Elastic Security opens public detection rules repo
ID: e32b4cd6-2b2c-5aca-9566-b16eb9a4e130
STIX ID: report--e32b4cd6-2b2c-5aca-9566-b16eb9a4e130
Feed Name: Elastic Security Labs
Elastic introduces a public detection-rules GitHub repository for Elastic Security, detailing its rule content (KQL/Lucene, future EQL, ML jobs), ECS-based portability, metadata standards, and contribution/testing workflows. The post explains the behavioral detection philosophy tied to MITRE ATT&CK, performance best practices, and how users receive rule updates in the detection engine, inviting community collaboration and contributions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
