Announcing the Elastic Bounty Program for Behavior Rule Protections
ID: c16e7230-e8c2-5ed2-a33d-614e81b7c869
STIX ID: report--c16e7230-e8c2-5ed2-a33d-614e81b7c869
Feed Name: Elastic Security Labs
Elastic announces a new chapter of its HackerOne bug bounty program focused on external validation of Elastic Security SIEM and EDR detection rules—initially targeting Windows Behavior Alerts during an incubation period from Jan 28, 2025 to Sept 1, 2025. The program invites researchers to demonstrate novel evasion and bypass techniques (e.g., avoiding alerts for execution via specific file types like LNK, JS, VBS, CHM) under defined constraints, with rewards based on impact and complexity. It provides clear scope, success criteria, submission requirements (reproducible steps, evidence, code), and exclusions (e.g., timing-based evasions, admin-required or kernel techniques, trivial or well-known methods), aiming to improve rule resilience against evolving MITRE ATT&CK techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
