elastic / elastic/docs-content
Better document what the subparts of Elastic Defend mean
- Dominant language
- No language data
- Stars
- 47
- Forks
- 261
- Avg merge
- 3d 21h
- Merged PRs (30d)
- 141
Description
At this time there is a lack of information of what exactly is meant by the subparts of Elastic Defend:
https://www.elastic.co/guide/en/security/master/configure-endpoint-integration-policy.html#event-collection
We should add some more information of what exactly we mean by Event collection. What does that mean from an Endpoint perspective.
I would review the following subparts as a first start:
- [ ] Ransomware Protection
- [ ] Memory threat protection
- [ ] Malicious behaviour detection
- [ ] Event Collection
- [ ] Credential Access
- [ ] DLL and Driver Load
- [ ] DNS
- [ ] File
- [ ] Network
- [ ] Process
- [ ] Registry
- [ ] Security
Especially for the latter what means e.g. a File Event under Windows respectively Linux or MacOS?
^^ @jmikell821
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.