-
Notifications
You must be signed in to change notification settings - Fork 635
Pull requests: elastic/detection-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[Rule Tuning] Microsoft Graph Request User Impersonation by Unusual Client
backport: auto
Domain: Cloud
Domain: Web
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#5861
opened Mar 20, 2026 by
terrancedejesus
Loading…
5 tasks
[Rule Tuning] Sensitive Audit Policy Sub-Category Disabled
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5859
opened Mar 20, 2026 by
w0rk3r
Loading…
[Rule Tuning] Misc Rule Tuning
backport: auto
bbr
Building Block Rules
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5858
opened Mar 20, 2026 by
w0rk3r
Loading…
[Tuning] Add Missing executable file extensions
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5857
opened Mar 19, 2026 by
Samirbous
Loading…
[Rule Tuning] Remove OIDC email scope from Microsoft Graph Email Access Rule
backport: auto
Domain: Cloud
Domain: Email
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#5856
opened Mar 19, 2026 by
terrancedejesus
Loading…
5 tasks
[FR] Initial DaC Issue Template
backport: auto
detections-as-code
enhancement
New feature or request
#5854
opened Mar 19, 2026 by
eric-forte-elastic
Loading…
5 tasks
[Rule Tuning] M365 Exchange Inbox Forwarding Rule Created
backport: auto
Domain: Cloud
Domain: SaaS
Integration: Microsoft 365
Rule: Tuning
tweaking or tuning an existing rule
#5852
opened Mar 19, 2026 by
terrancedejesus
Loading…
5 tasks
[New] RMM Rules
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#5848
opened Mar 18, 2026 by
Samirbous
Loading…
[New/tuning] WarLock coverage
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
Rule: Tuning
tweaking or tuning an existing rule
#5846
opened Mar 18, 2026 by
Samirbous
Loading…
[New Rules] AppArmor Exploitation (CrackArmor)
backport: auto
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#5842
opened Mar 17, 2026 by
Aegrah
Loading…
[Feature] Add support for immutable and rule_source fields in TOML export/import
backport: auto
python
Internal python for the repository
#5840
opened Mar 17, 2026 by
aarju
Loading…
5 tasks
WIP - Add batch processing to Kibana import-rules
enhancement
New feature or request
patch
#5834
opened Mar 13, 2026 by
eric-forte-elastic
•
Draft
5 tasks
WIP - [FR] [DAC] Initial Yaml Support
backport: auto
enhancement
New feature or request
patch
python
Internal python for the repository
#5821
opened Mar 10, 2026 by
eric-forte-elastic
•
Draft
5 tasks
[Tuning] Mis Rules Tuning
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5817
opened Mar 9, 2026 by
Samirbous
Loading…
Update dependency nodeenv to v1.10.0
backport: auto
community
#5800
opened Feb 28, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
Update Entity related rules with new tweaking or tuning an existing rule
_ea ML job ID and update minimum stack versions
backport: auto
Rule: Tuning
#5794
opened Feb 27, 2026 by
susan-shu-c
Loading…
5 tasks
Update dependency marko to v2.2.2
backport: auto
community
patch
#5735
opened Feb 18, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
[Rule Tuning & Deprecation] Tuning & Deprecating Promotion Rule
backport: auto
Integration: Cloud Defend
Cloud Defend Integration
Rule: Deprecation
removal of a rule
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
fix: Change bulk rule actions by updating deprecated
rule_ids to ids
backport: auto
community
#5711
opened Feb 10, 2026 by
IOITI
Loading…
2 tasks done
[FR] [DAC] Add Exception Duplication Checking
backport: auto
detections-as-code
enhancement
New feature or request
patch
python
Internal python for the repository
#5689
opened Feb 5, 2026 by
eric-forte-elastic
Loading…
5 tasks
[New Rule] Kubernetes Anonymous User Bound to ClusterRole
container
Integration: Kubernetes
Kubernetes Integration
Rule: New
Proposal for new rule
Team: TRADE
[New Rule] Potential Service Masquerading
backport: auto
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
Update actions/checkout digest
backport: auto
community
#5613
opened Jan 25, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
Update fjogeleit/http-request-action digest to c0b95d0
backport: auto
community
#5605
opened Jan 23, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
[Hunt Tuning] Fix Invalid ES|QL Syntax in Hunting Queries
backport: auto
Hunt: Tuning
Hunting
#5566
opened Jan 16, 2026 by
terrancedejesus
•
Draft
5 tasks
Previous Next
ProTip!
Type g i on any issue or pull request to go back to the issue listing page.