elastic / elastic/docs-content

Better document what the subparts of Elastic Defend mean

Open
#7,840 3 comments 0 reactions 0 assignees View on GitHub
Team:SKI
Dominant language
No language data
Stars
47
Forks
261
Avg merge
3d 21h
Merged PRs (30d)
141

Description

At this time there is a lack of information of what exactly is meant by the subparts of Elastic Defend:
https://www.elastic.co/guide/en/security/master/configure-endpoint-integration-policy.html#event-collection

We should add some more information of what exactly we mean by Event collection. What does that mean from an Endpoint perspective.
I would review the following subparts as a first start:
- [ ] Ransomware Protection
- [ ] Memory threat protection
- [ ] Malicious behaviour detection
- [ ] Event Collection
- [ ] Credential Access
- [ ] DLL and Driver Load
- [ ] DNS
- [ ] File
- [ ] Network
- [ ] Process
- [ ] Registry
- [ ] Security
Especially for the latter what means e.g. a File Event under Windows respectively Linux or MacOS?

^^ @jmikell821

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.