Skip to content

Pull requests: elastic/detection-rules

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

[Rule Tunings] AWS CloudWatch Deletion Rules backport: auto Domain: Cloud Integration: AWS AWS related rules Rule: Tuning tweaking or tuning an existing rule Team: TRADE
#5316 opened Nov 14, 2025 by imays11 Loading…
[Tuning] Agent Spoofing - Multiple Hosts Using Same Agent backport: auto Rule: Tuning tweaking or tuning an existing rule
#5313 opened Nov 13, 2025 by Samirbous Loading…
[Rule Tuning] AWS GuardDuty Detector Deletion backport: auto Domain: Cloud Integration: AWS AWS related rules Rule: Tuning tweaking or tuning an existing rule Team: TRADE
#5309 opened Nov 12, 2025 by imays11 Loading…
[Rule Tunings] AWS IAM Roles Anywhere Rules backport: auto Domain: Cloud Integration: AWS AWS related rules Rule: Tuning tweaking or tuning an existing rule Team: TRADE
#5307 opened Nov 12, 2025 by imays11 Loading…
[New] Potential Masquerading as Svchost backport: auto Domain: Endpoint OS: Windows windows related rules Rule: New Proposal for new rule
#5305 opened Nov 12, 2025 by Samirbous Loading…
[Tuning] Outbound Scheduled Task Activity via PowerShell backport: auto bug Something isn't working Domain: Endpoint Integration: Windows OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule
#5287 opened Nov 6, 2025 by Samirbous Loading…
[Rule Tuning] AWS IAM SAML Provider Updated backport: auto Domain: Cloud Integration: AWS AWS related rules Rule: Tuning tweaking or tuning an existing rule Team: TRADE
#5284 opened Nov 5, 2025 by imays11 Loading…
[Rule Tuning] AWS GetSessionToken Abuse backport: auto bbr Building Block Rules Domain: Cloud Integration: AWS AWS related rules Rule: Tuning tweaking or tuning an existing rule Team: TRADE
#5274 opened Nov 3, 2025 by imays11 Loading…
Renovate Updates backport: auto enhancement New feature or request patch python Internal python for the repository
#5258 opened Oct 28, 2025 by shashank-elastic Loading…
5 tasks
[Rule Tunings] AWS Multiple API Calls ESQL rules backport: auto bbr Building Block Rules Domain: Cloud Integration: AWS AWS related rules Rule: Tuning tweaking or tuning an existing rule Team: TRADE
#5238 opened Oct 21, 2025 by imays11 Loading…
Add rules for Azure Activity Logs/GCP Audit ML jobs backport: skip Domain: Cloud Integration: Azure azure related rules Integration: GCP GCP related rules minor ML machine learning related rule Rule: New Proposal for new rule
#5191 opened Oct 6, 2025 by jmcarlock Loading…
5 tasks
Update README for the installation of kibana and kql packages backport: auto community documentation Improvements or additions to documentation
#5177 opened Oct 2, 2025 by pberba Loading…
5 tasks
ProTip! no:milestone will show everything without a milestone.