Skip to content

Pull requests: SigmaHQ/sigma

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Sort

Pull requests list

Increased coverage for new libraries of AADinternals Rules Windows Pull request add/update windows related rules
#5186 opened Feb 6, 2025 by swachchhanda000 Loading…
Added new rule that detect execution of nimscan, a port scanner utility 2nd Review Needed PR need a second approval Rules Windows Pull request add/update windows related rules
#5184 opened Feb 5, 2025 by swachchhanda000 Loading…
Added new rules for Malware abusing grimresource and rtlo techniques 2nd Review Needed PR need a second approval Rules Windows Pull request add/update windows related rules
#5183 opened Feb 5, 2025 by swachchhanda000 Loading…
Update registry_set_disable_windows_event_log_access.yml Rules Windows Pull request add/update windows related rules
#5182 opened Feb 5, 2025 by Koifman Loading…
update Ssh proxy execution rule Rules Windows Pull request add/update windows related rules
#5181 opened Feb 5, 2025 by swachchhanda000 Loading…
Add proc_creation_win_parent_run_itself Author Input Required changes the require information from original author of the rules Rules Windows Pull request add/update windows related rules
#5180 opened Feb 4, 2025 by frack113 Loading…
Analytic for WDAC Policy abuse Author Input Required changes the require information from original author of the rules Rules Windows Pull request add/update windows related rules
#5175 opened Jan 30, 2025 by netgrain Loading…
feat: Potential Common Log File Exploit Rules Windows Pull request add/update windows related rules
#5173 opened Jan 26, 2025 by X-Junior Loading…
Tamper firewall by Registry Rules Windows Pull request add/update windows related rules
#5172 opened Jan 26, 2025 by frack113 Loading…
Discovery via registry queries detection added 2nd Review Needed PR need a second approval Rules Windows Pull request add/update windows related rules
#5165 opened Jan 19, 2025 by gbL2k Loading…
Update proc_creation_win_reg_windows_defender_tamper.yml Author Input Required changes the require information from original author of the rules Rules Windows Pull request add/update windows related rules Work In Progress Some changes are needed
#5148 opened Dec 31, 2024 by MalGamy12 Draft
Create new rule - Potential SSH Tunnel Persistence Install Using A Scheduled Task Rules Windows Pull request add/update windows related rules
#5146 opened Dec 30, 2024 by resp404nse Loading…
Create proc_creation_win_remote_access_tools_anydesk_set_password_via_cli.yml Rules Windows Pull request add/update windows related rules
#5143 opened Dec 25, 2024 by DanielKoifman Loading…
Privilege Escalation via CVE-2024-35250 Emerging-Threats Rules Work In Progress Some changes are needed
#5136 opened Dec 20, 2024 by Eyezuhk Loading…
Fix Linux Buffer Overflow Attempts detection to correctly use regexes Additional Data Needed Linux Pull request add/update linux related rules Rules
#5134 opened Dec 18, 2024 by kelnage Loading…
Lnx auditd user discovery Linux Pull request add/update linux related rules Rules
#5129 opened Dec 13, 2024 by CheraghiMilad Loading…
Proc creation lnx webshell detection Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules
#5128 opened Dec 13, 2024 by CheraghiMilad Loading…
Some paths added Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules
#5120 opened Dec 10, 2024 by CheraghiMilad Loading…
Some Images and one technique Added Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules
#5118 opened Dec 10, 2024 by CheraghiMilad Loading…
Add rule for insert or remove rootkit Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules Work In Progress Some changes are needed
#5114 opened Dec 8, 2024 by CheraghiMilad Loading…
Add rule for device driver discovery Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules Work In Progress Some changes are needed
#5113 opened Dec 8, 2024 by CheraghiMilad Loading…
Add rule for detect browser information discovery Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules
#5112 opened Dec 8, 2024 by CheraghiMilad Loading…
Test EDRSilencer Rules Windows Pull request add/update windows related rules
#5111 opened Dec 7, 2024 by frack113 Loading…
Add a new technique with a service 2nd Review Needed PR need a second approval Linux Pull request add/update linux related rules Rules
#5098 opened Nov 30, 2024 by CheraghiMilad Loading…
Proc creation lnx exfiltration data via sftp protocol (winscp tool) Linux Pull request add/update linux related rules Rules Work In Progress Some changes are needed
#5096 opened Nov 29, 2024 by CheraghiMilad Loading…
ProTip! What’s not been updated in a month: updated:<2025-01-07.