Skip to content

Improve macOS "Credentials from Password Stores - Keychain" rule#5848

Open
Niicolaa wants to merge 1 commit intoSigmaHQ:masterfrom
Niicolaa:feat/improve-macos-keychain-detection
Open

Improve macOS "Credentials from Password Stores - Keychain" rule#5848
Niicolaa wants to merge 1 commit intoSigmaHQ:masterfrom
Niicolaa:feat/improve-macos-keychain-detection

Conversation

@Niicolaa
Copy link
Contributor

Summary of the Pull Request

Improve macOS "Credentials from Password Stores - Keychain" rule

  • Add find-generic-password and find-internet-password with -w/-g flag requirements
  • modified export detection with filter to exclude public-only exports (certs/pubKeys)
  • Remove find-certificate (public data only) and login-keychain

Changelog

update: Credentials from Password Stores - Keychain

Example Log Event

n/a

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

- Add find-generic-password and find-internet-password with -w/-g flag requirements
- modified export detection with filter to exclude public-only exports (certs/pubKeys)
- Remove find-certificate (public data only) and login-keychain
@github-actions github-actions bot added Rules Review Needed The PR requires review MacOS Pull request add/update macos related rules labels Jan 30, 2026
@nasbench nasbench self-requested a review February 16, 2026 17:45
@nasbench nasbench self-assigned this Feb 16, 2026
@nasbench nasbench added this to the Sigma-February-Release milestone Feb 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

MacOS Pull request add/update macos related rules Review Needed The PR requires review Rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants