Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
100 rules
Azure AD Account Created and Deleted Shortly After Creation (Audit Logs)
Identifies successful Azure user creation and deletion in quick succession, consistent with short-lived account activity.
Mark Morowczynski '@markmorow', MikeDuddington, '@dudders1', Tim Shelton, Huntrule TeamAzureauditlogsHigh172Free2022-08-11Azure Entra Audit Logs: Temporary Access Pass Method Added to an Account
Flags admin registration of a temporary access pass method in Azure audit logs for user accounts.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh3910Free2022-08-10Azure Entra PIM Role Setting Changes in Audit Logs
Alerts on Azure PIM role setting update events recorded in audit logs.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh173Free2022-08-09Azure PIM Alert Setting Disabled (Audit Log Message Detection)
Flags Azure audit log events where PIM alerts are disabled (message: "Disable PIM Alert").
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh375Free2022-08-09Azure PIM Approval or Denial Recorded in Audit Logs
Flags Azure PIM elevation requests that are approved or denied in audit logs for investigation.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh164Free2022-08-09Azure Audit Logs: User Added to Privileged Eligibility Role
Alerts on Azure audit log events indicating a user was added as an eligible or permanent member to a privileged role.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh132Free2022-08-06Azure Audit Logs: Removal of Privileged Role Eligible Members
Flags Azure audit log events indicating bulk removal of eligible members from privileged roles.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh175Free2022-08-05Azure Audit Logs: Admin-initiated App Role Assignments and Privileged Delegated Permissions
Alerts on Azure audit events where an admin grants app roles to a service principal, enabling privileged application access.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsHigh90Free2022-07-28Azure audit logs: Delegated highly privileged permissions granted for all users
Alerts on Azure audit log events where delegated permissions are granted to all users.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsHigh90Free2022-07-28Azure Audit Logs: App Granted Microsoft Graph/Exchange/SharePoint/Azure AD Permissions
Alerts on Azure AD audit log entries where an app/service principal is granted delegated or app-role permissions to Microsoft services.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsHigh100Free2022-07-10Azure AD Sign-ins from Non-Compliant Devices
Alert on Entra ID sign-ins originating from devices flagged as non-compliant.
Michael Epping, '@mepples21', Huntrule TeamAzuresigninlogsHigh211Free2022-06-28Azure Audit Logs: User Added to Global or Device Administrator Roles
Alerts when Azure AD role-management events add users to Global or Device Administrator roles.
Michael Epping, '@mepples21', Huntrule TeamAzureauditlogsHigh315Free2022-06-28Azure AD/Entra Audit Logs: Device Registration Policy Changes
Alerts on Azure audit log events that set or modify the device registration policy.
Michael Epping, '@mepples21', Huntrule TeamAzureauditlogsHigh459Free2022-06-28Azure AD Sign-ins Using Legacy Authentication Client Applications
Alerts on Azure sign-ins using legacy protocol client apps (IMAP/POP3/SMTP/EWS/ActiveSync), which may indicate risky authentication usage.
Yochana Henderson, '@Yochana-H', Huntrule TeamAzuresigninlogsHigh152Free2022-06-17Azure Audit Logs: Application URI Configuration Changes (AppAddress)
Alerts on Azure audit log events indicating an application URI (AppAddress) was modified.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzureauditlogsHigh151Free2022-06-02