Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
313 rules
Suspicious SNS Publish to Phone Number for Smishing
This rule detects an SNS Publish call that targets a phone number directly, a smishing abuse pattern in the AWS SNS research by Elastic. Adversaries who compromise credentials use SNS to send SMS phishing messages at scale from the victim account. Direct phone number publishes outside of known messaging workflows can indicate account abuse and outbound phishing.
HuntRule TeamAwscloudtrailMedium123Premium2026-05-02Suspicious AWS SES Production Access Request via PutAccountDetails (Cloud Email Abuse)
This rule detects SES PutAccountDetails CloudTrail events that request production sending access to escape the SES sandbox, a burst of which was central to the cloud email service takeover campaign. It matters because attackers using leaked keys raise sending limits before launching large phishing campaigns.
HuntRule TeamAwscloudtrailMedium133Premium2026-04-30GCP Google Workspace Suspicious Login Events (Google Classified)
Alerts on Google Workspace login audit events classified by Google as suspicious, including less secure app and programmatic login types.
Tom Kluter, Huntrule TeamGcpgoogle_workspace.loginMedium93Free2026-04-28Google Workspace login activity: Out-of-domain email forwarding
Flags Google Workspace out-of-domain email forwarding events from audit logs on login.googleapis.com.
Tom kluter, Huntrule TeamGcpgoogle_workspace.loginMedium112Free2026-04-28Google Workspace login event flagged with gov_attack_warning
Alerts on Google Workspace login audit events marked with gov_attack_warning by Google’s risk signals.
Tom Kluter, Huntrule TeamGcpgoogle_workspace.loginMedium143Free2026-04-28Microsoft 365 inbound suspicious email delivered to Inbox or Junk
Alerts when Defender-labeled suspicious inbound emails are delivered to user Inbox/Junk in Microsoft 365.
Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule TeamM365auditMedium427Free2026-01-27AWS CloudTrail GuardDuty Detector Deleted or Disabled via UpdateDetector
Identifies successful GuardDuty detector deletion or disablement from CloudTrail, reducing GuardDuty monitoring coverage.
suktech24, Huntrule TeamAwscloudtrailHigh2010Free2025-11-27AWS CloudTrail: TruffleHog User-Agent Execution Detected
Flags AWS CloudTrail events with user agent "TruffleHog" to surface potential secret-scanning or credential-harvesting activity.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamAwscloudtrailMedium112Free2025-10-21AWS CloudTrail Detects EC2 DeleteFlowLogs API Calls
Flags successful EC2 DeleteFlowLogs API calls in CloudTrail indicating VPC Flow Logs were removed.
Ivan Saakov, Huntrule TeamAwscloudtrailHigh162Free2025-10-19AWS CloudTrail Account EnableRegion Command Usage
Alerts on AWS account region enablement via CloudTrail when the EnableRegion API call occurs.
Ivan Saakov, Sergey Zelenskiy, Huntrule TeamAwscloudtrailMedium93Free2025-10-19AWS CloudTrail ConsoleLogin Failed authentication
Flags CloudTrail ConsoleLogin events with "Failed authentication" to help identify possible credential-based attacks.
Ivan Saakov, Nasreddine Bencherchali, Huntrule TeamAwscloudtrailMedium151Free2025-10-19AWS CloudTrail S3 DeleteBucket Events with Successful Deletion
Flags successful CloudTrail DeleteBucket events indicating an S3 bucket was removed.
Ivan Saakov, Nasreddine Bencherchali, Huntrule TeamAwscloudtrailMedium164Free2025-10-19AWS KMS Imported Key Material Import or Deletion via CloudTrail
Detects AWS KMS imported key material events in CloudTrail, including import and deletion of imported key material.
toopricey, Huntrule TeamAwscloudtrailHigh133Free2025-10-18AWS CloudTrail Successful ConsoleLogin Events Without MFA
Flags successful AWS console logins with MFAUsed explicitly set to NO in CloudTrail.
Thuya@Hacktilizer, Ivan Saakov, Huntrule TeamAwscloudtrailMedium122Free2025-10-18AWS CloudTrail Detects STS GetCallerIdentity Calls with TruffleHog User-Agent
Identifies TruffleHog-labeled STS GetCallerIdentity calls in AWS CloudTrail, indicating possible AWS key validation or enumeration.
Adan Alvarez @adanalvarez, Huntrule TeamAwscloudtrailMedium301Free2025-10-12