Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
314 rules
Azure AD Audit: Trusted Root CA Added for Passwordless Certificate Authentication
Alerts on Azure AD changes that add a new trusted root CA for passwordless certificate-based authentication.
Harjot Shah Singh, '@cyb3rjy0t', Huntrule TeamAzureauditlogsMedium161Free2024-03-26Azure AD Audit Logs: Certificate-based authentication enabled via AuthenticationMethodsPolicy update
Flags Azure AD audit log events where the Authentication Methods policy is updated to enable certificate-based authentication.
Harjot Shah Singh, '@cyb3rjy0t', Huntrule TeamAzureauditlogsMedium256Free2024-03-26AWS CloudTrail GetSigninToken Requests with Suspected Console User-Agent
Flags CloudTrail GetSigninToken sign-in token requests with non-matching console user-agent patterns.
Chester Le Bron (@123Le_Bron), Huntrule TeamAwscloudtrailMedium3710Free2024-02-26GCP Google Workspace: Application ContextAwareAccess Setting Changed
Alerts on Google Workspace application setting changes affecting ContextAwareAccess access levels.
Bryan Lim, Huntrule TeamGcpgoogle_workspace.adminMedium152Free2024-01-12GCP Audit: Break-glass Keyword on Kubernetes Pod Create Overrides Binary Authorization
Flags GKE pod creation events where break-glass bypasses Binary Authorization image policy.
Bryan Lim, Huntrule TeamGcpgcp.auditMedium252Free2024-01-12GCP Audit Logs: Access Context Manager Access Policy Deletion
Flags GCP Access Context Manager audit events where granted access policy delete permissions occur.
Bryan Lim, Huntrule TeamGcpgcp.auditMedium378Free2024-01-12AWS S3 Bucket Versioning Disabled via PutBucketVersioning (CloudTrail)
Alerts on CloudTrail PutBucketVersioning requests that suspend S3 bucket versioning.
Sean Johnstone | Unit 42, Huntrule TeamAwscloudtrailMedium141Free2023-10-28AWS CloudTrail: AWS Identity Center Identity Provider Configuration Changes
Detects CloudTrail identity center events that associate or change the external identity provider configuration.
Michael McIntyre @wtfender, Huntrule TeamAwscloudtrailHigh122Free2023-09-27Microsoft 365 Audit: New Federated Domain Added
Alerts on Microsoft 365 audit events indicating a new federated domain was added.
Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule), Huntrule TeamM365auditMedium113Free2023-09-18Microsoft 365 Audit: Disabling Strong Authentication (MFA)
Flags Microsoft 365 audit events indicating MFA/strong authentication was disabled.
Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule), Huntrule TeamM365auditHigh386Free2023-09-18Azure Entra PIM Alerts: Too Many Global Administrators Assigned to Tenant
Alerts when Azure PIM reports an overabundance of Global Administrator role assignments in a tenant.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh103Free2023-09-14Azure AD PIM Redundant Assignment Alert When Privileged Role Not Used
Alerts on Azure PIM redundant privileged role assignments where the assigned role appears unused.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh303Free2023-09-14Azure PIM Role Activation Without MFA Alert (noMfaOnRoleActivationAlertIncident)
Alerts when Azure PIM signals role activation occurred without MFA.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh408Free2023-09-14Azure AD PIM Role Activations Too Frequent for Same User
Alerts when Azure PIM logs sequential activation renewals for the same role by the same user.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh151Free2023-09-14Azure PIM Alert: Privileged Role Assigned Outside PIM
Detects Azure PIM risk events indicating privileged role assignments were made outside PIM.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh194Free2023-09-14