Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
225 rules
Suspicious RDS Database Security Group Change (via cloudtrail)
mediumThis rule detects changes to the security group entries for RDS databases. This can indicate that a misconfiguration has occurred which potentially exposes the database to the public internet, a wider audience within the VPC or that removal of valid rules has occurred which could impact the availability of the database to legitimate services and users.
sigmaCloud2026-03-05Malicious AWS EC2 VM Export Failure (via cloudtrail)
lowThis rule detects an attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.
sigmaCloud2026-03-04Suspicious AWS EnableRegion Command Monitoring (via cloudtrail)
mediumThis rule detects the use of the EnableRegion command in AWS CloudTrail logs. While AWS has 30+ regions, some of them are enabled by default, others must be explicitly enabled in each account separately. There may be situations where security monitoring does not cover some new AWS regions. Monitoring the EnableRegion command is important for identifying potential persistence mechanisms employed by adversaries, as enabling additional regions can facilitate continued access and operations within an AWS environment.
sigmaCloud2026-03-04Suspicious Password Spray Behavior (via riskdetection)
highThis rule detects suggests that a password spray attack has been successfully performed.
sigmaCloudPaid2026-03-03Possible AWS STS GetCallerIdentity Enumeration Through TruffleHog (via cloudtrail)
mediumThis rule detects the use of TruffleHog for AWS credential validation by identifying GetCallerIdentity API calls where the userAgent suggests TruffleHog. Threat actors abuse TruffleHog to enumerate and validate exposed AWS keys. Successful exploitation enables threat actors to confirm the validity of compromised AWS credentials, facilitating further unauthorized access and actions within the AWS environment.
sigmaCloud2026-03-03Suspicious Application Via Device Code Authentication Flow (via signinlogs)
mediumThis rule detects device code flow is an OAuth 2.0 protocol flow specifically for input constrained devices and is not used in all environments. If this type of flow is seen in the environment and not being used in an input constrained device scenario, further investigation is warranted. This can be a misconfigured application or potentially something malicious.
sigmaCloud2026-03-02Suspicious PST Export Alert Via New-ComplianceSearchAction (via threat_management)
mediumThis rule detects when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell use and from the cloud.
sigmaCloud2026-03-01Suspicious Behavior Performed by Terminated User (via threat_management)
mediumThis rule detects when a Microsoft Cloud App Security reported for users whose account were terminated in Azure AD, but still perform activities in other platforms such as AWS or Salesforce. This is especially relevant for users who use another account to manage resources, since these accounts are frequently not terminated when a user leaves the company.
sigmaCloud2026-02-26Suspicious Azure Kubernetes Admission Controller (via activitylogs)
mediumThis rule detects when an admission controller is executed in Azure Kubernetes. A Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server. The behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster. An adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster. For example, adversaries can intercept and modify the pod creation operations in the cluster and add their hostile container to every created pod. An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials. An adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.
sigmaCloud2026-02-26Suspicious AWS Snapshot Backup Exfiltration (via cloudtrail)
mediumThis rule detects the modification of an EC2 snapshot's permissions to enable access from another account
sigmaCloud2026-02-26Suspicious Logon from a Risky IP Address (via threat_management)
mediumThis rule detects when a Microsoft Cloud App Security reported when a user signs into your sanctioned apps from a risky IP address.
sigmaCloud2026-02-25Suspicious Inbox Forwarding (via threat_management)
lowThis rule detects when a Microsoft Cloud App Security reported anomalous email forwarding rules, for example, if a user created an inbox rule that forwards a copy of all emails to an external address.
sigmaCloud2026-02-22Suspicious Windows LAPS Credential Dump From Entra ID (via auditlogs)
highThis rule detects when an account dumps the LAPS password from Entra ID.
sigmaCloudPaid2026-02-20Suspicious AWS GuardDuty Important Change (via cloudtrail)
highThis rule detects updates of the GuardDuty list of trusted IPs, perhaps to disable security alerts against hostile IPs.
sigmaCloudPaid2026-02-20Suspicious AWS Root Credentials (via cloudtrail)
mediumThis rule detects AWS root account use
sigmaCloud2026-02-19Suspicious Behavior from Anonymous IP Addresses (via threat_management)
mediumThis rule detects when a Microsoft Cloud App Security reported when users were active from an IP address that has been identified as an anonymous proxy IP address.
sigmaCloud2026-02-18Suspicious Google Cloud Firewall Modified or Deleted (via gcp.audit)
mediumThis rule detects when a firewall rule is modified or deleted in Google Cloud Platform (GCP).
sigmaCloud2026-02-18Possible Disabling of AWS Route 53 Domain Transfer Lock (via cloudtrail)
lowThis rule detects when a transfer lock was removed from a Route 53 domain. It is recommended to refrain from performing this action unless intending to transfer the domain to a different registrar.
sigmaCloud2026-02-16Suspicious Behavior from Infrequent Country (via threat_management)
mediumThis rule detects when a Microsoft Cloud App Security reported when a behavior occurs from a location that wasn't recently or never visited by any user in the organization.
sigmaCloud2026-02-15Possible Sign-ins by Unknown Devices (via signinlogs)
lowThis rule detects Sign-ins by unknown devices from non-Trusted locations.
sigmaCloud2026-02-12