Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
313 rules
Malicious S3 Object Encryption with Customer Provided Key via CopyObject
This rule detects S3 CopyObject or PutObject API calls that supply a customer provided SSE-C encryption key which is the technique used in the CopyObjection intrusion to encrypt a victim S3 bucket for ransom. Because the attacker holds the key AWS cannot recover the data making this a destructive extortion action. Detecting SSE-C on bulk object operations surfaces ransomware activity in cloud storage.
HuntRule TeamAwscloudtrailHigh62Premium2026-06-03Suspicious Azure OpenAI Training File Upload via Files Import Operation (via azure)
This rule detects the Azure OpenAI Files_Import and Files_Upload operations in diagnostic logs, the behavior Red Canary linked to model poisoning and data staging where an actor uploads fine-tuning files to an OpenAI resource. Unexpected file uploads to an Azure OpenAI deployment can indicate poisoning of training data or staging for later exfiltration.
HuntRule TeamAzureactivitylogsMedium162Premium2026-06-01Suspicious Credential Added to Existing Application for OAuth Persistence in Entra ID (via azure auditlogs)
This rule detects Entra ID audit events that add certificates or secrets to an existing application registration, the technique SolarWinds actors used to inject their own credentials into trusted OAuth apps for durable cloud access. New credentials on established applications can let an attacker authenticate as that service principal, so these changes should be reviewed as potential persistence.
HuntRule TeamAzureauditlogsMedium147Premium2026-06-01Suspicious AWS GetFederationToken Console Access by JavaGhost (via cloudtrail)
This rule detects use of the STS GetFederationToken API, which JavaGhost abuses to mint federated console sign-in sessions from stolen long-term IAM credentials. Generating console access via federation lets the actor operate interactively in the AWS account while blending with legitimate application-token usage.
HuntRule TeamAwscloudtrailMedium209Premium2026-05-30Suspicious Azure VM Extension Write for Credential Reset via Activity Log
This rule detects Azure Compute virtual machine extension write operations, the activity abused by the VMAccess password reset technique where an attacker supplies an arbitrary caller-controlled extension name to evade name-based detections. Adversaries use this to reset local credentials and gain persistent access to a VM. Unexpected extension writes on sensitive machines should be reviewed as account manipulation.
HuntRule TeamAzureactivitylogsMedium141Premium2026-05-29Suspicious Exchange Online Mail Flow Rule or Connector Creation via Compromised Account
This rule detects creation or modification of Exchange Online transport rules, inbound connectors, or DKIM signing configuration, matching post-compromise mailbox tampering observed in the Kali365 device code phishing ecosystem. Adversaries add mail flow rules and connectors to reroute, hide, or spoof mail after taking over an account. These mailbox-infrastructure changes support business email compromise and mass phishing distribution.
HuntRule TeamM365exchangeMedium82Premium2026-05-27Suspicious AWS EC2 Windows Password Retrieval via GetPasswordData
This rule detects use of the EC2 GetPasswordData API which returns the encrypted local administrator password for a Windows instance. In the Wiz hybrid cloud response case an attacker with stolen AWS credentials called GetPasswordData to recover local admin passwords and pivot onto EC2 hosts. This is important because password retrieval across instances is a strong precursor to interactive host access and lateral movement into the compute layer.
HuntRule TeamAwscloudtrailMedium122Premium2026-05-27Suspicious Boto3 Kali Linux User Agent in AWS CloudTrail Reconnaissance (via cloudtrail)
This rule detects AWS CloudTrail activity from the specific Boto3 1.42.73 build running on Kali Linux that TeamPCP used to enumerate IAM EC2 Lambda and Secrets Manager resources after stealing credentials. The pairing of this SDK version with a Kali offensive distribution user agent is a strong indicator of hands-on-keyboard cloud reconnaissance with stolen keys.
HuntRule TeamAwscloudtrailHigh4310Premium2026-05-23Malicious Cloud Storage Destruction by Cloud Build Service Account
This rule detects a Google Cloud Build default service account invoking storage bucket or object deletion which was abused to destroy data by triggering builds that ran attacker controlled steps. Destructive storage operations originating from a cloudbuild or compute default service account rather than a human principal indicate potential data destruction through the Cloud Build pipeline.
HuntRule TeamGcpgcp.auditMedium345Premium2026-05-20Suspicious AWS IAM User Creation Using Support Impersonation Name
This rule detects the creation of an AWS IAM user named aws_support which the TeamTNT Doppelganger campaign creates and grants administrative permissions to in order to establish a persistent privileged foothold disguised as a legitimate AWS support account.
HuntRule TeamAwscloudtrailHigh83Premium2026-05-20Suspicious IAM CreateLoginProfile For Root User via AWS AssumeRoot Abuse
This rule detects an IAM CreateLoginProfile event that establishes console access for the root user which follows abuse of STS AssumeRoot to plant durable access in a member account. Adversaries create a root login profile to convert temporary root credentials into persistent account takeover.
HuntRule TeamAwscloudtrailHigh261Premium2026-05-20Malicious Directory Enumeration With Recon Tooling User Agent via Azure AD Graph
This rule detects Azure AD Graph requests carrying user agents belonging to known enumeration frameworks such as AzureHound BloodHound and AADInternals as described in Elastic research on AAD Graph activity logs. These tool signatures against the legacy Graph service indicate active directory reconnaissance for privilege escalation paths.
HuntRule TeamAzureazureactivityHigh122Premium2026-05-19Suspicious Entra Device Code Authentication with Office Client and Automated User Agent
This rule detects Entra ID sign-ins using the device code authentication flow against the Microsoft Office client application from an automated python-requests user agent, matching the Kali365 device code phishing ecosystem. Adversaries phish device codes to obtain refresh tokens for the well-known Office client and replay them programmatically to access mailboxes. Device code flow paired with a scripted user agent is a strong indicator of token theft and mailbox compromise.
HuntRule TeamAzuresigninlogsHigh122Premium2026-05-18Suspicious GCP Bucket Deletion for Namespace Hijacking (via gcp)
This rule detects GCP storage bucket deletion operations that enable universal bucket hijacking, where an attacker recreates a same-named bucket in another account to intercept data. This tactic redirects storage transfer, pubsub, and logging outputs to adversary-controlled resources.
HuntRule TeamGcpgcp.auditMedium111Premium2026-05-17Suspicious AWS IAM Privilege Escalation via AttachUserPolicy of Administrator Policy
This rule detects an IAM AttachUserPolicy call that attaches an administrator managed policy to a user, a technique used by operators of exposed IAM keys tracked by Unit 42 to escalate privileges before launching cryptojacking instances. Attackers abuse leaked long-term keys to grant themselves full control of the account which enables large scale resource abuse.
HuntRule TeamAwscloudtrailHigh113Premium2026-05-17