-
-
Notifications
You must be signed in to change notification settings - Fork 2.3k
Issues: SigmaHQ/sigma
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
The DFIR Report Rule Modifications
2nd Review Needed
PR need a second approval
Emerging-Threats
Rules
Windows
Pull request add/update windows related rules
#5265
opened Apr 16, 2025 by
tsale
Loading…
Create win_system_possible_ipv6_dns_takeover.yml
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5242
opened Mar 22, 2025 by
NinnessOtu
Loading…
Adding rule for detecting recaptcha phish process executions
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
updated adfind related rules
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
Added new Fortinet Fortigate rules
2nd Review Needed
PR need a second approval
Additional Data Needed
Rules
#5197
opened Feb 20, 2025 by
inthecyber
Loading…
Updated and Added rule related to Autorun Registry
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
Added new rules for Malware abusing grimresource and rtlo techniques
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5183
opened Feb 5, 2025 by
swachchhanda000
Loading…
Analytic for WDAC Policy abuse
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5175
opened Jan 30, 2025 by
netgrain
Loading…
add rule for impair system power settings
2nd Review Needed
PR need a second approval
Linux
Pull request add/update linux related rules
Rules
#5090
opened Nov 24, 2024 by
CheraghiMilad
Loading…
detect vacuuming of journald as clearing syslog
2nd Review Needed
PR need a second approval
Linux
Pull request add/update linux related rules
Rules
#5050
opened Oct 14, 2024 by
wieso-itzi
Loading…
Create proc_creation_win_code_devtunnel_tunneling.yaml
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5004
opened Sep 9, 2024 by
0xAnalyst
Loading…
ProTip!
Follow long discussions with comments:>50.