Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,331 rules
Azure Entra Risk Detection: SuspiciousIPAddress Sign-In From Malicious IP
Alerts on Azure Entra sign-in risk events marked suspiciousIPAddress, suggesting origin from a known malicious IP.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh101Free2023-09-07Azure risk detection: Malicious IP sign-in risk event based on sign-in failure rate
Flags Azure risk events for sign-ins associated with malicious IPs using maliciousIPAddress failure-rate indications.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh152Free2023-09-07Windows Registry ZoneMap ProtocolDefaults Downgraded to My Computer for HTTP/HTTPS
Flags IE/Windows ZoneMap changes setting HTTP/HTTPS ProtocolDefaults DWORD 0x00000000 to the My Computer zone.
Nasreddine Bencherchali (Nextron Systems), Michael Haag (idea), Huntrule TeamWindowsregistry_setHigh301Free2023-09-05Windows Process Creation: IE ZoneMap ProtocolDefaults downgraded to My Computer for HTTP/HTTPS
Flags Windows command lines that set IE ZoneMap ProtocolDefaults for HTTP to the My Computer (zone 0) trust level.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh268Free2023-09-05Linux Process Creating esxcli System Permission Set Admin for an Account
Alerts when esxcli is run to set Admin permissions via the system/permission set flags.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh143Free2023-09-04Azure Entra sign-in risk: Unfamiliar sign-in properties
Alerts on Azure risk events where sign-in properties are marked unfamiliar compared to a user’s historical patterns.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh92Free2023-09-03Azure SAML Token Issuer Anomaly via riskdetection
Flags Azure risk events where a SAML token’s issuer and claims look anomalous or attacker-like.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh123Free2023-09-03Azure Entra suspicious browser risk events across multiple tenants and countries
Flags Azure suspicious browser risk events tied to anomalous sign-ins across tenants and countries from the same browser.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh1810Free2023-09-03Azure Entra ID risk event: successful password spray detection
Flags Azure Entra ID risk events indicating a successful password spray attempt.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh125Free2023-09-03Azure Entra ID sign-in risk: new country (riskEventType newCountry)
Flags Azure AD risk events where a sign-in is assessed as originating from a new country for the user.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh457Free2023-09-03Azure Identity Risk: Sign-ins from Malware-Infected IP Addresses
Flags Azure sign-in risk events originating from malware-infected IP addresses linked to bot-server communication.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh193Free2023-09-03Azure AD LeakedCredentials Risk Event Indicates User Credential Exposure
Alerts on Azure AD risk events indicating user credentials were leaked (riskEventType: leakedCredentials).
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh152Free2023-09-03Azure risk event: Suspicious inbox manipulation rules that delete or move messages or folders
Alerts on Azure risk events for suspicious inbox rules that delete or move mailbox items.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh161Free2023-09-03Azure Risk Event: Suspicious Inbox Forwarding
Alerts on Azure Identity Protection risk events indicating inbox forwarding to an external address.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh335Free2023-09-03Azure AD User Login Risk: Impossible Travel from Distant Locations
Flags Azure Entra risk events tagged as impossibleTravel indicating implausible geographic sign-in travel within a short time.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh91Free2023-09-03