<!-- Before submitting an issue to tune a rule, be sure to reference CONTRIBUTING.md ---> ## Description <!-- Provide a detailed description of the suggested changes --> Review rules for Endgame compatibility and add index. - Create an endgame stack for testing purposes. - Check datasets and make sure our rule query aligns. - Check the fields in the query to make sure the field is available in the endgame event. - Document differences between the Endgame dataset and Endpoint dataset if any appear. cc @DefSecSentinel @Samirbous @w0rk3r @shashank-elastic