Skip to content

Pull requests: SigmaHQ/sigma

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Sort

Pull requests list

Added ordinal of ShellExec_RunDLL Rules Windows Pull request add/update windows related rules
#5082 opened Nov 16, 2024 by swachchhanda000 Loading…
Detect RTLO extension spoofing, MITRE T1036.002 in File-Events Rules Windows Pull request add/update windows related rules
#5081 opened Nov 15, 2024 by cod3nym Loading…
Archive New Rule References
#5080 opened Nov 15, 2024 by github-actions bot Loading…
Detects the immediate execution of Python web servers (e.g., http.server) via the command line interface (CLI) Linux Pull request add/update linux related rules Rules Work In Progress Some changes are needed
#5079 opened Nov 13, 2024 by mlakri Loading…
Create net_connection_win_susp_azurefd_connection.yml 2nd Review Needed PR need a second approval Rules Windows Pull request add/update windows related rules
#5077 opened Nov 11, 2024 by IsaacDunham Loading…
Update proc_creation_win_expand_cabinet_files.yml 2nd Review Needed PR need a second approval Rules Windows Pull request add/update windows related rules
#5075 opened Nov 10, 2024 by MalGamy12 Loading…
Create Suspicious_Access_Attempt_to_the_cert Windows_Share_Possible_C… Rules Windows Pull request add/update windows related rules Work In Progress Some changes are needed
#5073 opened Nov 7, 2024 by NinnessOtu Loading…
RightToLeft Obfuscation - PowerShell Author Input Required changes the require information from original author of the rules Rules Windows Pull request add/update windows related rules Work In Progress Some changes are needed
#5072 opened Nov 6, 2024 by FilipPwn Draft
This is a proposal for SUID Enumeration Using Find Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules Work In Progress Some changes are needed
#5071 opened Nov 4, 2024 by mlakri Draft
Add more imgaes to the rule (proc_creation_lnx_omigod_scx_runasprovider_executeshellcommand) Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules Work In Progress Some changes are needed
#5069 opened Nov 2, 2024 by CheraghiMilad Draft
Create microsoft365_teams_guest_rmm_deployment.yml Author Input Required changes the require information from original author of the rules Rules Work In Progress Some changes are needed
#5066 opened Nov 1, 2024 by prashanthpulisetti Loading…
Converted Auditd rules Linux Pull request add/update linux related rules Rules
#5059 opened Oct 22, 2024 by defensivedepth Loading…
Create proc_creation_win_reg_add_AutoAdminLogon_key.yml Rules Windows Pull request add/update windows related rules
#5053 opened Oct 16, 2024 by Mahir-Ali-khan Loading…
detect vacuuming of journald as clearing syslog Linux Pull request add/update linux related rules Rules
#5050 opened Oct 14, 2024 by wieso-itzi Loading…
Update proc_creation_win_run_from_zip.yml Author Input Required changes the require information from original author of the rules Rules Work In Progress Some changes are needed
#5047 opened Oct 13, 2024 by CheraghiMilad Loading…
Add Suspicius Setup16 Parent Rules Windows Pull request add/update windows related rules Work In Progress Some changes are needed
#5046 opened Oct 13, 2024 by frack113 Loading…
Update win_security_register_new_logon_process_by_rubeus.yml Rules Windows Pull request add/update windows related rules
#5041 opened Oct 9, 2024 by Koifman Loading…
Exfiltration Over Alternative Protocol - Linux Author Input Required changes the require information from original author of the rules Linux Pull request add/update linux related rules Rules Work In Progress Some changes are needed
#5035 opened Oct 6, 2024 by CheraghiMilad Loading…
Update Suspicious Double Extension File Execution Rules Rules Windows Pull request add/update windows related rules Work In Progress Some changes are needed
#5030 opened Oct 1, 2024 by MalGamy12 Loading…
new_rules Rules
#5023 opened Sep 23, 2024 by saakovv Loading…
aws_new_rules Author Input Required changes the require information from original author of the rules Rules Work In Progress Some changes are needed
#5021 opened Sep 21, 2024 by saakovv Loading…
github-new-rules Rules Work In Progress Some changes are needed
#5018 opened Sep 20, 2024 by saakovv Loading…
Modify or Delete AWS RDS Cluster Rules
#5017 opened Sep 20, 2024 by saakovv Loading…
ProTip! Find all pull requests that aren't related to any open issues with -linked:issue.