Skip to content

Conversation

@swachchhanda000
Copy link
Collaborator

@swachchhanda000 swachchhanda000 commented Dec 15, 2025

Summary of the Pull Request

Changelog

chore: add regression test for wmic related rules
fix: Process Reconnaissance Via Wmic.EXE- filter usage of 'call terminate'
fix: Potential Product Reconnaissance Via Wmic.EXE - filter csproduct
fix: Service Reconnaissance Via Wmic.EXE - filter stopservice and startservice

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@github-actions github-actions bot added Rules Review Needed The PR requires review Windows Pull request add/update windows related rules labels Dec 15, 2025
@X-Junior X-Junior added Author Input Required changes the require information from original author of the rules and removed Review Needed The PR requires review labels Dec 18, 2025
@swachchhanda000 swachchhanda000 added Review Needed The PR requires review and removed Author Input Required changes the require information from original author of the rules labels Dec 18, 2025
@nasbench nasbench added the Author Input Required changes the require information from original author of the rules label Dec 21, 2025
@swachchhanda000 swachchhanda000 removed the Author Input Required changes the require information from original author of the rules label Dec 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Review Needed The PR requires review Rules Windows Pull request add/update windows related rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants