Skip to content

Pull requests: elastic/detection-rules

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

[Tuning] Rare Connection to WebDAV Target backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule
#5604 opened Jan 23, 2026 by Samirbous Loading…
[doc fix] Adjust wording in the docs for Kibana import/export commands backport: auto enhancement New feature or request patch python Internal python for the repository
#5600 opened Jan 22, 2026 by traut Loading…
5 tasks
[New] Multiple Vulnerabilities by Asset via Wiz backport: auto patch Rule: New Proposal for new rule Rule: Tuning tweaking or tuning an existing rule
#5598 opened Jan 22, 2026 by Samirbous Loading…
[fix] Preserve actions[].params.message field formatting during rule export from the repo backport: auto bug Something isn't working maintenance Internal changes patch python Internal python for the repository
#5597 opened Jan 22, 2026 by traut Loading…
1 of 5 tasks
[Tuning] Potential Ransomware Behavior - Note Files by System backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule
#5595 opened Jan 21, 2026 by Samirbous Loading…
[New/Tuning] General API Abuse D4C/K8s Rules backport: auto container Integration: Cloud Defend Cloud Defend Integration Integration: Kubernetes Kubernetes Integration OS: Linux Rule: New Proposal for new rule Rule: Tuning tweaking or tuning an existing rule Team: TRADE
#5591 opened Jan 21, 2026 by Aegrah Loading…
[Tuning] ESQL Dynamic unique value fields backport: auto Domain: Endpoint OS: Linux OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule
#5569 opened Jan 16, 2026 by Samirbous Loading…
Add investigation fields to beaconing rules
#5536 opened Jan 7, 2026 by susan-shu-c Draft
5 tasks
Added logic to main.py to use the created_at and updated_at values if they exist backport: auto enhancement New feature or request patch python Internal python for the repository
#5444 opened Dec 10, 2025 by aarju Loading…
2 tasks
ProTip! Follow long discussions with comments:>50.