Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
18 rules
Suspicious AWS Console Phishing MFA Relay Endpoints
This rule detects requests to the MFA relay endpoints of the AWS console phishing kit that intercept second-factor codes delivered by email, SMS, or authenticator app. The kit prompts victims for their one-time codes and forwards them so the operator can complete authentication in real time. Traffic to these email, sms, and gauth relay paths on a login-lookalike host indicates active MFA interception.
HuntRule TeamWebproxyMedium00Premium2026-09-15Suspicious Azure AD MFA Fatigue Repeated Push Denials
This rule detects Entra ID sign-in events with result code 500121, which records that a multifactor authentication request was denied by the user. A burst of these denials for a single userPrincipalName indicates an MFA fatigue or push-bombing attack where an adversary holding valid credentials repeatedly prompts the victim hoping for an accidental approval. This is important because sustained denials often precede a coerced approval and account takeover.
HuntRule TeamAzuresigninlogsMedium30Premium2026-09-14Suspicious AWS Console Login Without MFA
This rule detects a successful AWS Management Console sign-in where additionalEventData.MFAUsed is No, indicating interactive access with only a password or root credentials and no second factor. Adversaries who compromise console credentials rely on non-MFA logins to gain hands-on-keyboard access, a pattern GuardDuty also flags as IAMUser ConsoleLoginSuccess. This is important because non-MFA console logins are a primary indicator of account takeover.
HuntRule TeamAwscloudtrailMedium171Premium2026-07-04AWS CloudTrail Successful ConsoleLogin Events Without MFA
Flags successful AWS console logins with MFAUsed explicitly set to NO in CloudTrail.
Thuya@Hacktilizer, Ivan Saakov, Huntrule TeamAwscloudtrailMedium142Free2025-10-18Azure AD Audit: Update User Risk and MFA Registration Policy
Flags Azure AD audit events showing updates to user risk and MFA registration policy.
Harjot Singh (@cyb3rjy0t), Huntrule TeamAzureauditlogsHigh162Free2024-08-13Cisco Duo MFA Success Triggered by Admin-Assigned Bypass Code
Alert on Duo successful MFA logins that are attributed to bypass-user codes.
Nikita Khalimonenkov, Huntrule TeamCiscoduoMedium246Free2024-04-17Microsoft 365 Audit: Disabling Strong Authentication (MFA)
Flags Microsoft 365 audit events indicating MFA/strong authentication was disabled.
Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule), Huntrule TeamM365auditHigh386Free2023-09-18Azure PIM Role Activation Without MFA Alert (noMfaOnRoleActivationAlertIncident)
Alerts when Azure PIM signals role activation occurred without MFA.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh408Free2023-09-14Okta FastPass blocks phishing authentication attempts via MFA
Alerts on Okta FastPass MFA failures where the declined reason indicates a known phishing attempt.
Austin Songer @austinsonger, Huntrule TeamOktaoktaHigh234Free2023-05-07Azure Sign-in Success with Legacy Client User-Agent Indicators (MFA Bypass Suspicion)
Alerts on successful Azure sign-ins using legacy client user-agent markers that may indicate MFA bypass attempts.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamAzuresigninlogsHigh172Free2023-03-20Azure Sign-In: Successful single-factor atRisk logins from non-registered devices
Alerts on at-risk successful Azure sign-ins from devices with missing trust type when MFA isn’t required.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamAzuresigninlogsHigh90Free2023-01-10Azure AD Sign-in Success Without MFA (Single-Factor Authentication)
Alerts on successful Azure AD sign-ins where MFA was not required and only single-factor authentication was used.
MikeDuddington, '@dudders1', Huntrule TeamAzuresigninlogsLow90Free2022-07-27Azure Sign-In Logs: Device Registration or Join Success Without MFA
Flags successful device registration/join attempts in Azure when MFA was not performed per Conditional Access.
Michael Epping, '@mepples21', Huntrule TeamAzuresigninlogsMedium162Free2022-06-28Azure Sign-in Logs: MFA Denied Based on Authentication Requirement
Flags Azure sign-ins requiring MFA where the status indicates "MFA Denied."
AlertIQ, Huntrule TeamAzuresigninlogsMedium113Free2022-03-24Azure Audit Logs: Successful Disable Strong Authentication Indicates MFA Disabled
Alerts on successful MFA disable actions in Azure audit logs that could weaken account authentication.
"@ionsor, Huntrule Team"AzureauditlogsMedium153Free2022-02-08