elastic / elastic/detection-rules

[FR] Pre-Built Elastic Auditd Ruleset

Open
#4,713 2 comments 1 reaction 1 assignee Claimed by @Aegrah View on GitHub
backlog enhancement OS: Linux Security Content Team: TRADE
Dominant language
Python
Stars
2.7k
Forks
696
Avg merge
4d 17h
Merged PRs (30d)
87

Description

### Summary

The detection rules repository has multiple rules that require Auditd rules to work properly. The investigation guides contain the information needed to create the rule file, however, it would be convenient to have a full OOTB elastic Auditd ruleset available that contains all rules necessary to run all OOTB detection rules.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.