Skip to content

Actions: elastic/detection-rules

backport

Actions

Loading...
Loading

Show workflow options

Create status badge

Loading
5,701 workflow runs
5,701 workflow runs

Filter by Event

Filter by Status

Filter by Branch

Filter by Actor

Lock versions for releases: 8.11,8.12,8.13,8.14,8.15,8.16
backport #11498: Pull request #4267 closed by shashank-elastic
November 11, 2024 16:59 5m 22s
November 11, 2024 16:59 5m 22s
Lock versions for releases: 8.11,8.12,8.13,8.14,8.15,8.16
backport #11497: Pull request #4267 labeled by Mikaayenson
November 11, 2024 16:48 44s
November 11, 2024 16:48 44s
Lock versions for releases: 8.11,8.12,8.13,8.14,8.15,8.16
backport #11496: Pull request #4266 closed by shashank-elastic
November 11, 2024 16:15 46s
November 11, 2024 16:15 46s
[New] First Time Seen User Auth via DeviceCode Protocol
backport #11495: Pull request #4153 closed by Samirbous
November 11, 2024 13:04 5m 18s
November 11, 2024 13:04 5m 18s
[New] Remote Desktop File Opened from Suspicious Path
backport #11494: Pull request #4251 closed by shashank-elastic
November 11, 2024 12:38 5m 22s
November 11, 2024 12:38 5m 22s
[Rule Tuning] Add Investigation Fields to Specific AWS Rules
backport #11493: Pull request #4261 closed by terrancedejesus
November 9, 2024 04:11 5m 27s
November 9, 2024 04:11 5m 27s
[Rule Tuning] Tuning Process Termination followed by Deletion
backport #11492: Pull request #4173 closed by w0rk3r
November 8, 2024 19:38 5m 22s
November 8, 2024 19:38 5m 22s
[New Rule] Potential Hex Payload Execution
backport #11491: Pull request #4241 closed by Aegrah
November 8, 2024 18:15 5m 31s
November 8, 2024 18:15 5m 31s
[New Rule] Memory Swap Modification
backport #11490: Pull request #4239 closed by Aegrah
November 8, 2024 18:06 5m 39s
November 8, 2024 18:06 5m 39s
[New Rule] Unusual Interactive Shell Launched from System User
backport #11489: Pull request #4238 closed by Aegrah
November 8, 2024 17:24 5m 39s
November 8, 2024 17:24 5m 39s
[New Rule] Web Server Spawned via Python
backport #11488: Pull request #4236 closed by Aegrah
November 8, 2024 17:16 6m 34s
November 8, 2024 17:16 6m 34s
[New Rule] Directory Creation in /bin directory
backport #11487: Pull request #4227 closed by Aegrah
November 8, 2024 17:07 5m 28s
November 8, 2024 17:07 5m 28s
[New Rule] Hidden Directory Creation via Unusual Parent
backport #11486: Pull request #4226 closed by Aegrah
November 8, 2024 16:58 5m 14s
November 8, 2024 16:58 5m 14s
[New Rule] Security File Access via Common Utilities
backport #11485: Pull request #4243 closed by Aegrah
November 8, 2024 16:41 5m 14s
November 8, 2024 16:41 5m 14s
[New Rule] Potential Data Splitting Detected
backport #11484: Pull request #4235 closed by Aegrah
November 8, 2024 16:33 5m 56s
November 8, 2024 16:33 5m 56s
[New Rule] Private Key Searching Activity
backport #11483: Pull request #4242 closed by Aegrah
November 8, 2024 16:13 5m 30s
November 8, 2024 16:13 5m 30s
[New Rule] IPv4/IPv6 Forwarding Activity
backport #11482: Pull request #4240 closed by Aegrah
November 8, 2024 16:06 5m 38s
November 8, 2024 16:06 5m 38s
[New Rule] Curl SOCKS Proxy Activity from Unusual Parent
backport #11481: Pull request #4237 closed by Aegrah
November 8, 2024 15:51 5m 26s
November 8, 2024 15:51 5m 26s
Update ATT&CK coverage URL(s) in docs/ATT&CK-coverage.md
backport #11480: Pull request #4265 closed by shashank-elastic
November 8, 2024 14:57 5m 16s
November 8, 2024 14:57 5m 16s
Fix extra new line in ATT&CK-coverage.md
backport #11479: Pull request #4263 closed by shashank-elastic
November 8, 2024 14:43 5m 17s
November 8, 2024 14:43 5m 17s
Account for CCS '::' index pattern
backport #11478: Pull request #4258 labeled by shashank-elastic
November 8, 2024 13:40 44s
November 8, 2024 13:40 44s
Update ATT&CK coverage URL(s) in docs/ATT&CK-coverage.md
backport #11477: Pull request #4265 labeled by shashank-elastic
November 8, 2024 13:24 50s
November 8, 2024 13:24 50s
Update ATT&CK coverage URL(s) in docs/ATT&CK-coverage.md
backport #11476: Pull request #4265 labeled by shashank-elastic
November 8, 2024 13:23 44s
November 8, 2024 13:23 44s
Fix extra new line in ATT&CK-coverage.md
backport #11475: Pull request #4263 labeled by shashank-elastic
November 8, 2024 13:09 42s
November 8, 2024 13:09 42s
Update ATT&CK coverage URL(s) in docs/ATT&CK-coverage.md
backport #11474: Pull request #4264 closed by shashank-elastic
November 8, 2024 13:08 44s
November 8, 2024 13:08 44s