Platform / product
azure Sigma detection rules
131 community-maintained Sigma detection rules in the library target the azure platform. Browse by severity, inspect the detection logic and MITRE ATT&CK mapping, and open the original Sigma YAML before using a rule in your detection engineering workflow.
Account Created And Deleted Within A Close Time Frame
highDetects when an account was created and deleted in a short period of time.
azure · auditlogs
Activity From Anonymous IP Address
highIdentifies that users were active from an IP address that has been identified as an anonymous proxy IP address.
azure · riskdetection
Added Credentials to Existing Application
highDetects when a new credential is added to an existing application. Any additional credentials added outside of expected processes could be a malicious actor using those credentials.
azure · auditlogs
Anomalous Token
highIndicates that there are abnormal characteristics in the token such as an unusual token lifetime or a token that is played from an unfamiliar location.
azure · riskdetection
Anomalous User Activity
highIndicates that there are anomalous patterns of behavior like suspicious changes to the directory.
azure · riskdetection
Anonymous IP Address
highIndicates sign-ins from an anonymous IP address, for example, using an anonymous browser or VPN.
azure · riskdetection
App Granted Microsoft Permissions
highDetects when an application is granted delegated or app role permissions for Microsoft Graph, Exchange, Sharepoint, or Azure AD
azure · auditlogs
App Granted Privileged Delegated Or App Permissions
highDetects when administrator grants either application permissions (app roles) or highly privileged delegated permissions
azure · auditlogs
Application AppID Uri Configuration Changes
highDetects when a configuration change is made to an applications AppID URI.
azure · auditlogs
Application URI Configuration Changes
highDetects when a configuration change is made to an applications URI. URIs for domain names that no longer exist (dangling URIs), not using HTTPS, wildcards at the end of the domain, URIs that are no unique to that app, or URIs that point to domains you do not control should be investigated.
azure · auditlogs
Atypical Travel
highIdentifies two sign-ins originating from geographically distant locations, where at least one of the locations may also be atypical for the user, given past behavior.
azure · riskdetection
Azure AD Account Credential Leaked
highIndicates that the user's valid credentials have been leaked.
azure · riskdetection
Azure AD Threat Intelligence
highIndicates user activity that is unusual for the user or consistent with known attack patterns.
azure · riskdetection
Azure Subscription Permission Elevation Via ActivityLogs
highDetects when a user has been elevated to manage all Azure Subscriptions. This change should be investigated immediately if it isn't planned. This setting could allow an attacker access to Azure subscriptions in your environment.
azure · activitylogs
Azure Subscription Permission Elevation Via AuditLogs
highDetects when a user has been elevated to manage all Azure Subscriptions. This change should be investigated immediately if it isn't planned. This setting could allow an attacker access to Azure subscriptions in your environment.
azure · auditlogs
Bulk Deletion Changes To Privileged Account Permissions
highDetects when a user is removed from a privileged role. Bulk changes should be investigated.
azure · auditlogs
Changes to Device Registration Policy
highMonitor and alert for changes to the device registration policy.
azure · auditlogs
Changes To PIM Settings
highDetects when changes are made to PIM roles
azure · auditlogs
Delegated Permissions Granted For All Users
highDetects when highly privileged delegated permissions are granted on behalf of all users
azure · auditlogs
Discovery Using AzureHound
highDetects AzureHound (A BloodHound data collector for Microsoft Azure) activity via the default User-Agent that is used during its operation after successful authentication.
azure · signinlogs
Impossible Travel
highIdentifies user activities originating from geographically distant locations within a time period shorter than the time it takes to travel from the first location to the second.
azure · riskdetection
Invalid PIM License
highIdentifies when an organization doesn't have the proper license for PIM and is out of compliance.
azure · pim
Malicious IP Address Sign-In Failure Rate
highIndicates sign-in from a malicious IP address based on high failure rates.
azure · riskdetection
Malicious IP Address Sign-In Suspicious
highIndicates sign-in from a malicious IP address known to be malicious at time of sign-in.
azure · riskdetection
New Country
highDetects sign-ins from new countries. The detection considers past activity locations to determine new and infrequent locations.
azure · riskdetection
Password Spray Activity
highIndicates that a password spray attack has been successfully performed.
