-
-
Notifications
You must be signed in to change notification settings - Fork 2.5k
Pull requests: SigmaHQ/sigma
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Okta Session Impersonation
Review Needed
The PR requires review
Rules
#5816
opened Dec 27, 2025 by
zendannyy
Loading…
update: disable autologger session
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5815
opened Dec 26, 2025 by
swachchhanda000
Loading…
new: Disable credential guard
Maintenance
Related to additions and update of the repository features
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5814
opened Dec 26, 2025 by
swachchhanda000
Loading…
new: AMSI Disabled via Registry Modification
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5813
opened Dec 25, 2025 by
swachchhanda000
Loading…
chore: t1562.001 regression tests
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5812
opened Dec 23, 2025 by
swachchhanda000
•
Draft
new: Vulnerable Driver Blocklist and HVCI Disable via Registry
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5811
opened Dec 22, 2025 by
swachchhanda000
Loading…
PUA - NSSM Execution
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5810
opened Dec 19, 2025 by
swachchhanda000
Loading…
update: internal tools registry tampering
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5808
opened Dec 17, 2025 by
swachchhanda000
Loading…
chore: add regression test for wmic related rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5807
opened Dec 15, 2025 by
swachchhanda000
Loading…
Update bitsadmin rules with regresstion tests
Rules
Windows
Pull request add/update windows related rules
add: Linux Security Capability Set Via Setfattr Utility
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
#5800
opened Dec 8, 2025 by
EzLucky
Loading…
ci: 🤖 Fix URL for sigma_schema_url
Maintenance
Related to additions and update of the repository features
Review Needed
The PR requires review
#5797
opened Dec 7, 2025 by
frack113
Loading…
cve-2025-49666 detection rule
Additional Data Needed
Author Input Required
changes the require information from original author of the rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5796
opened Dec 6, 2025 by
17patmaks
Loading…
6 tasks done
Add SSH brute force detection rule
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
fix: FPs on docker images
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
feat: Shai-Hulud: The Second Coming Rules
Emerging-Threats
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
add: Linux setcap setuid
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
Add detection rule for Chaos/Darkside Ransomware style hidden Cmd launching suspicious targets
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Add DPI-based network rule for responder footprints detection
Additional Data Needed
Author Input Required
changes the require information from original author of the rules
Review Needed
The PR requires review
Rules
#5751
opened Nov 11, 2025 by
cogResearch
Loading…
feat: phantom DLL hijacking rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
3 New rules
Additional Data Needed
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5747
opened Nov 8, 2025 by
louiselalanne
Loading…
new: bindfltapi.dll execution by suspicious process
Rules
Windows
Pull request add/update windows related rules
#5744
opened Nov 6, 2025 by
vl43den
Loading…
Feat: susp msix/appX package installation detection
Maintenance
Related to additions and update of the repository features
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
API_Hooking_detection
Linux
Pull request add/update linux related rules
Rules
#5739
opened Nov 2, 2025 by
AAtashGar
Loading…
Previous Next
ProTip!
What’s not been updated in a month: updated:<2025-11-27.