elastic / endpoint-package
File Age & Freshness

File age measurements show the distribution of file ages (days since the first commit) and the file freshness (days since the latest commit).

Summary
File Change History Overall
File Age Distribution Overall
Days since first update
  • There are 140 files with 67,482 lines of code in files.
    • 118 files that are 366+ days old (65,111 lines of code)
    • 10 files that are 181-365 days old (1,057 lines of code)
    • 12 files that are 91-180 days old (1,314 lines of code)
    • 0 files that are 31-90 days old (0 lines of code)
    • 0 files that are 1-30 days old (0 lines of code)
96% | 1% | 1% | 0% | 0%
Legend:
366+
181-365
91-180
31-90
1-30

explore: grouped by folders | grouped by age
File Freshness Distribution Overall
Days since last update
  • There are 140 files with 67,482 lines of code in files.
    • 57 files have been last changed 366+ days ago (17,111 lines of code)
    • 19 files have been last changed 181-365 days ago (9,669 lines of code)
    • 44 files have been last changed 91-180 days ago (18,845 lines of code)
    • 5 files have been last changed 31-90 days ago (6,607 lines of code)
    • 15 files have been last changed 1-30 days ago (15,250 lines of code)
25% | 14% | 27% | 9% | 22%
Legend:
366+
181-365
91-180
31-90
1-30

explore: grouped by folders | grouped by freshness
File Change History per File Extension
yaml, json, md, go, py, txt, sh, mod, svg, cfg, gitignore, gitattributes, prettierignore
File Age Distribution per Extension
Days since first update
366+
181-365
91-180
31-90
1-30
yaml96% | 1% | 1% | 0% | 0%
go100% | 0% | 0% | 0% | 0%
py100% | 0% | 0% | 0% | 0%
File Freshness Distribution per Extension
Days since last update
366+
181-365
91-180
31-90
1-30
yaml24% | 14% | 28% | 9% | 22%
go55% | 44% | 0% | 0% | 0%
py100% | 0% | 0% | 0% | 0%
File Change History per Logical Decomposition
primary
primary (file age distribution)
Days since first update
366+
181-365
91-180
31-90
1-30
schemas100% | 0% | 0% | 0% | 0%
custom_subsets100% | 0% | 0% | 0% | 0%
custom_documentation70% | 12% | 16% | 0% | 0%
scripts100% | 0% | 0% | 0% | 0%
custom_schemas100% | 0% | 0% | 0% | 0%
ROOT100% | 0% | 0% | 0% | 0%
primary (file freshness distribution)
Days since last update
366+
181-365
91-180
31-90
1-30
schemas21% | 15% | 25% | 10% | 25%
custom_subsets60% | 4% | 5% | 13% | 16%
custom_documentation12% | 10% | 63% | 3% | 10%
scripts64% | 35% | 0% | 0% | 0%
custom_schemas100% | 0% | 0% | 0% | 0%
ROOT0% | 0% | 100% | 0% | 0%
Oldest Files (Top 50)
File# lines# unitscreatedlast modified# changes
(days)
# contributorsfirst
contributor
latest
contributor
process.yaml
in schemas/v0
336 - 2019-12-19 2020-02-19 6 5 andrew.stucki@elastic.co marshall.main@elastic.co
file.yaml
in schemas/v0
102 - 2019-12-19 2020-02-19 6 5 andrew.stucki@elastic.co marshall.main@elastic.co
_template.yaml
in schemas/v0
97 - 2019-12-19 2020-02-19 5 4 andrew.stucki@elastic.co marshall.main@elastic.co
imageload.yaml
in schemas/v0
102 - 2020-01-21 2020-02-19 5 5 andrew.stucki@elastic.co marshall.main@elastic.co
dns.yaml
in schemas/v0
102 - 2020-01-21 2020-02-19 5 5 andrew.stucki@elastic.co marshall.main@elastic.co
network.yaml
in schemas/v0
102 - 2020-01-21 2020-02-19 5 5 andrew.stucki@elastic.co marshall.main@elastic.co
registry.yaml
in schemas/v0
102 - 2020-01-21 2020-02-19 5 5 andrew.stucki@elastic.co marshall.main@elastic.co
custom_endgame.yaml
in custom_schemas/endgame
426 - 2020-02-26 2020-04-23 3 2 jonathan.buttner@elastic.co 56361221+jonathan-buttner@u...
network.yaml
in custom_subsets/legacy
105 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
process.yaml
in custom_subsets/legacy
102 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
dns.yaml
in custom_subsets/legacy
93 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
metadata.yaml
in custom_subsets/elastic_endpoint/metadata
79 - 2020-02-27 2022-06-29 19 7 jonathan.buttner@elastic.co 56368752+ferullo@users.nore...
