Skip to content

Sync Sigma detections from security_content_sigma PR #38 - #4323

Closed
P4T12ICK wants to merge 1 commit into
developfrom
sigma/pr-38-37602892322.1
Closed

P4T12ICK wants to merge 1 commit into
developfrom
sigma/pr-38-37602892322.1

Conversation

@P4T12ICK

@P4T12ICK P4T12ICK commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Details

Sigma rules added or modified in splunk/security_content_sigma (PR #38) were converted to ESCU detections with sigmaspl convert --output-format security_content.

Each converted file replaces detections/<same relative path>. Review the diff for fields sigmaspl rewrote.

Added Sigma rules

None.

Modified Sigma rules

rules/endpoint/bitsadmin_download_file.yml

Renamed Sigma rules

None.

Deleted Sigma rules

Matching detections were left in place. Remove them in this pull request if that is intended.

Deleted paths

None.

Checklist

  • CI/CD jobs passed
  • Validated SPL logic
  • Validated tags, description, and how to implement
  • Verified references match analytic

Convert added and modified rules into ESCU detections.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant