Open ghost opened 3 years ago
Pinging @elastic/security-solution (Team: SecuritySolution)
Reviewed & Assigned to @MadameSheema
Pinging @elastic/security-threat-hunting (Team:Threat Hunting)
@karanbirsingh-qasource can you please try to reproduce this on 7.13.2? Do you happen to share in private the instance details to connect to it?
Hi @MadameSheema
we have validated this issue on 7.13.2 with same field and value that is process.args: C:\Windows\system32\notepad.exe
and found that issue is occuring there too.
Moreover as stated earlier issue is occuring only for this specific value and not occuring for other process mimikatz,power shell.
Build Details:
Version: 7.13.2 BC1
Commit:288dada92621719c3e812310124f12e7824ee571
Build:288dada92621719c3e812310124f12e7824ee571
Screen-Cast https://user-images.githubusercontent.com/59917825/122343377-41f1a700-cf63-11eb-86a6-de3f6133990a.mp4
Logs:
Exported Timeline : timelines_export.zip
Additionally we have shared the Instance details over mail with you.
Thanks
Hi @MadameSheema
we have validated this issue on 7.15.0-SNAPSHOT and found it is still occuring . Timeline result got zero on adding the process.args in timeline drop bar.
Note: This issue is only for the process.name: "notepad.exe" in timeline search bar.
Build Details:
Version:7.15.0-SNAPSHOT
commit:00fcc2cd00d309f4c17db4ec7d552bc54fbd1b81
Build:43271
Snap-Shoot:
Build Details:
VERSION: 8.11.0 BC9
BUILD: 68160
COMMIT: f2ea0c43ec0d854259d63d926b97e5c556b5f6b2
Preconditions:
This PC
ā> Windows (C:)
ā> Windows
ā> System32
Describe the bug:
Empty Timeline result forprocess.args
field with value C:\WINDOWS\system32\notepad.exe
Steps to reproduce:
Security
-> Timelines
-> Create New Timeline
process.name.caseless:notepad.exe
process.args: C:\WINDOWS\system32\notepad.exe
in the Timeline Queryprocess.args: C:|WINDOWS\system32\notepad.exe
in the Timeline Query and drag and drop a different process.args
field value containing Notepad.exe
In my case, I selected the process.args
field value process.args: "C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2309.28.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe"
kibana.alert.rule.name: Malware Detection Alert
under the Search bar at the topEdit filter
from the pop under menu list selectionData View
and Select a field field options show Current behavior
process.args
field with value C:\WINDOWS\system32\notepad.exe
shows empty timeline result
Expected behavior:
process.args
field with value C:\WINDOWS\system32\notepad.exe
should show timeline result
8.11 BC9
and the behavior is still showing and occurring for the specific value C:\WINDOWS\system32\notepad.exe
Program Files
and not as an application with System32, then there is no issue and the Timeline populates forprocess.args
for Notepad.exe
Program Files
and using System32
and have provided details of the observed behavior in the screenshots and recording.**Screenshot showing behavior of process.args
field value C:\WINDOWS\system32\notepad.exe
empty timeline
Screenshot showing filtering of process.name.caseless: notepad.exe
to filter events containg notepad.exe
regardless of string case. Also, shows the process.args: C:\WINDOWS\system32\notepad.exe
that displayed from the filtered results:
Screenshot showing behavior of a process.args
containing Notepad.exe running with a different field value: process.args: "C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2309.28.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe"
timeline population:
https://github.com/elastic/kibana/assets/35679937/fdfa03ec-8e64-4fde-84ac-39380127ef1e
Behavior is still occurring in 8.11.0 BC9
latest release for System 32 Notepad.exe application value: C:\IWNDOWS\system32\notepad.exe
. The behavior is associated only with this process.args
and does not display empty timeline for any other process.args
value that are not opened in Systems32.
@MadameSheema and @XavierM FYI Updated Observations
Describe the bug Empty Timeline result for process.args field with value
C:\WINDOWS\system32\notepad.exe
Build Details:
Browser Details: N/A
Browser Details All
Preconditions
Steps to Reproduce 1.Go to Case Tab. 2.Create Timeline. 3.Enter
process.name : "notepad.exe"
in timeline search bar. 4.Result will be returned for above query. 5.drag theprocess.arg
field and drop to timeline search bar.Note: This issue is occurring only with notepad application.
Actual Result Empty Timeline result for specific field value C:\WINDOWS\system32\notepad.exe as process.args
Expected Result Correct Timeline result should be returned for
process.args
field with valueC:\WINDOWS\system32\notepad.exe
Whats Working
Whats Not Working
Screen-Shoot
https://user-images.githubusercontent.com/59917825/122206026-8bd48180-cebe-11eb-95c2-2ecc9fe59fb5.mp4
https://user-images.githubusercontent.com/59917825/122206042-8f680880-cebe-11eb-94e3-c9daa130e78e.mp4
logs Exported Timeline : timelines_export.zip