Skip to content

Pull requests: elastic/detection-rules

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

[New/Tuning] DNS Tunneling via NsLookup backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule
#6381 opened Jul 3, 2026 by Samirbous Contributor Loading…
[Rule Tuning] First Time Seen DNS Query to RMM Domain backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule
#6380 opened Jul 2, 2026 by w0rk3r Contributor Loading…
[Rule Tuning] Windows Misc Tunings backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule
#6379 opened Jul 2, 2026 by w0rk3r Contributor Loading…
WIP - Initial MITRE v19 Support detections-as-code enhancement New feature or request patch python Internal python for the repository
#6367 opened Jul 1, 2026 by eric-forte-elastic Contributor Draft
5 tasks
[New Rule] Microsoft Defender XDR Promotion Rules backport: auto bbr Building Block Rules Rule: New Proposal for new rule Rule: Tuning tweaking or tuning an existing rule
#6360 opened Jun 30, 2026 by terrancedejesus Contributor Loading…
5 tasks
[Rule Tuning] Entra ID OAuth Device Code Phishing via AiTM backport: auto Domain: Cloud Domain: Identity Integration: Azure azure related rules Rule: Tuning tweaking or tuning an existing rule
#6358 opened Jun 30, 2026 by terrancedejesus Contributor Loading…
5 tasks
[New] GKE Kubernetes Rules backport: auto Domain: Cloud Integration: GCP GCP related rules Rule: New Proposal for new rule
#6357 opened Jun 30, 2026 by Samirbous Contributor Loading…
[Rule Tuning] Migrate Phase 1 vendor fields to ECS and trim non-ecs schema patch Rule: Tuning tweaking or tuning an existing rule schema
#6328 opened Jun 23, 2026 by Mikaayenson Contributor Draft
3 of 5 tasks
ProTip! Adding no:label will show everything without a label.