Non-Windows Detection Rules

7,646 detection rules across 16 platforms, from 7 rule sources. These cover Linux, macOS, cloud, SaaS, identity, and network telemetry: rules that do not map to a Windows event. The Windows event catalog and its rules live on the home page.

Search rule titles and descriptions, or combine operators like platform:linux technique:T1059 or vendor:elastic domain:cloud.