-
-
Notifications
You must be signed in to change notification settings - Fork 2.3k
Issues: SigmaHQ/sigma
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
feat: Suspicious CrushFTP Child Process
Author Input Required
changes the require information from original author of the rules
Emerging-Threats
Rules
Work In Progress
Some changes are needed
#5261
opened Apr 10, 2025 by
swachchhanda000
Loading…
Sigma rules to detect CVE 2025 29824 and susp BLF File Creation
Author Input Required
changes the require information from original author of the rules
Emerging-Threats
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5260
opened Apr 10, 2025 by
swachchhanda000
Loading…
Add rule to detect makecab staging of LOLBins
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5254
opened Apr 4, 2025 by
alexegorov1
Loading…
New Rules : PowerShell Console History File Access - file_access + proc_creation
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5253
opened Apr 4, 2025 by
EzLucky
Loading…
fixed fps in some rules specifically remote thread creation related
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
microsoft_sql_dangerous_operations
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
Automatically update heatmap json when new rule is pushed to master.
Author Input Required
changes the require information from original author of the rules
Maintenance
Related to additions and update of the repository features
Work In Progress
Some changes are needed
#5213
opened Feb 26, 2025 by
JrOrOneEquals1
Loading…
Updated to exclude false positives from common CLI searches like "fin…
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5209
opened Feb 24, 2025 by
kagebunsher
Loading…
Add detection rule for importing KMS key material, usable for AWS ran…
Author Input Required
changes the require information from original author of the rules
Rules
#5193
opened Feb 12, 2025 by
toopricey
Loading…
Add proc_creation_win_parent_run_itself
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5180
opened Feb 4, 2025 by
frack113
Loading…
Update proc_creation_win_reg_windows_defender_tamper.yml
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
Proc creation lnx webshell detection
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5128
opened Dec 13, 2024 by
CheraghiMilad
•
Draft
Some paths added
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5120
opened Dec 10, 2024 by
CheraghiMilad
•
Draft
Some Images and one technique Added
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5118
opened Dec 10, 2024 by
CheraghiMilad
Loading…
Add rule for insert or remove rootkit
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5114
opened Dec 8, 2024 by
CheraghiMilad
Loading…
Add rule for device driver discovery
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5113
opened Dec 8, 2024 by
CheraghiMilad
Loading…
Add rule for detect browser information discovery
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5112
opened Dec 8, 2024 by
CheraghiMilad
Loading…
This is a proposal for SUID Enumeration Using Find
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
Create microsoft365_teams_guest_rmm_deployment.yml
Author Input Required
changes the require information from original author of the rules
Rules
Work In Progress
Some changes are needed
#5066
opened Nov 1, 2024 by
prashanthpulisetti
Loading…
Converted Auditd rules
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5059
opened Oct 22, 2024 by
defensivedepth
Loading…
aws_new_rules
Author Input Required
changes the require information from original author of the rules
Rules
Work In Progress
Some changes are needed
#5021
opened Sep 21, 2024 by
saakovv
Loading…
ProTip!
no:milestone will show everything without a milestone.