file.yaml
in custom_subsets/legacy
75 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
imageload.yaml
in custom_subsets/legacy
68 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
registry.yaml
in custom_subsets/legacy
66 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
alert.yaml
in custom_subsets/legacy
18 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
main.py
in scripts/event_schema_generator
61 5 2020-03-27 2020-06-18 6 3 jonathan.buttner@elastic.co 56361221+jonathan-buttner@u...
policy.yaml
in custom_subsets/elastic_endpoint/policy
69 - 2020-05-11 2022-06-29 14 7 56440728+nnamdifrankie@user... 56368752+ferullo@users.nore...
process.yaml
in schemas/v1/process
3435 - 2020-06-17 2025-04-25 51 17 jonathan.buttner@elastic.co asuka.nakajima@elastic.co
file.yaml
in schemas/v1/file
2903 - 2020-06-17 2024-09-20 39 18 jonathan.buttner@elastic.co 53329154+jdu2600@users.nore...
library.yaml
in schemas/v1/library
2738 - 2020-06-17 2025-04-25 45 16 jonathan.buttner@elastic.co asuka.nakajima@elastic.co
network.yaml
in schemas/v1/network
2460 - 2020-06-17 2023-12-12 27 11 jonathan.buttner@elastic.co pzl@users.noreply.github.com
registry.yaml
in schemas/v1/registry
1994 - 2020-06-17 2024-09-20 30 12 jonathan.buttner@elastic.co 53329154+jdu2600@users.nore...
security.yaml
in schemas/v1/security
1926 - 2020-06-17 2025-01-30 30 13 jonathan.buttner@elastic.co 81707160+ricardo-estc@users...
policy.yaml
in schemas/v1/policy
1692 - 2020-06-17 2024-12-17 36 15 jonathan.buttner@elastic.co 39905449+intxgo@users.norep...
malware_event.yaml
in custom_subsets/elastic_endpoint/alerts
1140 - 2020-06-17 2023-04-13 23 11 jonathan.buttner@elastic.co 56367679+trinity2019@users....
metadata.yaml
in schemas/v1/metadata
1115 - 2020-06-17 2024-09-20 29 13 jonathan.buttner@elastic.co 53329154+jdu2600@users.nore...
process.yaml
in custom_subsets/elastic_endpoint/process
309 - 2020-06-17 2025-04-25 35 14 jonathan.buttner@elastic.co asuka.nakajima@elastic.co
file.yaml
in custom_subsets/elastic_endpoint/file
260 - 2020-06-17 2024-06-28 26 13 jonathan.buttner@elastic.co asuka.nakajima@elastic.co
library.yaml
in custom_subsets/elastic_endpoint/library
240 - 2020-06-17 2025-04-25 30 12 jonathan.buttner@elastic.co asuka.nakajima@elastic.co
network.yaml
in custom_subsets/elastic_endpoint/network
211 - 2020-06-17 2022-10-18 14 7 jonathan.buttner@elastic.co omolola.akinleye@elastic.co
registry.yaml
in custom_subsets/elastic_endpoint/registry
158 - 2020-06-17 2024-04-09 15 8 jonathan.buttner@elastic.co 42078554+gabriellandau@user...
security.yaml
in custom_subsets/elastic_endpoint/security
157 - 2020-06-17 2025-01-30 15 9 jonathan.buttner@elastic.co 81707160+ricardo-estc@users...
unquarantine.yaml
in schemas/v1/file
1247 - 2020-06-25 2023-12-12 21 11 55718608+marshallmain@users... pzl@users.noreply.github.com
unquarantine.yaml
in custom_subsets/elastic_endpoint/file
76 - 2020-06-25 2022-06-29 7 4 55718608+marshallmain@users... 56368752+ferullo@users.nore...
so_decoder.py
in scripts/saved_object_decoder
62 4 2020-07-07 2020-08-25 2 2 56361221+jonathan-buttner@u... 56361221+jonathan-buttner@u...
metrics.yaml
in schemas/v1/metrics
2182 - 2020-07-13 2024-09-20 27 14 56361221+jonathan-buttner@u... 53329154+jdu2600@users.nore...
metrics.yaml
in custom_subsets/elastic_endpoint/metrics
63 - 2020-07-13 2022-06-29 8 3 56361221+jonathan-buttner@u... 56368752+ferullo@users.nore...
exported_fields.go
in scripts/generate-docs
142 9 2020-07-15 2020-10-01 3 2 jonathan.buttner@elastic.co 56361221+jonathan-buttner@u...
main.go
in scripts/generate-docs
66 4 2020-07-15 2023-07-31 3 3 jonathan.buttner@elastic.co 56368752+ferullo@users.nore...
sample_event.go
in scripts/generate-docs
45 3 2020-07-15 2020-10-01 3 2 jonathan.buttner@elastic.co 56361221+jonathan-buttner@u...
