eqllib is a library of event based analytics, written in EQL to detect adversary behaviors identified in MITRE ATT&CK® .
Endgame has joined forces with Elastic, and EQL is now in the Detection Engine of Kibana! To find the latest rules written in EQL, KQL or Lucene for the Elastic Stack, please visit elastic/detection-rules on GitHub.
© Copyright 2019, Endgame Revision 30243396 .