Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Detections] Endpoint Exceptions workflow should allow OS selection #94304

Open
kevinlog opened this issue Mar 10, 2021 · 1 comment
Open

[Detections] Endpoint Exceptions workflow should allow OS selection #94304

kevinlog opened this issue Mar 10, 2021 · 1 comment
Labels
Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.

Comments

@kevinlog
Copy link
Contributor

Describe the feature:
We currently support both Mac and Windows Malware alerts. In the Exceptions workflow, there isn't an option to select a specific OS. As a result, when creating an Exception, it will be assigned to both Mac and Windows and the Endpoint will download an Exceptions artifact that contains Exceptions intended for either OS regardless of the OS the Endpoint is running on.

Exceptions modal, no OS selection:
image

After creating the Exception, you can see that it applies to both OSs:
image

The proposal here is to allow the user to select the OS in the Exceptions workflow so that they can differentiate as they see fit.

The pre-populated modal could pre-select an OS based on the OS that the Endpoint Alert originated from.

Describe a specific use case for the feature:

  • As a user I want to maintain a set of Exceptions specific to Mac Endpoints that are not sent to Windows Endpoints.
@kevinlog kevinlog added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Mar 10, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Projects
None yet
Development

No branches or pull requests

2 participants