-
Notifications
You must be signed in to change notification settings - Fork 617
Pull requests: elastic/detection-rules
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[New] Newly Observed Process Exhibiting CPU Spike
backport: auto
Domain: Endpoint
Rule: New
Proposal for new rule
#5635
opened Jan 27, 2026 by
Samirbous
Loading…
chore: Fix lock version for 9.3.2 Release
backport: auto
Rule: Tuning
tweaking or tuning an existing rule
#5634
opened Jan 27, 2026 by
eric-forte-elastic
•
Draft
5 tasks
[New Rule] Okta AiTM Session Cookie Replay Detection
backport: auto
Domain: Cloud
Domain: Identity
Integration: Okta
okta related rules
Rule: New
Proposal for new rule
#5627
opened Jan 26, 2026 by
terrancedejesus
Loading…
5 tasks
README fixes
backport: auto
documentation
Improvements or additions to documentation
maintenance
Internal changes
patch
#5616
opened Jan 26, 2026 by
traut
Loading…
1 of 5 tasks
Update actions/checkout digest
backport: auto
community
#5613
opened Jan 25, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
Update fjogeleit/http-request-action digest to c0b95d0
backport: auto
community
#5605
opened Jan 23, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
[doc fix] Adjust wording in the docs for Kibana import/export commands
backport: auto
enhancement
New feature or request
patch
python
Internal python for the repository
#5600
opened Jan 22, 2026 by
traut
Loading…
5 tasks
[Rule Tuning] Unsigned DLL Side-Loading from a Suspicious Folder: Add Downloads path and fix subdirectory evasion
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: Tuning
tweaking or tuning an existing rule
#5592
opened Jan 21, 2026 by
ailiffa
Loading…
4 tasks
[Hunt Tuning] Fix Invalid ES|QL Syntax in Hunting Queries
backport: auto
Hunt: Tuning
Hunting
#5566
opened Jan 16, 2026 by
terrancedejesus
Loading…
5 tasks
[New Rule] Multiple High-Severity Alerts for Privileged AD User
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
[New Rule] Potential PowerShell Obfuscated Script via High Entropy
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
#5554
opened Jan 12, 2026 by
w0rk3r
Loading…
[New Rule] PowerShell Script Block Entropy Outlier via MAD Z-Score
backport: auto
Domain: Endpoint
OS: Windows
windows related rules
Rule: New
Proposal for new rule
Update actions/setup-python digest to a309ff8
backport: auto
community
#5527
opened Jan 3, 2026 by
elastic-renovate-prod
bot
Loading…
1 task
Update actions/checkout action to v6
backport: auto
community
#5349
opened Nov 20, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update dependency marshmallow to v4
backport: auto
community
#5330
opened Nov 17, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update dependency elasticsearch to v9
backport: auto
community
#5329
opened Nov 17, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update actions/upload-artifact action to v6
backport: auto
community
#5328
opened Nov 17, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update actions/setup-python action to v6
backport: auto
community
#5326
opened Nov 17, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update actions/setup-go action to v6
backport: auto
community
#5325
opened Nov 17, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
Update dependency elasticsearch to ~=8.19.3
backport: auto
community
#5100
opened Sep 12, 2025 by
elastic-renovate-prod
bot
Loading…
1 task
[Rule Tuning] Standardize Azure / M365 Rule Contents
backlog
backport: auto
#5035
opened Aug 28, 2025 by
terrancedejesus
•
Draft
5 tasks
Previous Next
ProTip!
Mix and match filters to narrow down what you’re looking for.