Files
elastic-protections-artifacts/behavior
2026-04-30 12:33:54 +05:30
..
2026-04-30 03:17:05 +00:00
2026-04-30 12:33:54 +05:30

Elastic Security Malicious Behavior Protection Rules

Prebuilt high signal EQL rules that runs on the endpoint to disrupt malicious behavior, this layer of prevention equips Elastic Agent to protect Linux, Windows, and macOS hosts from a broad range of attack techniques with a major focus on the following tactics :

Prevention is achieved by pairing post-execution analytics with response actions to kill a specific process or a full process tree tailored to stop the adversary at the initial stages of the attack. Each protection rule is mapped to the most relevant MITRE ATT&CK tactic, technique and subtechnique.

The true positive rate that we aim to maintain is at least 70%, thus we prioritize analytics logic precision to reduce detection scope via prevention.

Another example of our commitment to openness in security is our existing public Detection Rules repository where we share EQL rules that run on the SIEM side, and that have a broader detection logic which make them more suitable for detection and hunting.

Latest Release

artifact version hash
production-rules-linux-v1 1.0.115 987cb885b57385b684aa4eb40d07e9407a43ece9a08df3ab776a3112457669bd
production-rules-macos-v1 1.0.115 f4c8739efafae8e932b7c8c5fb38ec9a86e3f9703212326abecae89acedade14
production-rules-windows-v1 1.0.115 7df2a890c948179bb6033c4c91c15cf462414bf17237040df1316b8e417124b3

Rules Summary per Tactic

Note: New Production Rules since last version ('1.0.115', '1.0.114') by OS/MITRE Tactic.

Tactic Windows Linux macOS Total by Tactic
Command and Control 1 0 0 1
Defense Evasion 0 1 0 1
Execution 1 1 1 3
Persistence 1 0 1 2
Total by OS 3 2 2 7

Note: Latest Total Production Rules by OS/MITRE Tactic.

Tactic Windows Linux macOS Total by Tactic
Collection 12 0 8 20
Command and Control 40 11 41 92
Credential Access 52 7 35 94
Defense Evasion 322 48 61 431
Discovery 20 1 1 22
Execution 95 59 105 259
Exfiltration 0 0 2 2
Impact 19 6 2 27
Initial Access 62 1 2 65
Lateral Movement 10 2 1 13
Persistence 61 26 21 108
Privilege Escalation 73 14 9 96
Total by OS 766 175 288 1229