Repository navigation
[system/security] - Drop empty process.args token from trailing whitespace - #20907
Conversation
The Event ID 4688 command-line tokenizer split winlog.event_data.CommandLine on whitespace but never discarded empty tokens. Windows records a no-argument process launch with a trailing space after the quoted executable path, so the final space produced a spurious empty-string element in process.args and inflated process.args_count by one (e.g. "...\notepad.exe" with a trailing space yielded args_count 2 instead of 1). Consecutive spaces between real arguments had the same effect. Skip empty tokens both when splitting on whitespace and when emitting the final token, so process.args and process.args_count reflect the actual argument list. Add a pipeline test case for a no-argument launch with a trailing space. Co-authored-by: Cursor <cursoragent@cursor.com>
Add the changelog entry and bump the package version for the system.security process.args and process.args_count fix. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
✅ Elastic Docs Style Checker (Vale)No issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
|
✅ All changelog entries have the correct PR link. |
|
🟢 No issues across the latest commits fce9be2.
🤖 AI-Generated Review | Vera Review Bot - v0.2.7 | 📚 Knowledge base: integration-skills
|
| start = i + 1; | ||
| } | ||
| if (i == ctx.winlog.event_data.CommandLine.length() - 1) { | ||
| if (i == ctx.winlog.event_data.CommandLine.length() - 1 && start <= end) { |
There was a problem hiding this comment.
The same code exists in windows forwarded security_standard.
🚀 Benchmarks reportTo see the full report comment with |
💚 Build Succeeded
cc @ShourieG |
|
Tick the box to add this pull request to the merge queue (same as
|
|
Package system - 2.23.1 containing this change is available at https://epr.elastic.co/package/system/2.23.1/ |
…tespace (#20911) windows.forwarded: drop empty process.args token from trailing whitespace The Event ID 4688 command-line tokenizer split winlog.event_data.CommandLine on whitespace but never discarded empty tokens. Windows records a no-argument process launch with a trailing space after the quoted executable path, so the final space produced a spurious empty-string element in process.args and inflated process.args_count by one (e.g. "...\notepad.exe" with a trailing space yielded args_count 2 instead of 1). Consecutive spaces between real arguments had the same effect. This mirrors the same fix already applied to the system.security pipeline in #20907. Skip empty tokens both when splitting on whitespace and when emitting the final token, so process.args and process.args_count reflect the actual argument list. Add a pipeline test case for a no-argument launch with a trailing space and bump the package to 3.9.2. --------- Co-authored-by: Cursor <cursoragent@cursor.com>
Type of change
Proposed commit message
Checklist
changelog.ymlfile.Author's Checklist
How to test this PR locally
Related issues
Screenshots