Skip to content

Add detection for Lynx Ransomware execution flags - #6082

Open
Swarup-Ingale wants to merge 16 commits into
SigmaHQ:masterfrom
Swarup-Ingale:feature/lynx-ransomware-detection
Open

Add detection for Lynx Ransomware execution flags#6082
Swarup-Ingale wants to merge 16 commits into
SigmaHQ:masterfrom
Swarup-Ingale:feature/lynx-ransomware-detection

Conversation

@Swarup-Ingale

@Swarup-Ingale Swarup-Ingale commented Jun 25, 2026

Copy link
Copy Markdown

Description

Submitting a new Sigma rule to detect the execution of Lynx Ransomware.

The detection logic targets specific command-line flags (--noprint and --mode fast) observed in recent intrusions during the December 2025 campaign.

Source CTI: The DFIR Report - Cats Got Your Files: Lynx Ransomware

Checklist

  • I have read the SigmaHQ conventions and ensured this rule perfectly aligns with them.
  • The rule has been placed in the appropriate directory (rules-emerging-threats/2026/Malware/).
  • YAML syntax is valid and passes local yamllint checks.
  • All automated workflow tests are passing.
  • Rule logic has been strictly validated.
  • High-quality threat intelligence references are included.

@github-actions github-actions Bot added Rules Review Needed The PR requires review Windows Pull request add/update windows related rules labels Jun 25, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Welcome @Swarup-Ingale 👋

It looks like this is your first pull request on the Sigma rules repository!

Please make sure to read the SigmaHQ conventions to make sure your contribution is adhering to best practices and has all the necessary elements in place for a successful approval.

Thanks again, and welcome to the Sigma community! 😃

If you want to engage more with the community for official support, general discussions or announcements:

👉 Join our Discord server

@swachchhanda000 swachchhanda000 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HI @Swarup-Ingale,

Thank you for your submission. Before we proceed with the technical review, please address the following:


  1. Please update your PR summary to follow our predefined PR summary template. It’s easy for us to track the changes with that change.
  2. Since this is a dedicated rule for a specific ransomware, it falls under the Emerging Threats category. Please move it to rules-emerging-threats.
  3. Please verify that you have followed the SigmHQ conventions and look the already merged rules/PR to understand what a successful merge typically requires.
  4. Also, make sure all tests are passing. To run tests locally, please refer to the contribution guide.

@Swarup-Ingale

Copy link
Copy Markdown
Author

@swachchhanda000 All requested changes have been addressed! The PR summary is updated, the rule is moved to rules-emerging-threats/2026/Malware/, and the local yamllint errors/CRLF line endings are fixed. Let me know if you need anything else!

@Swarup-Ingale

Copy link
Copy Markdown
Author

Any Follow ups ??

@nasbench

nasbench commented Jul 8, 2026

Copy link
Copy Markdown
Member

Any Follow ups ??

No rush. We review the PR when we get to them.

@Swarup-Ingale

Copy link
Copy Markdown
Author

okay .. Thanks for reviewing

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Review Needed The PR requires review Rules Windows Pull request add/update windows related rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants