Skip to content

Pull requests: elastic/detection-rules

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Assigned to nobody Loading
Sort

Pull requests list

[FR] Workflow Updates for Automatically Bumping Stack Version backport: auto ci/cd enhancement New feature or request
#5941 opened Apr 9, 2026 by eric-forte-elastic Contributor Loading…
5 tasks
Fix TOML transform sections for Tomlet / docs-builder backport: auto Domain: Endpoint OS: Windows windows related rules
#5931 opened Apr 8, 2026 by Mpdreamz Member Loading…
5 tasks
[Rule Tuning] Update MDE tags to "Microsoft Defender XDR" backport: auto bbr Building Block Rules Domain: Endpoint OS: Windows windows related rules patch Rule: Tuning tweaking or tuning an existing rule
#5927 opened Apr 7, 2026 by w0rk3r Contributor Loading…
[New] Diverse AWS rules backport: auto Domain: Cloud Integration: AWS AWS related rules Rule: New Proposal for new rule Rule: Tuning tweaking or tuning an existing rule
#5913 opened Apr 3, 2026 by Samirbous Contributor Loading…
[Tuning] Execution via GitHub Actions Runner backport: auto Domain: Endpoint Rule: Tuning tweaking or tuning an existing rule
#5892 opened Mar 27, 2026 by Samirbous Contributor Loading…
[New Rules] macOS Unified Logs Login Window and XProtect Detections backport: auto dev rule meant to be non-prod / non-shipping integration: Unified_Logs OS: macOS patch Rule: New Proposal for new rule
#5874 opened Mar 23, 2026 by DefSecSentinel Contributor Loading…
4 tasks
[New Rules] macOS Unified Logs TCC Detection Rules backport: auto dev rule meant to be non-prod / non-shipping integration: Unified_Logs OS: macOS patch Rule: New Proposal for new rule
#5870 opened Mar 23, 2026 by DefSecSentinel Contributor Loading…
6 tasks
[New Rules] macOS Unified Logs Apple Event Detections backport: auto dev rule meant to be non-prod / non-shipping Hunting integration: Unified_Logs OS: macOS patch Rule: New Proposal for new rule
#5867 opened Mar 23, 2026 by DefSecSentinel Contributor Loading…
5 tasks
[Feature] Add support for immutable and rule_source fields in TOML export/import backport: auto python Internal python for the repository
#5840 opened Mar 17, 2026 by aarju Contributor Loading…
5 tasks
ProTip! Type g p on any issue or pull request to go back to the pull request listing page.