Skip to content

update: expand LOLBIN file-drop detection coverage#6007

Open
swachchhanda000 wants to merge 2 commits into
SigmaHQ:masterfrom
swachchhanda000:susp_hh_file_creation
Open

update: expand LOLBIN file-drop detection coverage#6007
swachchhanda000 wants to merge 2 commits into
SigmaHQ:masterfrom
swachchhanda000:susp_hh_file_creation

Conversation

@swachchhanda000

Copy link
Copy Markdown
Collaborator

Summary of the Pull Request

Changelog

update: Legitimate Application Dropped Executable - add .pyc, .jar extensions
update: Legitimate Application Dropped Script - add various scripts extensions

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@github-actions github-actions Bot added Rules Review Needed The PR requires review Windows Pull request add/update windows related rules labels May 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Review Needed The PR requires review Rules Windows Pull request add/update windows related rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants