# What if there are no rules enabled?

**URL:** <https://discuss.elastic.co/t/what-if-there-are-no-rules-enabled/320714>\
**Category:** Elastic Security\
**Created:** [December 7, 2022, 7:35pm UTC](https://discuss.elastic.co/t/what-if-there-are-no-rules-enabled/320714 "2022-12-07T19:35:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lamp123432](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Post date:** [December 7, 2022, 7:35pm UTC](https://discuss.elastic.co/t/what-if-there-are-no-rules-enabled/320714/1 "2022-12-07T19:35:22Z")

</div>

Will Elastic Security / Endpoint Protection still protect/prevent malware without the rules enabled in the SIEM?

---

<div class="post-metadata">

**Author:** ![Venkata\_Raja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/venkata_raja/32/114264_2.png) [@Venkata\_Raja](https://discuss.elastic.co/u/Venkata_Raja)\
**Post date:** [December 8, 2022, 3:48am UTC](https://discuss.elastic.co/t/what-if-there-are-no-rules-enabled/320714/2 "2022-12-08T03:48:24Z")

</div>

Hi,

Protection/prevention is based on the option you choose while creating endpoint protection policy(This will not depend on rules). By Default protection will be enabled.  
And By default malware rule will be enabled.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 5, 2023, 3:49am UTC](https://discuss.elastic.co/t/what-if-there-are-no-rules-enabled/320714/3 "2023-01-05T03:49:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
