Downloadable rule updates

edit

This section lists all updates to prebuilt detection rules, made available with the Prebuilt Security Detection Rules integration in Fleet.

To update your installed rules to the latest versions, follow the instructions in Update Elastic prebuilt rules.

For previous rule updates, please navigate to the last version.

Update version Date New rules Updated rules Notes

8.17.2

08 Jan 2025

20

10

This release includes new rules for Linux, Azure and Elastic Defend integration. Deprecated rules include Suspicious File Changes Activity Detected New rules for Linux include detection for persistence and defense evasion. New rules for Azure include detection for credential access. New Rules for Elastic Defend include detection for defense evasion, execution and impact. Additionally, significant rule tuning for Linux, Windows and Okta rules has been added for better rule efficacy and performance.

8.17.1

10 Dec 2024

5

6

This release includes new rules for AWS, and AWS Bedrock integration. New rules for AWS include detection for persistence. New rules for AWS Bedrock include detection for LLM prompt injection and LLM jailbreak. Additionally, significant rule tuning for AWS, Github, AWS Bedrock and Azure rules has been added for better rule efficacy and performance.