elastic / elastic/endpoint

Elastic Defend not providing library load events for CldApi.dll

Open
#103 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Swift
Stars
47
Forks
9
PR merge metrics
No merged PRs in 30d

Description

My team is trying to build a simple detection rule to alert on non-standard processes loading `C:\Windows\System32\CldApi.dll`.
Example detection in KQL:
```kql
event.dataset : "endpoint.events.library" and
host.os.family : "windows" and
dll.name : *CldApi.dll and not
( process.name.caseless : (
"onedrive.exe" or
"onedrivesetup.exe" or
"filecoauth.exe" or
"explorer.exe" ) and
process.code_signature.subject_name : "Microsoft Corporation" and
process.code_signature.status : "trusted"
)
```

Unfortunately, during testing of our rule we figured out that Elastic Defend is not forwarding library events related to the loading of this DLL. We were able to test this using powershell:
```
PS C:\Users\user> Add-Type -TypeDefinition @"
>> using System;
>> using System.Runtime.InteropServices;
>> public class NativeLoader {
>> [DllImport("kernel32.dll", SetLastError = true)]
>> public static extern IntPtr LoadLibrary(string lpFileName);
>> }
>> "@
PS C:\Users\user> $cldapi = [NativeLoader]::LoadLibrary("CldApi.dll")
PS C:\Users\user> Get-Process -Id $PID | Select -ExpandProperty Modules | ? { $_.ModuleName -like "*CldApi*" }
```

This shows that we are loading the cloud api library but this event never appears in Elasticsearch/Kibana. We have already tried disabling `[linux,mac,windows].advanced.event_filter.default` (setting value to `false`) in the Elastic Defend policy advanced settings. We also validated we have no custom event filters that would be removing these events.

Is there another setting we are missing? Or is this expected of defend?

---
**Environment**

- OS: Windows 11 25H2 (build 26200.8246)
- Elastic Agent: 9.3.3

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.