Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New page about allowlisting Elastic Endpoint in 3rd-party AV software #4439

Merged
merged 7 commits into from
Dec 21, 2023

Conversation

benironside
Copy link
Contributor

@benironside benironside commented Dec 9, 2023

Addresses #3535 by adding a new page with information about how to allowlist Elastic Endpoint in 3rd-party AV software on different OSes.

Preview: Allowlist Elastic Endpoint

@benironside benironside added the enhancement New feature or request label Dec 9, 2023
@benironside benironside requested a review from ferullo December 9, 2023 00:45
@benironside benironside self-assigned this Dec 9, 2023
@benironside benironside requested a review from a team as a code owner December 9, 2023 00:45
Copy link

github-actions bot commented Dec 9, 2023

A documentation preview will be available soon.
Help us out by validating the Buildkite preview and reporting issues here.

Copy link
Contributor

mergify bot commented Dec 9, 2023

This pull request does not have a backport label. Could you fix it @benironside? 🙏
To fixup this pull request, you need to add the backport labels for the needed
branches, such as:

  • v7.x is the label to automatically backport to the 7.x branch.
  • v7./d./d is the label to automatically backport to the 7./d branch. /d is the digit

NOTE: backport-skip has been added to this pull request.

Copy link
Collaborator

@ferullo ferullo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor changes requested. Thanks for doing this @benironside !

gabriellandau
gabriellandau previously approved these changes Dec 11, 2023
Copy link
Contributor

@gabriellandau gabriellandau left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No blockers, but since we're adding this to the regular docs, it would be good to bring some version of this important point along from the GH doc:

It is important to note that file-, folder-, and path-based exclusions/exceptions are distinct from Trusted Applications and will NOT achieve the same result. The goal here is to ignore actions taken BY a process, not ignore the file that the process was spawned from. Files are different from processes.

Without it, we'll have users creating pointless file exceptions without achieving their desired results.

@gabriellandau gabriellandau self-requested a review December 11, 2023 15:53
@ferullo
Copy link
Collaborator

ferullo commented Dec 11, 2023

This document can be backported to 8.0+ with the requested changes.

If the original macOS Endpoint path is used (i.e. /Library/Elastic/Endpoint/elastic-endpoint) this can be backported to 7.17 as well.

@gabriellandau @ricardoungureanu please contradict me if you disagree.

benironside and others added 2 commits December 11, 2023 12:43
Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
Copy link
Contributor

@nastasha-solomon nastasha-solomon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just a handful of suggestions and minor corrections. LGTM otherwise!

@ferullo ferullo dismissed their stale review December 12, 2023 15:10

my requested changes were made, thanks

mergify bot pushed a commit that referenced this pull request Dec 21, 2023
…#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)
mergify bot pushed a commit that referenced this pull request Dec 21, 2023
…#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)
mergify bot pushed a commit that referenced this pull request Dec 21, 2023
…#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

# Conflicts:
#	docs/management/manage-intro.asciidoc
mergify bot pushed a commit that referenced this pull request Dec 21, 2023
…#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

# Conflicts:
#	docs/management/manage-intro.asciidoc
mergify bot pushed a commit that referenced this pull request Dec 21, 2023
…#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

# Conflicts:
#	docs/management/manage-intro.asciidoc
mergify bot pushed a commit that referenced this pull request Dec 21, 2023
…#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

# Conflicts:
#	docs/management/manage-intro.asciidoc
mergify bot pushed a commit that referenced this pull request Dec 21, 2023
…#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

# Conflicts:
#	docs/management/manage-intro.asciidoc
benironside added a commit that referenced this pull request Dec 21, 2023
…#4439) (#4505)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
benironside added a commit that referenced this pull request Dec 21, 2023
…#4439) (#4506)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
benironside added a commit that referenced this pull request Dec 21, 2023
…#4439) (#4507)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
benironside added a commit that referenced this pull request Dec 21, 2023
…#4439) (#4508)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
benironside added a commit that referenced this pull request Dec 21, 2023
…#4439) (#4509)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
benironside added a commit that referenced this pull request Dec 21, 2023
…#4439) (#4510)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
benironside added a commit that referenced this pull request Dec 21, 2023
…#4439) (#4511)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
benironside added a commit that referenced this pull request Dec 21, 2023
…#4439) (#4512)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
benironside added a commit that referenced this pull request Dec 31, 2023
…ftware (backport #4439) (#4517)

* New page about allowlisting Elastic Endpoint in 3rd-party AV software (#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

# Conflicts:
#	docs/management/manage-intro.asciidoc

* fix merge conflict

---------

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <benjamin.ironside@elastic.co>
benironside added a commit that referenced this pull request Dec 31, 2023
…ftware (backport #4439) (#4516)

* New page about allowlisting Elastic Endpoint in 3rd-party AV software (#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

# Conflicts:
#	docs/management/manage-intro.asciidoc

* fix merge conflict

---------

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <benjamin.ironside@elastic.co>
benironside added a commit that referenced this pull request Dec 31, 2023
…ftware (backport #4439) (#4515)

* New page about allowlisting Elastic Endpoint in 3rd-party AV software (#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

# Conflicts:
#	docs/management/manage-intro.asciidoc

* fix merge conflict

---------

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <benjamin.ironside@elastic.co>
benironside added a commit that referenced this pull request Dec 31, 2023
…ftware (backport #4439) (#4513)

* New page about allowlisting Elastic Endpoint in 3rd-party AV software (#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

# Conflicts:
#	docs/management/manage-intro.asciidoc

* fixes merge conflict

---------

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <benjamin.ironside@elastic.co>
benironside added a commit that referenced this pull request Dec 31, 2023
…ftware (backport #4439) (#4514)

* New page about allowlisting Elastic Endpoint in 3rd-party AV software (#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 08a7c08)

# Conflicts:
#	docs/management/manage-intro.asciidoc

* fixes merge conflict

---------

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <benjamin.ironside@elastic.co>
acorretti pushed a commit that referenced this pull request Nov 19, 2024
…ftware (backport #4439) (#4515)

* New page about allowlisting Elastic Endpoint in 3rd-party AV software (#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 424e4be)

# Conflicts:
#	docs/management/manage-intro.asciidoc

* fix merge conflict

---------

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <benjamin.ironside@elastic.co>
acorretti pushed a commit that referenced this pull request Nov 19, 2024
…ftware (backport #4439) (#4513)

* New page about allowlisting Elastic Endpoint in 3rd-party AV software (#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 424e4be)

# Conflicts:
#	docs/management/manage-intro.asciidoc

* fixes merge conflict

---------

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <benjamin.ironside@elastic.co>
acorretti pushed a commit that referenced this pull request Nov 19, 2024
…ftware (backport #4439) (#4516)

* New page about allowlisting Elastic Endpoint in 3rd-party AV software (#4439)

* Adds new page about allowlisting Elastic Endpoint

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* Update docs/management/admin/allowlist-endpoint-3rd-party-av.asciidoc

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>

* incorporates feedback

* incorporates Gabriel Landau's feedback

---------

Co-authored-by: Daniel Ferullo <56368752+ferullo@users.noreply.github.com>
(cherry picked from commit 424e4be)

# Conflicts:
#	docs/management/manage-intro.asciidoc

* fix merge conflict

---------

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Co-authored-by: Benjamin Ironside Goldstein <benjamin.ironside@elastic.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Document what exceptions users should add to other AV products for Endpoint
6 participants