elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.97k stars 502 forks source link

[Bug] Adversary File Alerts not generating with executing respective files #3273

Open arvindersingh-qasource opened 1 year ago

arvindersingh-qasource commented 1 year ago

Describe the bug Adversary File Alerts not generating with executing respective files

Build Details

Web link : https://34.42.103.232/  
Version : smp-dev-3-50-0-20ab71a-1084
Sensor : 3.64.4

Browser Details This issue is occurring on all browsers.

Preconditions

  1. NIN3 SMP3.50 must be available.
  2. Alert files must be available on endpoint.

Steps to Reproduce

  1. RDP to Endpoint.
  2. Execute the respective Alert File.
  3. Navigate to SMP.
  4. Observe that respective Alert is not generated over SMP.

Type of Alerts

Actual Result Adversary File Alerts not generating with executing respective files

Expected Result Adversary File Alerts should be generating with executing respective files or provide any work around to generate the above mentioned Alerts.

muskangulati-qasource commented 1 year ago

Reviewed and assigned to @charlie-pichette !!

charlie-pichette commented 1 year ago

@brokensound77 is this something your team handles?