<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>LogTriage — Detection Rules &amp; Blog</title>
  <link>https://logtriage.app/</link>
  <description>Validated Sigma detection rules (each one proven to fire on a real malicious log sample and stay silent on a benign one) and engineering notes on log analysis and risk scoring.</description>
  <language>en</language>
  <lastBuildDate>Fri, 18 Sep 2026 00:00:00 GMT</lastBuildDate>
  <atom:link href="https://logtriage.app/rss.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>Detect Web Attack Recon and SQL Injection in Zeek HTTP Logs</title>
    <link>https://logtriage.app/rules/zeek-http-web-attack-recon/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/zeek-http-web-attack-recon/</guid>
    <description>A validated Sigma rule that flags sensitive-file probing (.env, wp-admin, config.php), SQL injection, and attack tooling in Zeek (Bro) http.log network telemetry.</description>
    <category>Detection Rules</category>
    <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect Anonymous S3 Object Reads and Malicious Uploads in Server Access Logs</title>
    <link>https://logtriage.app/rules/s3-anonymous-access-exfiltration/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/s3-anonymous-access-exfiltration/</guid>
    <description>A validated Sigma rule that flags unauthenticated (ANONYMOUS) object downloads from S3 buckets and script uploads into them, using S3 server access logs.</description>
    <category>Detection Rules</category>
    <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect SQL Injection and Follow-on Data Exfiltration in nginx Access Logs</title>
    <link>https://logtriage.app/rules/nginx-sqli-data-exfiltration/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/nginx-sqli-data-exfiltration/</guid>
    <description>A validated Sigma rule that flags SQL injection probing — UNION SELECT, boolean tests, time-based payloads, and sqlmap tooling — in nginx and Apache access logs.</description>
    <category>Detection Rules</category>
    <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect Super Admin Grants and 2SV Tampering in Google Workspace Audit Logs</title>
    <link>https://logtriage.app/rules/google-workspace-admin-takeover/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/google-workspace-admin-takeover/</guid>
    <description>A validated Sigma rule that flags Google Workspace admin takeover — super-admin role grants, two-step-verification being disabled for users, and suspicious logins in the Admin Reports API.</description>
    <category>Detection Rules</category>
    <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect Windows Password Spraying with Event ID 4625</title>
    <link>https://logtriage.app/rules/windows-4625-password-spray/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/windows-4625-password-spray/</guid>
    <description>A validated Sigma rule that flags password spraying and brute force against Windows and Active Directory using failed-logon Event ID 4625 and its SubStatus codes.</description>
    <category>Detection Rules</category>
    <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect GitHub Organization Takeover and Backdooring in Audit Logs</title>
    <link>https://logtriage.app/rules/github-audit-org-takeover/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/github-audit-org-takeover/</guid>
    <description>A validated Sigma rule that flags GitHub org takeover — 2FA being disabled, repos destroyed, backdoor members added, and webhooks planted for source-code exfiltration.</description>
    <category>Detection Rules</category>
    <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect MFA Fatigue and Bypass Abuse in Duo Security Logs</title>
    <link>https://logtriage.app/rules/duo-mfa-fatigue-bypass/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/duo-mfa-fatigue-bypass/</guid>
    <description>A validated Sigma rule that flags MFA push-bombing, user-reported fraud, and bypass-code abuse in Duo Security authentication logs.</description>
    <category>Detection Rules</category>
    <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect SSH Brute Force and User Enumeration in Linux auth.log</title>
    <link>https://logtriage.app/rules/authlog-ssh-brute-force/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/authlog-ssh-brute-force/</guid>
    <description>A validated Sigma rule that flags SSH brute-force and username-enumeration attacks in Linux auth.log — repeated Failed password and Invalid user events from one source.</description>
    <category>Detection Rules</category>
    <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect Credential Stuffing in Okta System Log</title>
    <link>https://logtriage.app/rules/okta-credential-stuffing/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/okta-credential-stuffing/</guid>
    <description>A validated Sigma rule that flags credential stuffing in the Okta System Log — a burst of failed sign-ins from one source, ending in a lockout or a success.</description>
    <category>Detection Rules</category>
    <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect Kubernetes Secret Exfiltration in Audit Logs</title>
    <link>https://logtriage.app/rules/k8s-secret-exfiltration/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/k8s-secret-exfiltration/</guid>
    <description>A validated Sigma rule that flags Kubernetes secret exfiltration — get/list access to Secrets from an unexpected user or service account in the K8s audit log.</description>
    <category>Detection Rules</category>
    <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect IAM Privilege Escalation in GCP Cloud Audit Logs</title>