doc_template.go
in scripts/generate-docs
45 1 2020-07-15 2020-10-01 3 2 jonathan.buttner@elastic.co 56361221+jonathan-buttner@u...
packages.go
in scripts/generate-docs
21 1 2020-07-15 2020-07-20 2 2 jonathan.buttner@elastic.co 56361221+jonathan-buttner@u...
process_yaml.py
in scripts/yaml_merger
21 2 2020-08-05 2020-08-11 2 2 56440728+nnamdifrankie@user... 56361221+jonathan-buttner@u...
tools.go
in scripts/go-tools
4 - 2020-08-25 2020-08-25 1 1 56361221+jonathan-buttner@u... 56361221+jonathan-buttner@u...
ransomware_event.yaml
in schemas/v1/alerts
9701 - 2020-10-26 2025-01-14 27 12 55718608+marshallmain@users... 53329154+jdu2600@users.nore...
ransomware_event.yaml
in custom_subsets/elastic_endpoint/alerts
725 - 2020-10-26 2022-11-28 11 7 55718608+marshallmain@users... 42078554+gabriellandau@user...
collection.yaml
in schemas/v1/collection
694 - 2020-12-14 2023-09-27 8 5 56440728+nnamdifrankie@user... 56366649+nicholasberlin@use...
collection.yaml
in custom_subsets/elastic_endpoint/collection
28 - 2020-12-14 2020-12-14 1 1 56440728+nnamdifrankie@user... 56440728+nnamdifrankie@user...
memory_protection_event.yaml
in custom_subsets/elastic_endpoint/alerts
829 - 2021-04-15 2025-02-25 18 11 42078554+gabriellandau@user... asuka.nakajima@elastic.co
Files Not Recently Changed (Top 50)
File# lines# unitscreatedlast modified# changes
(days)
# contributorsfirst
contributor
latest
contributor
_template.yaml
in schemas/v0
97 - 2019-12-19 2020-02-19 5 4 andrew.stucki@elastic.co marshall.main@elastic.co
registry.yaml
in schemas/v0
102 - 2020-01-21 2020-02-19 5 5 andrew.stucki@elastic.co marshall.main@elastic.co
network.yaml
in schemas/v0
102 - 2020-01-21 2020-02-19 5 5 andrew.stucki@elastic.co marshall.main@elastic.co
dns.yaml
in schemas/v0
102 - 2020-01-21 2020-02-19 5 5 andrew.stucki@elastic.co marshall.main@elastic.co
file.yaml
in schemas/v0
102 - 2019-12-19 2020-02-19 6 5 andrew.stucki@elastic.co marshall.main@elastic.co
imageload.yaml
in schemas/v0
102 - 2020-01-21 2020-02-19 5 5 andrew.stucki@elastic.co marshall.main@elastic.co
process.yaml
in schemas/v0
336 - 2019-12-19 2020-02-19 6 5 andrew.stucki@elastic.co marshall.main@elastic.co
custom_endgame.yaml
in custom_schemas/endgame
426 - 2020-02-26 2020-04-23 3 2 jonathan.buttner@elastic.co 56361221+jonathan-buttner@u...
main.py
in scripts/event_schema_generator
61 5 2020-03-27 2020-06-18 6 3 jonathan.buttner@elastic.co 56361221+jonathan-buttner@u...
alert.yaml
in custom_subsets/legacy
18 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
registry.yaml
in custom_subsets/legacy
66 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
imageload.yaml
in custom_subsets/legacy
68 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
file.yaml
in custom_subsets/legacy
75 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
dns.yaml
in custom_subsets/legacy
93 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
process.yaml
in custom_subsets/legacy
102 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
network.yaml
in custom_subsets/legacy
105 - 2020-02-27 2020-06-29 3 3 jonathan.buttner@elastic.co 55718608+marshallmain@users...
packages.go
in scripts/generate-docs
21 1 2020-07-15 2020-07-20 2 2 jonathan.buttner@elastic.co 56361221+jonathan-buttner@u...
process_yaml.py
in scripts/yaml_merger
21 2 2020-08-05 2020-08-11 2 2 56440728+nnamdifrankie@user... 56361221+jonathan-buttner@u...
tools.go
in scripts/go-tools
4 - 2020-08-25 2020-08-25 1 1 56361221+jonathan-buttner@u... 56361221+jonathan-buttner@u...
so_decoder.py
in scripts/saved_object_decoder
62 4 2020-07-07 2020-08-25 2 2 56361221+jonathan-buttner@u... 56361221+jonathan-buttner@u...
doc_template.go
in scripts/generate-docs
45 1 2020-07-15 2020-10-01 3 2 jonathan.buttner@elastic.co 56361221+jonathan-buttner@u...
sample_event.go
in scripts/generate-docs
45 3 2020-07-15 2020-10-01 3 2 jonathan.buttner@elastic.co 56361221+jonathan-buttner@u...
