-
-
Notifications
You must be signed in to change notification settings - Fork 2.4k
Pull requests: SigmaHQ/sigma
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Winrs
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
fix: add filters on some reg related rules
Emerging-Threats
False-Positive Fix
Pull Request fixes a false positive with one of the rules
Rules
Windows
Pull request add/update windows related rules
#5601
opened Aug 19, 2025 by
swachchhanda000
Loading…
Feat: extend syslog clearing rule - add variants & empty-file idioms
Linux
Pull request add/update linux related rules
Ready to Merge
Rules
Add fp filter for some more rules
False-Positive Fix
Pull Request fixes a false positive with one of the rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5598
opened Aug 15, 2025 by
swachchhanda000
Loading…
Registry Modifications through VBScripts
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
update: suspicious file activity related to file sharing websites
2nd Review Needed
PR need a second approval
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5574
opened Aug 1, 2025 by
swachchhanda000
Loading…
[New Rule] - Unusual svchost Command Line Parameter
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5550
opened Jul 28, 2025 by
Liran017
Loading…
update: windowsInstaller com object related rules
Rules
Windows
Pull request add/update windows related rules
#5548
opened Jul 28, 2025 by
swachchhanda000
Loading…
New Sigma Rule : AWS GuardDuty Detector Deleted Or Updated Added
Rules
#5536
opened Jul 20, 2025 by
suKTech24
Loading…
Fix: FileFix - Suspicious Child Process from Browser File Upload Abuse
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5527
opened Jul 16, 2025 by
seanthegeek
Loading…
Suspicious Use of for Loop with Directory Search in CMD
Rules
Windows
Pull request add/update windows related rules
#5519
opened Jul 10, 2025 by
jstnk9
Loading…
[New Rule] - Detect NTFS symlink behavior modifications using fsutil command
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5504
opened Jun 30, 2025 by
tsale
Loading…
feat: Reg shell open command
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5487
opened Jun 17, 2025 by
swachchhanda000
Loading…
Update: Suspicious Copy From or To System Directory
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5482
opened Jun 16, 2025 by
swachchhanda000
Loading…
update: SquiblyTwo Related Rules
Rules
Windows
Pull request add/update windows related rules
#5476
opened Jun 12, 2025 by
swachchhanda000
Loading…
feat: Renamed Schtasks Execution
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5475
opened Jun 12, 2025 by
swachchhanda000
Loading…
Process Name Masquerading
2nd Review Needed
PR need a second approval
Linux
Pull request add/update linux related rules
Rules
#5470
opened Jun 5, 2025 by
CheraghiMilad
Loading…
Hacktool - Defendnot Execution
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5469
opened Jun 5, 2025 by
swachchhanda000
Loading…
fix: make use of enriched auditd fields
Linux
Pull request add/update linux related rules
Rules
#5468
opened Jun 5, 2025 by
phantinuss
Loading…
add proc_modules method
Linux
Pull request add/update linux related rules
Rules
#5460
opened Jun 3, 2025 by
CheraghiMilad
Loading…
fix logic of detection section
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5458
opened Jun 3, 2025 by
CheraghiMilad
Loading…
fix logic of detection section
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5457
opened Jun 2, 2025 by
CheraghiMilad
Loading…
fix logic of detection
Author Input Required
changes the require information from original author of the rules
Linux
Pull request add/update linux related rules
Rules
Work In Progress
Some changes are needed
#5456
opened Jun 2, 2025 by
CheraghiMilad
Loading…
change suid_dumpable config
Author Input Required
changes the require information from original author of the rules
Emerging-Threats
Rules
Work In Progress
Some changes are needed
#5454
opened Jun 2, 2025 by
CheraghiMilad
Loading…
ProTip!
Updated in the last three days: updated:>2025-10-20.