Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Elasticsearch_rules — Elastic version of SOC prime watcher rules | Kitploit
Tools/GitHubGitHub/corelight/elasticsearch_rules
Network SecurityThreat IntelligenceIntrusion DetectionCurated ResourcesLog Analysis
GitHubcorelight/elasticsearch_rules

Elasticsearch_rules

Elastic version of SOC prime watcher rules

View Repository
3061 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Elasticsearch_rules

ElasticSearch Detection version of SOC prime watcher rules with some new Corelight rules

Please note some of these rules should be tuned to your environment.

To load in Elastic, download the ndjson and expand Security and go to alerts. Click on Managed Alerts and click import rules and upload the file to Elastic. This will create two new tags one Zeek - These rules will work on OS Zeek and Corelight, and the other Corelight will only work with Corelight Data.

Download Tool