-
-
Notifications
You must be signed in to change notification settings - Fork 2.3k
Pull requests: SigmaHQ/sigma
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
FP filters
Rules
Windows
Pull request add/update windows related rules
#5167
opened Jan 21, 2025 by
djlukic
Loading…
Discovery via registry queries detection added
Rules
Windows
Pull request add/update windows related rules
#5165
opened Jan 19, 2025 by
gbL2k
Loading…
Feat: tamper windows event log
Rules
Windows
Pull request add/update windows related rules
#5162
opened Jan 16, 2025 by
X-Junior
Loading…
Update proc_creation_win_reg_windows_defender_tamper.yml
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5148
opened Dec 31, 2024 by
MalGamy12
Loading…
Create new rule - Potential SSH Tunnel Persistence Install Using A Scheduled Task
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5146
opened Dec 30, 2024 by
resp404nse
Loading…
Create proc_creation_win_remote_access_tools_anydesk_set_password_via_cli.yml
Rules
Windows
Pull request add/update windows related rules
#5143
opened Dec 25, 2024 by
DanielKoifman
Loading…
Privilege Escalation via CVE-2024-35250
Emerging-Threats
Rules
Work In Progress
Some changes are needed
#5136
opened Dec 20, 2024 by
Eyezuhk
Loading…
Fix Linux Buffer Overflow Attempts detection to correctly use regexes
Additional Data Needed
Linux
Pull request add/update linux related rules
Rules
#5134
opened Dec 18, 2024 by
kelnage
Loading…
Lnx auditd user discovery
Linux
Pull request add/update linux related rules
Rules
#5129
opened Dec 13, 2024 by
CheraghiMilad
Loading…
Proc creation lnx webshell detection
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5128
opened Dec 13, 2024 by
CheraghiMilad
Loading…
Some paths added
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5120
opened Dec 10, 2024 by
CheraghiMilad
Loading…
Some Images and one technique Added
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5118
opened Dec 10, 2024 by
CheraghiMilad
Loading…
Add rule for insert or remove rootkit
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5114
opened Dec 8, 2024 by
CheraghiMilad
Loading…
Add rule for device driver discovery
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5113
opened Dec 8, 2024 by
CheraghiMilad
Loading…
Add rule for detect browser information discovery
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5112
opened Dec 8, 2024 by
CheraghiMilad
Loading…
Test EDRSilencer
Rules
Windows
Pull request add/update windows related rules
#5111
opened Dec 7, 2024 by
frack113
Loading…
Add a new technique with a service
2nd Review Needed
PR need a second approval
Linux
Pull request add/update linux related rules
Rules
#5098
opened Nov 30, 2024 by
CheraghiMilad
Loading…
Proc creation lnx exfiltration data via sftp protocol (winscp tool)
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5096
opened Nov 29, 2024 by
CheraghiMilad
Loading…
add rule for impair system power settings
2nd Review Needed
PR need a second approval
Linux
Pull request add/update linux related rules
Rules
#5090
opened Nov 24, 2024 by
CheraghiMilad
Loading…
Update proc_creation_win_findstr_security_keyword_lookup.yml
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5085
opened Nov 20, 2024 by
MalGamy12
Loading…
Detects the immediate execution of Python web servers (e.g., http.server) via the command line interface (CLI)
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5079
opened Nov 13, 2024 by
mlakri
Loading…
Create Suspicious_Access_Attempt_to_the_cert Windows_Share_Possible_C…
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5073
opened Nov 7, 2024 by
NinnessOtu
Loading…
RightToLeft Obfuscation - PowerShell
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
This is a proposal for SUID Enumeration Using Find
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
Create microsoft365_teams_guest_rmm_deployment.yml
Author Input Required
changes the require information from original author of the rules
Rules
Work In Progress
Some changes are needed
#5066
opened Nov 1, 2024 by
prashanthpulisetti
Loading…
Previous Next
ProTip!
Type g i on any issue or pull request to go back to the issue listing page.