-
-
Notifications
You must be signed in to change notification settings - Fork 2.3k
Pull requests: SigmaHQ/sigma
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Promote Older Rules From
experimental
to test
#5216
opened Mar 1, 2025 by
github-actions
bot
Loading…
Add Rule: Zeek rule looking for suspicious file downloads
Ready to Merge
Rules
#5214
opened Feb 27, 2025 by
signalblur
Loading…
Automatically update heatmap json when new rule is pushed to master.
Maintenance
Related to additions and update of the repository features
Work In Progress
Some changes are needed
#5213
opened Feb 26, 2025 by
JrOrOneEquals1
Loading…
Update Nslookup PowerShell Download Cradle Rule with Extended Coverage
Ready to Merge
Rules
Windows
Pull request add/update windows related rules
#5211
opened Feb 25, 2025 by
HannesWid
Loading…
Updated to exclude false positives from common CLI searches like "fin…
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5209
opened Feb 24, 2025 by
kagebunsher
Loading…
Fixed fps and added coverage for ARM based windows dotnet paths
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5208
opened Feb 24, 2025 by
swachchhanda000
Loading…
Updated Anydesk related rules
Ready to Merge
Rules
Windows
Pull request add/update windows related rules
#5207
opened Feb 24, 2025 by
swachchhanda000
Loading…
First commit
Rules
Windows
Pull request add/update windows related rules
#5205
opened Feb 23, 2025 by
YousefNein
Loading…
Veeam get creds
Ready to Merge
Rules
Windows
Pull request add/update windows related rules
#5204
opened Feb 23, 2025 by
swachchhanda000
Loading…
updated adfind related rules
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5203
opened Feb 23, 2025 by
swachchhanda000
Loading…
New rule contribution for latest Public Report - case #27244
Ready to Merge
Rules
Windows
Pull request add/update windows related rules
#5198
opened Feb 20, 2025 by
DFIR-Detection
Loading…
Added new Fortinet Fortigate rules
2nd Review Needed
PR need a second approval
Additional Data Needed
Rules
#5197
opened Feb 20, 2025 by
inthecyber
•
Draft
Updated and Added rule related to Autorun Registry
Ready to Merge
Rules
Windows
Pull request add/update windows related rules
#5196
opened Feb 17, 2025 by
swachchhanda000
Loading…
Add detection rule for importing KMS key material, usable for AWS ran…
Author Input Required
changes the require information from original author of the rules
Rules
#5193
opened Feb 12, 2025 by
toopricey
Loading…
Add rule: Suspicious Certutil Decoding (experimental)
Rules
Windows
Pull request add/update windows related rules
#5188
opened Feb 7, 2025 by
Peter-Daniel-hkr
Loading…
Added new rules for Malware abusing grimresource and rtlo techniques
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5183
opened Feb 5, 2025 by
swachchhanda000
Loading…
update Ssh proxy execution rule
Rules
Windows
Pull request add/update windows related rules
#5181
opened Feb 5, 2025 by
swachchhanda000
Loading…
Add proc_creation_win_parent_run_itself
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5180
opened Feb 4, 2025 by
frack113
Loading…
Analytic for WDAC Policy abuse
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5175
opened Jan 30, 2025 by
netgrain
Loading…
Tamper firewall by Registry
Rules
Windows
Pull request add/update windows related rules
#5172
opened Jan 26, 2025 by
frack113
Loading…
Discovery via registry queries detection added
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5165
opened Jan 19, 2025 by
xlazarg
Loading…
Update proc_creation_win_reg_windows_defender_tamper.yml
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
Create new rule - Potential SSH Tunnel Persistence Install Using A Scheduled Task
Rules
Windows
Pull request add/update windows related rules
#5146
opened Dec 30, 2024 by
resp404nse
Loading…
Create proc_creation_win_remote_access_tools_anydesk_set_password_via_cli.yml
Rules
Windows
Pull request add/update windows related rules
#5143
opened Dec 25, 2024 by
DanielKoifman
Loading…
Previous Next
ProTip!
Type g p on any issue or pull request to go back to the pull request listing page.