We've upgraded our stack to 7.6.0 yesterday, and we love the new Detections mechanism!
I'm aware these are in beta, but some of the definitions have a boolean 'or' where there should be an 'and'.
This is particularly where the rule is ' from/to the Internet'.
eg. SMB Activity to the Internet definition is 'network.transport: tcp and destination.port: (139 or 445) and ( network.direction: outbound or ( source.ip: (10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and not destination.ip: (10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) ) )'
This will result in detections for '10.0.0.1 to 10.0.0.2:445' when it shouldn't.
I've highlighted the 'or' that should be changed to 'and'