-
-
Notifications
You must be signed in to change notification settings - Fork 2.5k
Pull requests: SigmaHQ/sigma
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
add: Linux Security Capability Set Via Setfattr Utility
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
#5800
opened Dec 8, 2025 by
EzLucky
Loading…
Update The PR requires review
Rules
Potential Malicious Usage of CloudTrail System Manager
Review Needed
fix: aurora fps
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5798
opened Dec 8, 2025 by
swachchhanda000
Loading…
ci: 🤖 Fix URL for sigma_schema_url
Maintenance
Related to additions and update of the repository features
Ready to Merge
Review Needed
The PR requires review
#5797
opened Dec 7, 2025 by
frack113
Loading…
cve-2025-49666 detection rule
Additional Data Needed
Author Input Required
changes the require information from original author of the rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5796
opened Dec 6, 2025 by
17patmaks
Loading…
6 tasks done
new: CVE-2025-55182 react2shell rules
Emerging-Threats
Review Needed
The PR requires review
Rules
#5795
opened Dec 6, 2025 by
swachchhanda000
Loading…
Add SSH brute force detection rule
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
bugfix: update proc_creation_macos_gui_input_capture.yml - osascript …
MacOS
Pull request add/update macos related rules
Ready to Merge
Review Needed
The PR requires review
Rules
Metadata Updates - Batch 1
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
fix: Add fps filter observed on ARM-based Windows updates
Ready to Merge
Rules
Windows
Pull request add/update windows related rules
Recon via RDP Logging Event
Ready to Merge
Rules
Windows
Pull request add/update windows related rules
Add Detection Rule for Oracle OIM Pre-Auth Authentication Bypass (CVE-2025-61757)
Emerging-Threats
Review Needed
The PR requires review
Rules
Work In Progress
Some changes are needed
#5781
opened Nov 29, 2025 by
YxinMiracle
Loading…
fix: FPs on docker images
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
fix: add some filters or tune rules to reduce false positives
Ready to Merge
Rules
Windows
Pull request add/update windows related rules
feat: more edrfreeze rules
Maintenance
Related to additions and update of the repository features
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
#5777
opened Nov 27, 2025 by
swachchhanda000
Loading…
Added rules related to ArcGIS Server Object Extension abuse
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
feat: Shai-Hulud: The Second Coming Rules
Emerging-Threats
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
add: Linux setcap setuid
Linux
Pull request add/update linux related rules
Review Needed
The PR requires review
Rules
Add detection rule for Chaos/Darkside Ransomware style hidden Cmd launching suspicious targets
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
Add DPI-based network rule for responder footprints detection
Additional Data Needed
Author Input Required
changes the require information from original author of the rules
Review Needed
The PR requires review
Rules
#5751
opened Nov 11, 2025 by
cogResearch
Loading…
feat: phantom DLL hijacking rules
Author Input Required
changes the require information from original author of the rules
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
3 New rules
Additional Data Needed
Author Input Required
changes the require information from original author of the rules
Rules
Windows
Pull request add/update windows related rules
#5747
opened Nov 8, 2025 by
louiselalanne
Loading…
new: bindfltapi.dll execution by suspicious process
Rules
Windows
Pull request add/update windows related rules
#5744
opened Nov 6, 2025 by
vl43den
Loading…
Feat: susp msix/appX package installation detection
Maintenance
Related to additions and update of the repository features
Review Needed
The PR requires review
Rules
Windows
Pull request add/update windows related rules
Previous Next
ProTip!
Add no:assignee to see everything that’s not assigned.