-
-
Notifications
You must be signed in to change notification settings - Fork 2.4k
Pull requests: SigmaHQ/sigma
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
chore: update evtx baseline to v0.8.2
Bug
Indicates a bug with one of the tools and features provided by the project
Maintenance
Related to additions and update of the repository features
Work In Progress
Some changes are needed
#5679
opened Oct 6, 2025 by
phantinuss
•
Draft
feat: add nftables delete/flush to modify system firewall selection set
Linux
Pull request add/update linux related rules
Rules
#5677
opened Oct 3, 2025 by
vl43den
Loading…
add detection rule for suspicious use of BrowserCore.exe in PRT extra…
Rules
Windows
Pull request add/update windows related rules
#5676
opened Oct 3, 2025 by
e0909
Loading…
feat: enhance lsass procdump with additional flags and service names
Rules
Windows
Pull request add/update windows related rules
#5675
opened Oct 3, 2025 by
vl43den
Loading…
October Hunting rules
Rules
Windows
Pull request add/update windows related rules
#5674
opened Oct 2, 2025 by
skaynum
Loading…
feat: add detection rules for CVE-2025-32463 sudo chroot vulnerability
2nd Review Needed
PR need a second approval
Emerging-Threats
Rules
Adding persistence and curl data exfil for AMOS and renaming of folder to Atomic MacOS Stealer
Emerging-Threats
Rules
#5669
opened Oct 2, 2025 by
JasonPhang98
Loading…
Update proc_creation_win_werfaultsecure_process_freeze.yml
Rules
Windows
Pull request add/update windows related rules
#5663
opened Sep 30, 2025 by
EzLucky
Loading…
feat: add detection for CVE-2025-20333 and CVE-2025-20362
Emerging-Threats
Rules
#5662
opened Sep 27, 2025 by
swachchhanda000
Loading…
Disable ASLR Protection
Linux
Pull request add/update linux related rules
Rules
#5661
opened Sep 26, 2025 by
CheraghiMilad
Loading…
feat: add rule to detect deletion of RunMRU registry key
Rules
Windows
Pull request add/update windows related rules
#5660
opened Sep 25, 2025 by
swachchhanda000
Loading…
feat: shai hulud worm targeting npm supply chain attack
2nd Review Needed
PR need a second approval
Emerging-Threats
Rules
Windows
Pull request add/update windows related rules
#5658
opened Sep 24, 2025 by
swachchhanda000
Loading…
feat: rules to detect EDR_Freeze
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5657
opened Sep 24, 2025 by
swachchhanda000
Loading…
Bit new rule
Linux
Pull request add/update linux related rules
Rules
Windows
Pull request add/update windows related rules
#5655
opened Sep 23, 2025 by
AAtashGar
Loading…
FP filters
2nd Review Needed
PR need a second approval
False-Positive Fix
Pull Request fixes a false positive with one of the rules
Rules
Windows
Pull request add/update windows related rules
#5654
opened Sep 22, 2025 by
djlukic
Loading…
feat: ppl protected lsass dump via wsass.exe
Rules
Windows
Pull request add/update windows related rules
#5652
opened Sep 16, 2025 by
swachchhanda000
Loading…
Api new rule
Linux
Pull request add/update linux related rules
Rules
#5651
opened Sep 15, 2025 by
AAtashGar
Loading…
Timer new rule
Linux
Pull request add/update linux related rules
Rules
#5650
opened Sep 15, 2025 by
AAtashGar
Loading…
Apt backdoor new rule
Linux
Pull request add/update linux related rules
Rules
#5649
opened Sep 15, 2025 by
AAtashGar
Loading…
feat: goldendMSA attack
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5646
opened Sep 11, 2025 by
swachchhanda000
Loading…
feat: susp service priv esc and phantom hijack rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5643
opened Sep 8, 2025 by
swachchhanda000
Loading…
feat: iis webserver logs deletion
2nd Review Needed
PR need a second approval
Rules
Windows
Pull request add/update windows related rules
#5640
opened Sep 2, 2025 by
swachchhanda000
Loading…
added new technique
Linux
Pull request add/update linux related rules
Rules
#5634
opened Aug 28, 2025 by
CheraghiMilad
Loading…
Update win_system_hack_smbexec.yml
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5632
opened Aug 28, 2025 by
k4nfr3
Loading…
Previous Next
ProTip!
Type g i on any issue or pull request to go back to the issue listing page.