According to the text received, an automatic translation of a Elastic Security Labs publication, Elastic classifies its preconfigured SIEM rules along four dimensions: Noise, Performance, Threat and Profile. The text cites more than 2,100 rules, of which 385 carry the Profile: Recommended tag and 296 carry the Aggressive tag; the remaining, about 62% of the list, are deliberately left untagged. The source says the tags are recalculated every month using a 30-day window of deployment telemetry, including alert volume, number of distinct clusters, firing density and execution times, plus the rule file itself.
The source states that classification is deterministic and that large language models are used only as a fallback for the Threat dimension, when the heuristic catalog gives no answer. A pipeline opens one draft pull request per month, and the review team decides before any change is merged. Note that the title cites 1,781 rules while the text mentions more than 2,100; the excerpt does not explain the difference and is truncated before the Noise section. To verify, consult the original article indicated in the source, on the Elastic Security Labs website, and check the rule count and methodology in the public detection rules repository.