Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
225 rules
Suspicious Change of Google Cloud Service Account (via gcp.audit)
mediumThis rule detects when a service account is modified in Google Cloud.
sigmaCloud2026-03-21Suspicious Invalid PIM License (via pim)
highThis rule detects when an organization doesn't have the proper license for PIM and is out of compliance.
sigmaCloudPaid2026-03-18Suspicious Azure Subscription Permission Elevation Through ActivityLogs (via activitylogs)
highThis rule detects when a user has been elevated to manage all Azure Subscriptions. This change should be investigated immediately if it isn't planned. This setting could enable an adversary access to Azure subscriptions in your environment.
sigmaCloudPaid2026-03-18Suspicious Number Of Resource Creation Or Deployment Activities (via activitylogs)
mediumThis rule detects number of VM creations or deployment activities occur in Azure via the azureactivity log.
sigmaCloud2026-03-17Suspicious Change to Authentication Method (via auditlogs)
mediumThis rule detects to authentication method could be an indicator of an adversary adding an auth method to the account so they can have continued access.
sigmaCloud2026-03-16Suspicious Microsoft 365 - User Restricted from Sending Email (via threat_management)
mediumThis rule detects when a Security Compliance Center reported a user who exceeded sending limits of the service policies and because of this has been restricted from sending email.
sigmaCloud2026-03-15Suspicious Google Workspace Granted Domain API Access (via google_workspace.admin)
mediumThis rule detects when an API access service account is granted domain authority.
sigmaCloud2026-03-14Azure Unusual Authentication Interruption (via signinlogs)
mediumThis rule detects when there is a interruption in the authentication process.
sigmaCloud2026-03-14Suspicious User State Changed From Guest To Member (via auditlogs)
mediumThis rule detects the change of user type from "Guest" to "Member" for potential elevation of privilege.
sigmaCloud2026-03-13Possible AWS S3 Data Management Manipulation (via cloudtrail)
lowThis rule detects when a user tampers with S3 data management in Amazon Web Services.
sigmaCloud2026-03-13Suspicious End User Consent Blocked (via auditlogs)
mediumThis rule detects when end user consent is blocked due to risk-based consent.
sigmaCloud2026-03-12Suspicious Google Cloud Kubernetes Admission Controller (via gcp.audit)
mediumThis rule detects when an admission controller is executed in GCP Kubernetes. A Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server. The behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster. An adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster. For example, adversaries can intercept and modify the pod creation operations in the cluster and add their hostile container to every created pod. An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials. An adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.
sigmaCloud2026-03-11Suspicious Google Cloud SQL Database Modified or Deleted (via gcp.audit)
mediumThis rule detects when a Cloud SQL DB has been modified or deleted.
sigmaCloud2026-03-10Possible AWS EKS Cluster Created or Deleted (via cloudtrail)
lowThis rule detects when an EKS cluster is created or deleted.
sigmaCloud2026-03-10Suspicious Google Cloud Kubernetes RoleBinding (via gcp.audit)
mediumThis rule detects the creation or patching of potential hostile RoleBinding. This includes RoleBindings and ClusterRoleBinding.
sigmaCloud2026-03-06Suspicious Removal of GCP Access Policy (via gcp.audit)
mediumThis rule detects when an access policy that is applied to a GCP cloud resource is deleted. An adversary would be able to remove access policies to gain access to a GCP cloud resource.
sigmaCloud2026-03-05Suspicious Removal of Azure Kubernetes Events (via activitylogs)
mediumThis rule detects when Events are deleted in Azure Kubernetes. An adversary may delete events in Azure Kubernetes seeking to evade detection.
sigmaCloud2026-03-05Suspicious Azure Device or Configuration Modified or Deleted (via activitylogs)
mediumThis rule detects when a device or device configuration in azure is modified or deleted.
sigmaCloud2026-03-05Suspicious Azure Application Security Group Modified or Deleted (via activitylogs)
mediumThis rule detects when a application security group is modified or deleted.
sigmaCloud2026-03-05Possible Bucket Enumeration on AWS (via cloudtrail)
lowThis rule detects potential enumeration of AWS buckets via ListBuckets.
sigmaCloud2026-03-05