-
-
Notifications
You must be signed in to change notification settings - Fork 2.5k
Pull requests: SigmaHQ/sigma
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Improve DNS Exfiltration detection logic for Invoke-DNSExfiltrator (#…
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5801
opened Dec 9, 2025 by
toheeb-orelope
Loading…
add: Linux Security Capability Set Via Setfattr Utility
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
#5800
opened Dec 8, 2025 by
EzLucky
Loading…
Update The PR requires review
Rules
Potential Malicious Usage of CloudTrail System Manager
Review Needed
ci: 🤖 Fix URL for sigma_schema_url
Maintenance
Related to additions and update of the repository features
Ready to Merge
Review Needed
The PR requires review
#5797
opened Dec 7, 2025 by
frack113
Loading…
cve-2025-49666 detection rule
Additional Data Needed
Author Input Required
changes the require information from original author of the rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5796
opened Dec 6, 2025 by
17patmaks
Loading…
6 tasks done
new: CVE-2025-55182 react2shell rules
Emerging-Threats
Review Needed
The PR requires review
Rules
#5795
opened Dec 6, 2025 by
swachchhanda000
Loading…
Add SSH brute force detection rule
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
Metadata Updates - Batch 1
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
Add Detection Rule for Oracle OIM Pre-Auth Authentication Bypass (CVE-2025-61757)
Emerging-Threats
Review Needed
The PR requires review
Rules
Work In Progress
Some changes are needed
#5781
opened Nov 29, 2025 by
YxinMiracle
Loading…
fix: FPs on docker images
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
feat: more edrfreeze rules
Maintenance
Related to additions and update of the repository features
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5777
opened Nov 27, 2025 by
swachchhanda000
Loading…
Added rules related to ArcGIS Server Object Extension abuse
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
feat: Shai-Hulud: The Second Coming Rules
Emerging-Threats
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
add: Linux setcap setuid
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
Add detection rule for Chaos/Darkside Ransomware style hidden Cmd launching suspicious targets
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
Add DPI-based network rule for responder footprints detection
Additional Data Needed
Author Input Required
changes the require information from original author of the rules
Review Needed
The PR requires review
Rules
#5751
opened Nov 11, 2025 by
cogResearch
Loading…
feat: phantom DLL hijacking rules
Author Input Required
changes the require information from original author of the rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
3 New rules
Additional Data Needed
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5747
opened Nov 8, 2025 by
louiselalanne
Loading…
new: bindfltapi.dll execution by suspicious process
Rules
Windows
Pull request add/update windows related rules
#5744
opened Nov 6, 2025 by
vl43den
Loading…
Feat: susp msix/appX package installation detection
Maintenance
Related to additions and update of the repository features
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
API_Hooking_detection
Linux
Pull request add/update linux related rules
Rules
#5739
opened Nov 2, 2025 by
AAtashGar
Loading…
Add detection rules for abuse of OpenEDR's response features
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5716
opened Oct 22, 2025 by
tsale
Loading…
macOS process create detections related to Bluenoroff macOS intrusion
MacOS
Pull request add/update macos related rules
Rules
#5700
opened Oct 17, 2025 by
stuartjash
Loading…
add detection rule for suspicious use of BrowserCore.exe in PRT extra…
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#5676
opened Oct 3, 2025 by
e0909
Loading…
Previous Next
ProTip!
Type g i on any issue or pull request to go back to the issue listing page.