Skip to content

Fix remove documentation from references#6048

Open
kurisukun wants to merge 2 commits into
SigmaHQ:masterfrom
swisspostcs:fix_remove-documentation-from-references
Open

Fix remove documentation from references#6048
kurisukun wants to merge 2 commits into
SigmaHQ:masterfrom
swisspostcs:fix_remove-documentation-from-references

Conversation

@kurisukun

Copy link
Copy Markdown

Summary of the Pull Request

Removing refereces to the tool Krueger in the rule. Since process "System" is filtered in the rule and only fires an alert when an uncommon executable writes in \Windows\System32\CodeIntegrity\.

Changelog

fix: Potentially Suspicious WDAC Policy File Creation - remove references of Krueger
new: Potentially Suspicious WDAC Policy File Creation - add regression test

Example Log Event

Fixed Issues

EVTX and JSON files for regression tests were added.

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@github-actions

github-actions Bot commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

Welcome 👋

It looks like this is your first pull request on the Sigma rules repository!

Please make sure to read the SigmaHQ conventions to make sure your contribution is adhering to best practices and has all the necessary elements in place for a successful approval.

Thanks again, and welcome to the Sigma community! 😃

@github-actions github-actions Bot added Rules Review Needed The PR requires review Windows Pull request add/update windows related rules labels Jun 3, 2026
@swachchhanda000 swachchhanda000 requested a review from X-Junior June 5, 2026 11:53
- id: 1d2de8a6-4803-4fde-b85b-f58f3aa7a705
title: Potentially Suspicious WDAC Policy File Creation
regression_tests_info:
- name: Negative Detection Test

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Currently we only accept positive detection tests. So I will be removing this.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kurisukun i do not have permission over your fork, please remove the testing related files

@nasbench nasbench added this to the Sigma-May-Release milestone Jun 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Review Needed The PR requires review Rules Windows Pull request add/update windows related rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants