-
Notifications
You must be signed in to change notification settings - Fork 618
Pull requests: elastic/detection-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[Rule Tuning] Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource
backport: auto
Domain: Identity
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#5589
opened Jan 20, 2026 by
terrancedejesus
Loading…
5 tasks
[Rule Tuning] M365 Threat Intelligence Signal
backport: auto
bbr
Building Block Rules
Domain: Cloud
Domain: SaaS
Integration: Microsoft 365
Rule: Tuning
tweaking or tuning an existing rule
#5587
opened Jan 20, 2026 by
terrancedejesus
Loading…
5 tasks
[New] Newly Observed High Severity Suricata Alert
backport: auto
Domain: Network
Rule: New
Proposal for new rule
#5585
opened Jan 20, 2026 by
Samirbous
Loading…
[Tuning] Suricata and Elastic Defend Network Correlation
backport: auto
Rule: Tuning
tweaking or tuning an existing rule
#5583
opened Jan 20, 2026 by
Samirbous
Loading…
[Rule Tuning] Adding D4C Compatibility to Compatible K8s-related Rules
backport: auto
bbr
Building Block Rules
container
Domain: Endpoint
OS: Linux
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
[Rule Tuning] Removing tweaking or tuning an existing rule
Team: TRADE
host.os.type from K8s Rules
backport: auto
container
Rule: Tuning
#5577
opened Jan 19, 2026 by
Aegrah
Loading…
[Tuning] ESQL Dynamic unique value fields
backport: auto
Domain: Endpoint
OS: Linux
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5569
opened Jan 16, 2026 by
Samirbous
Loading…
[Hunt Tuning] Fix Invalid ES|QL Syntax in Hunting Queries
backport: auto
Hunt: Tuning
Hunting
#5566
opened Jan 16, 2026 by
terrancedejesus
Loading…
5 tasks
[Rule Tunings] AWS remove target.entity.id and actor.entity.id fields
backport: auto
Domain: Cloud
Integration: AWS
AWS related rules
Rule: Tuning
tweaking or tuning an existing rule
Team: TRADE
#5563
opened Jan 15, 2026 by
imays11
Loading…
[New Rules] Reintroduction of Defend for Containers (D4C) Ruleset
backport: auto
container
Integration: Cloud Defend
Cloud Defend Integration
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#5561
opened Jan 15, 2026 by
Aegrah
Loading…
[New] Lateral Movement Alerts from a Newly Observed Entity
backport: auto
Rule: New
Proposal for new rule
#5557
opened Jan 14, 2026 by
Samirbous
Loading…
[Tuning] Rare Connection to WebDAV Target
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5556
opened Jan 13, 2026 by
Samirbous
Loading…
[New Rule] Multiple High-Severity Alerts for Privileged AD User
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
[New Rule] Potential PowerShell Obfuscated Script via High Entropy
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#5554
opened Jan 12, 2026 by
w0rk3r
Loading…
[New Rule] PowerShell Script Block Entropy Outlier via MAD Z-Score
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
Update actions/setup-python digest to 83679a8
backport: auto
community
#5527
opened Jan 3, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
Added logic to main.py to use the created_at and updated_at values if they exist
backport: auto
enhancement
New feature or request
patch
python
Internal python for the repository
#5444
opened Dec 10, 2025 by
aarju
Loading…
2 tasks
Update actions/checkout action to v6
backport: auto
community
#5349
opened Nov 20, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update dependency marshmallow to v4
backport: auto
community
#5330
opened Nov 17, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update dependency elasticsearch to v9
backport: auto
community
#5329
opened Nov 17, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update actions/upload-artifact action to v6
backport: auto
community
#5328
opened Nov 17, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update actions/checkout digest
backport: auto
community
stale
60 days of inactivity
#5327
opened Nov 17, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update actions/setup-python action to v6
backport: auto
community
#5326
opened Nov 17, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Previous Next
ProTip!
Filter pull requests by the default branch with base:main.