Pull requests: SigmaHQ/sigma
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
fix: FP found in-the-wild
Rules
Windows
Pull request add/update windows related rules
#4342
opened Jul 5, 2023 by
frack113
Loading…
Add posh_ps_reg_query_registry
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#4339
opened Jul 2, 2023 by
frack113
Loading…
fix: FP found in-the-wild
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#4337
opened Jun 30, 2023 by
phantinuss
Loading…
Create posh_pm_susp_netfirewallrule_reco.yml
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#4336
opened Jun 28, 2023 by
securepeacock
Loading…
feat: new rules & updates
Rules
Windows
Pull request add/update windows related rules
#4328
opened Jun 22, 2023 by
nasbench
Loading…
Added filter on legitimate system non-wmiprvse processes loading WMI modules to reduce the false-positivies
Work In Progress
Some changes are needed
#4316
opened Jun 16, 2023 by
swachchhanda000
•
Draft
Detect use of gpu-launcher for electron application
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
Create proc_creation_macos_usage_of_jamf.yml
MacOS
Pull request add/update macos related rules
Rules
Work In Progress
Some changes are needed
#4300
opened Jun 7, 2023 by
gr00T0x
Loading…
Permiso p0-LUCR-1 (aka GUI-vil)
2nd Review Needed
PR need a second approval
Cloud
Pull request add/update cloud related rules
Rules
#4295
opened Jun 6, 2023 by
danielbohannon
Loading…
Permiso p0-LUCR-1 (aka GUI-vil)
Author Input Required
changes the require information from original author of the rules
Cloud
Pull request add/update cloud related rules
Rules
#4294
opened Jun 6, 2023 by
danielbohannon
Loading…
Permiso p0-LUCR-1 (aka GUI-vil)
2nd Review Needed
PR need a second approval
Cloud
Pull request add/update cloud related rules
Rules
#4293
opened Jun 6, 2023 by
danielbohannon
Loading…
Add new 2 rules for BlueSky Ransomware and MSSQL Logon Fail
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
Update .yamllint to include indentation rules and quoted-strings rules
Work In Progress
Some changes are needed
Add rule: rules/windows/file/file_event/file_event_win_cve_2023_27363…
Emerging-Threats
Rules
Windows
Pull request add/update windows related rules
Work In Progress
Some changes are needed
#4239
opened May 16, 2023 by
greg-workspace
Loading…
Create okta_detect_suspicious_push_challenge.yml
Cloud
Pull request add/update cloud related rules
Rules
Work In Progress
Some changes are needed
#4238
opened May 15, 2023 by
austinsonger
•
Draft
Create [Draft] okta_detect_repeated_user_rejections.yml
Author Input Required
changes the require information from original author of the rules
#4237
opened May 15, 2023 by
austinsonger
•
Draft
Permissions granted over a Cloud Service Account
Author Input Required
changes the require information from original author of the rules
Cloud
Pull request add/update cloud related rules
Rules
Work In Progress
Some changes are needed
#4233
opened May 11, 2023 by
TheEis4Extra
•
Draft
Create microsoft365_susp_email_forwarding.yml
Cloud
Pull request add/update cloud related rules
Rules
Work In Progress
Some changes are needed
Update proc_creation_macos_add_to_admin_group.yml
MacOS
Pull request add/update macos related rules
Rules
Work In Progress
Some changes are needed
#4155
opened Mar 30, 2023 by
D4rkCiph3r
Loading…
Create proc_creation_macos_in-memory_payload_transfer.yml
2nd Review Needed
PR need a second approval
MacOS
Pull request add/update macos related rules
Rules
Work In Progress
Some changes are needed
#4127
opened Mar 20, 2023 by
D4rkCiph3r
Loading…
Create proc_creation_macos_enable_root_account.yml
2nd Review Needed
PR need a second approval
MacOS
Pull request add/update macos related rules
Rules
Work In Progress
Some changes are needed
#4055
opened Feb 18, 2023 by
D4rkCiph3r
Loading…
ProTip!
Exclude everything labeled
bug with -label:bug.

Formed in 2009, the Archive Team (not to be confused with the archive.org Archive-It Team) is a rogue archivist collective dedicated to saving copies of rapidly dying or deleted websites for the sake of history and digital heritage. The group is 100% composed of volunteers and interested parties, and has expanded into a large amount of related projects for saving online and digital history.
