Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
18 rules
Azure Sign-in Log MFA Interrupted via Strong Auth Failures
Identifies Azure sign-ins that fail during strong/MFA authentication, suggesting blocked credential attempts.
AlertIQ, Huntrule TeamAzuresigninlogsMedium235Free2021-10-10Okta MFA Deactivation or Full Factor Reset Event Detection
Flags Okta events indicating MFA deactivation or reset_all actions by a user or actor.
Austin Songer @austinsonger, Huntrule TeamOktaoktaMedium397Free2021-09-21Google Workspace: Admin audit events where strong authentication is allowed without enforcement (MFA disabled)
Alerts on Google Workspace admin changes that set strong authentication/MFA enforcement to false.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium522Free2021-08-26