Skip to content

Actions: elastic/detection-rules

Community

Actions

Loading...
Loading

Show workflow options

Create status badge

Loading
1,063 workflow runs
1,063 workflow runs

Filter by Event

Filter by Status

Filter by Branch

Filter by Actor

[New Rules] Veeam Credential Access DRs
Community #2022: Pull request #3516 opened by w0rk3r
March 15, 2024 09:21 17s
March 15, 2024 09:21 17s
[FR] Update Python Dependency Versions
Community #2021: Pull request #3515 opened by Mikaayenson
March 15, 2024 04:09 12s
March 15, 2024 04:09 12s
[FR] Independently package kql / kibana and bump to py3.12
Community #2020: Pull request #3514 opened by Mikaayenson
March 15, 2024 00:52 10s
March 15, 2024 00:52 10s
[FR] Add python3.12 setup in backport workflows
Community #2019: Pull request #3513 opened by Mikaayenson
March 15, 2024 00:37 14s
March 15, 2024 00:37 14s
[Meta] Prepare 20 Linux ES|QL Hunts
Community #2017: Issue #3511 opened by Aegrah
March 14, 2024 12:40 12s
March 14, 2024 12:40 12s
[FR] Add support for dataviews in the rule schema
Community #2016: Pull request #3510 opened by Mikaayenson
March 13, 2024 21:13 10s
March 13, 2024 21:13 10s
[FR] Update schemas to support runtime fields
Community #2015: Issue #3509 opened by Mikaayenson
March 13, 2024 20:18 15s
March 13, 2024 20:18 15s
[Rule Tuning] Potential Reverse Shell via UDP
Community #2014: Pull request #3508 opened by Aegrah
March 13, 2024 13:26 14s
March 13, 2024 13:26 14s
[New Rules] mprotect() RWX Binary Execution
Community #2013: Pull request #3507 opened by Aegrah
March 13, 2024 13:18 13s
March 13, 2024 13:18 13s
[Rule Tuning] Multiple Okta Client Addresses for a Single User Session
Community #2012: Issue #3506 opened by ksavchuk
March 13, 2024 08:41 14s
March 13, 2024 08:41 14s
[Rule Tuning] Replace KQL exceptions for Query DSL Exceptions
Community #2011: Pull request #3505 opened by w0rk3r
March 12, 2024 21:02 12s
March 12, 2024 21:02 12s
Update collection_microsoft_365_new_inbox_rule.toml
Community #2010: Pull request #3504 opened by acumen-kevinr
March 11, 2024 22:39 10s
March 11, 2024 22:39 10s
Update collection_microsoft_365_new_inbox_rule.toml
Community #2009: Pull request #3503 opened by acumen-kevinr
March 11, 2024 22:36 13s
March 11, 2024 22:36 13s
[Rule Tuning] Guided Onboarding Rule
Community #2008: Pull request #3502 opened by w0rk3r
March 11, 2024 12:20 13s
March 11, 2024 12:20 13s
[Rule Tuning] Improve Compatibility in WIndows Detection Rules - Part 1
Community #2007: Pull request #3501 opened by w0rk3r
March 8, 2024 20:04 14s
March 8, 2024 20:04 14s
[Rule Tuning] AWS Route Table Modified or Deleted
Community #2005: Issue #3499 opened by leandrojmp
March 8, 2024 18:30 12s
March 8, 2024 18:30 12s
[Rule Tuning] AWS Route Table Created
Community #2004: Issue #3498 opened by leandrojmp
March 8, 2024 18:22 10s
March 8, 2024 18:22 10s
Beaconing - Add whitelist to rules, with some more processes
Community #2003: Pull request #3497 opened by susan-shu-c
March 8, 2024 16:15 9s
March 8, 2024 16:15 9s
[Rule Tuning] Review KQL Syntax used to exclude Windows Paths
Community #2002: Issue #3496 opened by w0rk3r
March 8, 2024 11:44 13s
March 8, 2024 11:44 13s
[Tuning] event.action and event.type change
Community #2001: Pull request #3495 opened by Aegrah
March 8, 2024 09:44 13s
March 8, 2024 09:44 13s
March 7, 2024 19:04 13s
[FR] Independently package kql / kibana and bump to py3.12
Community #1998: Pull request #3492 opened by Mikaayenson
March 6, 2024 21:38 12s
March 6, 2024 21:38 12s
ProTip! You can narrow down the results and go further in time using created:<2024-03-06 or the other filters available.