Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
67 rules
AWS CloudTrail GuardDuty Detector Deleted or Disabled via UpdateDetector
Identifies successful GuardDuty detector deletion or disablement from CloudTrail, reducing GuardDuty monitoring coverage.
sigmaCloudhigh2025-11-27AWS CloudTrail Detects EC2 DeleteFlowLogs API Calls
Flags successful EC2 DeleteFlowLogs API calls in CloudTrail indicating VPC Flow Logs were removed.
sigmaCloudhigh2025-10-19AWS KMS Imported Key Material Import or Deletion via CloudTrail
Detects AWS KMS imported key material events in CloudTrail, including import and deletion of imported key material.
sigmaCloudhigh2025-10-18M365 Audit: Successful Intune Company Portal login via Cmsi
Flags successful Company Portal (Intune) logins via Cmsi audit events that may indicate Conditional Access bypass attempts.
sigmaCloudhigh2025-01-08AWS CloudTrail: RDS Cluster Modification or Deletion (ModifyDBCluster/DeleteDBCluster)
Detects CloudTrail ModifyDBCluster or DeleteDBCluster actions on AWS RDS clusters.
sigmaCloudhigh2024-12-06Azure AD Audit: Update User Risk and MFA Registration Policy
Flags Azure AD audit events showing updates to user risk and MFA registration policy.
sigmaCloudhigh2024-08-13AWS CloudTrail SSM SendCommand Successful Execution for Instance
Identifies successful AWS SSM SendCommand executions recorded in CloudTrail.
sigmaCloudhigh2024-07-11AWS CloudTrail: Instance Profile Role Assumed Actions Outside SSM RegisterManagedInstance
Identifies CloudTrail activity from assumed-role instance identities when it is not part of SSM RegisterManagedInstance.
sigmaCloudhigh2024-07-11AWS CloudTrail: AWS Identity Center Identity Provider Configuration Changes
Detects CloudTrail identity center events that associate or change the external identity provider configuration.
sigmaCloudhigh2023-09-27Microsoft 365 Audit: Disabling Strong Authentication (MFA)
Flags Microsoft 365 audit events indicating MFA/strong authentication was disabled.
sigmaCloudhigh2023-09-18Azure Entra PIM Alerts: Too Many Global Administrators Assigned to Tenant
Alerts when Azure PIM reports an overabundance of Global Administrator role assignments in a tenant.
sigmaCloudhigh2023-09-14Azure AD PIM Redundant Assignment Alert When Privileged Role Not Used
Alerts on Azure PIM redundant privileged role assignments where the assigned role appears unused.
sigmaCloudhigh2023-09-14Azure PIM Role Activation Without MFA Alert (noMfaOnRoleActivationAlertIncident)
Alerts when Azure PIM signals role activation occurred without MFA.
sigmaCloudhigh2023-09-14Azure AD PIM Role Activations Too Frequent for Same User
Alerts when Azure PIM logs sequential activation renewals for the same role by the same user.
sigmaCloudhigh2023-09-14Azure PIM Alert: Privileged Role Assigned Outside PIM
Detects Azure PIM risk events indicating privileged role assignments were made outside PIM.
sigmaCloudhigh2023-09-14Azure PIM Invalid License Alert Incident
Alerts when Azure PIM reports an invalid or missing license condition for the organization.
sigmaCloudhigh2023-09-14Azure PIM Stale Sign-In Alert for Privileged Role Accounts
Alerts when Azure PIM reports a privileged account has gone stale due to no sign-in activity.
sigmaCloudhigh2023-09-14Azure (Entra ID) Risk Detection: Threat Intelligence-Driven Unusual User Activity
Flags Azure AD risk investigation events tied to threat-intelligence sign-in indicators using riskdetection telemetry.
sigmaCloudhigh2023-09-07Azure Risk Detection: Attempted Primary Refresh Token (PRT) Access
Identifies Azure risk events indicating an attempted PRT access that can enable lateral movement or credential theft.
sigmaCloudhigh2023-09-07Azure Entra Risk Detection: SuspiciousIPAddress Sign-In From Malicious IP
Alerts on Azure Entra sign-in risk events marked suspiciousIPAddress, suggesting origin from a known malicious IP.
sigmaCloudhigh2023-09-07