# Prebuilt Rule Customization is an Enterprise feature?!

**URL:** <https://discuss.elastic.co/t/prebuilt-rule-customization-is-an-enterprise-feature/377312>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [April 19, 2025, 4:14pm UTC](https://discuss.elastic.co/t/prebuilt-rule-customization-is-an-enterprise-feature/377312 "2025-04-19T16:14:46Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![nemhods](https://avatars.discourse-cdn.com/v4/letter/n/48db29/32.png) [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Post date:** [April 19, 2025, 4:14pm UTC](https://discuss.elastic.co/t/prebuilt-rule-customization-is-an-enterprise-feature/377312/1 "2025-04-19T16:14:46Z")

</div>

Hey,

I was excited to read about prebuilt rule customization, which would alleviate my pain of duplicating prebuilt rules just to add some minute detail.

However, I was shocked to see this not just not in the free version, but is behind the _enterprise_ subscription tier. I would like to discuss the reasoning behind this decision. When you start putting quality of life features behind your highest subscription tier, I don't understand it anymore. To me this is akin to locking dark mode or bulk editing behind enterprise tier. Elastic is already shamefully on the sso.tax list for locking SSO behind subscriptions, but this is a new level IMO.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/4/5429a861580742f74b389436e7537a6f6d8123f2.png)
