Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
314 rules
AWS CloudTrail Detects STS GetCallerIdentity Calls with TruffleHog User-Agent
Identifies TruffleHog-labeled STS GetCallerIdentity calls in AWS CloudTrail, indicating possible AWS key validation or enumeration.
Adan Alvarez @adanalvarez, Huntrule TeamAwscloudtrailMedium301Free2025-10-12M365 Audit: Successful Intune Company Portal login via Cmsi
Flags successful Company Portal (Intune) logins via Cmsi audit events that may indicate Conditional Access bypass attempts.
Josh Nickels, Marius Rothenbücher, Huntrule TeamM365auditHigh422Free2025-01-08AWS CloudTrail: CreateFunctionUrlConfig Indicates Lambda Function URL Added
Flags when a Lambda Function URL configuration is created via the CreateFunctionUrlConfig API call.
Ivan Saakov, Huntrule TeamAwscloudtrailMedium152Free2024-12-19AWS EC2 ImportKeyPair Activity Monitoring (CloudTrail)
Flags CloudTrail EC2 ImportKeyPair events that may indicate newly imported SSH key access setup.
Ivan Saakov, Huntrule TeamAwscloudtrailMedium91Free2024-12-19AWS IAM SAML Provider Deletion via CloudTrail
Alerts on successful CloudTrail events where an AWS SAML provider is deleted, signaling potential disruption of admin/security access.
Ivan Saakov, Huntrule TeamAwscloudtrailMedium1710Free2024-12-19AWS CloudTrail: RDS Cluster Modification or Deletion (ModifyDBCluster/DeleteDBCluster)
Detects CloudTrail ModifyDBCluster or DeleteDBCluster actions on AWS RDS clusters.
Ivan Saakov, Huntrule TeamAwscloudtrailHigh202Free2024-12-06Azure AD: StrongAuthenticationRequirement Set to Disabled/State=0
Alerts on Azure Entra user updates that change StrongAuthenticationRequirement to a disabled State ("State":0).
Harjot Singh (@cyb3rjy0t), Huntrule TeamAzureauditlogsMedium239Free2024-08-21Azure AD Audit: Update User Risk and MFA Registration Policy
Flags Azure AD audit events showing updates to user risk and MFA registration policy.
Harjot Singh (@cyb3rjy0t), Huntrule TeamAzureauditlogsHigh152Free2024-08-13AWS CloudTrail SSM SendCommand Successful Execution for Instance
Identifies successful AWS SSM SendCommand executions recorded in CloudTrail.
jamesc-grafana, Huntrule TeamAwscloudtrailHigh237Free2024-07-11AWS RDS Security Group Changes via CloudTrail
Flags CloudTrail RDS events that create, delete, or change DB security group ingress rules.
jamesc-grafana, Huntrule TeamAwscloudtrailMedium173Free2024-07-11AWS CloudTrail ELB/ALB Security Group Changes via ApplySecurityGroupsToLoadBalancer or SetSecurityGroups
Alerts on CloudTrail events that change ELB/ALB security groups by applying or setting load balancer security groups.
jamesc-grafana, Huntrule TeamAwscloudtrailMedium121Free2024-07-11AWS CloudTrail Security Group Ingress/Egress Rule Changes
Alerts on AWS security group ingress/egress rule authorizations or revocations seen in CloudTrail EC2 events.
jamesc-grafana, Huntrule TeamAwscloudtrailMedium389Free2024-07-11AWS CloudTrail: CreateRoute Adds New Network Route to a Route Table
Flags CloudTrail EC2 CreateRoute events indicating a new route was added to an AWS route table.
jamesc-grafana, Huntrule TeamAwscloudtrailMedium333Free2024-07-11AWS CloudTrail: CreateNetworkAclEntry Adds Network ACL Rules
Identifies when EC2 network ACL entries are created in AWS via CloudTrail.
jamesc-grafana, Huntrule TeamAwscloudtrailLow152Free2024-07-11AWS CloudTrail: Instance Profile Role Assumed Actions Outside SSM RegisterManagedInstance
Identifies CloudTrail activity from assumed-role instance identities when it is not part of SSM RegisterManagedInstance.
jamesc-grafana, Huntrule TeamAwscloudtrailHigh123Free2024-07-11