EDR - Endpoint Detection & Response : Rule Generation

EDR Rules and how to generate new rules for a better EDR Security.
This thread is open for any discussion on this subject.
What new rules do you want to see to detect what kind of behavior?