exported_fields.go
in scripts/generate-docs
142 9 2020-07-15 2020-10-01 3 2 jonathan.buttner@elastic.co 56361221+jonathan-buttner@u...
collection.yaml
in custom_subsets/elastic_endpoint/collection
28 - 2020-12-14 2020-12-14 1 1 56440728+nnamdifrankie@user... 56440728+nnamdifrankie@user...
action_responses.yaml
in custom_subsets/elastic_endpoint/action_responses
48 - 2021-09-20 2021-09-27 2 1 am.struktr@gmail.com am.struktr@gmail.com
linux_event_model_event.yaml
in custom_subsets/elastic_endpoint/alerts
327 - 2022-03-22 2022-06-21 3 1 karl.godard@elastic.co karl.godard@elastic.co
metrics.yaml
in custom_subsets/elastic_endpoint/metrics
63 - 2020-07-13 2022-06-29 8 3 56361221+jonathan-buttner@u... 56368752+ferullo@users.nore...
policy.yaml
in custom_subsets/elastic_endpoint/policy
69 - 2020-05-11 2022-06-29 14 7 56440728+nnamdifrankie@user... 56368752+ferullo@users.nore...
unquarantine.yaml
in custom_subsets/elastic_endpoint/file
76 - 2020-06-25 2022-06-29 7 4 55718608+marshallmain@users... 56368752+ferullo@users.nore...
metadata.yaml
in custom_subsets/elastic_endpoint/metadata
79 - 2020-02-27 2022-06-29 19 7 jonathan.buttner@elastic.co 56368752+ferullo@users.nore...
linux_event_model_event.yaml
in custom_subsets/elastic_endpoint/process
350 - 2022-03-22 2022-09-20 6 2 karl.godard@elastic.co kg@cmd.com
network.yaml
in custom_subsets/elastic_endpoint/network
211 - 2020-06-17 2022-10-18 14 7 jonathan.buttner@elastic.co omolola.akinleye@elastic.co
ransomware_event.yaml
in custom_subsets/elastic_endpoint/alerts
725 - 2020-10-26 2022-11-28 11 7 55718608+marshallmain@users... 42078554+gabriellandau@user...
malware_event.yaml
in custom_subsets/elastic_endpoint/alerts
1140 - 2020-06-17 2023-04-13 23 11 jonathan.buttner@elastic.co 56367679+trinity2019@users....
main.go
in scripts/generate-docs
66 4 2020-07-15 2023-07-31 3 3 jonathan.buttner@elastic.co 56368752+ferullo@users.nore...
linux_file_endpoint_unquarantine.yaml
in custom_documentation/src/endpoint/data_stream/file/linux
56 - 2023-09-07 2023-09-07 1 1 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
macos_file_endpoint_unquarantine.yaml
in custom_documentation/src/endpoint/data_stream/file/macos
56 - 2023-09-07 2023-09-07 1 1 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
windows_file_endpoint_unquarantine.yaml
in custom_documentation/src/endpoint/data_stream/file/windows
56 - 2023-09-07 2023-09-07 1 1 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
metadata.yaml
in custom_documentation/src/endpoint/data_stream/metadata
61 - 2023-09-07 2023-09-07 1 1 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
windows_network_dns_lookup_requested.yaml
in custom_documentation/src/endpoint/data_stream/network/windows
71 - 2023-09-07 2023-09-07 1 1 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
windows_registry_query.yaml
in custom_documentation/src/endpoint/data_stream/registry/windows
74 - 2023-09-07 2023-09-07 1 1 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
windows_registry_modification.yaml
in custom_documentation/src/endpoint/data_stream/registry/windows
76 - 2023-09-07 2023-09-07 1 1 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
macos_file_mount.yaml
in custom_documentation/src/endpoint/data_stream/file/macos
76 - 2023-09-07 2023-09-26 3 2 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
macos_file_launch_daemon.yaml
in custom_documentation/src/endpoint/data_stream/file/macos
77 - 2023-09-07 2023-09-26 3 2 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
collection.yaml
in schemas/v1/collection
694 - 2020-12-14 2023-09-27 8 5 56440728+nnamdifrankie@user... 56366649+nicholasberlin@use...
macos_library_load.yaml
in custom_documentation/src/endpoint/data_stream/library/macos
82 - 2023-10-31 2023-10-31 1 1 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
action_responses.yaml
in schemas/v1/action_responses
752 - 2021-09-20 2023-12-12 9 6 am.struktr@gmail.com pzl@users.noreply.github.com
unquarantine.yaml
in schemas/v1/file
1247 - 2020-06-25 2023-12-12 21 11 55718608+marshallmain@users... pzl@users.noreply.github.com
network.yaml
in schemas/v1/network
2460 - 2020-06-17 2023-12-12 27 11 jonathan.buttner@elastic.co pzl@users.noreply.github.com
linux_event_model_event.yaml
in schemas/v1/alerts
2551 - 2022-03-22 2023-12-12 10 5 karl.godard@elastic.co pzl@users.noreply.github.com
Most Recently Created Files (Top 50)
File# lines# unitscreatedlast modified# changes
(days)
# contributorsfirst
contributor
latest
contributor
macos_security_gatekeeper_override.yaml
in custom_documentation/src/endpoint/data_stream/security/macos
80 - 2025-01-30 2025-02-06 2 1 81707160+ricardo-estc@users... 81707160+ricardo-estc@users...
