Open ghost opened 3 years ago
@manishgupta-qasource Please review
Reviewed & Assigend to @MadameSheema
@XavierM can you please help to prioritise this? thanks
@deepikakeshav-qasource @manishgupta-qasource the event in the screenshot on the left has a different timestamp than the event on the right, I think that executable information may just not be present in the event on the left for any variety of reasons. Do you have a link to an environment you are seeing this on to verify if that is the case by chance?
Hi @kqualters-elastic
We have shared the environment credentials through email. Subject: [Environments Details for: #87456]
Please let us know if anything else is required from our end.
Thanks!!
Hi @MadameSheema,
We have validated this ticket on 7.13.0 BC4 build and observed that issue is Fixed. Details and process.executable information is displayed for mimikatz.exe when events are 0.
Build Details:
Version:7.13.0 BC4
Commit:5a6bad454ffe263aafed54cbd3f764253694bf37
Build:40749
Screenshot:
Hence, We are closing this ticket and adding the label as "QA Validated".
Thanks!!
Hi @MadameSheema,
We have observed that this issue is occurring on the 7.17.0 BC1 build as well as on the latest snapshot builds for both 8.0.0 & 8.1.0. The details and process.executable is not being displayed for mimikatz node for a prevention alert.
Please find below the testing details: Build details 7.17.0 Build: 46386 Commit:c9b31753ccda9d79ad1f6f7b106674a7ba430000 Artifacts link: https://staging.elastic.co/7.17.0-2a228a35/summary-7.17.0.html
8.0.0 Build: 48894 Commit: 9087e164c6890aa9b3a4ae61746753fabdfb27d2 Artifact page: https://artifacts-api.elastic.co/v1/search/8.0.0-SNAPSHOT
8.1.0 Build: 49385 Commit: 348bfb8b33f418d504489cd4a212539d7e04f256 Artifact page: https://artifacts-api.elastic.co/v1/search/8.1.0-SNAPSHOT
Screenshots:
Hence, we are reopening this issue.
Thanks!!
Hi @MadameSheema ,
We have validated this issue on 7.17.0 BC2 on-prem and observed that issue is Still Occurring.
Please find the below details:
Build Details:
Version: 7.17.0 BC2 on-prem
Build: 46488
Commit: a6fd029464413f6979099d7a3d4232c5194a269d
Screenshot:
Thanks!!
@michaelolo24 can you please help to prioritize this issue? Thanks :)
@kqualters-elastic Were you ever able to reproduce the issue?
Description No details and process.executable information is displaying for mimikatz.exe when events are 0.
Build Details:
Browser Details: All
Preconditions:
Steps to Reproduce:
Impacted Test case: N/A
Actual Result: No details and process.executable information is displaying for mimikatz.exe when events are 0.
Expected Result: Details and process.executable information should be displayed for mimikatz.exe when events are 0.
What's working: This is not occurring for cmd.exe when events are 0
What's not working: N/A
Screenshot: Mimikatz.exe![mimikatz_details_process](https://user-images.githubusercontent.com/61860752/103761560-dc58d080-503c-11eb-8700-bf7745b81699.jpg)
Cmd.exe![cmd_0_events](https://user-images.githubusercontent.com/61860752/103761493-c5b27980-503c-11eb-8ec2-de72b080e442.jpg)