-
Notifications
You must be signed in to change notification settings - Fork 554
Pull requests: elastic/detection-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[New Rule] Potential Malicious PowerShell Based on Alert Correlation
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4635
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule] Dynamic IEX Reconstruction via Method String Access
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#4634
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule] Potential Dynamic IEX Reconstruction via Environment Variables
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#4633
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via Special Character Overuse
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4632
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via High Numeric Character Proportion
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4631
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4630
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule][BBR] Potential PowerShell Obfuscation via High Special Character Proportion
backport: auto
bbr
Building Block Rules
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4629
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule] Adding Coverage for AWS related rules
Rule: New
Proposal for new rule
AWS IAM or STS API Calls via Temporary Session Tokens
backport: auto
Domain: Cloud
Integration: AWS
#4628
opened Apr 16, 2025 by
terrancedejesus
Loading…
5 tasks
[Rule Tuning] Potential DLL Side-Loading via Trusted Microsoft Programs
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#4627
opened Apr 16, 2025 by
w0rk3r
Loading…
[New Rule] Adding Coverage for AWS related rules
Rule: New
Proposal for new rule
AWS IAM Virtual MFA Device Registration
backport: auto
Domain: Cloud
Integration: AWS
#4626
opened Apr 16, 2025 by
terrancedejesus
Loading…
5 tasks
[New Rule] Adding Coverage for AWS related rules
Rule: New
Proposal for new rule
AWS CLI with Kali Linux Fingerprint Identified
backport: auto
Domain: Cloud
Integration: AWS
#4625
opened Apr 16, 2025 by
terrancedejesus
Loading…
5 tasks
[New Rule] Adding Coverage for AWS related rules
Rule: New
Proposal for new rule
AWS S3 Static Site JavaScript File Uploaded
backport: auto
Domain: Cloud
Integration: AWS
#4617
opened Apr 15, 2025 by
terrancedejesus
Loading…
5 tasks
[New Rule] Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4615
opened Apr 15, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via Invalid Escape Sequences
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#4614
opened Apr 15, 2025 by
w0rk3r
Loading…
Hunting - add New feature or request
Hunting
patch
generate-json
command
backport: auto
enhancement
#4613
opened Apr 15, 2025 by
hop-dev
Loading…
2 tasks done
[New Rule] PowerShell Obfuscation via Negative Index String Reversal
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4610
opened Apr 14, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via Reverse Keywords
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4609
opened Apr 14, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via Character Array Reconstruction
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#4608
opened Apr 14, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via String Concatenation
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4607
opened Apr 14, 2025 by
w0rk3r
Loading…
[New] Windows Sandbox with Sensitive Configuration
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4606
opened Apr 14, 2025 by
Samirbous
Loading…
[New] RemoteMonologue Attack rules
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4604
opened Apr 14, 2025 by
Samirbous
Loading…
[New Rule] Threat Intel Email Indicator Match
backport: auto
patch
python
Internal python for the repository
Rule: New
Proposal for new rule
schema
#4598
opened Apr 4, 2025 by
w0rk3r
Loading…
[New Rule] Potential PowerShell Obfuscation via String Reordering
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#4595
opened Apr 3, 2025 by
w0rk3r
Loading…
[enhancement] In esql validation, allow any order of metadata
backport: auto
community
patch
python
Internal python for the repository
#4579
opened Mar 28, 2025 by
frederikb96
Loading…
5 tasks done
Previous Next
ProTip!
Follow long discussions with comments:>50.