-
Notifications
You must be signed in to change notification settings - Fork 611
Pull requests: elastic/detection-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[Rule Tuning] PowerShell Rules - Misc Tuning/Severity Bumps
backport: auto
bbr
Building Block Rules
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5486
opened Dec 17, 2025 by
w0rk3r
Loading…
[Rule Tuning] Linux DR Tuning - 4
backport: auto
Domain: Endpoint
OS: Linux
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5484
opened Dec 17, 2025 by
Aegrah
Loading…
[Rule Tuning] Linux DR Tuning - 3
backport: auto
Domain: Endpoint
OS: Linux
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5483
opened Dec 17, 2025 by
Aegrah
Loading…
[Tuning] Diverse Rules Tuning
backport: auto
Domain: Endpoint
OS: Linux
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5482
opened Dec 17, 2025 by
Samirbous
Loading…
[Rule Tuning] Linux DR Tuning - 2
backport: auto
Domain: Endpoint
OS: Linux
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5481
opened Dec 17, 2025 by
Aegrah
Loading…
[Tuning] Top Noisy Windows BBR
backport: auto
bbr
Building Block Rules
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5480
opened Dec 17, 2025 by
Samirbous
Loading…
[Rule Tunings] AWS New Terms History Window Reduction
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5479
opened Dec 16, 2025 by
imays11
Loading…
[Rule Tuning] Entra ID User Sign-in with Unusual Client
backport: auto
Domain: Cloud
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#5473
opened Dec 16, 2025 by
terrancedejesus
Loading…
5 tasks
[New Rules] Several GitHub Related Rules
backport: auto
Integration: GitHub
GitHub integration
Rule: New
Proposal for new rule
Team: TRADE
#5470
opened Dec 16, 2025 by
Aegrah
Loading…
[Rule Tuning] Shared Object Created or Changed by Previously Unknown …
backport: auto
Domain: Endpoint
OS: Linux
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5469
opened Dec 16, 2025 by
Aegrah
Loading…
[Rule Tuning] AWS Service Quotas Multi-Region GetServiceQuota Requests
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5468
opened Dec 15, 2025 by
imays11
Loading…
[Rule Tuning] AWS CLI with Kali Linux Fingerprint Identified
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5467
opened Dec 15, 2025 by
imays11
Loading…
[Rule Tuning] Entra ID User Sign-in with Unusual Registered Device
backport: auto
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#5466
opened Dec 15, 2025 by
terrancedejesus
Loading…
5 tasks
[Rule Tuning] Entra ID OAuth PRT Issuance to Non-Managed Device Detected
backport: auto
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#5464
opened Dec 15, 2025 by
terrancedejesus
Loading…
5 tasks
[Rule Tuning] Entra ID OAuth user_impersonation Scope for Unusual User and Client
backport: auto
Rule: Tuning
tweaking or tuning an existing rule
#5462
opened Dec 15, 2025 by
terrancedejesus
Loading…
5 tasks
[New] Alerts From Multiple Integrations by Entity
backport: auto
esql
ES|QL
Rule: New
Proposal for new rule
#5460
opened Dec 15, 2025 by
Samirbous
Loading…
[Rule Tuning] AWS EventBridge Rule Disabled or Deleted
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5458
opened Dec 12, 2025 by
imays11
Loading…
[Rule Tuning] AWS SQS Queue Purge
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5457
opened Dec 12, 2025 by
imays11
Loading…
[Rule Tunings] AWS Config Rule Tunings
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5456
opened Dec 12, 2025 by
imays11
Loading…
[Rule Tunings] AWS Lambda Rules
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5451
opened Dec 11, 2025 by
imays11
Loading…
[Rule Tunings] AWS Route 53 Rules
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5448
opened Dec 10, 2025 by
imays11
Loading…
[New] React2Shell Network Security Alert
backport: auto
Domain: Network
emerging-threat
patch
Rule: New
Proposal for new rule
#5445
opened Dec 10, 2025 by
Samirbous
Loading…
Added logic to main.py to use the created_at and updated_at values if they exist
backport: auto
enhancement
New feature or request
patch
python
Internal python for the repository
#5444
opened Dec 10, 2025 by
aarju
Loading…
2 tasks
[New] Suricata and Elastic Defend Network Correlation
backport: auto
Domain: Endpoint
Domain: Network
Rule: New
Proposal for new rule
#5443
opened Dec 10, 2025 by
Samirbous
Loading…
Previous Next
ProTip!
Follow long discussions with comments:>50.