-
-
Notifications
You must be signed in to change notification settings - Fork 2.4k
Pull requests: SigmaHQ/sigma
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
feat: usage of restic for potential data exfiltration
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5713
opened Oct 21, 2025 by
swachchhanda000
Loading…
fix: rules for blackByte ransomware and wce detection
Emerging-Threats
Rules
Windows
Pull request add/update windows related rules
#5712
opened Oct 21, 2025 by
swachchhanda000
Loading…
2
feat: add AWS TruffleHog PUA detection rule
Rules
#5711
opened Oct 21, 2025 by
swachchhanda000
Loading…
Add filter for EventLogs in file_event_win_create
Rules
Windows
Pull request add/update windows related rules
#5710
opened Oct 20, 2025 by
dmytro-khadzhy-blackthorn
Loading…
Fix remaining issues
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
Add New Detection Rules for Grixba Malware Reconnaissance Activities
Rules
Windows
Pull request add/update windows related rules
#5707
opened Oct 19, 2025 by
YxinMiracle
Loading…
fix: filter onedrive creating pfx file
Ready to Merge
Rules
Windows
Pull request add/update windows related rules
macOS process create detections related to Bluenoroff macOS intrusion
MacOS
Pull request add/update macos related rules
Rules
#5700
opened Oct 17, 2025 by
stuartjash
Loading…
feat: usage or installation of wsl kali linux
Ready to Merge
Rules
Windows
Pull request add/update windows related rules
Create windows_smb_ipc_admin_no_signing.yml
Ready to Merge
Rules
Windows
Pull request add/update windows related rules
add detection rule for suspicious use of BrowserCore.exe in PRT extra…
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5676
opened Oct 3, 2025 by
e0909
Loading…
Hunting rules for Hex Staging Attack and HTML Phishing Attachment
2nd Review Needed
PR need a second approval
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5674
opened Oct 2, 2025 by
skaynum
Loading…
Adding persistence and curl data exfil for AMOS and renaming of folder to Atomic MacOS Stealer
Additional Data Needed
Author Input Required
changes the require information from original author of the rules
Emerging-Threats
Rules
Work In Progress
Some changes are needed
#5669
opened Oct 2, 2025 by
JasonPhang98
Loading…
Wsl rules
Additional Data Needed
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5668
opened Oct 1, 2025 by
Liran017
Loading…
feat: add detection for CVE-2025-20333 and CVE-2025-20362
Emerging-Threats
Rules
#5662
opened Sep 27, 2025 by
swachchhanda000
Loading…
Disable ASLR Protection
2nd Review Needed
PR need a second approval
Linux
Pull request add/update linux related rules
Rules
feat: add rule to detect deletion of RunMRU registry key
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5660
opened Sep 25, 2025 by
swachchhanda000
Loading…
FP filters
False-Positive Fix
Pull Request fixes a false positive with one of the rules
Ready to Merge
Rules
Windows
Pull request add/update windows related rules
feat: ppl protected lsass dump via wsass.exe
Rules
Windows
Pull request add/update windows related rules
#5652
opened Sep 16, 2025 by
swachchhanda000
Loading…
feat: goldendMSA attack
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5646
opened Sep 11, 2025 by
swachchhanda000
Loading…
feat: susp service priv esc and phantom hijack rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5643
opened Sep 8, 2025 by
swachchhanda000
Loading…
added new technique
2nd Review Needed
PR need a second approval
Linux
Pull request add/update linux related rules
Rules
Previous Next
ProTip!
Find all pull requests that aren't related to any open issues with -linked:issue.