Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Azure PIM Role Activation Without MFA Alert (noMfaOnRoleActivationAlertIncident)
Alerts when Azure PIM signals role activation occurred without MFA.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh408Free2023-09-14Azure AD PIM Role Activations Too Frequent for Same User
Alerts when Azure PIM logs sequential activation renewals for the same role by the same user.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh111Free2023-09-14Azure PIM Alert: Privileged Role Assigned Outside PIM
Detects Azure PIM risk events indicating privileged role assignments were made outside PIM.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh194Free2023-09-14Azure PIM Invalid License Alert Incident
Alerts when Azure PIM reports an invalid or missing license condition for the organization.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh272Free2023-09-14Azure PIM Stale Sign-In Alert for Privileged Role Accounts
Alerts when Azure PIM reports a privileged account has gone stale due to no sign-in activity.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh301Free2023-09-14Windows: Headless Chromium Browser Execution via --headless
Alerts on headless Chromium-based browser launches on Windows using the "--headless" command-line flag.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow80Free2023-09-12Windows Process Creation: wmic.exe call terminate Attempt
Alerts on wmic.exe being executed with “call terminate”, indicating an attempt to terminate a process on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium122Free2023-09-11Windows Process Creation: Execution of Renamed curl.exe via PE Metadata
Alerts on Windows process launches whose PE metadata matches curl.exe even when the executable image is renamed.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium459Free2023-09-11Windows Chromium Headless Execution with Mockbin/Mocky URL
Alerts when a Chromium-based browser runs headless on Windows with a mockbin-like URL in the command line.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2023-09-11Windows Suspicious Creation of .dmp/.hdmp Files by Shell or Script Hosts
Alerts on .dmp/.dump/.hdmp file creation by common Windows shells and scripting engines.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium172Free2023-09-07Okta user.session.start via anonymising proxy service
Identifies Okta user session starts where the session is marked as using an anonymizing proxy.
kelnage, Huntrule TeamOktaoktaHigh364Free2023-09-07Okta: End-user Reported Suspicious Activity Account Event Detection
Flags Okta end-user self-submitted reports of potentially suspicious activity on their account.
kelnage, Huntrule TeamOktaoktaHigh298Free2023-09-07Okta Admin Console: New admin console activity via policy.evaluate_sign_on heuristics
Alerts when Okta policy evaluation shows POSITIVE debug heuristics for activity targeting the Okta Admin Console.
kelnage, Huntrule TeamOktaoktaHigh81Free2023-09-07Okta System Log: New Identity Provider Created via system.idp.lifecycle.create
Alerts on Okta events indicating a new identity provider was created.
kelnage, Huntrule TeamOktaoktaMedium103Free2023-09-07Azure (Entra ID) Risk Detection: Threat Intelligence-Driven Unusual User Activity
Flags Azure AD risk investigation events tied to threat-intelligence sign-in indicators using riskdetection telemetry.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh207Free2023-09-07