अपडेट पर वापस जाएँ
New releaseSep 9, 2026

detection-rules dev-v2.2.0

Elastic Security के लिए SIEM डिटेक्शन नियम विकसित करें, मान्य करें और प्रकाशित करें, जिसमें Python CLI टूलिंग, KQL पार्सिंग, Kibana एकीकरण और पैकेज्ड थ्रेट हंटिंग क्वेरी शामिल हैं।

साझा करें

Supported Python versions Unit Tests Chat ATT&CK navigator coverage

Detection Rules

Detection Rules, Elastic Security द्वारा उपयोग किए जाने वाले rules का घर है। इस रिपॉज़िटरी का उपयोग Elastic Security के Detection Engine के लिए rules के विकास, रखरखाव, परीक्षण, सत्यापन और रिलीज़ के लिए किया जाता है।

इस रिपॉज़िटरी की घोषणा सबसे पहले Elastic के ब्लॉग पोस्ट, Elastic Security ने सार्वजनिक detection rules रिपॉज़िटरी खोली में की गई थी। अतिरिक्त सामग्री के लिए, साथ में दिया गया वेबिनार देखें, Elastic Security: detection rules के लिए सार्वजनिक रिपॉज़िटरी का परिचय।

विषय-सूची

इस रिपॉज़िटरी का अवलोकन

Detection Rules में केवल स्टैटिक rule फ़ाइलों से अधिक सामग्री है। इस रिपॉज़िटरी में Detections-as-code पाइपलाइन बनाने, Python में यूनिट टेस्टिंग और Kibana में Detection Engine के साथ एकीकरण के लिए कोड भी शामिल है।

फ़ोल्डरविवरण
detection_rules/rule पार्सिंग, सत्यापन और पैकेजिंग के लिए Python मॉड्यूल
etc/विविध फ़ाइलें, जैसे ECS और Beats स्कीमा तथा कॉन्फ़िगरेशन फ़ाइलें
hunting/रूट डायरेक्टरी जहाँ threat hunting पैकेज और क्वेरी संग्रहीत की जाती हैं
kibana/Kibana और Detection Engine के लिए API कॉल्स को संभालने हेतु Python लाइब्रेरी
kql/Kibana Query Language को पार्स और सत्यापित करने के लिए Python लाइब्रेरी
rules/रूट डायरेक्टरी जहाँ rules संग्रहीत होते हैं
rules_building_block/रूट डायरेक्टरी जहाँ building block rules संग्रहीत होते हैं
tests/rules के यूनिट परीक्षण के लिए Python कोड

आरंभ करना

हालाँकि rules को मैन्युअल रूप से .toml फ़ाइलें बनाकर जोड़ा जा सकता है, लेकिन हम इसकी अनुशंसा नहीं करते। इस रिपॉज़िटरी में एक Python मॉड्यूल भी शामिल है जो rule निर्माण और यूनिट परीक्षण में सहायता करता है। यदि आपके पास Python 3.12+ है, तो निर्भरताएँ (dependencies) स्थापित करने के लिए makefile का उपयोग करके नीचे दिया गया कमांड चलाएँ:

✗ make
python3.12 -m pip install --upgrade pip setuptools
Looking in indexes: https://pypi.org/simple
Requirement already satisfied: pip in /opt/homebrew/lib/python3.12/site-packages (24.0)
Requirement already satisfied: setuptools in /opt/homebrew/lib/python3.12/site-packages (69.1.1)
python3.12 -m venv ./env/detection-rules-build
./env/detection-rules-build/bin/pip install --upgrade pip setuptools
Looking in indexes: https://pypi.org/simple
Requirement already satisfied: pip in ./env/detection-rules-build/lib/python3.12/site-packages (24.0)
Collecting setuptools
  Using cached setuptools-69.1.1-py3-none-any.whl.metadata (6.2 kB)
Using cached setuptools-69.1.1-py3-none-any.whl (819 kB)
Installing collected packages: setuptools
Successfully installed setuptools-69.1.1
Installing kql and kibana packages...
...

या निम्न कमांड का उपयोग करके निर्भरताएँ स्थापित करें:

$ pip3 install ".[dev]"
Collecting jsl==0.2.4
  Downloading jsl-0.2.4.tar.gz (21 kB)
Collecting jsonschema==3.2.0
  Downloading jsonschema-3.2.0-py2.py3-none-any.whl (56 kB)
     |████████████████████████████████| 56 kB 318 kB/s
Collecting requests==2.22.0
  Downloading requests-2.22.0-py2.py3-none-any.whl (57 kB)
     |████████████████████████████████| 57 kB 1.2 MB/s
Collecting Click==7.0
  Downloading Click-7.0-py2.py3-none-any.whl (81 kB)
     |████████████████████████████████| 81 kB 2.6 MB/s
...

नोट: kibana और kql पैकेज PyPI पर उपलब्ध नहीं हैं और इन्हें lib डायरेक्टरी से स्थापित किया जाना चाहिए। hunting पैकेज में वैकल्पिक निर्भरताएँ हैं जिन्हें pip3 install ".[hunting]" के साथ स्थापित किया जाना है।


# Install from the repository
pip3 install git+https://github.com/elastic/detection-rules.git#subdirectory=lib/kibana
pip3 install git+https://github.com/elastic/detection-rules.git#subdirectory=lib/kql

# Or locally for development
pip3 install lib/kibana lib/kql

याद रखें, यदि आप वर्चुअल एनवायरनमेंट का उपयोग कर रहे हैं तो उसे सक्रिय करना सुनिश्चित करें। यदि make के माध्यम से स्थापित किया गया है, तो संबंधित वर्चुअल एनवायरनमेंट env/detection-rules-build/ में बनाया जाता है। यदि आपको Python 3.12 एनवायरनमेंट का उपयोग करने में परेशानी हो रही है, तो कृपया हमारी समस्या निवारण मार्गदर्शिका में प्रासंगिक अनुभाग देखें।

यह पुष्टि करने के लिए कि सब कुछ ठीक से स्थापित हो गया है, --help फ़्लैग के साथ चलाएँ

$  python -m detection_rules --help

Usage: detection_rules [OPTIONS] COMMAND [ARGS]...

  Commands for detection-rules repository.

Options:
  -D, --debug / -N, --no-debug  Print full exception stacktrace on errors
  -h, --help                    Show this message and exit.

श्रेणियाँ