Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
225 rules
Suspicious Azure Firewall Modified or Deleted (via activitylogs)
mediumThis rule detects when a firewall is created, modified, or deleted.
sigmaCloud2026-05-15Suspicious PUA - AWS TruffleHog Execution (via cloudtrail)
mediumThis rule detects the execution of TruffleHog, a popular open-source tool used for scanning repositories for secrets and sensitive information, within an AWS environment. It has been reported to be used by threat actors for credential harvesting. All detections should be investigated to determine if the use is authorized by security teams or potentially malicious.
sigmaCloud2026-05-15Suspicious Anonymous IP Address (via riskdetection)
highThis rule detects suggests sign-ins from an anonymous IP address, for example, using an anonymous browser or VPN.
sigmaCloudPaid2026-05-13Suspicious New Network Route Added (via cloudtrail)
mediumThis rule detects the addition of a new network route to a route table in AWS.
sigmaCloud2026-05-13Malicious Use Of IMDS Credentials Outside Of AWS Infrastructure (via cloudtrail)
highThis rule detects when an instance identity has taken an action that isn't inside SSM. This can indicate that a compromised EC2 instance is being used as a pivot point.
sigmaCloudPaid2026-05-13Behavior from Suspicious IP Addresses (via threat_detection)
mediumThis rule detects when a Microsoft Cloud App Security reported users were active from an IP address identified as risky by Microsoft Threat Intelligence. These IP addresses are involved in hostile activities, such as Botnet C&C, and may indicate compromised account.
sigmaCloud2026-05-11Suspicious Azure Firewall Rule Collection Modified or Deleted (via activitylogs)
mediumThis rule detects when Rule Collections (Application, NAT, and Network) is being modified or deleted.
sigmaCloud2026-05-11Suspicious Azure Kubernetes Sensitive Role Access (via activitylogs)
mediumThis rule detects when ClusterRoles/Roles are being modified or deleted.
sigmaCloud2026-05-10Possible End User Consent (via auditlogs)
lowThis rule detects when an end user consents to an application
sigmaCloud2026-05-08Suspicious Removal of SES Identity Has Been (via cloudtrail)
mediumThis rule detects an instance of an SES identity being deleted via the "DeleteIdentity" event. This may be an indicator of an adversary removing the account that carried out anomalous or hostile activities
sigmaCloud2026-05-06Suspicious User Removed From Group With CA Policy Change Access (via auditlogs)
mediumThis rule detects group membership removal of groups that have CA policy modification access
sigmaCloud2026-05-05Malicious Sign-In From Malware Infected IP (via riskdetection)
highThis rule detects suggests sign-ins from IP addresses infected with malware that is known to actively communicate with a bot server.
sigmaCloudPaid2026-05-03Suspicious Google Cloud Kubernetes CronJob (via gcp.audit)
mediumThis rule detects when a Google Cloud Kubernetes CronJob runs in Azure Cloud. Kubernetes Job is a controller that generates one or more pods and ensures that a specified number of them successfully terminate. Kubernetes Job can be leveraged to run containers that perform finite tasks for batch jobs. Kubernetes CronJob is leveraged to schedule Jobs. An Adversary may use Kubernetes CronJob for scheduling execution of hostile code that would run as a container in the cluster.
sigmaCloud2026-04-30Suspicious Azure DNS Zone Modified or Deleted (via activitylogs)
mediumThis rule detects when DNS zone is modified or deleted.
sigmaCloud2026-04-30Suspicious LoadBalancer Security Group Change (via cloudtrail)
mediumThis rule detects changes to the security groups linked with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB). This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an adversary is attempting to enable new connections into a VPC or subnet controlled by the account.
sigmaCloud2026-04-30Suspicious Google Cloud Service Account Disabled or Deleted (via gcp.audit)
mediumThis rule detects when a service account is disabled or deleted in Google Cloud.
sigmaCloud2026-04-29Suspicious Azure Network Security Configuration Modified or Deleted (via activitylogs)
mediumThis rule detects when a network security configuration is modified or deleted.
sigmaCloud2026-04-28Suspicious Azure Kubernetes CronJob (via activitylogs)
mediumThis rule detects when a Azure Kubernetes CronJob runs in Azure Cloud. Kubernetes Job is a controller that generates one or more pods and ensures that a specified number of them successfully terminate. Kubernetes Job can be leveraged to run containers that perform finite tasks for batch jobs. Kubernetes CronJob is leveraged to schedule Jobs. An Adversary may use Kubernetes CronJob for scheduling execution of hostile code that would run as a container in the cluster.
sigmaCloud2026-04-28Possible AWS Glue Development Endpoint Behavior (via cloudtrail)
lowThis rule detects possible anomalous glue development endpoint activity.
sigmaCloud2026-04-28Suspicious Sign-in Failure Due to Conditional Access Requirements Not Met (via signinlogs)
highThis rule detects define a baseline threshold for failed sign-ins due to Conditional Access failures
sigmaCloudPaid2026-04-26