Skip to content

Pull requests: elastic/detection-rules

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

[Bug] Update Min Stack Calculation to Include Patch Version backport: auto bug Something isn't working patch python Internal python for the repository
#6289 opened Jun 17, 2026 by eric-forte-elastic Contributor Loading…
5 tasks
[Rule Tuning] Misc. Linux DR Tunings backport: auto Domain: Endpoint OS: Linux Rule: Tuning tweaking or tuning an existing rule Team: TRADE
#6285 opened Jun 17, 2026 by Aegrah Contributor Loading…
[New Rule] Azure VM Boot Diagnostics Retrieved backport: auto Domain: Cloud Domain: Endpoint Integration: Azure azure related rules Rule: New Proposal for new rule
#6275 opened Jun 15, 2026 by terrancedejesus Contributor Loading…
5 tasks
WIP - [FR] Add optional user agent string for DaC commands detections-as-code enhancement New feature or request kibana-module related to the kibana module patch python Internal python for the repository
#6268 opened Jun 11, 2026 by eric-forte-elastic Contributor Draft
5 tasks
[Rule Tuning] Azure Compute VM Command Executed backport: auto Domain: Cloud Domain: Endpoint Integration: Azure azure related rules Rule: Tuning tweaking or tuning an existing rule
#6266 opened Jun 10, 2026 by terrancedejesus Contributor Loading…
5 tasks
[Rule Tuning] Add Corelight support for existing rules backport: auto Domain: Network Integration: Corelight patch python Internal python for the repository Rule: Tuning tweaking or tuning an existing rule schema Team: TRADE
#6261 opened Jun 9, 2026 by eric-forte-elastic Contributor Loading…
5 tasks
[Rule Tuning] Add pfSense support for existing rules backport: auto Domain: Network Integration: pfSense patch python Internal python for the repository Rule: Tuning tweaking or tuning an existing rule schema Team: TRADE
#6260 opened Jun 9, 2026 by eric-forte-elastic Contributor Loading…
5 tasks
Allow filter-only KQL custom rule exports backport: auto community enhancement New feature or request patch python Internal python for the repository
#6253 opened Jun 4, 2026 by srkyn Loading…
[Rule Tuning] Multiple Alerts in Different ATT&CK Tactics on a Single Host backport: auto Rule: Tuning tweaking or tuning an existing rule
#6252 opened Jun 4, 2026 by Mikaayenson Contributor Loading…
1 of 5 tasks
[Rule Tuning] Misc. Linux DRs backport: auto Domain: Endpoint OS: Linux Rule: Tuning tweaking or tuning an existing rule Team: TRADE
#6250 opened Jun 4, 2026 by Aegrah Contributor Loading…
ProTip! Add no:assignee to see everything that’s not assigned.