macos_security_ssh_log_on.yaml
in custom_documentation/src/endpoint/data_stream/security/macos
77 - 2025-01-30 2025-02-06 2 1 81707160+ricardo-estc@users... 81707160+ricardo-estc@users...
macos_security_log_on.yaml
in custom_documentation/src/endpoint/data_stream/security/macos
77 - 2025-01-30 2025-02-06 2 1 81707160+ricardo-estc@users... 81707160+ricardo-estc@users...
macos_security_rdp_log_on.yaml
in custom_documentation/src/endpoint/data_stream/security/macos
77 - 2025-01-30 2025-02-06 2 1 81707160+ricardo-estc@users... 81707160+ricardo-estc@users...
windows_api_amsi.yaml
in custom_documentation/src/endpoint/data_stream/api/windows
76 - 2025-01-14 2025-01-14 1 1 53329154+jdu2600@users.nore... 53329154+jdu2600@users.nore...
linux_network_dns_lookup_result.yaml
in custom_documentation/src/endpoint/data_stream/network/linux
65 - 2025-01-10 2025-01-10 1 1 56366649+nicholasberlin@use... 56366649+nicholasberlin@use...
linux_process_ptrace.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
202 - 2025-01-09 2025-01-17 2 2 8418476+fearful-symmetry@us... 56366649+nicholasberlin@use...
linux_process_shmget.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
202 - 2025-01-09 2025-01-17 2 2 8418476+fearful-symmetry@us... 56366649+nicholasberlin@use...
linux_network_attempted_accepted_and_disconnect.yaml
in custom_documentation/src/endpoint/data_stream/network/linux
87 - 2024-12-11 2024-12-17 2 2 56366649+nicholasberlin@use... 39905449+intxgo@users.norep...
macos_network_connection_attempted_and_disconnect.yaml
in custom_documentation/src/endpoint/data_stream/network/macos
84 - 2024-12-11 2024-12-17 2 2 56366649+nicholasberlin@use... 39905449+intxgo@users.norep...
windows_network_attempted_accepted_and_disconnect.yaml
in custom_documentation/src/endpoint/data_stream/network/windows
81 - 2024-12-11 2024-12-17 2 2 56366649+nicholasberlin@use... 39905449+intxgo@users.norep...
linux_process_memfd_create.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
206 - 2024-11-25 2025-01-17 4 3 8418476+fearful-symmetry@us... 56366649+nicholasberlin@use...
windows_api_kernel_audit.yaml
in custom_documentation/src/endpoint/data_stream/api/windows
72 - 2024-10-08 2025-01-14 3 3 asuka.nakajima@elastic.co 53329154+jdu2600@users.nore...
windows_api_asm.yaml
in custom_documentation/src/endpoint/data_stream/api/windows
79 - 2024-10-02 2025-01-14 2 2 asuka.nakajima@elastic.co 53329154+jdu2600@users.nore...
windows_api_tcpip.yaml
in custom_documentation/src/endpoint/data_stream/api/windows
76 - 2024-10-02 2025-01-10 3 2 asuka.nakajima@elastic.co 39905449+intxgo@users.norep...
windows_process_create_and_exit.yaml
in custom_documentation/src/endpoint/data_stream/process/windows
135 - 2024-09-27 2025-04-25 5 3 56366649+nicholasberlin@use... asuka.nakajima@elastic.co
windows_api_threat_intelligence.yaml
in custom_documentation/src/endpoint/data_stream/api/windows
115 - 2024-09-26 2025-01-08 3 3 39905449+intxgo@users.norep... 42078554+gabriellandau@user...
macos_process_fork_exec_exit.yaml
in custom_documentation/src/endpoint/data_stream/process/macos
103 - 2024-09-25 2025-03-27 4 3 56366649+nicholasberlin@use... brian.mckinney@elastic.co
windows_api_win32k.yaml
in custom_documentation/src/endpoint/data_stream/api/windows
97 - 2024-09-24 2025-01-14 5 3 asuka.nakajima@elastic.co 53329154+jdu2600@users.nore...
windows_api_wmi.yaml
in custom_documentation/src/endpoint/data_stream/api/windows
86 - 2024-09-24 2025-01-14 4 3 asuka.nakajima@elastic.co 53329154+jdu2600@users.nore...
