Skip to content
 
 

Latest commit

 

History

8 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

Elasticsearch_rules

ElasticSearch Detection version of SOC prime watcher rules with some new Corelight rules

Please note some of these rules should be tuned to your environment.

To load in Elastic, download the ndjson and expand Security and go to alerts. Click on Managed Alerts and click import rules and upload the file to Elastic. This will create two new tags one Zeek - These rules will work on OS Zeek and Corelight, and the other Corelight will only work with Corelight Data.

About

Elastic version of SOC prime watcher rules

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors