stale Sign-In Alert for Privileged Role Accounts
Alerts when Azure PIM reports a privileged account has gone stale due to no sign-in activity.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh301Free2023-09-14Azure (Entra ID) Risk Detection: Threat Intelligence-Driven Unusual User Activity
Flags Azure AD risk investigation events tied to threat-intelligence sign-in indicators using riskdetection telemetry.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh217Free2023-09-07Azure Risk Detection: Attempted Primary Refresh Token (PRT) Access
Identifies Azure risk events indicating an attempted PRT access that can enable lateral movement or credential theft.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh242Free2023-09-07Azure Entra Risk Detection: SuspiciousIPAddress Sign-In From Malicious IP
Alerts on Azure Entra sign-in risk events marked suspiciousIPAddress, suggesting origin from a known malicious IP.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh91Free2023-09-07Azure risk detection: Malicious IP sign-in risk event based on sign-in failure rate
Flags Azure risk events for sign-ins associated with malicious IPs using maliciousIPAddress failure-rate indications.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh152Free2023-09-07Azure Entra sign-in risk: Unfamiliar sign-in properties
Alerts on Azure risk events where sign-in properties are marked unfamiliar compared to a user’s historical patterns.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh82Free2023-09-03Azure SAML Token Issuer Anomaly via riskdetection
Flags Azure risk events where a SAML token’s issuer and claims look anomalous or attacker-like.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh123Free2023-09-03Azure Entra suspicious browser risk events across multiple tenants and countries
Flags Azure suspicious browser risk events tied to anomalous sign-ins across tenants and countries from the same browser.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh1810Free2023-09-03Azure Entra ID risk event: successful password spray detection
Flags Azure Entra ID risk events indicating a successful password spray attempt.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh125Free2023-09-03Azure Entra ID sign-in risk: new country (riskEventType newCountry)
Flags Azure AD risk events where a sign-in is assessed as originating from a new country for the user.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh457Free2023-09-03Azure Identity Risk: Sign-ins from Malware-Infected IP Addresses
Flags Azure sign-in risk events originating from malware-infected IP addresses linked to bot-server communication.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh193Free2023-09-03