Skip to content

[FR] Pre-Built Elastic Auditd Ruleset #4713

Open
@Aegrah

Description

@Aegrah

Summary

The detection rules repository has multiple rules that require Auditd rules to work properly. The investigation guides contain the information needed to create the rule file, however, it would be convenient to have a full OOTB elastic Auditd ruleset available that contains all rules necessary to run all OOTB detection rules.

Metadata

Metadata

Assignees

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions