Detection Rules

A free, growing library of Sigma detection rules. Every rule is grounded in a real attack LogTriage detects, mapped to its log format and MITRE ATT&CK technique, and validated against real sample logs — it has to fire on the malicious sample and stay quiet on the benign one before it ships.

New rules added regularly. Copy any rule into your SIEM — or upload your logs to LogTriage and let it detect these automatically.

CRITICAL GitHub Audit Log ✓ validated

Detect GitHub Organization Takeover and Backdooring in Audit Logs

LTR-0014 · T1098, T1195.002, T1562.001, T1537

CRITICAL Duo Security ✓ validated

Detect MFA Fatigue and Bypass Abuse in Duo Security Logs

LTR-0013 · T1621, T1078.004, T1556.006

HIGH Linux auth.log / secure ✓ validated

Detect SSH Brute Force and User Enumeration in Linux auth.log

LTR-0011 · T1110.001, T1110.003, T1078

HIGH Windows Event Log ✓ validated

Detect Windows Password Spraying with Event ID 4625

LTR-0012 · T1110.003, T1110.001, T1078.002

HIGH Okta System Log ✓ validated

Detect Credential Stuffing in Okta System Log

LTR-0007 · T1110.004, T1110.001

HIGH GCP Cloud Audit Log ✓ validated

Detect IAM Privilege Escalation in GCP Cloud Audit Logs

LTR-0008 · T1098, T1078.004

HIGH Kubernetes Audit Log ✓ validated

Detect Kubernetes Secret Exfiltration in Audit Logs

LTR-0009 · T1552.007, T1078

HIGH Cloudflare Logs ✓ validated

Detect Path Traversal & Sensitive-File Recon in Cloudflare Logs

LTR-0010 · T1190, T1083, T1595.001

HIGH Microsoft 365 Unified Audit Log ✓ validated

Detect Business Email Compromise via Malicious Inbox Rules (Microsoft 365)

LTR-0006 · T1114.003, T1564.008

HIGH Azure AD Sign-In Logs ✓ validated

Detect Legacy-Auth MFA Bypass in Azure AD Sign-In Logs

LTR-0004 · T1078.004, T1556

MEDIUM AWS VPC Flow Logs ✓ validated

Detect Port Scanning in AWS VPC Flow Logs

LTR-0005 · T1046, T1595.001

HIGH nginx / Apache access logs ✓ validated

Detect Credential Stuffing Against Authentication Endpoints (nginx / web logs)

LTR-0001 · T1110.004, T1110.001

HIGH AWS CloudTrail ✓ validated

Detect IAM Privilege Escalation in AWS CloudTrail

LTR-0002 · T1098, T1078.004, T1484

CRITICAL Microsoft Sysmon ✓ validated

Detect LSASS Credential Dumping with Sysmon

LTR-0003 · T1003.001, T1055