Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Microsoft 365 Audit: Disabling Strong Authentication (MFA)
Flags Microsoft 365 audit events indicating MFA/strong authentication was disabled.
sigmaCloudhigh2023-09-18Azure Entra PIM Alerts: Too Many Global Administrators Assigned to Tenant
Alerts when Azure PIM reports an overabundance of Global Administrator role assignments in a tenant.
sigmaCloudhigh2023-09-14Azure AD PIM Redundant Assignment Alert When Privileged Role Not Used
Alerts on Azure PIM redundant privileged role assignments where the assigned role appears unused.
sigmaCloudhigh2023-09-14Azure PIM Role Activation Without MFA Alert (noMfaOnRoleActivationAlertIncident)
Alerts when Azure PIM signals role activation occurred without MFA.
sigmaCloudhigh2023-09-14Azure AD PIM Role Activations Too Frequent for Same User
Alerts when Azure PIM logs sequential activation renewals for the same role by the same user.
sigmaCloudhigh2023-09-14Azure PIM Alert: Privileged Role Assigned Outside PIM
Detects Azure PIM risk events indicating privileged role assignments were made outside PIM.
sigmaCloudhigh2023-09-14Azure PIM Invalid License Alert Incident
Alerts when Azure PIM reports an invalid or missing license condition for the organization.
sigmaCloudhigh2023-09-14Azure PIM Stale Sign-In Alert for Privileged Role Accounts
Alerts when Azure PIM reports a privileged account has gone stale due to no sign-in activity.
sigmaCloudhigh2023-09-14Windows Chromium Headless Execution with Mockbin/Mocky URL
Alerts when a Chromium-based browser runs headless on Windows with a mockbin-like URL in the command line.
sigmaWindowshigh2023-09-11Okta user.session.start via anonymising proxy service
Identifies Okta user session starts where the session is marked as using an anonymizing proxy.
sigmaIdentityhigh2023-09-07Okta: End-user Reported Suspicious Activity Account Event Detection
Flags Okta end-user self-submitted reports of potentially suspicious activity on their account.
sigmaIdentityhigh2023-09-07Okta Admin Console: New admin console activity via policy.evaluate_sign_on heuristics
Alerts when Okta policy evaluation shows POSITIVE debug heuristics for activity targeting the Okta Admin Console.
sigmaIdentityhigh2023-09-07Azure (Entra ID) Risk Detection: Threat Intelligence-Driven Unusual User Activity
Flags Azure AD risk investigation events tied to threat-intelligence sign-in indicators using riskdetection telemetry.
sigmaCloudhigh2023-09-07Azure Risk Detection: Attempted Primary Refresh Token (PRT) Access
Identifies Azure risk events indicating an attempted PRT access that can enable lateral movement or credential theft.
sigmaCloudhigh2023-09-07Azure Entra Risk Detection: SuspiciousIPAddress Sign-In From Malicious IP
Alerts on Azure Entra sign-in risk events marked suspiciousIPAddress, suggesting origin from a known malicious IP.
sigmaCloudhigh2023-09-07Azure risk detection: Malicious IP sign-in risk event based on sign-in failure rate
Flags Azure risk events for sign-ins associated with malicious IPs using maliciousIPAddress failure-rate indications.
sigmaCloudhigh2023-09-07Windows Registry ZoneMap ProtocolDefaults Downgraded to My Computer for HTTP/HTTPS
Flags IE/Windows ZoneMap changes setting HTTP/HTTPS ProtocolDefaults DWORD 0x00000000 to the My Computer zone.
sigmaWindowshigh2023-09-05Windows Process Creation: IE ZoneMap ProtocolDefaults downgraded to My Computer for HTTP/HTTPS
Flags Windows command lines that set IE ZoneMap ProtocolDefaults for HTTP to the My Computer (zone 0) trust level.
sigmaWindowshigh2023-09-05Linux Process Creating esxcli System Permission Set Admin for an Account
Alerts when esxcli is run to set Admin permissions via the system/permission set flags.
sigmaLinuxhigh2023-09-04Azure Entra sign-in risk: Unfamiliar sign-in properties
Alerts on Azure risk events where sign-in properties are marked unfamiliar compared to a user’s historical patterns.
sigmaCloudhigh2023-09-03