# elastic/protections-artifacts

Elastic Security detection content for Endpoint

Repository: https://github.com/elastic/protections-artifacts
Canonical: https://ross.abutalabs.com/products/protections-artifacts
Homepage: https://www.elastic.co/security/endpoint-security
Language: YARA
License: NOASSERTION
License Family: other
Last push: 2026-08-20T10:09:02+00:00

## Health v2 (maintenance only)
Score: 76/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 98, release rhythm 35, longevity 100
- inputs: {"age_days": 1562, "days_push": 13, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1482, forks 167 (observed 2026-08-28T04:04:51.188264+00:00)

## What it is
Elastic's open repository of endpoint detection content, including EQL-based behavior rules, YARA malware rules, and ransomware protection artifacts for Elastic Security. It is automatically generated from Elastic's internal detection logic and serves as the transparent home for their endpoint protection rules.

## Use cases
- find yara rules to detect malware samples
- get ransomware detection signatures for endpoint protection
- write EQL behavior rules for threat hunting
- map endpoint detection coverage to MITRE ATT&CK
- review detection logic used by Elastic Endpoint Security
- build custom threat detection rules for my SIEM

## When to choose
- you use Elastic Security or Elastic Endpoint and want to inspect or extend its detection content
- you need high-quality, actively maintained YARA and behavior-based detection rules
- you want transparent, open detection logic for endpoint threat protection

## When to avoid
- you need a standalone antivirus engine rather than detection rule content
- you want to contribute code changes, since the repository is auto-generated and does not accept pull requests
- you need detection content under a permissive open-source license, as this is Elastic License 2.0

## Facets
- artifact type: dataset
- maturity: active
- function: security, vulnerability-scanning, parser
- domain: security, developer-tools
- platform: cross-platform, windows
- tags: yara-rules, detection-rules, endpoint-security, ransomware, malware-detection, eql, threat-detection, elastic-security, macos, linux

## Member repositories
- elastic/protections-artifacts (main) score 76

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:51.188264+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:34:06.555092+00:00, confidence not recorded.
  - readme: https://github.com/elastic/protections-artifacts (fetched 2026-08-28T04:04:51.188264+00:00, sha de0db7a4f077)
  - homepage: https://www.elastic.co/security/endpoint-security (fetched 2026-08-29T11:40:42.687166+00:00, sha c5db46d43c59)
  - site_page: https://www.elastic.co/about (fetched 2026-08-29T11:40:42.696468+00:00, sha dcc190ae197d)
  - site_page: https://www.elastic.co/getting-started (fetched 2026-08-29T11:40:42.700048+00:00, sha 7de41ab1d939)
  - site_page: https://www.elastic.co/docs (fetched 2026-08-29T11:40:42.703684+00:00, sha c4139162fd2c)
  - site_page: https://www.elastic.co/partners/ai-ecosystem (fetched 2026-08-29T11:40:42.698300+00:00, sha 87dba7e5abe6)
  - site_page: https://www.elastic.co/integrations/data-integrations (fetched 2026-08-29T11:40:42.701755+00:00, sha 75f0e785f92a)
  - site_page: https://www.elastic.co/search-labs (fetched 2026-08-29T11:40:42.705267+00:00, sha 4474e57454b5)
  - site_page: https://www.elastic.co/pricing (fetched 2026-08-29T11:40:42.706946+00:00, sha 6ab7886d790c)
  - site_page: https://www.elastic.co/security/xdr (fetched 2026-08-29T11:40:42.708846+00:00, sha 79ee5eb71a2c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
