Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
313 rules
Suspicious Azure NSG Rule Opening SSH to the Internet
This rule detects creation or modification of a Network Security Group rule that exposes SSH port 22 to any source address, the network-backdoor action performed in the Azure Fabric intrusion to enable inbound remote access. Opening management ports to 0.0.0.0/0 is a high-risk change and a common cloud persistence step.
HuntRule TeamAzureactivitylogsMedium131Premium2026-05-16Malicious EKS Access Policy Association Granting Cluster Admin
This rule detects CloudTrail AssociateAccessPolicy events that attach the AmazonEKSClusterAdminPolicy or AmazonEKSAdminPolicy to an EKS access entry. Wiz Research showed this new access management API can be abused to grant an attacker principal cluster administrator rights, so unexpected admin grants should be treated as potential privilege escalation.
HuntRule TeamAwscloudtrailHigh164Premium2026-05-15Suspicious Retrieval of AWS Secrets Manager Values (via cloudtrail)
This rule detects GetSecretValue and BatchGetSecretValue calls against Secrets Manager, a credentials-from-cloud-stores technique used to harvest database passwords, API keys and tokens after gaining access to an AWS account. Cloud secret-store access is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting these reads surfaces bulk secret harvesting.
HuntRule TeamAwscloudtrailMedium121Premium2026-05-15Malicious Office 365 Email Forwarding Rule to External Domain (via office365)
This rule detects creates a forwarding rules to a non company email in order to collect information.
HuntRule TeamAzureoffice365High244Premium2026-05-14Suspicious AWS Secrets Manager Bulk Secret Retrieval via BatchGetSecretValue
This rule detects the AWS Secrets Manager BatchGetSecretValue API which returns multiple secret values in a single call. Wiz observed attackers accessing stored secrets after compromising cloud credentials during hybrid cloud intrusions. This is important because bulk secret retrieval is a common credential-access step that harvests database passwords and API keys enabling deeper movement across cloud and on-prem systems.
HuntRule TeamAwscloudtrailMedium209Premium2026-05-12Suspicious IAM Policy Attachment Granting AdministratorAccess
This rule detects an AttachUserPolicy call that attaches the AWS managed AdministratorAccess policy to an IAM user. After compromising an EC2 instance and stealing IMDS credentials the attacker created a rogue IAM user and granted it full administrator rights for persistence and privilege escalation. Sudden attachment of AdministratorAccess to a user is high-signal for cloud account takeover.
HuntRule TeamAwscloudtrailHigh444Premium2026-05-11Malicious Active Directory Federated Trust Added (via office365)
This rule detects scenarios where an federated trust is added by an attacker.
HuntRule TeamAzureoffice365High93Premium2026-05-11Suspicious AWS SSO Token Creation and Role Credential Retrieval (via cloudtrail)
This rule detects the AWS SSO CreateToken and GetRoleCredentials calls against sso.amazonaws.com, the API sequence Red Canary described adversaries using to replay cached SSO tokens stolen from the .aws sso cache. When these calls originate from multiple IP addresses in a short window they indicate an actor exchanging a stolen access token for STS role credentials.
HuntRule TeamAwscloudtrailMedium122Premium2026-05-10Suspicious Mail Send via Microsoft Graph by Application Identity via M365 Audit
This rule detects mail sent through the Microsoft Graph sendMail action by an application or agent identity, the delivery step an attacker uses after hijacking an Entra assistive agent to send internal spearphishing. Because agents that gain send-mail access can distribute malicious links from a trusted internal identity, Graph-driven mail sends attributed to service principals should be reviewed against recent consent grants.
HuntRule TeamM365auditLow82Premium2026-05-09Suspicious Credential Added to Application or Service Principal in Entra ID (via azure)
This rule detects new password or certificate credentials being added to an Entra ID application or service principal, the persistence technique Silk Typhoon uses to abuse OAuth applications and service principals holding administrative permissions. Adversaries append their own secrets to trusted applications to authenticate as the app and access mail, OneDrive, and SharePoint through MSGraph, so unexpected credential additions signal a supply-chain identity compromise.
HuntRule TeamAzureauditlogsMedium3410Premium2026-05-09Suspicious OAuth Consent Grant to Mail Access Permissions via Azure AD
This rule detects OAuth application consent grants that request mailbox read/send and offline access scopes in Azure AD audit logs. This aligns with the Huntress traitorware campaign where adversaries consent legitimate mail clients to gain persistent mailbox access, letting them read and send mail via issued tokens without touching the password.
HuntRule TeamAzureauditlogsMedium113Premium2026-05-09Suspicious AWS STS Role Chaining From Temporary Session Credentials (via cloudtrail)
This rule detects an AWS STS AssumeRole call whose caller is already an assumed-role session, the role chaining pattern attackers use to mint successive ASIA temporary credentials and persist beyond a single session expiry. Chained AssumeRole invocations extend stolen access and evade credential lifetime controls. Detecting assumed-role principals assuming further roles surfaces this persistence technique.
HuntRule TeamAwscloudtrailMedium105Premium2026-05-08Malicious Azure Storage and Compute Destruction via Key Listing and Snapshot Deletion
This rule detects Azure operations that list storage account keys and delete storage or compute snapshots. Microsoft observed Storm-0501 combining these to exfiltrate then destroy cloud data and backups for extortion. Bulk key retrieval followed by resource and snapshot deletion is destructive impact activity, so these operations should be treated as a possible cloud ransomware event.
HuntRule TeamAzureactivitylogsMedium435Premium2026-05-06Suspicious Member Added to Privileged Directory Role in Entra ID
This rule detects Entra ID audit events adding a member to a directory role such as Global Administrator. Wiz Research observed Midnight Blizzard elevating principals into privileged roles to broaden access, so unexpected role membership changes can indicate an account manipulation and privilege escalation attempt.
HuntRule TeamAzureauditlogsMedium1810Premium2026-05-04Suspicious High-Privilege Microsoft Graph Application Role Grant via Azure Audit (via azure)
This rule detects the assignment of high-privilege Microsoft Graph application roles such as AppRoleAssignment.ReadWrite.All, Directory.ReadWrite.All, or RoleManagement.ReadWrite.Directory to a service principal, an escalation path into Azure highlighted by Red Canary. Granting these permissions lets an app rewrite directory roles and grant itself further access, making it a powerful and stealthy persistence mechanism that should be tightly controlled.
HuntRule TeamAzureauditlogsHigh125Premium2026-05-03