Source overview

elastic/detection-rules

Official Elastic SIEM detection rules — TOML wrapping EQL/KQL/Lucene queries, mapped to ATT&CK.

elastic-detection-rules · Elastic TOML · upstream repo ↗ · Elastic License 2.0

Rules indexed 2075 9 atomic-IOC hidden · include 128 deprecated hidden · include
ATT&CK techniques 446
Newest rule 2026-10-07 checked 2026-10-08

How detections work here

Elastic's own detection content, run as scheduled queries against Elasticsearch by the Detection Engine. This is the model most of this index assumes: a query, a lookback window, an interval.

Do not confuse it with elastic-protections-artifacts, which ships inside the Elastic Defend agent and runs on the endpoint.

How rules are written

TOML, with [metadata] and [rule] tables. The important field is language, because this source carries several query languages — kuery, eql, esql — and the rule's type selects which engine runs it. That is why this is one of the few sources here with a meaningful content-type breakdown: query, eql, esql, threshold, new_terms, machine_learning and threat_match are genuinely different detection mechanisms, not labels.

index declares the indices searched and from the lookback (now-9m). risk_score is a 1–100 integer, which we preserve and also bucket into this site's five-level severity — both are shown on a rule's page.

Reading a rule on this site

Two prose fields map to distinct places, and the distinction is worth knowing: setup becomes the implementation guide (what you must configure before the rule works), while note becomes triage notes (what to do when it fires). Elastic's note fields are unusually thorough investigation guides, often longer than the rule itself.

ATT&CK comes from the [[rule.threat]] blocks and is generally complete.

Gotchas

  • type = "machine_learning" rules have no readable query — they reference a trained job by name. The rule tells you what it alerts on, not how it decides.
  • Every rule is scoped to specific index patterns and Elastic integrations. A rule is only deployable if you are shipping that integration's data in that shape.
  • Some investigation guides are noted upstream as generated with AI assistance and reviewed. Read them as a starting point.

Severity

Status


Platforms

endpoint 985 windows 458 sentinel_one_cloud_funnel 437 crowdstrike 328 m365_defender 262 system 254 aws 212 auditd_manager 147 +54 more

Content types

eql 972 query 456 esql 281 new_terms 232 machine_learning 106 threshold 28


Recently modified

all →
Anthropic Admin Role Assigned to User 2026-10-07
Anthropic Primary Owner Transferred 2026-10-07
AWS Bedrock AgentCore with Public Network Browser or Code Interpreter Sandbox 2026-10-07
GCP Vertex AI Caller Impossible Travel 2026-10-07
GCP Vertex AI High Request and Token Volume 2026-10-07

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.