linux_process_fork_exec_exit.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
209 - 2024-09-18 2025-01-17 3 2 56366649+nicholasberlin@use... 56366649+nicholasberlin@use...
macos_network_dns_lookup_result.yaml
in custom_documentation/src/endpoint/data_stream/network/macos
85 - 2024-09-12 2024-12-17 2 2 81707160+ricardoungureanu@u... 39905449+intxgo@users.norep...
windows_volume_device_mount.yaml
in custom_documentation/src/endpoint/data_stream/volume_device/windows
73 - 2024-01-17 2024-01-17 1 1 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
windows_volume_device_unmount.yaml
in custom_documentation/src/endpoint/data_stream/volume_device/windows
64 - 2024-01-17 2024-01-17 1 1 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
macos_library_load.yaml
in custom_documentation/src/endpoint/data_stream/library/macos
82 - 2023-10-31 2023-10-31 1 1 56368752+ferullo@users.nore... 56368752+ferullo@users.nore...
macos_file_access.yaml
in custom_documentation/src/endpoint/data_stream/file/macos
64 - 2023-10-31 2024-09-04 2 2 56368752+ferullo@users.nore... 42078554+gabriellandau@user...
windows_shellcode_thread.yaml
in custom_documentation/src/endpoint/data_stream/alerts/windows
261 - 2023-09-07 2025-01-24 5 3 56368752+ferullo@users.nore... 53329154+jdu2600@users.nore...
linux_malware_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/linux
231 - 2023-09-07 2025-01-10 6 3 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
metrics.yaml
in custom_documentation/src/endpoint/data_stream/metrics
206 - 2023-09-07 2025-04-29 9 6 56368752+ferullo@users.nore... mcnichols@gmail.com
linux_process_text_output.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
205 - 2023-09-07 2025-01-17 5 3 56368752+ferullo@users.nore... 56366649+nicholasberlin@use...
linux_memory_threat_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/linux
205 - 2023-09-07 2025-01-10 4 2 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
windows_malware_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/windows
204 - 2023-09-07 2025-01-10 6 2 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
linux_process_gid_change.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
203 - 2023-09-07 2025-01-17 4 2 56368752+ferullo@users.nore... 56366649+nicholasberlin@use...
linux_process_uid_change.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
203 - 2023-09-07 2025-01-17 4 2 56368752+ferullo@users.nore... 56366649+nicholasberlin@use...
linux_process_already_running.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
202 - 2023-09-07 2025-01-17 5 3 56368752+ferullo@users.nore... 56366649+nicholasberlin@use...
linux_process_session_id_change.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
199 - 2023-09-07 2025-01-17 4 2 56368752+ferullo@users.nore... 56366649+nicholasberlin@use...
windows_ransomware_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/windows
174 - 2023-09-07 2025-01-10 4 2 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
macos_malware_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/macos
149 - 2023-09-07 2025-01-10 5 3 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
windows_memory_threat_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/windows
145 - 2023-09-07 2025-01-10 6 3 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
windows_malicious_behavior_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/windows
140 - 2023-09-07 2025-04-29 6 3 56368752+ferullo@users.nore... 42078554+gabriellandau@user...
linux_malicious_behavior_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/linux
132 - 2023-09-07 2025-01-10 4 2 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
macos_memory_threat_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/macos
129 - 2023-09-07 2025-01-10 4 2 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
macos_malicious_behavior_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/macos
119 - 2023-09-07 2025-01-10 5 2 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
windows_process_already_running.yaml
in custom_documentation/src/endpoint/data_stream/process/windows
109 - 2023-09-07 2025-04-25 5 4 56368752+ferullo@users.nore... asuka.nakajima@elastic.co
policy_response.yaml
in custom_documentation/src/endpoint/data_stream/policy
103 - 2023-09-07 2024-12-17 3 2 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
macos_process_remote_thread.yaml
in custom_documentation/src/endpoint/data_stream/process/macos
94 - 2023-09-07 2025-03-27 5 4 56368752+ferullo@users.nore... brian.mckinney@elastic.co
windows_library_load.yaml
in custom_documentation/src/endpoint/data_stream/library/windows
91 - 2023-09-07 2025-04-25 4 3 56368752+ferullo@users.nore... asuka.nakajima@elastic.co
windows_file_create.yaml
in custom_documentation/src/endpoint/data_stream/file/windows
83 - 2023-09-07 2024-09-24 4 4 56368752+ferullo@users.nore... asuka.nakajima@elastic.co
windows_file_rename.yaml
in custom_documentation/src/endpoint/data_stream/file/windows
83 - 2023-09-07 2024-09-04 4 3 56368752+ferullo@users.nore... 42078554+gabriellandau@user...
macos_file_rename.yaml
in custom_documentation/src/endpoint/data_stream/file/macos
82 - 2023-09-07 2024-09-04 5 4 56368752+ferullo@users.nore... 42078554+gabriellandau@user...
