logo

Elevate Your Threat Hunting with Elastic

ID: 31ad0d62-792b-5f0b-aa91-413849cfc3f7

STIX ID: report--31ad0d62-792b-5f0b-aa91-413849cfc3f7

Feed Name: Elastic Security Labs

Date Published: 2024-10-18

Date Updated: 2026-04-27

...
...

Elastic announces a new Hunting package in the Detection Rules repository that delivers curated, MITRE ATT&CK-mapped hunting queries across endpoints, cloud, network, and other integrations, plus CLI tooling to generate, search, run, and manage hunts. The resource aims to complement SIEM/EDR detections, offering standardized TOML/Markdown queries in multiple languages (ES|QL, EQL, KQL, OsQuery, YARA), and includes an example hunt for suspicious Okta OAuth client-credentials activity, with guidance on creating, indexing, and executing hunts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.