elastic / elastic/detection-rules
[FR] Pre-Built Elastic Auditd Ruleset
Open
backlog
enhancement
OS: Linux
Security Content
Team: TRADE
- Dominant language
- Python
- Stars
- 2.7k
- Forks
- 696
- Avg merge
- 4d 17h
- Merged PRs (30d)
- 87
Description
### Summary
The detection rules repository has multiple rules that require Auditd rules to work properly. The investigation guides contain the information needed to create the rule file, however, it would be convenient to have a full OOTB elastic Auditd ruleset available that contains all rules necessary to run all OOTB detection rules.
Contributor guide
Assessment
This issue has not been assessed yet.