-
Notifications
You must be signed in to change notification settings - Fork 600
Pull requests: elastic/detection-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[Tuning] Startup or Run Key Registry Modification
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5137
opened Sep 18, 2025 by
Samirbous
Loading…
[New Rule] Entra ID Actor Token User Impersonation Abuse
backport: auto
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
Rule: New
Proposal for new rule
#5136
opened Sep 18, 2025 by
terrancedejesus
Loading…
5 tasks
[Rule Tuning] Mark some field optional for 3rd party compatibility
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5135
opened Sep 18, 2025 by
w0rk3r
Loading…
[Rule Tuning] Suspicious PowerShell Engine ImageLoad
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5134
opened Sep 18, 2025 by
w0rk3r
Loading…
[New Rule] Node.js Pre or Post-Install Script Execution
backport: auto
Domain: Endpoint
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#5131
opened Sep 18, 2025 by
Aegrah
Loading…
[New Rule] GitHub Authentication Token Access via Node.js
backport: auto
Domain: Endpoint
emerging-threat
OS: Linux
Rule: New
Proposal for new rule
Team: TRADE
#5130
opened Sep 18, 2025 by
Aegrah
Loading…
[New Rule] Credential Access via TruffleHog Execution
backport: auto
Domain: Endpoint
emerging-threat
OS: Linux
OS: macOS
OS: Windows
windows related rules
Rule: New
Proposal for new rule
Team: TRADE
#5129
opened Sep 18, 2025 by
Aegrah
Loading…
[Bug] Point test_schemas ES|QL to tests/data
backport: auto
community
#5127
opened Sep 18, 2025 by
17cell
Loading…
Update dependency pyflakes to v3.4.0
backport: auto
community
#5126
opened Sep 17, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update dependency pre-commit to v3.8.0
backport: auto
community
#5121
opened Sep 16, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update dependency pep8-naming to v0.15.1
backport: auto
community
#5120
opened Sep 16, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update dependency nodeenv to v1.9.1
backport: auto
community
#5117
opened Sep 16, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
[New Rule] Azure RBAC Built-In Administrator Roles Assigned
backport: auto
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
Rule: New
Proposal for new rule
#5113
opened Sep 15, 2025 by
terrancedejesus
Loading…
5 tasks
[Rule Tuning] Microsoft Entra ID Elevated Access to User Access Administrator
backport: auto
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#5107
opened Sep 15, 2025 by
terrancedejesus
Loading…
5 tasks
Update dependency marko to v2.2.0
backport: auto
community
#5103
opened Sep 14, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update dependency flake8 to v7.3.0
backport: auto
community
#5102
opened Sep 14, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update dependency elasticsearch to ~=8.19.0
backport: auto
community
#5100
opened Sep 12, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update dependency PyGithub to v2.8.1
backport: auto
community
#5099
opened Sep 12, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update dependency Click to ~=8.2.1
backport: auto
community
#5098
opened Sep 12, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update tj-actions/changed-files action to v46.0.5
backport: auto
community
#5097
opened Sep 12, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
[Rule Tuning] Azure AD Global Administrator Role Assigned
backport: auto
Domain: Cloud
Domain: Identity
Integration: Azure
azure related rules
Rule: Tuning
tweaking or tuning an existing rule
#5090
opened Sep 11, 2025 by
terrancedejesus
Loading…
5 tasks
CLI next gen - timeline templates, value lists, and more
backport: auto
community
python
Internal python for the repository
#5042
opened Aug 30, 2025 by
frederikb96
Loading…
[Rule Tuning] Standardize Azure / M365 Rule Contents
backport: auto
#5035
opened Aug 28, 2025 by
terrancedejesus
•
Draft
5 tasks
feat: ESQL query validation against Elastic cluster
backport: auto
enhancement
New feature or request
esql
ES|QL
Hunting
minor
python
Internal python for the repository
test-suite
unit and other testing components
Previous Next
ProTip!
Type g i on any issue or pull request to go back to the issue listing page.