logo

Announcing the Elastic Bounty Program for Behavior Rule Protections

ID: c16e7230-e8c2-5ed2-a33d-614e81b7c869

STIX ID: report--c16e7230-e8c2-5ed2-a33d-614e81b7c869

Feed Name: Elastic Security Labs

Date Published: 2025-01-29

Date Updated: 2026-04-27

...
...

Elastic announces a new chapter of its HackerOne bug bounty program focused on external validation of Elastic Security SIEM and EDR detection rules—initially targeting Windows Behavior Alerts during an incubation period from Jan 28, 2025 to Sept 1, 2025. The program invites researchers to demonstrate novel evasion and bypass techniques (e.g., avoiding alerts for execution via specific file types like LNK, JS, VBS, CHM) under defined constraints, with rewards based on impact and complexity. It provides clear scope, success criteria, submission requirements (reproducible steps, evidence, code), and exclusions (e.g., timing-based evasions, admin-required or kernel techniques, trivial or well-known methods), aiming to improve rule resilience against evolving MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.