Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
225 rules
Suspicious AWS ConsoleLogin Failed Authentication (via cloudtrail)
mediumThis rule detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.
sigmaCloud2026-04-06Suspicious Login to Disabled Account (via signinlogs)
mediumThis rule detects failed attempts to sign in to disabled accounts.
sigmaCloud2026-04-05Suspicious Account Disabled or Blocked for Sign in Attempts (via signinlogs)
mediumThis rule detects when an account is disabled or blocked for sign in but tried to log in
sigmaCloud2026-04-05Possible MFA Bypass Via Legacy Client Authentication (via signinlogs)
highThis rule detects successful authentication from potential clients using legacy authentication via user agent strings. This could be a sign of MFA bypass using a password spray attack.
sigmaCloudPaid2026-04-04Suspicious Impossible Travel (via riskdetection)
highThis rule detects user activities originating from geographically distant locations within a time period shorter than the time it takes to travel from the first location to the second.
sigmaCloudPaid2026-04-04Suspicious New Federated Domain Added - Exchange (via exchange)
mediumThis rule detects the addition of a new Federated Domain.
sigmaCloud2026-04-03Suspicious Disabled MFA to Bypass Authentication Mechanisms (via auditlogs)
mediumThis rule detects detection for when multi factor authentication has been disabled, which might indicate a hostile behavior to bypass authentication mechanisms.
sigmaCloud2026-04-03Possible AWS STS GetSessionToken Misuse (via cloudtrail)
lowThis rule detects the anomalous use of GetSessionToken. Tokens could be created and used by adversaries to move laterally and escalate privileges.
sigmaCloud2026-04-03Microsoft 365 - Potential Ransomware Activity (via threat_management)
mediumThis rule detects when a Microsoft Cloud App Security reported when a user uploads files to the cloud that might be infected with ransomware.
sigmaCloud2026-04-02Suspicious Azure Active Directory Hybrid Health AD FS Service Delete (via activitylogs)
mediumThis rule detects this detection uses azureactivity logs (Administrative category) to identify the deletion of an Azure AD Hybrid health AD FS service instance in a tenant. A threat actor can create a new AD Health ADFS service and create a fake server to spoof AD FS signing logs. The health AD FS service can then be deleted after it is not longer needed via HTTP requests to Azure.
sigmaCloud2026-04-02Possible Creation of AWS ElastiCache Security Group (via cloudtrail)
lowThis rule detects when an ElastiCache security group has been created.
sigmaCloud2026-04-02Suspicious Google Workspace Role Modified or Deleted (via google_workspace.admin)
mediumThis rule detects when an a role is modified or deleted in Google Workspace.
sigmaCloud2026-03-31Suspicious Bulk Removal Changes To Privileged Account Permissions (via auditlogs)
highThis rule detects when a user is removed from a privileged role. Bulk changes should be investigated.
sigmaCloudPaid2026-03-30Possible Enumeration Via AzureHound (via signinlogs)
highThis rule detects AzureHound (A BloodHound data collector for Microsoft Azure) behavior via the default User-Agent that is used during its operation after successful authentication.
sigmaCloudPaid2026-03-29Malicious IP Address Sign-In Failure Rate (via riskdetection)
highThis rule detects suggests sign-in from a hostile IP address based on high failure rates.
sigmaCloudPaid2026-03-29Suspicious Account Lockout (via signinlogs)
mediumThis rule detects user account which has been locked because the user tried to sign in too many times with an incorrect user ID or password.
sigmaCloud2026-03-27Possible Malicious Use of CloudTrail System Manager (via cloudtrail)
highThis rule detects when System Manager successfully runs commands against an instance.
sigmaCloudPaid2026-03-26Suspicious New Root Certificate Authority Added (via auditlogs)
mediumThis rule detects newly added root certificate authority to an AzureAD tenant to support certificate based authentication.
sigmaCloud2026-03-25Suspicious CA Policy Updated by Non Approved Actor (via auditlogs)
mediumThis rule detects conditional access changes. Is Initiated by (actor) approved to make changes? Review Modified Properties and compare "old" vs "new" value.
sigmaCloud2026-03-24Suspicious SignIns From A Non Registered Device (via signinlogs)
highThis rule detects risky authentication from a non AD registered device without MFA being required.
sigmaCloudPaid2026-03-22