huntrule
RulesPricingHow it works

Every published rule

Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.

24 rules

  • Suspicious Okta API Token Revoked (via okta)

    medium

    This rule detects when a API Token is revoked.

    sigmaIdentity
    2026-01-15
  • Suspicious Cisco Duo Successful MFA Authentication Through Bypass Code (via duo)

    medium

    This rule detects when a successful MFA authentication occurs due to the use of a bypass code. A bypass code is a temporary passcode created by an administrator for a specific user to access a Duo-protected application. These are generally used as "backup codes," so that enrolled users who are having problems with their mobile devices (e.g., mobile service is disrupted, the device is lost or stolen, etc.) or who temporarily can't use their enrolled devices (on a plane without mobile data services) can still access their Duo-protected systems.

    sigmaIdentity
    2026-01-11
  • Possible Okta Password in AlternateID Field (via okta)

    high

    This rule detects when a user has potentially entered their password into the username field, which will cause the password to be retained in log files.

    sigmaIdentityPaid
    2026-01-10
  • Suspicious Okta MFA Reset or Deactivated (via okta)

    medium

    This rule detects when an attempt at deactivating or resetting MFA.

    sigmaIdentity
    2026-01-10
Previous2 / 2Next

The threat is new.
Your detection should not be late.

The library is public and free to read. Every rule shows the reporting behind it, the telemetry it needs and where it falls short.

HuntRuleHuntRule

Detection rules built from the latest attacker techniques. Expert-reviewed, source-backed Sigma.

Library

  • All rules
  • Pricing

Project

  • How it works
  • Sign in

Resources

  • Rules API
  • llms.txt
  • Sitemap

Company

  • Contact

© 2026 HuntRule

Validate every rule against your own telemetry before you alert on it.