K
kostastsale
@kostastsale
First rule: Mon Jan 10 2022 00:00:00 GMT+0000 (Coordinated Universal Time)
Commits on SigmaHQPull Requests0rules authored
28sole author
9co-authored
By Severity
critical
0
high
23
medium
13
low
1
informational
0
By Status
stable
0
test
33
experimental
4
deprecated
0
unsupported
0
0
Total Rules
0
Stable Rules
0
High / Critical
0
Log Source Types
Recent RulesAll rules →
Potentially Suspicious File Creation by OpenEDR's ITSMService
Thu Feb 19 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
mediumDetection
OpenEDR Spawning Command Shell
Thu Feb 19 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
mediumDetection
Suspicious Filename with Embedded Base64 Commands
Sat Nov 22 2025 00:00:00 GMT+0000 (Coordinated Universal Time)
highDetection
Potentially Suspicious Long Filename Pattern - Linux
Sat Nov 22 2025 00:00:00 GMT+0000 (Coordinated Universal Time)
lowThreat Hunt
Kerberoasting Activity - Initial Query
Fri Jan 21 2022 00:00:00 GMT+0000 (Coordinated Universal Time)
mediumDetection
Obfuscated PowerShell OneLiner Execution
Mon May 09 2022 00:00:00 GMT+0000 (Coordinated Universal Time)
highDetection
Browse all 37 rules by kostastsale
Filter the full rule library to see only their contributions