-
-
Notifications
You must be signed in to change notification settings - Fork 2.4k
Pull requests: SigmaHQ/sigma
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
add rule to detect vshadow.exe with -exec parameter
Rules
Windows
Pull request add/update windows related rules
#5478
opened Jun 12, 2025 by
kivi280
Loading…
update: SquiblyTwo Related Rules
Rules
Windows
Pull request add/update windows related rules
#5476
opened Jun 12, 2025 by
swachchhanda000
Loading…
feat: Renamed Schtasks Execution
Rules
Windows
Pull request add/update windows related rules
#5475
opened Jun 12, 2025 by
swachchhanda000
Loading…
Process Name Masquerading
Linux
Pull request add/update linux related rules
Rules
#5470
opened Jun 5, 2025 by
CheraghiMilad
Loading…
Hacktool - Defendnot Execution
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5469
opened Jun 5, 2025 by
swachchhanda000
Loading…
fix: make use of enriched auditd fields
Linux
Pull request add/update linux related rules
Rules
#5468
opened Jun 5, 2025 by
phantinuss
Loading…
PowerShell MSI Install via WindowsInstaller COM From Remote Location
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5466
opened Jun 5, 2025 by
vx3r
Loading…
add proc_modules method
Linux
Pull request add/update linux related rules
Rules
#5460
opened Jun 3, 2025 by
CheraghiMilad
Loading…
fix logic of detection section
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5458
opened Jun 3, 2025 by
CheraghiMilad
Loading…
fix logic of detection section
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5457
opened Jun 2, 2025 by
CheraghiMilad
Loading…
fix logic of detection
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5456
opened Jun 2, 2025 by
CheraghiMilad
Loading…
The sysctl method has been added
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5455
opened Jun 2, 2025 by
CheraghiMilad
Loading…
change suid_dumpable config
Author Input Required
changes the require information from original author of the rules
Emerging-Threats
Rules
Work In Progress
Some changes are needed
#5454
opened Jun 2, 2025 by
CheraghiMilad
Loading…
add another technique
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5450
opened Jun 1, 2025 by
CheraghiMilad
Loading…
Create proc_creation_win_tacticalrmm_install_via_cli.yml
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5442
opened May 29, 2025 by
egycondor
Loading…
clear journalctl logs
Linux
Pull request add/update linux related rules
Rules
#5439
opened May 27, 2025 by
CheraghiMilad
Loading…
feat: BadSuccessor dMSA Abuse for Privileges Escalation
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5433
opened May 24, 2025 by
swachchhanda000
Loading…
New rules: MeshAgent arguments
MacOS
Pull request add/update macos related rules
Rules
Windows
Pull request add/update windows related rules
#5426
opened May 19, 2025 by
norbert791
Loading…
chore: give back list of promoted rules
2nd Review Needed
PR need a second approval
Maintenance
Related to additions and update of the repository features
#5420
opened May 15, 2025 by
ariel-anieli
Loading…
Add correlation rules from AT project
Correlation-Rules
Rules
Windows
Pull request add/update windows related rules
Indirect Command Execution via SFTP ProxyCommand
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5414
opened May 13, 2025 by
swachchhanda000
Loading…
Add rule: Office Macro Phishing Initial Access detection
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5411
opened May 10, 2025 by
arjun-tarakesh
Loading…
Fix: image_load/image_load_susp_unsigned_dll: simplify and use valid statu…
Rules
Windows
Pull request add/update windows related rules
#5410
opened May 8, 2025 by
Ti-R
Loading…
New Google Workspace rules
2nd Review Needed
PR need a second approval
Cloud
Pull request add/update cloud related rules
Rules
#5409
opened May 7, 2025 by
Luke57
Loading…
Add more keys concerned with lsa ppl protection
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5399
opened May 1, 2025 by
swachchhanda000
Loading…
Previous Next
ProTip!
Type g p on any issue or pull request to go back to the pull request listing page.