beats icon indicating copy to clipboard operation
beats copied to clipboard

[Winlogbeat] Handle additional grok patterns in microsoft defender pipelines for file paths

Open nfritts opened this issue 6 months ago • 1 comments

https://github.com/elastic/integrations/blob/a74f0bf780d1d4a39986bca9bf2f1de1ba04e4ec/packages/windows/data_stream/windows_defender/elasticsearch/ingest_pipeline/default.yml#L160-L164

The above needs to be updated. There are events (specifically event ID 1121 related to Exploit Guard) that instead of having an _ prefixing the path, have just the path with no prefix. IE: Path: C:\\Windows\\System32\\svchost.exe

nfritts avatar Jun 18 '25 20:06 nfritts

Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)

elasticmachine avatar Jun 18 '25 20:06 elasticmachine