-
-
Notifications
You must be signed in to change notification settings - Fork 2.3k
Pull requests: SigmaHQ/sigma
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Dfir-report-27138
Rules
Windows
Pull request add/update windows related rules
#5174
opened Jan 27, 2025 by
tsale
Loading…
Tamper firewall by Registry
Rules
Windows
Pull request add/update windows related rules
#5172
opened Jan 26, 2025 by
frack113
Loading…
Add missing detection.emerging-threats tags
Emerging-Threats
Rules
#5169
opened Jan 24, 2025 by
frack113
Loading…
FP filters
Rules
Windows
Pull request add/update windows related rules
#5167
opened Jan 21, 2025 by
djlukic
Loading…
Discovery via registry queries detection added
Rules
Windows
Pull request add/update windows related rules
#5165
opened Jan 19, 2025 by
gbL2k
Loading…
Feat: tamper windows event log
Rules
Windows
Pull request add/update windows related rules
#5162
opened Jan 16, 2025 by
X-Junior
Loading…
Update proc_creation_win_reg_windows_defender_tamper.yml
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5148
opened Dec 31, 2024 by
MalGamy12
Loading…
Create new rule - Potential SSH Tunnel Persistence Install Using A Scheduled Task
Rules
Windows
Pull request add/update windows related rules
#5146
opened Dec 30, 2024 by
resp404nse
Loading…
Create proc_creation_win_remote_access_tools_anydesk_set_password_via_cli.yml
Rules
Windows
Pull request add/update windows related rules
#5143
opened Dec 25, 2024 by
DanielKoifman
Loading…
Privilege Escalation via CVE-2024-35250
Emerging-Threats
Rules
Work In Progress
Some changes are needed
#5136
opened Dec 20, 2024 by
Eyezuhk
Loading…
Fix Linux Buffer Overflow Attempts detection to correctly use regexes
Additional Data Needed
Linux
Pull request add/update linux related rules
Rules
#5134
opened Dec 18, 2024 by
kelnage
Loading…
Lnx auditd user discovery
Linux
Pull request add/update linux related rules
Rules
#5129
opened Dec 13, 2024 by
CheraghiMilad
Loading…
Proc creation lnx webshell detection
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5128
opened Dec 13, 2024 by
CheraghiMilad
Loading…
Some paths added
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5120
opened Dec 10, 2024 by
CheraghiMilad
Loading…
Some Images and one technique Added
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5118
opened Dec 10, 2024 by
CheraghiMilad
Loading…
Add rule for insert or remove rootkit
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5114
opened Dec 8, 2024 by
CheraghiMilad
Loading…
Add rule for device driver discovery
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5113
opened Dec 8, 2024 by
CheraghiMilad
Loading…
Add rule for detect browser information discovery
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
#5112
opened Dec 8, 2024 by
CheraghiMilad
Loading…
Test EDRSilencer
Rules
Windows
Pull request add/update windows related rules
#5111
opened Dec 7, 2024 by
frack113
Loading…
Add a new technique with a service
2nd Review Needed
PR need a second approval
Linux
Pull request add/update linux related rules
Rules
#5098
opened Nov 30, 2024 by
CheraghiMilad
Loading…
Proc creation lnx exfiltration data via sftp protocol (winscp tool)
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5096
opened Nov 29, 2024 by
CheraghiMilad
Loading…
add rule for impair system power settings
2nd Review Needed
PR need a second approval
Linux
Pull request add/update linux related rules
Rules
#5090
opened Nov 24, 2024 by
CheraghiMilad
Loading…
Update proc_creation_win_findstr_security_keyword_lookup.yml
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5085
opened Nov 20, 2024 by
MalGamy12
Loading…
Detects the immediate execution of Python web servers (e.g., http.server) via the command line interface (CLI)
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5079
opened Nov 13, 2024 by
mlakri
Loading…
Previous Next
ProTip!
Type g p on any issue or pull request to go back to the pull request listing page.