-
Notifications
You must be signed in to change notification settings - Fork 640
Pull requests: elastic/detection-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[Rule Tuning] Entra ID Service Principal with Unusual Source ASN
backport: auto
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#5915
opened Apr 3, 2026 by
terrancedejesus
Loading…
5 tasks
[New/Tuning] Diverse AWS rules
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
Rule: New
Proposal for new rule
Rule: Tuning
tweaking or tuning an existing rule
#5913
opened Apr 3, 2026 by
Samirbous
Loading…
Update actions/checkout digest
backport: auto
community
#5912
opened Apr 3, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
[New Rule] AWS S3 Rapid Bucket Posture API Calls from a Single Principal
backport: auto
Domain: Cloud
emerging-threat
Integration: AWS
AWS related rules
Rule: New
Proposal for new rule
Team: TRADE
#5911
opened Apr 2, 2026 by
imays11
Loading…
[New Rule][Rule Tuning] AWS Organizations/Account Discovery Coverage
backport: auto
Domain: Cloud
emerging-threat
Integration: AWS
AWS related rules
Rule: New
Proposal for new rule
Rule: Tuning
tweaking or tuning an existing rule
#5910
opened Apr 1, 2026 by
imays11
Loading…
Add Entity related integrations ML rules with _ea job IDs and min_stack_version 9.4.0
backport: auto
Integration: DED
Integration: DGA
Integration: LMD
Integration: LotL
integration: ProblemChild
ML
machine learning related rule
Rule: Tuning
tweaking or tuning an existing rule
#5909
opened Apr 1, 2026 by
susan-shu-c
Loading…
5 tasks
Update dependency requests to ~=2.33.1
backport: auto
community
#5907
opened Apr 1, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
[Rule Tuning] Misc Windows
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5906
opened Apr 1, 2026 by
w0rk3r
Loading…
[Tuning] Remote Management Access Launch After MSI Install
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5901
opened Mar 30, 2026 by
Samirbous
Loading…
[Rule Tuning] Windows High-Severity Rules Revamp - 2
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5900
opened Mar 30, 2026 by
w0rk3r
Loading…
[Rule Tuning] Windows High-Severity Rules Revamp - 1
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
patch
Rule: Tuning
tweaking or tuning an existing rule
Security Content
#5899
opened Mar 30, 2026 by
w0rk3r
Loading…
Update dependency PyGithub to v2.9.0
backport: auto
community
#5898
opened Mar 30, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
Move docs workflows to elastic/docs-actions
backport: auto
#5897
opened Mar 30, 2026 by
Mpdreamz
Loading…
1 task
[Rule Tuning] Entra ID Illicit Consent Grant via Registered Application - Fix New Terms Field
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#5894
opened Mar 27, 2026 by
terrancedejesus
•
Draft
5 tasks
[Tuning] Execution via GitHub Actions Runner
backport: auto
Domain: Endpoint
Rule: Tuning
tweaking or tuning an existing rule
#5892
opened Mar 27, 2026 by
Samirbous
Loading…
[New] Long Base64 Encoded Command via Scripting Interpreter
backport: auto
Domain: Endpoint
Rule: New
Proposal for new rule
#5891
opened Mar 27, 2026 by
Samirbous
Loading…
[New Rule] Kubernetes Pod Creation Using Common Debug or Base Images
backport: auto
container
Integration: Kubernetes
Kubernetes Integration
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#5890
opened Mar 27, 2026 by
Aegrah
Loading…
Fix: Add comprehensive unit tests for non-ecs-schema.json and clean up data (#2322)
backport: auto
community
#5879
opened Mar 24, 2026 by
chidoziemanagwu
Loading…
6 of 7 tasks
[New Rules] macOS Unified Logs Login Window and XProtect Detections
backport: auto
dev
rule meant to be non-prod / non-shipping
integration: Unified_Logs
OS: macOS
patch
Rule: New
Proposal for new rule
#5874
opened Mar 23, 2026 by
DefSecSentinel
Loading…
4 tasks
[New Rules] macOS Unified Logs TCC Detection Rules
backport: auto
dev
rule meant to be non-prod / non-shipping
integration: Unified_Logs
OS: macOS
patch
Rule: New
Proposal for new rule
#5870
opened Mar 23, 2026 by
DefSecSentinel
Loading…
6 tasks
[New Rules] macOS Unified Logs Apple Event Detections
backport: auto
dev
rule meant to be non-prod / non-shipping
Hunting
integration: Unified_Logs
OS: macOS
patch
Rule: New
Proposal for new rule
#5867
opened Mar 23, 2026 by
DefSecSentinel
Loading…
5 tasks
[Feature] Add support for immutable and rule_source fields in TOML export/import
backport: auto
python
Internal python for the repository
#5840
opened Mar 17, 2026 by
aarju
Loading…
5 tasks
WIP - Add batch processing to Kibana import-rules
enhancement
New feature or request
patch
#5834
opened Mar 13, 2026 by
eric-forte-elastic
•
Draft
5 tasks
WIP - [FR] [DAC] Initial Yaml Support
backport: auto
enhancement
New feature or request
patch
python
Internal python for the repository
#5821
opened Mar 10, 2026 by
eric-forte-elastic
•
Draft
5 tasks
Previous Next
ProTip!
Exclude everything labeled
bug with -label:bug.