logo

Elastic Security opens public detection rules repo

ID: e32b4cd6-2b2c-5aca-9566-b16eb9a4e130

STIX ID: report--e32b4cd6-2b2c-5aca-9566-b16eb9a4e130

Feed Name: Elastic Security Labs

Date Published: 2022-05-20

Date Updated: 2026-04-27

...
...

Elastic introduces a public detection-rules GitHub repository for Elastic Security, detailing its rule content (KQL/Lucene, future EQL, ML jobs), ECS-based portability, metadata standards, and contribution/testing workflows. The post explains the behavioral detection philosophy tied to MITRE ATT&CK, performance best practices, and how users receive rule updates in the detection engine, inviting community collaboration and contributions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.