Ross ROSS = Recommend OSS · open-source software intelligence for agents

elastic/protections-artifacts resource

Elastic Security detection content for Endpoint observed · 2026-08-28

github.com/elastic/protections-artifacts · homepage · YARA · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

76/100

  • Activity 98
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1562
  • days_rel: n/a
  • days_push: 13
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1482 stars · 167 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Elastic's open repository of endpoint detection content, including EQL-based behavior rules, YARA malware rules, and ransomware protection artifacts for Elastic Security. It is automatically generated from Elastic's internal detection logic and serves as the transparent home for their endpoint protection rules.

Use cases

  • find yara rules to detect malware samples
  • get ransomware detection signatures for endpoint protection
  • write EQL behavior rules for threat hunting
  • map endpoint detection coverage to MITRE ATT&CK
  • review detection logic used by Elastic Endpoint Security
  • build custom threat detection rules for my SIEM

When to choose

  • you use Elastic Security or Elastic Endpoint and want to inspect or extend its detection content
  • you need high-quality, actively maintained YARA and behavior-based detection rules
  • you want transparent, open detection logic for endpoint threat protection

When to avoid

  • you need a standalone antivirus engine rather than detection rule content
  • you want to contribute code changes, since the repository is auto-generated and does not accept pull requests
  • you need detection content under a permissive open-source license, as this is Elastic License 2.0

Facets

dataset · maturity active

security vulnerability-scanning parser security developer-tools cross-platform windows yara-rules detection-rules endpoint-security ransomware malware-detection eql threat-detection elastic-security macos linux

10 sources

Member repositories

RepositoryRoleHealth v2
elastic/protections-artifactsmain76

For agents

markdown · JSON · MCP: product_card(name="elastic/protections-artifacts")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem