Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,453 rules
Azure Entra sign-in risk: Unfamiliar sign-in properties
Alerts on Azure risk events where sign-in properties are marked unfamiliar compared to a user’s historical patterns.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh92Free2023-09-03Azure SAML Token Issuer Anomaly via riskdetection
Flags Azure risk events where a SAML token’s issuer and claims look anomalous or attacker-like.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh123Free2023-09-03Azure Entra suspicious browser risk events across multiple tenants and countries
Flags Azure suspicious browser risk events tied to anomalous sign-ins across tenants and countries from the same browser.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh1810Free2023-09-03Azure Entra ID risk event: successful password spray detection
Flags Azure Entra ID risk events indicating a successful password spray attempt.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh125Free2023-09-03Azure Entra ID sign-in risk: new country (riskEventType newCountry)
Flags Azure AD risk events where a sign-in is assessed as originating from a new country for the user.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh457Free2023-09-03Azure Identity Risk: Sign-ins from Malware-Infected IP Addresses
Flags Azure sign-in risk events originating from malware-infected IP addresses linked to bot-server communication.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh193Free2023-09-03Azure AD LeakedCredentials Risk Event Indicates User Credential Exposure
Alerts on Azure AD risk events indicating user credentials were leaked (riskEventType: leakedCredentials).
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh152Free2023-09-03Azure risk event: Suspicious inbox manipulation rules that delete or move messages or folders
Alerts on Azure risk events for suspicious inbox rules that delete or move mailbox items.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh161Free2023-09-03Azure Risk Event: Suspicious Inbox Forwarding
Alerts on Azure Identity Protection risk events indicating inbox forwarding to an external address.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh335Free2023-09-03Azure AD User Login Risk: Impossible Travel from Distant Locations
Flags Azure Entra risk events tagged as impossibleTravel indicating implausible geographic sign-in travel within a short time.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh91Free2023-09-03Azure Entra ID Identity Protection Unlikely Travel Risk Events
Alerts on unlikelyTravel risk events tied to geographically distant sign-ins and potential deviation from user travel history.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh162Free2023-09-03Azure RiskDetection flags riskyIPAddress from anonymous proxy IP addresses
Alerts when Azure reports user activity linked to a risky anonymous proxy IP address.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh2410Free2023-09-03Azure Entra ID anomalous user activity risk event
Alerts on Azure AD risk events indicating anomalous user activity via riskEventType=anomalousUserActivity.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh121Free2023-09-03Suspicious Child Process Spawned by WinRAR.exe on Windows
Alerts when WinRAR.exe launches command, scripting, or proxy execution binaries on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-08-31Qakbot Uninstaller Execution via QbotUninstall.exe (Windows Process Creation)
Alerts on execution of the QbotUninstall.exe uninstaller when it matches known Qakbot uninstaller hashes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2023-08-31