azure · riskdetection
PIM Alert Setting Changes To Disabled
highDetects when PIM alerts are set to disabled.
azure · auditlogs
PIM Approvals And Deny Elevation
highDetects when a PIM elevation is approved or denied. Outside of normal operations should be investigated.
azure · auditlogs
Potential MFA Bypass Using Legacy Client Authentication
highDetects successful authentication from potential clients using legacy authentication via user agent strings. This could be a sign of MFA bypass using a password spray attack.
azure · signinlogs
Primary Refresh Token Access Attempt
highIndicates access attempt to the PRT resource which can be used to move laterally into an organization or perform credential theft
azure · riskdetection
Privilege Role Sign-In Outside Expected Controls
highDetects failed sign-in due to user not meeting expected controls for adminitrators
azure · signinlogs
Roles Activated Too Frequently
highIdentifies when the same privilege role has multiple activations by the same user.
azure · pim
Roles Activation Doesn't Require MFA
highIdentifies when a privilege role can be activated without performing mfa.
azure · pim
Roles Are Not Being Used
highIdentifies when a user has been assigned a privilege role and are not using that role.
azure · pim
Roles Assigned Outside PIM
highIdentifies when a privilege role assignment has taken place outside of PIM and may indicate an attack.
azure · pim
SAML Token Issuer Anomaly
highIndicates the SAML token issuer for the associated SAML token is potentially compromised. The claims included in the token are unusual or match known attacker patterns
azure · riskdetection
Sign-in Failure Due to Conditional Access Requirements Not Met
highDefine a baseline threshold for failed sign-ins due to Conditional Access failures
azure · signinlogs
Sign-In From Malware Infected IP
highIndicates sign-ins from IP addresses infected with malware that is known to actively communicate with a bot server.
azure · riskdetection
Sign-ins from Non-Compliant Devices
highMonitor and alert for sign-ins where the device was non-compliant.
azure · signinlogs
Stale Accounts In A Privileged Role
highIdentifies when an account hasn't signed in during the past n number of days.
azure · pim
Suspicious Browser Activity
highIndicates anomalous behavior based on suspicious sign-in activity across multiple tenants from different countries in the same browser
azure · riskdetection
Suspicious Inbox Forwarding Identity Protection
highIndicates suspicious rules such as an inbox rule that forwards a copy of all emails to an external address
azure · riskdetection
Suspicious Inbox Manipulation Rules
highDetects suspicious rules that delete or move messages or folders are set on a user's inbox.
azure · riskdetection
Suspicious SignIns From A Non Registered Device
highDetects risky authentication from a non AD registered device without MFA being required.
azure · signinlogs
Temporary Access Pass Added To An Account
highDetects when a temporary access pass (TAP) is added to an account. TAPs added to priv accounts should be investigated
azure · auditlogs
Too Many Global Admins
highIdentifies an event where there are there are too many accounts assigned the Global Administrator role.
azure · pim
Unfamiliar Sign-In Properties
highDetects sign-in with properties that are unfamiliar to the user. The detection considers past sign-in history to look for anomalous sign-ins.
azure · riskdetection
Use of Legacy Authentication Protocols
highAlert on when legacy authentication has been used on an account
azure · signinlogs
User Added To Privilege Role
highDetects when a user is added to a privileged role.
azure · auditlogs
User Risk and MFA Registration Policy Updated
highDetects changes and updates to the user risk and MFA registration policy. Attackers can modified the policies to Bypass MFA, weaken security thresholds, facilitate further attacks, maintain persistence.
azure · auditlogs
Users Added to Global or Device Admin Roles
highMonitor and alert for users added to device admin roles.
azure · auditlogs
Windows LAPS Credential Dump From Entra ID
highDetects when an account dumps the LAPS password from Entra ID.
azure · auditlogs
Account Created And Deleted By Non Approved Users
mediumDetects accounts that are created or deleted by non-approved users.
azure · auditlogs
Account Disabled or Blocked for Sign in Attempts
mediumDetects when an account is disabled or blocked for sign in but tried to log in
azure · signinlogs
Account Lockout
mediumIdentifies user account which has been locked because the user tried to sign in too many times with an incorrect user ID or password.
