Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Azure SAML Token Issuer Anomaly via riskdetection
Flags Azure risk events where a SAML token’s issuer and claims look anomalous or attacker-like.
sigmaCloudhigh2023-09-03Azure Entra suspicious browser risk events across multiple tenants and countries
Flags Azure suspicious browser risk events tied to anomalous sign-ins across tenants and countries from the same browser.
sigmaCloudhigh2023-09-03Azure Entra ID risk event: successful password spray detection
Flags Azure Entra ID risk events indicating a successful password spray attempt.
sigmaCloudhigh2023-09-03Azure Entra ID sign-in risk: new country (riskEventType newCountry)
Flags Azure AD risk events where a sign-in is assessed as originating from a new country for the user.
sigmaCloudhigh2023-09-03Azure Identity Risk: Sign-ins from Malware-Infected IP Addresses
Flags Azure sign-in risk events originating from malware-infected IP addresses linked to bot-server communication.
sigmaCloudhigh2023-09-03Azure AD LeakedCredentials Risk Event Indicates User Credential Exposure
Alerts on Azure AD risk events indicating user credentials were leaked (riskEventType: leakedCredentials).
sigmaCloudhigh2023-09-03Azure risk event: Suspicious inbox manipulation rules that delete or move messages or folders
Alerts on Azure risk events for suspicious inbox rules that delete or move mailbox items.
sigmaCloudhigh2023-09-03Azure Risk Event: Suspicious Inbox Forwarding
Alerts on Azure Identity Protection risk events indicating inbox forwarding to an external address.
sigmaCloudhigh2023-09-03Azure AD User Login Risk: Impossible Travel from Distant Locations
Flags Azure Entra risk events tagged as impossibleTravel indicating implausible geographic sign-in travel within a short time.
sigmaCloudhigh2023-09-03Azure Entra ID Identity Protection Unlikely Travel Risk Events
Alerts on unlikelyTravel risk events tied to geographically distant sign-ins and potential deviation from user travel history.
sigmaCloudhigh2023-09-03Azure RiskDetection flags riskyIPAddress from anonymous proxy IP addresses
Alerts when Azure reports user activity linked to a risky anonymous proxy IP address.
sigmaCloudhigh2023-09-03Azure Entra ID anomalous user activity risk event
Alerts on Azure AD risk events indicating anomalous user activity via riskEventType=anomalousUserActivity.
sigmaCloudhigh2023-09-03Qakbot Uninstaller Execution via QbotUninstall.exe (Windows Process Creation)
Alerts on execution of the QbotUninstall.exe uninstaller when it matches known Qakbot uninstaller hashes.
sigmahigh2023-08-31Suspicious rundll32 Single-Digit DLL Execution with DllRegisterServer on Windows
Flags rundll32.exe running 1.dll with DllRegisterServer, a pattern seen in suspicious DLL execution.
sigmahigh2023-08-31Suspicious WinRAR Child Process Execution Attempt on Windows (CVE-2023-38331)
Alerts on WinRAR spawning command/scripting child processes tied to Temp\Rar$ activity consistent with CVE-2023-38331 exploitation attempts.
sigmahigh2023-08-30Windows: WinRAR double-extension file creation with space in Temp Rar$ path
Alerts on WinRAR-created Temp Rar$ files with double extensions separated by a space on Windows.
sigmahigh2023-08-30Suspicious LOLBIN Copy From Windows System Directories Using Windows Copy Tools
Flags cmd/PowerShell/robocopy/xcopy commands that copy known LOLBINs out of System32/SysWOW64/WinSxS.
sigmaWindowshigh2023-08-29Windows: Local User Creation via net.exe with DarkGate and SafeMode
Alerts on net.exe adding a local user when the command line includes “DarkGate” and “SafeMode”.
sigmahigh2023-08-27Windows Fake wermgr.exe Execution via Renamed cmd/powershell/powershell_ise
Detects disguised execution of cmd or PowerShell by matching original file name with a wermgr.exe process image.
sigmahigh2023-08-23Windows File Creation of wermgr.exe in Uncommon Directory (Potential CVE-2023-36874)
Alerts on wermgr.exe creation in atypical Windows directories that may indicate filename spoofing.
sigmahigh2023-08-23