elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.91k stars 493 forks source link

[Bug] Adversary File Alerts not generating with executing respective files #3273

Open arvindersingh-qasource opened 10 months ago

arvindersingh-qasource commented 10 months ago

Describe the bug Adversary File Alerts not generating with executing respective files

Build Details

Web link : https://34.42.103.232/  
Version : smp-dev-3-50-0-20ab71a-1084
Sensor : 3.64.4

Browser Details This issue is occurring on all browsers.

Preconditions

  1. NIN3 SMP3.50 must be available.
  2. Alert files must be available on endpoint.

Steps to Reproduce

  1. RDP to Endpoint.
  2. Execute the respective Alert File.
  3. Navigate to SMP.
  4. Observe that respective Alert is not generated over SMP.

Type of Alerts

Actual Result Adversary File Alerts not generating with executing respective files

Expected Result Adversary File Alerts should be generating with executing respective files or provide any work around to generate the above mentioned Alerts.

muskangulati-qasource commented 10 months ago

Reviewed and assigned to @charlie-pichette !!

charlie-pichette commented 10 months ago

@brokensound77 is this something your team handles?