K
kostastsale
@kostastsale
First rule: Mon Jan 10 2022 01:00:00 GMT+0100 (Central European Standard Time)
Commits on SigmaHQPull Requests0rules authored
28sole author
9co-authored
By Severity
critical
0
high
23
medium
13
low
1
informational
0
By Status
stable
0
test
33
experimental
4
deprecated
0
unsupported
0
0
Total Rules
0
Stable Rules
0
High / Critical
0
Log Source Types
Recent RulesAll rules →
Potentially Suspicious File Creation by OpenEDR's ITSMService
Thu Feb 19 2026 01:00:00 GMT+0100 (Central European Standard Time)
mediumDetection
OpenEDR Spawning Command Shell
Thu Feb 19 2026 01:00:00 GMT+0100 (Central European Standard Time)
mediumDetection
Suspicious Filename with Embedded Base64 Commands
Sat Nov 22 2025 01:00:00 GMT+0100 (Central European Standard Time)
highDetection
Potentially Suspicious Long Filename Pattern - Linux
Sat Nov 22 2025 01:00:00 GMT+0100 (Central European Standard Time)
lowThreat Hunt
Kerberoasting Activity - Initial Query
Fri Jan 21 2022 01:00:00 GMT+0100 (Central European Standard Time)
mediumDetection
Obfuscated PowerShell OneLiner Execution
Mon May 09 2022 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
Browse all 37 rules by kostastsale
Filter the full rule library to see only their contributions