Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
15 rules
AWS CloudTrail Successful ConsoleLogin Events Without MFA
Flags successful AWS console logins with MFAUsed explicitly set to NO in CloudTrail.
sigmaCloudmedium2025-10-18Azure AD Audit: Update User Risk and MFA Registration Policy
Flags Azure AD audit events showing updates to user risk and MFA registration policy.
sigmaCloudhigh2024-08-13Cisco Duo MFA Success Triggered by Admin-Assigned Bypass Code
Alert on Duo successful MFA logins that are attributed to bypass-user codes.
sigmaIdentitymedium2024-04-17Microsoft 365 Audit: Disabling Strong Authentication (MFA)
Flags Microsoft 365 audit events indicating MFA/strong authentication was disabled.
sigmaCloudhigh2023-09-18Azure PIM Role Activation Without MFA Alert (noMfaOnRoleActivationAlertIncident)
Alerts when Azure PIM signals role activation occurred without MFA.
sigmaCloudhigh2023-09-14Okta FastPass blocks phishing authentication attempts via MFA
Alerts on Okta FastPass MFA failures where the declined reason indicates a known phishing attempt.
sigmaIdentityhigh2023-05-07Azure Sign-in Success with Legacy Client User-Agent Indicators (MFA Bypass Suspicion)
Alerts on successful Azure sign-ins using legacy client user-agent markers that may indicate MFA bypass attempts.
sigmaCloudhigh2023-03-20Azure Sign-In: Successful single-factor atRisk logins from non-registered devices
Alerts on at-risk successful Azure sign-ins from devices with missing trust type when MFA isn’t required.
sigmaCloudhigh2023-01-10Azure AD Sign-in Success Without MFA (Single-Factor Authentication)
Alerts on successful Azure AD sign-ins where MFA was not required and only single-factor authentication was used.
sigmaCloudlow2022-07-27Azure Sign-In Logs: Device Registration or Join Success Without MFA
Flags successful device registration/join attempts in Azure when MFA was not performed per Conditional Access.
sigmaCloudmedium2022-06-28Azure Sign-in Logs: MFA Denied Based on Authentication Requirement
Flags Azure sign-ins requiring MFA where the status indicates "MFA Denied."
sigmaCloudmedium2022-03-24Azure Audit Logs: Successful Disable Strong Authentication Indicates MFA Disabled
Alerts on successful MFA disable actions in Azure audit logs that could weaken account authentication.
sigmaCloudmedium2022-02-08Azure Sign-in Log MFA Interrupted via Strong Auth Failures
Identifies Azure sign-ins that fail during strong/MFA authentication, suggesting blocked credential attempts.
sigmaCloudmedium2021-10-10Okta MFA Deactivation or Full Factor Reset Event Detection
Flags Okta events indicating MFA deactivation or reset_all actions by a user or actor.
sigmaIdentitymedium2021-09-21Google Workspace: Admin audit events where strong authentication is allowed without enforcement (MFA disabled)
Alerts on Google Workspace admin changes that set strong authentication/MFA enforcement to false.
sigmaCloudmedium2021-08-26