Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Opt-In Full Event Capture for Elastic Defend (Sysmon-like Functionality) #197932

Open
teamthanos opened this issue Oct 27, 2024 · 2 comments
Open
Labels
Team:Defend Workflows “EDR Workflows” sub-team of Security Solution

Comments

@teamthanos
Copy link

Description:

Currently, Elastic Defend’s event capture design prioritizes efficiency by focusing on detecting malicious behaviour in a cost-effective way, which involves deduplication and filtering of events deemed unnecessary for detection purposes. While this approach optimizes for CPU, bandwidth, and storage usage, it may not meet the needs of some organizations seeking full event visibility for comprehensive threat hunting or forensic analysis.

Problem Statement:

Many companies are opting to use Elastic Defend as their sole endpoint security solution, under the assumption that it provides full event capture akin to Sysmon. However, they are not aware that Elastic Defend filters and deduplicates events before sending them to the SIEM. This results in situations where critical events might be filtered out, potentially missing some scenarios or behaviours that an organization needs to monitor.

Organizations that require comprehensive monitoring often find themselves needing to install Sysmon alongside Elastic Defend, which increases complexity and resource consumption on the endpoint.

Feature Request:

Introduce an opt-in feature for Elastic Defend to provide full event capture capabilities, similar to what Sysmon offers. This feature would allow customers to:

Enable full event capture: A checkbox or configuration setting to capture all possible events without deduplication or filtering, effectively serving as a 1:1 replacement for Sysmon’s event monitoring.

Maintain the default efficiency mode: By default, Elastic Defend would continue to filter and deduplicate events for customers who prioritize performance and storage savings. The full capture mode would be an opt-in setting for those willing to accept higher resource usage for complete event monitoring.

Benefits:

Provides customers with the flexibility to choose between performance optimization and full visibility.
Reduces the need to install additional monitoring solutions (like Sysmon), thereby simplifying endpoint configuration and management.
Enhances Elastic Defend's value for customers who use the SIEM for advanced threat hunting and incident response.
Potential Challenges:

Full event capture may increase CPU usage, bandwidth, and storage requirements. However, organizations that opt-in would be doing so with this trade-off in mind.
Additional configuration options may increase the complexity of the Elastic Defend setup, requiring clear documentation and guidance for customers.

Conclusion:

This feature would offer a balanced approach to endpoint monitoring, catering to different organizational needs by making full event capture an optional, configurable setting. This would help bridge the gap for customers who seek a Sysmon-like experience within the Elastic ecosystem, enabling Elastic Defend to serve as a more comprehensive solution.

@botelastic botelastic bot added the needs-team Issues missing a team label label Oct 27, 2024
@mbondyra mbondyra added the Team:Defend Workflows “EDR Workflows” sub-team of Security Solution label Oct 28, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-defend-workflows (Team:Defend Workflows)

@botelastic botelastic bot removed the needs-team Issues missing a team label label Oct 28, 2024
@ferullo
Copy link
Contributor

ferullo commented Nov 7, 2024

Hi @teamthanos, Defend is focused on emitting security-relevant event telemetry, not full system telemetry. So we don't have near term plans to produce all the event telemetry you're probably imaging. However, we do seriously consider requests for individual event types on a case-by-case basis. So if there's something specific you're looking for let us know.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team:Defend Workflows “EDR Workflows” sub-team of Security Solution
Projects
None yet
Development

No branches or pull requests

4 participants