-
Notifications
You must be signed in to change notification settings - Fork 557
Pull requests: elastic/detection-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[New Rule] Suspicious Path Mounted
backport: auto
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#4664
opened Apr 25, 2025 by
Aegrah
Loading…
[New Rule] Git Repository or File Download to Suspicious Directory
backport: auto
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#4663
opened Apr 25, 2025 by
Aegrah
Loading…
[New Rule] Manual Mount Discovery via /etc/exports
backport: auto
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#4662
opened Apr 25, 2025 by
Aegrah
Loading…
[New Rule] Docker Release File Creation
backport: auto
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#4661
opened Apr 25, 2025 by
Aegrah
Loading…
[New Rule] Manual Memory Dumping via Proc Filesystem
backport: auto
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#4660
opened Apr 25, 2025 by
Aegrah
Loading…
[FN Tuning] Suspicious /proc/maps Discovery
backport: auto
Domain: Endpoint
OS: Linux
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#4659
opened Apr 25, 2025 by
Aegrah
Loading…
[New Rule] Potential Linux Tunneling and/or Port Forwarding via SSH Option
backport: auto
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#4658
opened Apr 25, 2025 by
Aegrah
Loading…
[FR] Add check-version-lock dev command
backport: auto
enhancement
New feature or request
patch
python
Internal python for the repository
#4650
opened Apr 24, 2025 by
eric-forte-elastic
Loading…
5 tasks
[New Rule] MSFT Tenant OAuth Phishing via First-Party VSCode Client
backport: auto
Domain: Cloud
emerging-threat
Integration: Azure
azure related rules
Integration: Microsoft 365
patch
Rule: New
Proposal for new rule
Rule: Tuning
tweaking or tuning an existing rule
#4642
opened Apr 23, 2025 by
terrancedejesus
Loading…
5 tasks
[Rule Tuning] Reduce Severity from Critical to High
backport: auto
Rule: Tuning
tweaking or tuning an existing rule
#4637
opened Apr 22, 2025 by
w0rk3r
Loading…
[New Rule] Potential Dynamic IEX Reconstruction via Environment Variables
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#4633
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via Special Character Overuse
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4632
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via High Numeric Character Proportion
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4631
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4630
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule][BBR] Potential PowerShell Obfuscation via High Special Character Proportion
backport: auto
bbr
Building Block Rules
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4629
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule] Adding Coverage for AWS related rules
Rule: New
Proposal for new rule
AWS S3 Static Site JavaScript File Uploaded
backport: auto
Domain: Cloud
Integration: AWS
#4617
opened Apr 15, 2025 by
terrancedejesus
Loading…
5 tasks
[New Rule] Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4615
opened Apr 15, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via Invalid Escape Sequences
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#4614
opened Apr 15, 2025 by
w0rk3r
Loading…
[New Rule] PowerShell Obfuscation via Negative Index String Reversal
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4610
opened Apr 14, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via Reverse Keywords
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4609
opened Apr 14, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via Character Array Reconstruction
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#4608
opened Apr 14, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via String Concatenation
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4607
opened Apr 14, 2025 by
w0rk3r
Loading…
[New] Windows Sandbox with Sensitive Configuration
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4606
opened Apr 14, 2025 by
Samirbous
Loading…
[enhancement] In esql validation, allow any order of metadata
backport: auto
community
patch
python
Internal python for the repository
#4579
opened Mar 28, 2025 by
frederikb96
Loading…
5 tasks done
Previous Next
ProTip!
Follow long discussions with comments:>50.