-
Notifications
You must be signed in to change notification settings - Fork 572
Pull requests: elastic/detection-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[FN Rule Tuning] Kubernetes User Exec into Pod
backport: auto
container
Integration: Kubernetes
Kubernetes Integration
OS: Linux
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#4814
opened Jun 17, 2025 by
Aegrah
Loading…
[Tuning] High Number of Process and/or Service Terminations"
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#4813
opened Jun 17, 2025 by
Samirbous
Loading…
[New Rule] Kubectl Permission Discovery
backport: auto
container
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#4812
opened Jun 17, 2025 by
Aegrah
Loading…
[New Rule] Kubeconfig File Discovery
backport: auto
container
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#4811
opened Jun 17, 2025 by
Aegrah
Loading…
[New Rule] Kubeconfig File Creation or Modification
backport: auto
container
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#4810
opened Jun 17, 2025 by
Aegrah
Loading…
[Rule Tuning] Container Management Utility Run Inside A Container
backport: auto
container
Domain: Endpoint
OS: Linux
Team: TRADE
#4809
opened Jun 17, 2025 by
Aegrah
Loading…
[Rule Tuning] AWS EC2 User Data Retrieval for EC2 Instance
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
patch
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#4808
opened Jun 17, 2025 by
imays11
Loading…
[Rule Tuning] Suspicious Microsoft 365 Mail Access by Unusual ClientAppId
backport: auto
Domain: Cloud
Domain: Email
patch
Rule: Tuning
tweaking or tuning an existing rule
#4806
opened Jun 16, 2025 by
terrancedejesus
Loading…
5 tasks
[New Rule] Entra ID User Signed In from Unusual Device
backport: auto
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
patch
Rule: New
Proposal for new rule
#4804
opened Jun 16, 2025 by
terrancedejesus
Loading…
5 tasks
[New Rule] Microsoft Entra ID Suspicious Cloud Device Registration
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
patch
Rule: New
Proposal for new rule
#4802
opened Jun 13, 2025 by
terrancedejesus
•
Draft
5 tasks
[New Rule] Suspicious ADRS Token Request by Microsoft Auth Broker
backport: auto
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
patch
Rule: New
Proposal for new rule
#4801
opened Jun 13, 2025 by
terrancedejesus
Loading…
5 tasks
[Rule Tuning] AWS IAM Assume Role Policy Update
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#4799
opened Jun 13, 2025 by
imays11
Loading…
[Rule Tuning] Suspicious Activity via Auth Broker On-Behalf-of Principal User
backport: auto
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#4793
opened Jun 11, 2025 by
terrancedejesus
Loading…
5 tasks
[New Rule] AWS CloudTrail Log Evasion
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
patch
Rule: New
Proposal for new rule
Team: TRADE
#4788
opened Jun 10, 2025 by
imays11
Loading…
[Rule Tuning] PowerShell ES|QL Rules Tuning
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#4785
opened Jun 10, 2025 by
w0rk3r
Loading…
[Rule Tuning] AWS EC2 Deprecated AMI Discovery
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
patch
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#4784
opened Jun 10, 2025 by
imays11
Loading…
[Rule Tuning] Expand Scope of Entra ID Brute Force Sign-In Attempts
backport: auto
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#4777
opened Jun 5, 2025 by
terrancedejesus
Loading…
5 tasks
[New Hunt] Potential Spoofed azure related rules
Integration: Microsoft 365
microsoftonline.com
via Fuzzy Match
backport: auto
Domain: Cloud
Domain: Endpoint
Domain: Identity
Domain: Network
Hunt: New
Hunting
Integration: Azure
#4770
opened Jun 3, 2025 by
terrancedejesus
Loading…
5 tasks
Bump setuptools from 75.2.0 to 78.1.1
backport: auto
community
dependencies
Pull requests that update a dependency file
major
python
Internal python for the repository
#4730
opened May 19, 2025 by
dependabot
bot
Loading…
[Rule: New] Potential Web Server Fuzzing Attempts Detected
backport: auto
community
#4720
opened May 12, 2025 by
MakoWish
Loading…
1 of 5 tasks
[New] Microsoft Entra ID Protection Alert and Device Registration
backport: auto
Domain: Cloud Workloads
Domain: Cloud
Integration: Azure
azure related rules
Integration: Microsoft 365
patch
Rule: New
Proposal for new rule
#4688
opened Apr 30, 2025 by
Samirbous
Loading…
[New] Potential SAP NetWeaver Exploitation rules
backport: auto
OS: Linux
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4666
opened Apr 26, 2025 by
Samirbous
Loading…
[enhancement] In esql validation, allow any order of metadata
backport: auto
community
patch
python
Internal python for the repository
#4579
opened Mar 28, 2025 by
frederikb96
Loading…
5 tasks done
Previous Next
ProTip!
Mix and match filters to narrow down what you’re looking for.