Skip to content

Conversation

@swachchhanda000
Copy link
Collaborator

@swachchhanda000 swachchhanda000 commented May 12, 2025

Summary of the Pull Request

Added more suspicious extension execution by mshta. Additional extensions were included because many malware variants are increasingly using alternative file types to evade detection. These extensions are often abused to launch malicious scripts through mshta.

Changelog

update: MSHTA Execution with Suspicious File Extensions - title changed and more susp extension added

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@github-actions github-actions bot added Rules Windows Pull request add/update windows related rules labels May 12, 2025
@phantinuss
Copy link
Collaborator

phantinuss commented May 16, 2025

please sort the list and don't remove the comments of exe/chm. Also: Is there a reason on why you removed dll and lnk?

@phantinuss phantinuss added the Author Input Required changes the require information from original author of the rules label May 16, 2025
@phantinuss phantinuss added 2nd Review Needed and removed Author Input Required changes the require information from original author of the rules labels May 16, 2025
@phantinuss phantinuss merged commit d44c380 into SigmaHQ:master Jun 11, 2025
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready to Merge Rules Windows Pull request add/update windows related rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants