Closed ShourieG closed 1 year ago
Pinging @elastic/security-external-integrations (Team:Security-External Integrations)
@marc-gr , @andrewkroh Do you think that the new api option in event.category will have any effect on the SEI shared integrations ?
aws.cloudtrail
aws.vpcflow
system.application
system.auth
system.security
system.system
windows.forwarded
windows.powershell
windows.powershell_operational
windows.sysmon_operational
I looked over the Windows Microsoft-Windows-Security-Auditing provider and didn't see anything that directly mentions "API" calls.
I think some of the event IDs within Symon could potentially be classified as event.category: api
. I think if an event directly mentions some Windows API call then the category should be added. For example event ID 8 directly relates to a CreateRemoteThread
API call.
For AWS cloudtrail I think every event is related to some REST API call. The ECS definition says "but can also include network protocols (such as SOAP, RPC, Websocket, REST, etc.)". That seems to qualify IMO.
@andrewkroh understood, so looks like this will be an enhancement for those packages. So can we get an approval for this PR and then add those separately as enhancements in another PR, since the 8.7 update is time sensitive? We will keep a track of the successive PRs in this meta issue .
SEI packages have been updated to 8.7 & merged. cc: @narph
This is a meta issue to track ECS 8.7 updates to Fleet integrations maintained by the elastic/security-external-integrations team.
ECS 8.7 Changes :
This is a summary of the changes in ECS 8.7. You can view the official changelog here.
Added :
No features added to ECS in 8.7 required changes in SEI packages.
added library option to event.category elastic/ecs#2154
SEI owned Integrations
All SEI integrations are updated in https://github.com/elastic/integrations/pull/5765
Integrations SEI contributes to
Currently the following integrations are being reviewed to check if the api option for event.category has any impact on the following packages (any inputs appreciated) :
SEI Integrations Checklist :
elastic/security-external-integrations:
Relates to : https://github.com/elastic/security-team/issues/5720