Repository navigation
[D4C] cloud_defend. Removed kubernetesPodId. Update docs. - #6112
Conversation
🌐 Coverage report
|
|
Karl, I think the readme should also act as the source of truth for our feature compatibility matrix: <style type="text/css"></style>
I also think we could replace the overview section with this text which I think does a better job of really describing the integration: How Container Workload Protection Works The policy determines which system behaviors (for example, process executions, file creations or deletions, etc) will result in an action. Actions are simple: logging the behavior to Elasticsearch, creating an alert in Elasticsearch, or blocking the behavior. Threat Detection The resulting telemetry data is transformed into an ECS document and streamed back to the user’s Elasticsearch cluster, where the Elastic Security SIEM evaluates the data to detect malicious behavior. Drift Detection & Prevention This policy is configured with an alert response, meaning that when drift conditions are detected, the matching event(s) are collected and written as an alert to the user’s Elasticsearch cluster. A prebuilt rule “escalation rule” in the SIEM watches for these alert documents and raises an alert in the SIEM when drift is detected. This policy can also be modified to block drift operations by changing the response action to block. Policies Policies are composed of selectors and responses. A given policy must contain at least one selector and one response. Currently, the system supports two types of selectors and responses, file and process. Selectors tell the service what system operations to match and have a number of conditions that can be grouped together (using a logical AND operation) to provide precise control. Responses instruct the system on what actions to take when system operations match selectors. |
|
@learhy I think your suggestions here are great, but they are outside the scope of the PR. I will transpose them into a new issue and we get them in the queue. |
|
OK-- Karl asked me to comment on the PR
Dan Rohan
…On May 9, 2023 at 9:57 PM -0500, Norrie Taylor ***@***.***>, wrote:
@learhy I think your suggestions here are great, but they are outside the scope of the PR. I will transpose them into a new issue and we get them in the queue.
—
Reply to this email directly, view it on GitHub, or unsubscribe.
You are receiving this because you were mentioned.Message ID: ***@***.***>
|
|
My bad, I've created the new issue linked above for my own clerical reasons :) |
|
Thanks for the comments @learhy I can make the change in this PR. This just avoids version churn as we're already at 1.0.5 |
|
@norrietaylor @learhy Did we want to add anything about having to uncomment "capabilities" in the yaml? |
|
I would love to see that. @learhy can you provide the text?On May 10, 2023, at 9:15 AM, Karl Godard ***@***.***> wrote:
@norrietaylor @learhy Did we want to add anything about having to uncomment "capabilities" in the yaml?
—Reply to this email directly, view it on GitHub, or unsubscribe.You are receiving this because you were mentioned.Message ID: ***@***.***>
|
|
Package cloud_defend - 1.0.6 containing this change is available at https://epr.elastic.co/search?package=cloud_defend |
|
Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform) |
* removed kubernetesPodId * pr link update * copy overhaul + support matrix * beta * formatting * formatting * formatting * words
What does this PR do?
Removes documentation for an unimplemented selector condition.
Checklist
changelog.ymlfile.