azure · signinlogs
Added Owner To Application
mediumDetects when a new owner is added to an application. This gives that account privileges to make modifications and configuration changes to the application.
azure · auditlogs
App Assigned To Azure RBAC/Microsoft Entra Role
mediumDetects when an app is assigned Azure AD roles, such as global administrator, or Azure RBAC roles, such as subscription owner.
azure · auditlogs
Application Using Device Code Authentication Flow
mediumDevice code flow is an OAuth 2.0 protocol flow specifically for input constrained devices and is not used in all environments. If this type of flow is seen in the environment and not being used in an input constrained device scenario, further investigation is warranted. This can be a misconfigured application or potentially something malicious.
azure · signinlogs
Applications That Are Using ROPC Authentication Flow
mediumResource owner password credentials (ROPC) should be avoided if at all possible as this requires the user to expose their current password credentials to the application directly. The application then uses those credentials to authenticate the user against the identity provider.
azure · signinlogs
Authentications To Important Apps Using Single Factor Authentication
mediumDetect when authentications to important application(s) only required single-factor authentication
azure · signinlogs
Azure Active Directory Hybrid Health AD FS New Server
mediumThis detection uses azureactivity logs (Administrative category) to identify the creation or update of a server instance in an Azure AD Hybrid health AD FS service. A threat actor can create a new AD Health ADFS service and create a fake server instance to spoof AD FS signing logs. There is no need to compromise an on-prem AD FS server. This can be done programmatically via HTTP requests to Azure.
azure · activitylogs
Azure Active Directory Hybrid Health AD FS Service Delete
mediumThis detection uses azureactivity logs (Administrative category) to identify the deletion of an Azure AD Hybrid health AD FS service instance in a tenant. A threat actor can create a new AD Health ADFS service and create a fake server to spoof AD FS signing logs. The health AD FS service can then be deleted after it is not longer needed via HTTP requests to Azure.
azure · activitylogs
Azure Application Deleted
mediumIdentifies when a application is deleted in Azure.
azure · auditlogs
Azure Application Gateway Modified or Deleted
mediumIdentifies when a application gateway is modified or deleted.
azure · activitylogs
Azure Application Security Group Modified or Deleted
mediumIdentifies when a application security group is modified or deleted.
azure · activitylogs
Azure Device No Longer Managed or Compliant
mediumIdentifies when a device in azure is no longer managed or compliant
azure · auditlogs
Azure Device or Configuration Modified or Deleted
mediumIdentifies when a device or device configuration in azure is modified or deleted.
azure · activitylogs
Azure DNS Zone Modified or Deleted
mediumIdentifies when DNS zone is modified or deleted.
azure · activitylogs
Azure Domain Federation Settings Modified
mediumIdentifies when an user or application modified the federation settings on the domain.
azure · auditlogs
Azure Firewall Modified or Deleted
mediumIdentifies when a firewall is created, modified, or deleted.
azure · activitylogs
Azure Firewall Rule Collection Modified or Deleted
mediumIdentifies when Rule Collections (Application, NAT, and Network) is being modified or deleted.
azure · activitylogs
Azure Firewall Rule Configuration Modified or Deleted
mediumIdentifies when a Firewall Rule Configuration is Modified or Deleted.
azure · activitylogs
Azure Key Vault Modified or Deleted
mediumIdentifies when a key vault is modified or deleted.
azure · activitylogs
Azure Keyvault Key Modified or Deleted
mediumIdentifies when a Keyvault Key is modified or deleted in Azure.
azure · activitylogs
Azure Keyvault Secrets Modified or Deleted
mediumIdentifies when secrets are modified or deleted in Azure.
azure · activitylogs
Azure Kubernetes Admission Controller
mediumIdentifies when an admission controller is executed in Azure Kubernetes. A Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server. The behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster. An adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster. For example, attackers can intercept and modify the pod creation operations in the cluster and add their malicious container to every created pod. An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials. An adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.
azure · activitylogs
Azure Kubernetes CronJob
mediumIdentifies when a Azure Kubernetes CronJob runs in Azure Cloud. Kubernetes Job is a controller that creates one or more pods and ensures that a specified number of them successfully terminate. Kubernetes Job can be used to run containers that perform finite tasks for batch jobs. Kubernetes CronJob is used to schedule Jobs. An Adversary may use Kubernetes CronJob for scheduling execution of malicious code that would run as a container in the cluster.
