-
Notifications
You must be signed in to change notification settings - Fork 571
[Security Content] Basic EDR Setup Guides - Phase 1 #4492
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
[Security Content] Basic EDR Setup Guides - Phase 1
⛔️ Tests failed:
|
⛔️ Tests failed:
|
⛔️ Tests failed:
|
I am marking this as a Draft until we discuss the rule size issue with D&R |
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. |
This has been closed due to inactivity. If you feel this is an error, please re-open and include a justifying comment. |
Issue
Resolves the "Brief Guides" section of https://github.com/elastic/ia-trade-team/issues/205
Summary
This adds the config guides information for Elastic Defend and 3rd party EDRs. This doesn't include Setup information for Windows Security Logs or Sysmon, I plan to add these in another PR.
I'm adding this note because users have frequently reached out via the community or SDHs with misconceptions about this.
Rendered example: