Skip to content

Pull requests: SigmaHQ/sigma

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

Add rule: potential NTLM authentication coercion tool execution Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6111 opened Jul 5, 2026 by ashish-cybersec Loading…
RoguePlanet Exploit Rules Emerging-Threats Review Needed The PR requires review Rules
#6109 opened Jul 4, 2026 by st0pp3r Contributor Loading…
fix: net user rules coverage and deprecate redundant rule Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6107 opened Jul 3, 2026 by swachchhanda000 Collaborator Loading…
Add proxy rule: Base64 Encoded URL In Web Request Review Needed The PR requires review Rules
#6106 opened Jul 3, 2026 by Usurper-Vladimir Loading…
Add rule detecting inbound SSH drops on MikroTik WAN Review Needed The PR requires review Rules
#6105 opened Jul 2, 2026 by OriolesMagic333 Loading…
1 task done
Add rule: indirect command execution via scp.exe Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6104 opened Jul 2, 2026 by ashish-cybersec Loading…
Add rule: arbitrary command execution via git config override Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6103 opened Jul 2, 2026 by ashish-cybersec Loading…
new: wmi activity ntEventLogFile ClearEventLog failed attempts Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6100 opened Jul 2, 2026 by swachchhanda000 Collaborator Loading…
Add detection for PnPUtil driver and device removal activity Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6099 opened Jul 1, 2026 by Kvvvvvvvvv Loading…
Add cross-platform discovery/collection rules Linux Pull request add/update linux related rules MacOS Pull request add/update macos related rules Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6095 opened Jun 29, 2026 by einlamye Contributor Loading…
Add Sysinternals tooling and driver/UAC detection rules Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6094 opened Jun 29, 2026 by einlamye Contributor Loading…
Add Active Directory / Kerberos attack detection rules Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6093 opened Jun 29, 2026 by einlamye Contributor Loading…
Add ADS abuse and signed-binary LOLBIN detection rules Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6092 opened Jun 29, 2026 by einlamye Contributor Loading…
Enrich ATT&CK tags (T1654/T1652) and dedupe bcdedit safeboot logic Review Needed The PR requires review Rules Threat-Hunting Windows Pull request add/update windows related rules
#6091 opened Jun 29, 2026 by einlamye Contributor Loading…
rules/windows: add Dev Tunnel hosting or creation process_creation rule Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6089 opened Jun 28, 2026 by BL3IP Loading…
new: Dindoor Backdoor Malware rule Emerging-Threats Review Needed The PR requires review Rules
#6083 opened Jun 25, 2026 by marcopedrinazzi Contributor Loading…
Add detection for Lynx Ransomware execution flags Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6082 opened Jun 25, 2026 by Swarup-Ingale Loading…
6 tasks done
ci: pin and cache Python dependencies for reproducible builds Maintenance Related to additions and update of the repository features Review Needed The PR requires review
#6080 opened Jun 24, 2026 by a0merr Loading…
new: Potential Browser Cache Smuggling Payload Extraction Review Needed The PR requires review Rules Windows Pull request add/update windows related rules
#6078 opened Jun 23, 2026 by Tetryl12 Loading…
Add rule for arbitrary file download via msoxmled.exe (LOLBAS) Author Input Required changes the require information from original author of the rules Review Needed The PR requires review Rules Windows Pull request add/update windows related rules Work In Progress Some changes are needed
#6072 opened Jun 21, 2026 by cor-b Loading…
ProTip! Updated in the last three days: updated:>2026-07-02.