Skip to content

Pull requests: elastic/detection-rules

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Reviews
Assignee
Filter by who’s assigned
Sort

Pull requests list

[Tuning] Suspicious WMI Event Subscription Created backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule
#4327 opened Dec 23, 2024 by Samirbous Loading…
[New Hunt] Persistence via Container backport: auto Hunt: New Hunting major OS: Linux Rule: Hunt bit noisy but useful for hunting Team: TRADE threat hunting Related to hunting/ library.
#4322 opened Dec 19, 2024 by Aegrah Loading…
[New Hunt] Persistence via Web Shells backport: auto Hunt: New Hunting OS: Linux Rule: Hunt bit noisy but useful for hunting Team: TRADE threat hunting Related to hunting/ library.
#4320 opened Dec 19, 2024 by Aegrah Loading…
[New Hunt] Linux PAM Persistence backport: auto Hunting OS: Linux Rule: Hunt bit noisy but useful for hunting Rule: New Proposal for new rule Team: TRADE
#4317 opened Dec 19, 2024 by Aegrah Loading…
[Rule Tuning] Windows misc Rule Tuning backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule
#4298 opened Dec 12, 2024 by w0rk3r Loading…
ProTip! Exclude everything labeled bug with -label:bug.