azure · activitylogs
Azure Kubernetes Events Deleted
mediumDetects when Events are deleted in Azure Kubernetes. An adversary may delete events in Azure Kubernetes in an attempt to evade detection.
azure · activitylogs
Azure Kubernetes Network Policy Change
mediumIdentifies when a Azure Kubernetes network policy is modified or deleted.
azure · activitylogs
Azure Kubernetes Pods Deleted
mediumIdentifies the deletion of Azure Kubernetes Pods.
azure · activitylogs
Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted
mediumDetects the creation or patching of potential malicious RoleBinding/ClusterRoleBinding.
azure · activitylogs
Azure Kubernetes Secret or Config Object Access
mediumIdentifies when a Kubernetes account access a sensitive objects such as configmaps or secrets.
azure · activitylogs
Azure Kubernetes Sensitive Role Access
mediumIdentifies when ClusterRoles/Roles are being modified or deleted.
azure · activitylogs
Azure Kubernetes Service Account Modified or Deleted
mediumIdentifies when a service account is modified or deleted.
azure · activitylogs
Azure Network Firewall Policy Modified or Deleted
mediumIdentifies when a Firewall Policy is Modified or Deleted.
azure · activitylogs
Azure Network Security Configuration Modified or Deleted
mediumIdentifies when a network security configuration is modified or deleted.
azure · activitylogs
Azure New CloudShell Created
mediumIdentifies when a new cloudshell is created inside of Azure portal.
azure · activitylogs
Azure Owner Removed From Application or Service Principal
mediumIdentifies when a owner is was removed from a application or service principal in Azure.
azure · auditlogs
Azure Point-to-site VPN Modified or Deleted
mediumIdentifies when a Point-to-site VPN is Modified or Deleted.
azure · activitylogs
Azure Service Principal Created
mediumIdentifies when a service principal is created in Azure.
azure · auditlogs
Azure Service Principal Removed
mediumIdentifies when a service principal was removed in Azure.
azure · auditlogs
Azure Suppression Rule Created
mediumIdentifies when a suppression rule is created in Azure. Adversary's could attempt this to evade detection.
azure · activitylogs
Azure Unusual Authentication Interruption
mediumDetects when there is a interruption in the authentication process.
azure · signinlogs
Azure Virtual Network Device Modified or Deleted
mediumIdentifies when a virtual network device is being modified or deleted. This can be a network interface, network virtual appliance, virtual hub, or virtual router.
azure · activitylogs
Azure Virtual Network Modified or Deleted
mediumIdentifies when a Virtual Network is modified or deleted in Azure.
azure · activitylogs
Azure VPN Connection Modified or Deleted
mediumIdentifies when a VPN connection is modified or deleted.
azure · activitylogs
Bitlocker Key Retrieval
mediumMonitor and alert for Bitlocker key retrieval.
azure · auditlogs
CA Policy Removed by Non Approved Actor
mediumMonitor and alert on conditional access changes where non approved actor removed CA Policy.
azure · auditlogs
CA Policy Updated by Non Approved Actor
mediumMonitor and alert on conditional access changes. Is Initiated by (actor) approved to make changes? Review Modified Properties and compare "old" vs "new" value.
azure · auditlogs
Certificate-Based Authentication Enabled
mediumDetects when certificate based authentication has been enabled in an Azure Active Directory tenant.
azure · auditlogs
Change to Authentication Method
mediumChange to authentication method could be an indicator of an attacker adding an auth method to the account so they can have continued access.
azure · auditlogs
Device Registration or Join Without MFA
mediumMonitor and alert for device registration or join events where MFA was not performed.
azure · signinlogs
Disabled MFA to Bypass Authentication Mechanisms
mediumDetection for when multi factor authentication has been disabled, which might indicate a malicious activity to bypass authentication mechanisms.
azure · auditlogs
End User Consent Blocked
mediumDetects when end user consent is blocked due to risk-based consent.
azure · auditlogs
Granting Of Permissions To An Account
mediumIdentifies IPs from which users grant access to other users on azure resources and alerts when a previously unseen source IP address is used.
