Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
225 rules
Suspicious AWS SecurityHub Findings Evasion (via cloudtrail)
highThis rule detects the modification of the findings on SecurityHub.
sigmaCloudPaid2026-04-26Suspicious Azure Subscription Permission Elevation Through AuditLogs (via auditlogs)
highThis rule detects when a user has been elevated to manage all Azure Subscriptions. This change should be investigated immediately if it isn't planned. This setting could enable an adversary access to Azure subscriptions in your environment.
sigmaCloudPaid2026-04-25Suspicious Azure Keyvault Key Modified or Deleted (via activitylogs)
mediumThis rule detects when a Keyvault Key is modified or deleted in Azure.
sigmaCloud2026-04-25Suspicious Unfamiliar Sign-In Properties (via riskdetection)
highThis rule detects sign-in with properties that are unfamiliar to the user. The detection considers past sign-in history to look for anomalous sign-ins.
sigmaCloudPaid2026-04-23Suspicious Change of Azure Domain Federation Settings (via auditlogs)
mediumThis rule detects when an user or application modified the federation settings on the domain.
sigmaCloud2026-04-22Suspicious User Added To Group With CA Policy Change Access (via auditlogs)
mediumThis rule detects group membership additions of groups that have CA policy modification access
sigmaCloud2026-04-21Suspicious App Granted Privileged Delegated Or App Permissions (via auditlogs)
highThis rule detects when administrator grants either application permissions (app roles) or highly privileged delegated permissions
sigmaCloudPaid2026-04-21Suspicious Azure Login Bypassing Conditional Access Policies (via audit)
highThis rule detects a successful login to the Microsoft Intune Company Portal which could enable bypassing Conditional Access Policies and InTune device trust using a tool like TokenSmith.
sigmaCloudPaid2026-04-20Possible Azure AD Only Single Factor Authentication Required (via signinlogs)
lowThis rule detects when users are authenticating without MFA being required.
sigmaCloud2026-04-20Suspicious SAML Token Issuer Anomaly (via riskdetection)
highThis rule detects suggests the SAML token issuer for the linked SAML token is potentially compromised. The claims included in the token are unusual or match known adversary patterns
sigmaCloudPaid2026-04-19Suspicious Removal of Azure Application (via auditlogs)
mediumThis rule detects when a application is deleted in Azure.
sigmaCloud2026-04-19Suspicious AWS ECS Task Definition That Queries The Credential Endpoint (via cloudtrail)
mediumThis rule detects when an Elastic Container Service (ECS) Task Definition includes a command to query the credential endpoint. This can indicate a potential adversary adding a backdoor to establish persistence or escalate privileges.
sigmaCloud2026-04-16Suspicious Certificate-Based Authentication Enabled (via auditlogs)
mediumThis rule detects when certificate based authentication has been enabled in an Azure Active Directory tenant.
sigmaCloud2026-04-15Suspicious Azure Kubernetes Secret or Config Object Access (via activitylogs)
mediumThis rule detects when a Kubernetes account access a sensitive objects such as configmaps or secrets.
sigmaCloud2026-04-13Suspicious Azure Key Vault Modified or Deleted (via activitylogs)
mediumThis rule detects when a key vault is modified or deleted.
sigmaCloud2026-04-13Possible AWS Route 53 Domain Transferred to Another Account (via cloudtrail)
lowThis rule detects when a request has been made to transfer a Route 53 domain to another AWS account.
sigmaCloud2026-04-13Suspicious Temporary Access Pass Added To An Account (via auditlogs)
highThis rule detects when a temporary access pass (TAP) is added to an account. TAPs added to priv accounts should be investigated
sigmaCloudPaid2026-04-11Suspicious OAuth App File Download Activities (via threat_management)
mediumThis rule detects when a Microsoft Cloud App Security reported when an app downloads multiple files from Microsoft SharePoint or Microsoft OneDrive in a manner that is unusual for the user.
sigmaCloud2026-04-08Suspicious Roles Activated Too Frequently (via pim)
highThis rule detects when the same privilege role has multiple activations by the same user.
sigmaCloudPaid2026-04-06Suspicious User Risk and MFA Registration Policy Updated (via auditlogs)
highThis rule detects changes and updates to the user risk and MFA registration policy. Attackers can modified the policies to Bypass MFA, weaken security thresholds, facilitate further attacks, maintain persistence.
sigmaCloudPaid2026-04-06