COMMITS
/ tests/logsource.json January 24, 2026
S
Merge PR #5741 from @swachchhanda000 - Add Splunk Rules for MSIX/AppX
Swachchhanda Shrawan Poudel committed
December 8, 2025
N
Merge PR #5793 from @nasbench - Rename Auditd Folder Entries and update SYSCALL field
Nasreddine Bencherchali committed
November 21, 2025
S
Merge PR #5662 from @swachchhanda000 - Cisco ASA/FP SSL VPN Exploit (CVE-2025-20333 / CVE-2025-20362)
Swachchhanda Shrawan Poudel committed
November 1, 2025
I
Merge PR #5197 from @inthecyber - Add new Fortinet Fortigate rules
InTheCyber committed
October 23, 2025
M
Merge PR #5686 from @mm-abdelghani - Unsigned or Unencrypted SMB Connection to Share Established
mm-abdelghani committed
September 22, 2025
A
Merge PR #5175 from @netgrain - Add `WDAC Policy File Creation In CodeIntegrity Folder`
Andreas Braathen committed
June 11, 2025
S
Merge PR #5416 from @swachchhanda000 - Detection of SAP NetViewer CVE-2025-31324 exploitation via webserver logs
Swachchhanda Shrawan Poudel committed
October 6, 2024
F
Merge PR #4935 from @frack113 - Add new IIS logsource and related rules
frack113 committed
May 10, 2024
April 25, 2024
A
Merge PR #4825 from @netgrain - New analytic for CVE-2024-3400
Andreas Braathen committed
April 24, 2024
N
Merge PR #4826 from @nasbench - Add coverage for CVE-2024-3400
Nasreddine Bencherchali committed
April 17, 2024
N
Merge PR #4814 from @nikitah4x - Add new rule to detect MFA bypass in Cisco Duo
nikitah4x committed
March 26, 2024
L
Merge PR #4694 from @LAripping - Add native Kubernetes detections
Leo Tsaousis committed
March 8, 2024
J
Merge PR #4695 from @defensivedepth - Add new rules based on OpenCanary tooling
Josh Brower committed
February 26, 2024
Z
February 8, 2024
J
D
November 6, 2023
A
Merge PR #4521 from @netgrain - Add New Rules Related To Pikabot
Andreas Braathen committed
November 3, 2023
F
Merge PR #4538 from @frack113 - Add Sigma CLI Configuration File
frack113 committed
October 23, 2023
October 12, 2023
N
Merge PR #4476 from @nasbench - re-organize cloud folder and other things
Nasreddine Bencherchali committed
September 18, 2023
C
Merge PR #4401 from @cyb3rjy0t - Add New O365 Related Rules
cyb3rjy0t committed
September 14, 2023
M
Merge PR #4445 from @MarkMorow - New Azure PIM Rules
Mark Morowczynski committed
August 8, 2023
N
chore: change service name to lowercase
Nasreddine Bencherchali committed
F
Fix to pass the tests
frack113 committed
May 18, 2023
N
feat: update logsource and rule
Nasreddine Bencherchali committed
May 8, 2023
F
Review Web logsource
frack113 committed
April 11, 2023
N
feat: new rules, updates and fp fixes (#4162)
Nasreddine Bencherchali committed
February 15, 2023
M
feat: add new application vulnerability rules (#4034)
Moti-H committed
January 22, 2023
F
Small update
frack113 committed
January 21, 2023
N
feat: update logsource with new service
Nasreddine Bencherchali committed
January 17, 2023
N
fix: broken logsource
Nasreddine Bencherchali committed
N
feat: update config files
Nasreddine Bencherchali committed
January 13, 2023
F
Merge pull request #3925 from frack113/lsa-server
frack113 committed
N
fix: apply suggestions from code review
Nasreddine Bencherchali committed
F
Add lsa-server
frack113 committed
F
Add UserName for taskscheduler
frack113 committed
January 11, 2023
N
feat: new rules related to appx packages
Nasreddine Bencherchali committed
F
Merge pull request #3889 from frack113/iso_evtx
frack113 committed
January 10, 2023
F
Update logsource.json
frack113 committed
January 9, 2023
F
Add win_vhdmp_mount_iso
frack113 committed
January 7, 2023
F
Filename normalisation
frack113 committed
January 4, 2023
F
remove duplicate value
frack113 committed
F
update logsource
frack113 committed
F
update logsource
frack113 committed
January 2, 2023
N
feat: add bitlocker channel
Nasreddine Bencherchali committed
F
Use W3C cs-uri-query
frack113 committed
F
Use W3C cs-uri-query
frack113 committed
F
Update W3C field name
frack113 committed
F
Update field name
frack113 committed