Skip to content

Pull requests: elastic/detection-rules

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

[Tuning] Remote Management Access Launch After MSI Install backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule
#5901 opened Mar 30, 2026 by Samirbous Loading…
[Rule Tuning] Windows High-Severity Rules Revamp - 2 backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule
#5900 opened Mar 30, 2026 by w0rk3r Draft
Move docs workflows to elastic/docs-actions backport: auto
#5897 opened Mar 30, 2026 by Mpdreamz Loading…
1 task
[Tuning] Execution via GitHub Actions Runner backport: auto Domain: Endpoint Rule: Tuning tweaking or tuning an existing rule
#5892 opened Mar 27, 2026 by Samirbous Loading…
[Rule Tuning] Add Supplemental Mitre Mappings backport: auto Domain: Cloud enhancement New feature or request Integration: AWS AWS related rules Integration: Azure azure related rules Integration: CyberArkPas CyberArkPas integration Integration: GCP GCP related rules Integration: Google Workspace ML machine learning related rule Rule: Tuning tweaking or tuning an existing rule Security Content test-suite unit and other testing components
#5876 opened Mar 23, 2026 by Mikaayenson Loading…
1 of 5 tasks
[New Rules] macOS Unified Logs TCC Detection Rules backport: auto dev rule meant to be non-prod / non-shipping integration: Unified_Logs OS: macOS patch Rule: New Proposal for new rule
#5870 opened Mar 23, 2026 by DefSecSentinel Loading…
6 tasks
[Feature] Add support for immutable and rule_source fields in TOML export/import backport: auto python Internal python for the repository
#5840 opened Mar 17, 2026 by aarju Loading…
5 tasks
WIP - [FR] [DAC] Initial Yaml Support backport: auto enhancement New feature or request patch python Internal python for the repository
#5821 opened Mar 10, 2026 by eric-forte-elastic Draft
5 tasks
Update Entity related rules with new _ea ML job ID and update minimum stack versions backport: auto Domain: Cloud Integration: AWS AWS related rules Integration: Azure azure related rules Integration: GCP GCP related rules ML machine learning related rule Rule: Tuning tweaking or tuning an existing rule
#5794 opened Feb 27, 2026 by susan-shu-c Loading…
2 of 5 tasks
ProTip! What’s not been updated in a month: updated:<2026-02-28.