    <link>https://logtriage.app/rules/gcp-iam-privilege-escalation/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/gcp-iam-privilege-escalation/</guid>
    <description>A validated Sigma rule that flags GCP privilege escalation — SetIamPolicy, service-account key creation, and custom role creation by an unexpected principal.</description>
    <category>Detection Rules</category>
    <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect Path Traversal &amp; Sensitive-File Recon in Cloudflare Logs</title>
    <link>https://logtriage.app/rules/cloudflare-path-traversal-recon/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/cloudflare-path-traversal-recon/</guid>
    <description>A validated Sigma rule that flags path traversal and sensitive-file probing in Cloudflare logs — /etc/passwd, .env, and directory-traversal attempts against your edge.</description>
    <category>Detection Rules</category>
    <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect Port Scanning in AWS VPC Flow Logs</title>
    <link>https://logtriage.app/rules/vpc-flow-port-scanning/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/vpc-flow-port-scanning/</guid>
    <description>A validated Sigma rule that flags port scanning in AWS VPC Flow Logs — REJECT-heavy connection bursts from a single source across many destination ports.</description>
    <category>Detection Rules</category>
    <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect Business Email Compromise via Malicious Inbox Rules (Microsoft 365)</title>
    <link>https://logtriage.app/rules/m365-bec-inbox-rule/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/m365-bec-inbox-rule/</guid>
    <description>A validated Sigma rule that flags business email compromise in the Microsoft 365 Unified Audit Log — attacker-created inbox rules and mailbox forwarding used to hide and exfiltrate mail.</description>
    <category>Detection Rules</category>
    <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect Legacy-Auth MFA Bypass in Azure AD Sign-In Logs</title>
    <link>https://logtriage.app/rules/azure-legacy-auth-mfa-bypass/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/azure-legacy-auth-mfa-bypass/</guid>
    <description>A validated Sigma rule that flags legacy authentication protocols in Azure AD / Entra sign-in logs — the most common way attackers sidestep MFA and conditional access.</description>
    <category>Detection Rules</category>
    <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect LSASS Credential Dumping with Sysmon</title>
    <link>https://logtriage.app/rules/sysmon-lsass-credential-dumping/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/sysmon-lsass-credential-dumping/</guid>
    <description>A validated Sigma rule that flags LSASS credential-dumping attempts in Sysmon — process access to lsass.exe with credential-theft access masks, the core technique behind Mimikatz and most hands-on-keyboard intrusions.</description>
    <category>Detection Rules</category>
    <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect Credential Stuffing Against Authentication Endpoints (nginx / web logs)</title>
    <link>https://logtriage.app/rules/nginx-credential-stuffing/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/nginx-credential-stuffing/</guid>
    <description>A validated Sigma rule that flags credential-stuffing campaigns in nginx and web-server access logs — high-volume failed logins from a single source against your auth endpoint, followed by a success.</description>
    <category>Detection Rules</category>
    <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detect IAM Privilege Escalation in AWS CloudTrail</title>
    <link>https://logtriage.app/rules/cloudtrail-iam-privilege-escalation/</link>
    <guid isPermaLink="true">https://logtriage.app/rules/cloudtrail-iam-privilege-escalation/</guid>
    <description>A validated Sigma rule that flags IAM privilege-escalation activity in AWS CloudTrail — policy attachment, inline policy injection, and password-policy tampering by an unexpected principal.</description>
    <category>Detection Rules</category>
    <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Detecting Impossible Travel Without Expensive UEBA Tooling</title>
    <link>https://logtriage.app/blog/impossible-travel-detection/</link>
    <guid isPermaLink="true">https://logtriage.app/blog/impossible-travel-detection/</guid>
    <description>Impossible travel detection doesn't need a UEBA platform — haversine distance and elapsed time on sign-in coordinates is enough.</description>
    <category>Blog</category>
    <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>What a Single Confirmed-Malicious Threat Intel Hit Should Do to Your Risk Score</title>
    <link>https://logtriage.app/blog/single-ti-hit-should-spike-score/</link>
    <guid isPermaLink="true">https://logtriage.app/blog/single-ti-hit-should-spike-score/</guid>
    <description>Why additive risk scoring under-reacts to a single confirmed-malicious threat intelligence verdict, and how a floor rule fixes it.</description>
    <category>Blog</category>
    <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Why a curl User-Agent Isn't Automatically Malicious</title>
    <link>https://logtriage.app/blog/context-aware-risk-scoring/</link>
    <guid isPermaLink="true">https://logtriage.app/blog/context-aware-risk-scoring/</guid>
    <description>Context-aware risk scoring explained: why the same user-agent string can be low risk on one endpoint and critical on another.</description>
    <category>Blog</category>
    <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
  </item>
</channel>
</rss>
