detection-rules icon indicating copy to clipboard operation
detection-rules copied to clipboard

Results 231 detection-rules issues
Sort by recently updated
recently updated
newest added

### Link to Rule https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_execution_suspicious_explorer_winword.toml ### Rule Tuning Type None ### Description It seems that there is a typo in the query: The query includes the process executable `"?:\\Windows\\SyWOW64\\explorer.exe"` which...

Rule: Tuning
community
Team: TRADE

### Link to Rule https://github.com/elastic/detection-rules/blob/main/rules/integrations/azure/credential_access_entra_signin_brute_force_microsoft_365.toml ### Rule Tuning Type False Positives - Reducing benign events mistakenly identified as threats. ### Description We have found that non-interactive signins with expired or...

Integration: Azure
Rule: Tuning
community
Integration: Microsoft 365
Team: TRADE
Domain: SaaS

# Pull Request *Issue link(s)*: #4575 ## Summary - What I changed Very simple fix to allow any order of esql metadata by adjusting the regex in the validation check....

python
community
backport: auto
patch

**Related to:** https://github.com/elastic/kibana/pull/201825#pullrequestreview-2470373688 ## Summary In Kibana, I upgraded the package with prebuilt rules from `v8.16.2-beta.1` to `v8.16.2` and got 64 detection rules that can be upgraded via the Security...

bug
Team: TRADE

Include exceptions for error codes, restricted to `NonInteractiveUserSignInLogs` and token refreshes: - 70043 : Refresh token expired or no longer valid due to conditional access frequency checks - 70044 :...

Integration: Azure
Domain: Cloud
Rule: Tuning
community
backport: auto

### Describe the Bug The CLI `python -m detection_rules kibana export-rules` doesnt work with a simple esql rule, where metadata is set according to [official documentation](https://www.elastic.co/guide/en/security/8.17/rules-ui-create.html#create-esql-rule). It always leads to:...

bug
community
Team: TRADE

### Repository Feature None ### Problem Description Currently, timeline templates are referenced by id and name in the exported rule files. However, the tempalte itself is not exported/cannot be imported...

enhancement
community
stale
Team: TRADE

### Repository Feature None ### Problem Description Whenever I have an concern with a rule and need to discuss it with anyone it's best to have the GitHub rule link...

enhancement
community
stale
Team: TRADE

## Parent Epic https://github.com/elastic/ia-trade-team/issues/276 ## Summary Explore how attackers abuse object ownership issues for privilege escalation, lateral movement, and persistence. - [ ] Read the whitepaper and decide on scenarios...

OS: Windows
backlog
Team: TRADE
Meta

### Describe the Bug ## Summary Creating a new terms rule via the CLI will currently not prompt the user to supply the new_terms field(s) preventing the user from being...

bug
Team: TRADE