Most Recently Changed Files (Top 50)
File# lines# unitscreatedlast modified# changes
(days)
# contributorsfirst
contributor
latest
contributor
actions.yaml
in schemas/v1/actions
774 - 2021-09-20 2025-05-02 10 6 am.struktr@gmail.com pzl@users.noreply.github.com
actions.yaml
in custom_subsets/elastic_endpoint/actions
64 - 2021-09-20 2025-05-02 4 3 am.struktr@gmail.com pzl@users.noreply.github.com
metrics.yaml
in custom_documentation/src/endpoint/data_stream/metrics
206 - 2023-09-07 2025-04-29 9 6 56368752+ferullo@users.nore... mcnichols@gmail.com
windows_malicious_behavior_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/windows
140 - 2023-09-07 2025-04-29 6 3 56368752+ferullo@users.nore... 42078554+gabriellandau@user...
windows_file_modification.yaml
in custom_documentation/src/endpoint/data_stream/file/windows
80 - 2023-09-07 2025-04-29 3 2 56368752+ferullo@users.nore... 42078554+gabriellandau@user...
windows_file_overwrite.yaml
in custom_documentation/src/endpoint/data_stream/file/windows
80 - 2023-09-07 2025-04-29 5 4 56368752+ferullo@users.nore... 42078554+gabriellandau@user...
rule_detection_event.yaml
in schemas/v1/alerts
6398 - 2021-08-18 2025-04-25 16 9 pzl@users.noreply.github.com 42077975+magermark@users.no...
process.yaml
in schemas/v1/process
3435 - 2020-06-17 2025-04-25 51 17 jonathan.buttner@elastic.co asuka.nakajima@elastic.co
library.yaml
in schemas/v1/library
2738 - 2020-06-17 2025-04-25 45 16 jonathan.buttner@elastic.co asuka.nakajima@elastic.co
rule_detection_event.yaml
in custom_subsets/elastic_endpoint/alerts
451 - 2021-08-18 2025-04-25 5 5 56730536+brian-mckinney@use... 42077975+magermark@users.no...
process.yaml
in custom_subsets/elastic_endpoint/process
309 - 2020-06-17 2025-04-25 35 14 jonathan.buttner@elastic.co asuka.nakajima@elastic.co
library.yaml
in custom_subsets/elastic_endpoint/library
240 - 2020-06-17 2025-04-25 30 12 jonathan.buttner@elastic.co asuka.nakajima@elastic.co
windows_process_create_and_exit.yaml
in custom_documentation/src/endpoint/data_stream/process/windows
135 - 2024-09-27 2025-04-25 5 3 56366649+nicholasberlin@use... asuka.nakajima@elastic.co
windows_process_already_running.yaml
in custom_documentation/src/endpoint/data_stream/process/windows
109 - 2023-09-07 2025-04-25 5 4 56368752+ferullo@users.nore... asuka.nakajima@elastic.co
windows_library_load.yaml
in custom_documentation/src/endpoint/data_stream/library/windows
91 - 2023-09-07 2025-04-25 4 3 56368752+ferullo@users.nore... asuka.nakajima@elastic.co
macos_process_fork_exec_exit.yaml
in custom_documentation/src/endpoint/data_stream/process/macos
103 - 2024-09-25 2025-03-27 4 3 56366649+nicholasberlin@use... brian.mckinney@elastic.co
macos_process_remote_thread.yaml
in custom_documentation/src/endpoint/data_stream/process/macos
94 - 2023-09-07 2025-03-27 5 4 56368752+ferullo@users.nore... brian.mckinney@elastic.co
macos_process_already_running.yaml
in custom_documentation/src/endpoint/data_stream/process/macos
82 - 2023-09-07 2025-03-27 5 4 56368752+ferullo@users.nore... brian.mckinney@elastic.co
api.yaml
in schemas/v1/api
5499 - 2023-01-18 2025-02-25 22 7 85187342+calladoum-elastic@... asuka.nakajima@elastic.co
memory_protection_event.yaml
in custom_subsets/elastic_endpoint/alerts
829 - 2021-04-15 2025-02-25 18 11 42078554+gabriellandau@user... asuka.nakajima@elastic.co
macos_security_gatekeeper_override.yaml
in custom_documentation/src/endpoint/data_stream/security/macos
80 - 2025-01-30 2025-02-06 2 1 81707160+ricardo-estc@users... 81707160+ricardo-estc@users...
macos_security_ssh_log_on.yaml
in custom_documentation/src/endpoint/data_stream/security/macos
77 - 2025-01-30 2025-02-06 2 1 81707160+ricardo-estc@users... 81707160+ricardo-estc@users...
macos_security_log_on.yaml
in custom_documentation/src/endpoint/data_stream/security/macos
77 - 2025-01-30 2025-02-06 2 1 81707160+ricardo-estc@users... 81707160+ricardo-estc@users...
macos_security_rdp_log_on.yaml
in custom_documentation/src/endpoint/data_stream/security/macos
77 - 2025-01-30 2025-02-06 2 1 81707160+ricardo-estc@users... 81707160+ricardo-estc@users...
