A newer version is available. Check out the latest documentation.

Downloadable rule updates

edit

This section lists all updates to prebuilt detection rules, made available with the Prebuilt Security Detection Rules integration in Fleet.

To update your installed rules to the latest versions, follow the instructions in Update Elastic prebuilt rules.

For previous rule updates, please navigate to the last version.

Update version Date New rules Updated rules Notes

8.18.3

30 Apr 2025

0

55

Version parity to ensure future updates are more meaningful and informative

8.18.2

28 Apr 2025

21

11

This release includes new rules for Windows, Linux, Azure and AWS. New rules for Windows include detection for defense evasion and execution New rules for Linux include detection for credential access, execution, privilege escalation, credential access, lateral movement and discovery. New rules for Azure include detection for initial access. New rules for AWS include detection for initial access and persistence. Additionally, significant rule tuning for MacOS, Windows, Microsoft 365, Linux and Azure rules has been added for better rule efficacy and performance.

8.18.1

08 Apr 2025

5

75

This release includes new rules for MacOS, Microsoft 365, AWS and PAD. New rules for MacOS include detection for command and control. New rules for Microsoft 365 include detection for initial access. New rules for AWS include detection for exfiltration. New rules for PAD include detection for privilege escalation. Elastic Defend for Container rules are deprecated. Additionally, significant rule tuning for Linux, Windows, Microsoft 365 and Azure rules has been added for better rule efficacy and performance.