-
-
Notifications
You must be signed in to change notification settings - Fork 2.2k
Pull requests: SigmaHQ/sigma
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
fix: NSIS install using $TEMP are flags matching rules
Rules
Windows
Pull request add/update windows related rules
#5152
opened Jan 3, 2025 by
Ti-R
Loading…
Promote Older Rules From
experimental
to test
#5149
opened Jan 1, 2025 by
github-actions
bot
Loading…
Update proc_creation_win_reg_windows_defender_tamper.yml
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5148
opened Dec 31, 2024 by
MalGamy12
Loading…
Create new rule - Potential SSH Tunnel Persistence Install Using A Scheduled Task
Rules
Windows
Pull request add/update windows related rules
#5146
opened Dec 30, 2024 by
resp404nse
Loading…
Create proc_creation_win_remote_access_tools_anydesk_set_password_via_cli.yml
Rules
Windows
Pull request add/update windows related rules
#5143
opened Dec 25, 2024 by
DanielKoifman
Loading…
Privilege Escalation via CVE-2024-35250
Author Input Required
changes the require information from original author of the rules
Emerging-Threats
Rules
Work In Progress
Some changes are needed
#5136
opened Dec 20, 2024 by
Eyezuhk
Loading…
Reg.exe Detections added
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5135
opened Dec 19, 2024 by
gbL2k
Loading…
Fix Linux Buffer Overflow Attempts detection to correctly use regexes
Additional Data Needed
Linux
Pull request add/update linux related rules
Rules
#5134
opened Dec 18, 2024 by
kelnage
Loading…
Lnx auditd user discovery
Linux
Pull request add/update linux related rules
Rules
#5129
opened Dec 13, 2024 by
CheraghiMilad
Loading…
Proc creation lnx webshell detection
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5128
opened Dec 13, 2024 by
CheraghiMilad
Loading…
Some paths added
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5120
opened Dec 10, 2024 by
CheraghiMilad
Loading…
Some Images and one technique Added
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5118
opened Dec 10, 2024 by
CheraghiMilad
Loading…
Add rule for insert or remove rootkit
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5114
opened Dec 8, 2024 by
CheraghiMilad
Loading…
Add rule for device driver discovery
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5113
opened Dec 8, 2024 by
CheraghiMilad
Loading…
Add rule for detect browser information discovery
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5112
opened Dec 8, 2024 by
CheraghiMilad
Loading…
Test EDRSilencer
Rules
Windows
Pull request add/update windows related rules
#5111
opened Dec 7, 2024 by
frack113
Loading…
Add a new technique with a service
2nd Review Needed
PR need a second approval
Linux
Pull request add/update linux related rules
Rules
#5098
opened Nov 30, 2024 by
CheraghiMilad
Loading…
Proc creation lnx exfiltration data via sftp protocol (winscp tool)
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5096
opened Nov 29, 2024 by
CheraghiMilad
Loading…
add rule for impair system power settings
2nd Review Needed
PR need a second approval
Linux
Pull request add/update linux related rules
Rules
#5090
opened Nov 24, 2024 by
CheraghiMilad
Loading…
Expand ESXi Detections with ESXCli & VIM-CMD Detections
2nd Review Needed
PR need a second approval
Linux
Pull request add/update linux related rules
Rules
#5087
opened Nov 23, 2024 by
AlbinoGazelle
Loading…
Update proc_creation_win_findstr_security_keyword_lookup.yml
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5085
opened Nov 20, 2024 by
MalGamy12
Loading…
Detects the immediate execution of Python web servers (e.g., http.server) via the command line interface (CLI)
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5079
opened Nov 13, 2024 by
mlakri
Loading…
Create Suspicious_Access_Attempt_to_the_cert Windows_Share_Possible_C…
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5073
opened Nov 7, 2024 by
NinnessOtu
Loading…
RightToLeft Obfuscation - PowerShell
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
Previous Next
ProTip!
Filter pull requests by the default branch with base:master.