-
Notifications
You must be signed in to change notification settings - Fork 638
Pull requests: elastic/detection-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[Rule Tuning] Python Path File (pth) Creation
backport: auto
Domain: Endpoint
OS: Linux
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5880
opened Mar 24, 2026 by
Aegrah
Loading…
Fix: Add comprehensive unit tests for non-ecs-schema.json and clean up data (#2322)
backport: auto
community
#5879
opened Mar 24, 2026 by
chidoziemanagwu
Loading…
6 of 7 tasks
[New Rule] M365 Azure Monitor Alert Email with Financial or Billing Theme
backport: auto
Domain: Email
Integration: Azure
azure related rules
patch
Rule: New
Proposal for new rule
schema
#5878
opened Mar 24, 2026 by
terrancedejesus
Loading…
5 tasks
[Rule Tuning] Update Mitre Mappings and tags
backport: auto
Domain: Cloud
enhancement
New feature or request
Integration: AWS
AWS related rules
Integration: Azure
azure related rules
Integration: CyberArkPas
CyberArkPas integration
Integration: GCP
GCP related rules
Integration: Google Workspace
ML
machine learning related rule
Rule: Tuning
tweaking or tuning an existing rule
Security Content
test-suite
unit and other testing components
#5876
opened Mar 23, 2026 by
Mikaayenson
Loading…
1 of 5 tasks
[New Rules] macOS Unified Logs Login Window and XProtect Detections
backport: auto
dev
rule meant to be non-prod / non-shipping
integration: Unified_Logs
OS: macOS
patch
Rule: New
Proposal for new rule
#5874
opened Mar 23, 2026 by
DefSecSentinel
Loading…
4 tasks
[Rule Tuning] M365 SharePoint/OneDrive File Access via PowerShell - Convert to new_terms
backport: auto
Domain: Cloud
Domain: SaaS
Domain: Storage
Integration: Azure
azure related rules
Integration: Microsoft 365
Rule: Tuning
tweaking or tuning an existing rule
#5873
opened Mar 23, 2026 by
terrancedejesus
Loading…
5 tasks
[New Rules] macOS Unified Logs TCC Detection Rules
backport: auto
dev
rule meant to be non-prod / non-shipping
integration: Unified_Logs
OS: macOS
patch
Rule: New
Proposal for new rule
#5870
opened Mar 23, 2026 by
DefSecSentinel
Loading…
6 tasks
[New Rules] macOS Unified Logs Apple Event Detections
backport: auto
dev
rule meant to be non-prod / non-shipping
Hunting
integration: Unified_Logs
OS: macOS
patch
Rule: New
Proposal for new rule
#5867
opened Mar 23, 2026 by
DefSecSentinel
Loading…
5 tasks
[Rule Tuning] M365 Identity Login from Atypical Travel Location - Reduce FP Noise
backport: auto
Domain: Cloud
Domain: SaaS
Integration: Microsoft 365
Rule: Tuning
tweaking or tuning an existing rule
#5866
opened Mar 23, 2026 by
terrancedejesus
Loading…
5 tasks
[Rule Tuning] Entra ID OAuth User Impersonation to Microsoft Graph
backport: auto
Domain: Cloud
Domain: Identity
Domain: Web
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#5864
opened Mar 23, 2026 by
terrancedejesus
Loading…
5 tasks
[Feature] Add support for immutable and rule_source fields in TOML export/import
backport: auto
python
Internal python for the repository
#5840
opened Mar 17, 2026 by
aarju
Loading…
5 tasks
WIP - Add batch processing to Kibana import-rules
enhancement
New feature or request
patch
#5834
opened Mar 13, 2026 by
eric-forte-elastic
•
Draft
5 tasks
WIP - [FR] [DAC] Initial Yaml Support
backport: auto
enhancement
New feature or request
patch
python
Internal python for the repository
#5821
opened Mar 10, 2026 by
eric-forte-elastic
•
Draft
5 tasks
Update dependency nodeenv to v1.10.0
backport: auto
community
#5800
opened Feb 28, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
Update Entity related rules with new tweaking or tuning an existing rule
_ea ML job ID and update minimum stack versions
backport: auto
Rule: Tuning
#5794
opened Feb 27, 2026 by
susan-shu-c
Loading…
5 tasks
Update dependency marko to v2.2.2
backport: auto
community
patch
#5735
opened Feb 18, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
[Rule Tuning & Deprecation] Tuning & Deprecating Promotion Rule
backport: auto
Integration: Cloud Defend
Cloud Defend Integration
Rule: Deprecation
removal of a rule
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
fix: Change bulk rule actions by updating deprecated
rule_ids to ids
backport: auto
community
#5711
opened Feb 10, 2026 by
IOITI
Loading…
2 tasks done
[FR] [DAC] Add Exception Duplication Checking
backport: auto
detections-as-code
enhancement
New feature or request
patch
python
Internal python for the repository
#5689
opened Feb 5, 2026 by
eric-forte-elastic
Loading…
5 tasks
[New Rule] Kubernetes Anonymous User Bound to ClusterRole
container
Integration: Kubernetes
Kubernetes Integration
Rule: New
Proposal for new rule
Team: TRADE
[New Rule] Potential Service Masquerading
backport: auto
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
Update actions/checkout digest
backport: auto
community
#5613
opened Jan 25, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
Update fjogeleit/http-request-action digest to c0b95d0
backport: auto
community
stale
60 days of inactivity
#5605
opened Jan 23, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
[Hunt Tuning] Fix Invalid ES|QL Syntax in Hunting Queries
backport: auto
Hunt: Tuning
Hunting
#5566
opened Jan 16, 2026 by
terrancedejesus
•
Draft
5 tasks
[New Rule] Multiple High-Severity Alerts for Privileged AD User
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
Previous Next
ProTip!
Type g p on any issue or pull request to go back to the pull request listing page.