elastic / elastic/endpoint

[Defend] Network Telemetry enhancements

Open
#76 1 comment 1 reaction 0 assignees View on GitHub
Dominant language
Swift
Stars
47
Forks
9
PR merge metrics
No merged PRs in 30d

Description

Sysmon captures domain names and network.protocol for network connection events using event ID 3.

As a user of Elastic Defend, I would like all connection events to include the domain and network protocol for events to analyze when possible. There may be a cost to resolve the domain from the IP but it seems to be worth it based on how Sysmon does it today.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.