Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[8.8] [Security Solution] Adds several new fields to allowed Exceptio…
…ns for Endpoint (elastic#159835) (elastic#159924) # Backport This will backport the following commits from `main` to `8.8`: - [[Security Solution] Adds several new fields to allowed Exceptions for Endpoint (elastic#159835)](elastic#159835) <!--- Backport version: 8.9.7 --> ### Questions ? Please refer to the [Backport tool documentation](https://github.com/sqren/backport) <!--BACKPORT [{"author":{"name":"Kevin Logan","email":"[email protected]"},"sourceCommit":{"committedDate":"2023-06-19T12:58:08Z","message":"[Security Solution] Adds several new fields to allowed Exceptions for Endpoint (elastic#159835)\n\n## Summary\r\n\r\nAdds the following new fields to allowed Exceptions for Endpoint after\r\ncustomer and internal requests.\r\n\r\nWe can backport this to `8.8.2` in addition to shipping in `8.9.0`\r\n\r\n```\r\n \"process.args\",\r\n \"process.parent.args\",\r\n \"dns.question.type\",\r\n \"file.pe.Ext.dotnet\",\r\n \"file.pe.Ext.streams.hash.md5\",\r\n \"file.pe.Ext.streams.hash.sha256\",\r\n \"file.pe.Ext.sections.hash.sha256\",\r\n \"file.pe.Ext.sections.hash.md5\",\r\n \"file.pe.Ext.streams.name\",\r\n \"Effective_process.entity_id\",\r\n \"Effective_process.executable\",\r\n \"Effective_process.name\",\r\n \"Effective_process.pid\"\r\n```\r\n\r\nSee the Endpoint Exception builder below with the new fields available\r\nfor use.\r\n\r\n\r\n![image](https://github.com/elastic/kibana/assets/56395104/1bafd68b-3b35-4543-92cb-37d379801b92)\r\n\r\n\r\n![image](https://github.com/elastic/kibana/assets/56395104/ff582e63-f93b-42ce-b95e-13965f75098a)\r\n\r\n\r\n![image](https://github.com/elastic/kibana/assets/56395104/87e1b214-4a76-459c-800d-eb6877ed3b9a)","sha":"3e61769cdaef20bff5b788c6c365dfa80c1ca8ba","branchLabelMapping":{"^v8.9.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:enhancement","Team:Defend Workflows","v8.8.0","v8.9.0"],"number":159835,"url":"https://github.com/elastic/kibana/pull/159835","mergeCommit":{"message":"[Security Solution] Adds several new fields to allowed Exceptions for Endpoint (elastic#159835)\n\n## Summary\r\n\r\nAdds the following new fields to allowed Exceptions for Endpoint after\r\ncustomer and internal requests.\r\n\r\nWe can backport this to `8.8.2` in addition to shipping in `8.9.0`\r\n\r\n```\r\n \"process.args\",\r\n \"process.parent.args\",\r\n \"dns.question.type\",\r\n \"file.pe.Ext.dotnet\",\r\n \"file.pe.Ext.streams.hash.md5\",\r\n \"file.pe.Ext.streams.hash.sha256\",\r\n \"file.pe.Ext.sections.hash.sha256\",\r\n \"file.pe.Ext.sections.hash.md5\",\r\n \"file.pe.Ext.streams.name\",\r\n \"Effective_process.entity_id\",\r\n \"Effective_process.executable\",\r\n \"Effective_process.name\",\r\n \"Effective_process.pid\"\r\n```\r\n\r\nSee the Endpoint Exception builder below with the new fields available\r\nfor use.\r\n\r\n\r\n![image](https://github.com/elastic/kibana/assets/56395104/1bafd68b-3b35-4543-92cb-37d379801b92)\r\n\r\n\r\n![image](https://github.com/elastic/kibana/assets/56395104/ff582e63-f93b-42ce-b95e-13965f75098a)\r\n\r\n\r\n![image](https://github.com/elastic/kibana/assets/56395104/87e1b214-4a76-459c-800d-eb6877ed3b9a)","sha":"3e61769cdaef20bff5b788c6c365dfa80c1ca8ba"}},"sourceBranch":"main","suggestedTargetBranches":["8.8"],"targetPullRequestStates":[{"branch":"8.8","label":"v8.8.0","labelRegex":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"},{"branch":"main","label":"v8.9.0","labelRegex":"^v8.9.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/159835","number":159835,"mergeCommit":{"message":"[Security Solution] Adds several new fields to allowed Exceptions for Endpoint (elastic#159835)\n\n## Summary\r\n\r\nAdds the following new fields to allowed Exceptions for Endpoint after\r\ncustomer and internal requests.\r\n\r\nWe can backport this to `8.8.2` in addition to shipping in `8.9.0`\r\n\r\n```\r\n \"process.args\",\r\n \"process.parent.args\",\r\n \"dns.question.type\",\r\n \"file.pe.Ext.dotnet\",\r\n \"file.pe.Ext.streams.hash.md5\",\r\n \"file.pe.Ext.streams.hash.sha256\",\r\n \"file.pe.Ext.sections.hash.sha256\",\r\n \"file.pe.Ext.sections.hash.md5\",\r\n \"file.pe.Ext.streams.name\",\r\n \"Effective_process.entity_id\",\r\n \"Effective_process.executable\",\r\n \"Effective_process.name\",\r\n \"Effective_process.pid\"\r\n```\r\n\r\nSee the Endpoint Exception builder below with the new fields available\r\nfor use.\r\n\r\n\r\n![image](https://github.com/elastic/kibana/assets/56395104/1bafd68b-3b35-4543-92cb-37d379801b92)\r\n\r\n\r\n![image](https://github.com/elastic/kibana/assets/56395104/ff582e63-f93b-42ce-b95e-13965f75098a)\r\n\r\n\r\n![image](https://github.com/elastic/kibana/assets/56395104/87e1b214-4a76-459c-800d-eb6877ed3b9a)","sha":"3e61769cdaef20bff5b788c6c365dfa80c1ca8ba"}}]}] BACKPORT--> Co-authored-by: Kevin Logan <[email protected]>
- Loading branch information