Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
100 rules
Azure Audit Logs: Application AppID URI Updates via App or Service Principal Changes
Alerts on Azure audit log entries indicating updates to an application or service principal AppID URI configuration.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzureauditlogsHigh101Free2022-06-02Azure Sign-in Logs: Conditional Access Blocked Sign-in Failures (ResultType 53003)
Alerts on Azure sign-ins blocked by Conditional Access when requirements are not met.
Yochana Henderson, '@Yochana-H', Huntrule TeamAzuresigninlogsHigh100Free2022-06-01Azure AuditLogs: Privileged role assignment to user access admin
Flags Azure AuditLogs events where a user is assigned to User Access Administrator, enabling full subscription management.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsHigh163Free2021-11-26Azure Activity Logs: Authorization ElevateAccess Grants Subscription-Level Management
Alerts on Azure Activity Log authorization elevation actions that can grant access to manage all subscriptions.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsHigh122Free2021-11-26AWS CloudTrail UpdateLoginProfile: Password/Authentication Profile Modified for Another User
Flags AWS IAM UpdateLoginProfile events where an account updates another user’s login profile password.
toffeebr33k, Huntrule TeamAwscloudtrailHigh3410Free2021-08-09AWS CloudTrail: Security Hub findings evasion via finding updates or deletions
Identifies Security Hub finding and insight modifications (update or delete) that may impair detection results.
Sittikorn S, Huntrule TeamAwscloudtrailHigh202Free2021-06-28AWS CloudTrail: RestoreDBInstanceFromDBSnapshot Creates Public RDS Instance
Detects RDS restores from snapshots that result in a publicly accessible database instance in AWS CloudTrail.
faloker, Huntrule TeamAwscloudtrailHigh461Free2020-02-12AWS EC2 ModifyInstanceAttribute userData Startup Script Change
Detects CloudTrail EC2 userData startup script changes made via ModifyInstanceAttribute.
faloker, Huntrule TeamAwscloudtrailHigh81Free2020-02-12AWS GuardDuty CreateIPSet Trusted IP Set Changes (CloudTrail)
Alerts on CloudTrail GuardDuty CreateIPSet events that add or update trusted IP address sets.
faloker, Huntrule TeamAwscloudtrailHigh102Free2020-02-11AWS CloudTrail: AWS Config Delivery Channel/Recorder Disabled
Identifies CloudTrail actions that delete AWS Config delivery channels or stop the configuration recorder.
vitaliy0x1, Huntrule TeamAwscloudtrailHigh112Free2020-01-21