Skip to content

Pull requests: SigmaHQ/sigma

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Sort

Pull requests list

fix: NSIS install using $TEMP are flags matching rules Rules Windows Pull request add/update windows related rules
#5152 opened Jan 3, 2025 by Ti-R Loading…
Archive New Rule References
#5150 opened Jan 1, 2025 by github-actions bot Loading…
Promote Older Rules From experimental to test
#5149 opened Jan 1, 2025 by github-actions bot Loading…
Update proc_creation_win_reg_windows_defender_tamper.yml 2nd Review Needed PR need a second approval Rules Windows Pull request add/update windows related rules
#5148 opened Dec 31, 2024 by MalGamy12 Loading…
Create new rule - Potential SSH Tunnel Persistence Install Using A Scheduled Task Rules Windows Pull request add/update windows related rules
#5146 opened Dec 30, 2024 by resp404nse Loading…
Create proc_creation_win_remote_access_tools_anydesk_set_password_via_cli.yml Rules Windows Pull request add/update windows related rules
#5143 opened Dec 25, 2024 by DanielKoifman Loading…
Privilege Escalation via CVE-2024-35250 Author Input Required changes the require information from original author of the rules Emerging-Threats Rules Work In Progress Some changes are needed
#5136 opened Dec 20, 2024 by Eyezuhk Loading…
Reg.exe Detections added Author Input Required changes the require information from original author of the rules Rules Windows Pull request add/update windows related rules
#5135 opened Dec 19, 2024 by gbL2k Loading…
Fix Linux Buffer Overflow Attempts detection to correctly use regexes Additional Data Needed Linux Pull request add/update linux related rules Rules
#5134 opened Dec 18, 2024 by kelnage Loading…
Lnx auditd user discovery Linux Pull request add/update linux related rules Rules
#5129 opened Dec 13, 2024 by CheraghiMilad Loading…
Proc creation lnx webshell detection Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules
#5128 opened Dec 13, 2024 by CheraghiMilad Loading…
Some paths added Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules
#5120 opened Dec 10, 2024 by CheraghiMilad Loading…
Some Images and one technique Added Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules
#5118 opened Dec 10, 2024 by CheraghiMilad Loading…
Add rule for insert or remove rootkit Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules Work In Progress Some changes are needed
#5114 opened Dec 8, 2024 by CheraghiMilad Loading…
Add rule for device driver discovery Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules Work In Progress Some changes are needed
#5113 opened Dec 8, 2024 by CheraghiMilad Loading…
Add rule for detect browser information discovery Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules
#5112 opened Dec 8, 2024 by CheraghiMilad Loading…
Test EDRSilencer Rules Windows Pull request add/update windows related rules
#5111 opened Dec 7, 2024 by frack113 Loading…
Add a new technique with a service 2nd Review Needed PR need a second approval Linux Pull request add/update linux related rules Rules
#5098 opened Nov 30, 2024 by CheraghiMilad Loading…
Proc creation lnx exfiltration data via sftp protocol (winscp tool) Linux Pull request add/update linux related rules Rules Work In Progress Some changes are needed
#5096 opened Nov 29, 2024 by CheraghiMilad Loading…
add rule for impair system power settings 2nd Review Needed PR need a second approval Linux Pull request add/update linux related rules Rules
#5090 opened Nov 24, 2024 by CheraghiMilad Loading…
Expand ESXi Detections with ESXCli & VIM-CMD Detections 2nd Review Needed PR need a second approval Linux Pull request add/update linux related rules Rules
#5087 opened Nov 23, 2024 by AlbinoGazelle Loading…
Update proc_creation_win_findstr_security_keyword_lookup.yml Rules Windows Pull request add/update windows related rules Work In Progress Some changes are needed
#5085 opened Nov 20, 2024 by MalGamy12 Loading…
Detects the immediate execution of Python web servers (e.g., http.server) via the command line interface (CLI) Linux Pull request add/update linux related rules Rules Work In Progress Some changes are needed
#5079 opened Nov 13, 2024 by mlakri Loading…
Create Suspicious_Access_Attempt_to_the_cert Windows_Share_Possible_C… Rules Windows Pull request add/update windows related rules Work In Progress Some changes are needed
#5073 opened Nov 7, 2024 by NinnessOtu Loading…
RightToLeft Obfuscation - PowerShell Author Input Required changes the require information from original author of the rules Rules Windows Pull request add/update windows related rules Work In Progress Some changes are needed
#5072 opened Nov 6, 2024 by FilipPwn Draft
ProTip! Filter pull requests by the default branch with base:master.