40 - 2023-08-15 2025-02-04 12 2 5281995+gogochan@users.nore... pzl@users.noreply.github.com
security.yaml
in schemas/v1/security
1926 - 2020-06-17 2025-01-30 30 13 jonathan.buttner@elastic.co 81707160+ricardo-estc@users...
security.yaml
in custom_subsets/elastic_endpoint/security
157 - 2020-06-17 2025-01-30 15 9 jonathan.buttner@elastic.co 81707160+ricardo-estc@users...
windows_shellcode_thread.yaml
in custom_documentation/src/endpoint/data_stream/alerts/windows
261 - 2023-09-07 2025-01-24 5 3 56368752+ferullo@users.nore... 53329154+jdu2600@users.nore...
linux_process_fork_exec_exit.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
209 - 2024-09-18 2025-01-17 3 2 56366649+nicholasberlin@use... 56366649+nicholasberlin@use...
linux_process_memfd_create.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
206 - 2024-11-25 2025-01-17 4 3 8418476+fearful-symmetry@us... 56366649+nicholasberlin@use...
linux_process_text_output.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
205 - 2023-09-07 2025-01-17 5 3 56368752+ferullo@users.nore... 56366649+nicholasberlin@use...
linux_process_gid_change.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
203 - 2023-09-07 2025-01-17 4 2 56368752+ferullo@users.nore... 56366649+nicholasberlin@use...
linux_process_uid_change.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
203 - 2023-09-07 2025-01-17 4 2 56368752+ferullo@users.nore... 56366649+nicholasberlin@use...
linux_process_ptrace.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
202 - 2025-01-09 2025-01-17 2 2 8418476+fearful-symmetry@us... 56366649+nicholasberlin@use...
linux_process_shmget.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
202 - 2025-01-09 2025-01-17 2 2 8418476+fearful-symmetry@us... 56366649+nicholasberlin@use...
linux_process_already_running.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
202 - 2023-09-07 2025-01-17 5 3 56368752+ferullo@users.nore... 56366649+nicholasberlin@use...
linux_process_session_id_change.yaml
in custom_documentation/src/endpoint/data_stream/process/linux
199 - 2023-09-07 2025-01-17 4 2 56368752+ferullo@users.nore... 56366649+nicholasberlin@use...
ransomware_event.yaml
in schemas/v1/alerts
9701 - 2020-10-26 2025-01-14 27 12 55718608+marshallmain@users... 53329154+jdu2600@users.nore...
api.yaml
in custom_subsets/elastic_endpoint/api
180 - 2023-01-18 2025-01-14 9 4 85187342+calladoum-elastic@... 53329154+jdu2600@users.nore...
windows_api_win32k.yaml
in custom_documentation/src/endpoint/data_stream/api/windows
97 - 2024-09-24 2025-01-14 5 3 asuka.nakajima@elastic.co 53329154+jdu2600@users.nore...
windows_api_wmi.yaml
in custom_documentation/src/endpoint/data_stream/api/windows
86 - 2024-09-24 2025-01-14 4 3 asuka.nakajima@elastic.co 53329154+jdu2600@users.nore...
windows_api_asm.yaml
in custom_documentation/src/endpoint/data_stream/api/windows
79 - 2024-10-02 2025-01-14 2 2 asuka.nakajima@elastic.co 53329154+jdu2600@users.nore...
windows_api_amsi.yaml
in custom_documentation/src/endpoint/data_stream/api/windows
76 - 2025-01-14 2025-01-14 1 1 53329154+jdu2600@users.nore... 53329154+jdu2600@users.nore...
windows_api_kernel_audit.yaml
in custom_documentation/src/endpoint/data_stream/api/windows
72 - 2024-10-08 2025-01-14 3 3 asuka.nakajima@elastic.co 53329154+jdu2600@users.nore...
linux_malware_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/linux
231 - 2023-09-07 2025-01-10 6 3 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
linux_memory_threat_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/linux
205 - 2023-09-07 2025-01-10 4 2 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
windows_malware_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/windows
204 - 2023-09-07 2025-01-10 6 2 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
windows_ransomware_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/windows
174 - 2023-09-07 2025-01-10 4 2 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
macos_malware_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/macos
149 - 2023-09-07 2025-01-10 5 3 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...
windows_memory_threat_alert.yaml
in custom_documentation/src/endpoint/data_stream/alerts/windows
145 - 2023-09-07 2025-01-10 6 3 56368752+ferullo@users.nore... 39905449+intxgo@users.norep...