Skip to main content

Command Overview

beacon rules list prints the active threat-detection rules used by beacon scan.
Command syntax
The output includes each rule id, severity, maturity status, and source. The source shows whether Beacon loaded the rule from the local store or the built-in baseline.

Examples

List active user-mode rules:
List active rules
List active system-mode rules:
List system-mode rules

Flags

beacon rules add

Install local rule files into the store.

beacon scan

Run active rules over local telemetry.