Skip to content

Pull requests: SigmaHQ/sigma

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

Fix rule to detect downloads via CertReq Rules Windows Pull request add/update windows related rules
#5727 opened Oct 27, 2025 by RiqTam Loading… Sigma-November-Release
1 new rule, 1 modification of older rule Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#5725 opened Oct 27, 2025 by Koifman Loading… Sigma-November-Release
Create win_trusted_for_delegation_rights.yml Rules Windows Pull request add/update windows related rules
#5723 opened Oct 24, 2025 by ShujiTsushima Loading…
Create enumeration_with_bloodhound_on_dc.yml Rules Windows Pull request add/update windows related rules
#5721 opened Oct 23, 2025 by ShujiTsushima Loading…
Fix #5603 2nd Review Needed PR need a second approval Rules Windows Pull request add/update windows related rules
#5720 opened Oct 22, 2025 by nasbench Loading… Sigma-October-Release
Add Regression Tests and Simulation Links - First Batch Maintenance Related to additions and update of the repository features Rules Windows Pull request add/update windows related rules
#5719 opened Oct 22, 2025 by nasbench Draft Sigma-November-Release
New rules related to recent reported ransom group activity (The Gentlemen) Rules Windows Pull request add/update windows related rules
#5717 opened Oct 22, 2025 by tropChaud Loading…
Add detection rules for abuse of OpenEDR's response features Rules Windows Pull request add/update windows related rules
#5716 opened Oct 22, 2025 by tsale Loading…
Fix remaining issues 2nd Review Needed PR need a second approval Rules Windows Pull request add/update windows related rules
#5708 opened Oct 19, 2025 by nasbench Loading… Sigma-October-Release
4
6
Add New Detection Rules for Grixba Malware Reconnaissance Activities Author Input Required changes the require information from original author of the rules Rules Windows Pull request add/update windows related rules Work In Progress Some changes are needed
#5707 opened Oct 19, 2025 by YxinMiracle Loading…
Merge PR #5706 from @swachchhanda000 - update PFX File Creation 2nd Review Needed PR need a second approval Awaiting Requested Review A review was requested from one of the maintainers Rules Windows Pull request add/update windows related rules
#5706 opened Oct 19, 2025 by swachchhanda000 Loading… Sigma-October-Release
macOS process create detections related to Bluenoroff macOS intrusion MacOS Pull request add/update macos related rules Rules
#5700 opened Oct 17, 2025 by stuartjash Loading…
add detection rule for suspicious use of BrowserCore.exe in PRT extra… Author Input Required changes the require information from original author of the rules Rules Windows Pull request add/update windows related rules Work In Progress Some changes are needed
#5676 opened Oct 3, 2025 by e0909 Loading…
Hunting rules for Hex Staging Attack and HTML Phishing Attachment 2nd Review Needed PR need a second approval Author Input Required changes the require information from original author of the rules Rules Windows Pull request add/update windows related rules
#5674 opened Oct 2, 2025 by skaynum Loading…
Wsl rules Additional Data Needed Author Input Required changes the require information from original author of the rules Rules Windows Pull request add/update windows related rules
#5668 opened Oct 1, 2025 by Liran017 Loading…
Disable ASLR Protection 2nd Review Needed PR need a second approval Linux Pull request add/update linux related rules Rules
#5661 opened Sep 26, 2025 by CheraghiMilad Loading… Sigma-October-Release
feat: ppl protected lsass dump via wsass.exe Rules Windows Pull request add/update windows related rules
#5652 opened Sep 16, 2025 by swachchhanda000 Loading…
feat: goldendMSA attack 2nd Review Needed PR need a second approval Rules Windows Pull request add/update windows related rules
#5646 opened Sep 11, 2025 by swachchhanda000 Loading…
feat: susp service priv esc and phantom hijack rules Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#5643 opened Sep 8, 2025 by swachchhanda000 Loading…
added new technique 2nd Review Needed PR need a second approval Linux Pull request add/update linux related rules Rules
#5634 opened Aug 28, 2025 by CheraghiMilad Loading… Sigma-October-Release
Added new linux rule 2nd Review Needed PR need a second approval Additional Data Needed Linux Pull request add/update linux related rules Rules
#5627 opened Aug 25, 2025 by tsale Loading… Sigma-October-Release
ProTip! Exclude everything labeled bug with -label:bug.