azure · activitylogs
Guest User Invited By Non Approved Inviters
mediumDetects when a user that doesn't have permissions to invite a guest user attempts to invite one.
azure · auditlogs
Guest Users Invited To Tenant By Non Approved Inviters
mediumDetects guest users being invited to tenant by non-approved inviters
azure · auditlogs
Login to Disabled Account
mediumDetect failed attempts to sign in to disabled accounts.
azure · signinlogs
Multi Factor Authentication Disabled For User Account
mediumDetects changes to the "StrongAuthenticationRequirement" value, where the state is set to "0" or "Disabled". Threat actors were seen disabling multi factor authentication for users in order to maintain or achieve access to the account. Also see in SIM Swap attacks.
azure · auditlogs
Multifactor Authentication Denied
mediumUser has indicated they haven't instigated the MFA prompt and could indicate an attacker has the password for the account.
azure · signinlogs
Multifactor Authentication Interrupted
mediumIdentifies user login with multifactor authentication failures, which might be an indication an attacker has the password for the account but can't pass the MFA challenge.
azure · signinlogs
New CA Policy by Non-approved Actor
mediumMonitor and alert on conditional access changes.
azure · auditlogs
New Root Certificate Authority Added
mediumDetects newly added root certificate authority to an AzureAD tenant to support certificate based authentication.
azure · auditlogs
Number Of Resource Creation Or Deployment Activities
mediumNumber of VM creations or deployment activities occur in Azure via the azureactivity log.
azure · activitylogs
Password Reset By User Account
mediumDetect when a user has reset their password in Azure AD
azure · auditlogs
Privileged Account Creation
mediumDetects when a new admin is created.
azure · auditlogs
Rare Subscription-level Operations In Azure
mediumIdentifies IPs from which users grant access to other users on azure resources and alerts when a previously unseen source IP address is used.
azure · activitylogs
Successful Authentications From Countries You Do Not Operate Out Of
mediumDetect successful authentications from countries you do not operate out of.
azure · signinlogs
User Access Blocked by Azure Conditional Access
mediumDetect access has been blocked by Conditional Access policies. The access policy does not allow token issuance which might be sights≈ of unauthorizeed login to valid accounts.
azure · signinlogs
User Added to an Administrator's Azure AD Role
mediumUser Added to an Administrator's Azure AD Role
azure · auditlogs
User Added To Group With CA Policy Modification Access
mediumMonitor and alert on group membership additions of groups that have CA policy modification access
azure · auditlogs
User Removed From Group With CA Policy Modification Access
mediumMonitor and alert on group membership removal of groups that have CA policy modification access
azure · auditlogs
User State Changed From Guest To Member
mediumDetects the change of user type from "Guest" to "Member" for potential elevation of privilege.
azure · auditlogs
Users Authenticating To Other Azure AD Tenants
mediumDetect when users in your Azure AD tenant are authenticating to other Azure AD Tenants.
azure · signinlogs
Azure AD Only Single Factor Authentication Required
lowDetect when users are authenticating without MFA being required.
azure · signinlogs
Azure Container Registry Created or Deleted
lowDetects when a Container Registry is created or deleted.
azure · activitylogs
Azure Kubernetes Cluster Created or Deleted
lowDetects when a Azure Kubernetes Cluster is created or deleted.
azure · activitylogs
Azure Sign-In With Axios User Agent
lowDetects sign-in attempts in Azure/Entra ID logs where the user agent contains "axios", indicating potential use of automated credential harvesting or AiTM phishing infrastructure. Axios is a Node.js HTTP client abused to intercept and replay stolen credentials and MFA tokens. When triaging results, analysts should: - Check the sign-in risk level, MFA status, and conditional access results for signs of bypass. - Look for sign-ins from unusual locations or IPs, especially if the same IP targets multiple accounts. - Prioritize successful sign-ins over failed ones, as they may indicate a completed credential replay or AiTM attack.
azure · signinlogs
End User Consent
lowDetects when an end user consents to an application
azure · auditlogs
Failed Authentications From Countries You Do Not Operate Out Of
lowDetect failed authentications from countries you do not operate out of.
azure · signinlogs
Sign-ins by Unknown Devices
lowMonitor and alert for Sign-ins by unknown devices from non-Trusted locations.
azure · signinlogs