Skip to content

Adding agent exclusion filters to dga, lmd and problemchild packages #13058

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 5 commits into from
Mar 20, 2025

Conversation

mgarzon
Copy link
Contributor

@mgarzon mgarzon commented Mar 11, 2025

As described in https://github.com/elastic/security-team/issues/11532, we have added filters to exclude any processing related to the elastic endpoint agents.

@mgarzon mgarzon requested review from a team as code owners March 11, 2025 14:02
Copy link
Contributor

@sodhikirti07 sodhikirti07 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@mgarzon The filters for DGA and problemchild look good. You'll need to add filter to the LMD jobs that aren't RDP based. Also, please bump the versions of manifest.yml and changelog.yml as well as transform.yml where necessary.

Copy link
Member

@susan-shu-c susan-shu-c left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for addressing comments from Kirti; this looks good to me

Copy link
Contributor

@sodhikirti07 sodhikirti07 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes look good to me! Did you try testing the packages locally? If so, could you please add screenshots?

@andrewkroh andrewkroh added Integration:dga Domain Generation Algorithm Detection Integration:lmd Lateral Movement Detection Integration:problemchild Living off the Land Attack Detection Team:Security-Applied ML Elastic Security Protections Machine Learning (ML) team [elastic/sec-applied-ml] labels Mar 13, 2025
@elasticmachine
Copy link

Pinging @elastic/sec-applied-ml (Team:Security-Applied ML)

Copy link
Contributor

@peteharverson peteharverson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mgarzon mgarzon enabled auto-merge (squash) March 20, 2025 15:13
@mgarzon mgarzon requested a review from sodhikirti07 March 20, 2025 15:17
Fixed indentation problem.
Copy link

Quality Gate failed Quality Gate failed

Failed conditions
0.0% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube

@elasticmachine
Copy link

💚 Build Succeeded

History

@mgarzon mgarzon merged commit cbcadd5 into main Mar 20, 2025
6 of 7 checks passed
@mgarzon mgarzon deleted the elastic-agent-filters branch March 20, 2025 17:55
@elastic-vault-github-plugin-prod

Package dga - 2.3.0 containing this change is available at https://epr.elastic.co/package/dga/2.3.0/

@elastic-vault-github-plugin-prod

Package lmd - 2.4.0 containing this change is available at https://epr.elastic.co/package/lmd/2.4.0/

@elastic-vault-github-plugin-prod

Package problemchild - 2.4.0 containing this change is available at https://epr.elastic.co/package/problemchild/2.4.0/

flexitrev pushed a commit that referenced this pull request Mar 25, 2025
…13058)

* Adding agent exclusion filters to dga, lmd and problemchild packages

* increasing version numbers and adding filters to datafeeds of lmd

* Filters in lmd-ml.json are not needed as they have been added to transform
flexitrev pushed a commit that referenced this pull request Mar 28, 2025
…13058)

* Adding agent exclusion filters to dga, lmd and problemchild packages

* increasing version numbers and adding filters to datafeeds of lmd

* Filters in lmd-ml.json are not needed as they have been added to transform
flexitrev pushed a commit that referenced this pull request Mar 28, 2025
…13058)

* Adding agent exclusion filters to dga, lmd and problemchild packages

* increasing version numbers and adding filters to datafeeds of lmd

* Filters in lmd-ml.json are not needed as they have been added to transform
flexitrev pushed a commit that referenced this pull request Mar 28, 2025
…13058)

* Adding agent exclusion filters to dga, lmd and problemchild packages

* increasing version numbers and adding filters to datafeeds of lmd

* Filters in lmd-ml.json are not needed as they have been added to transform
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Integration:dga Domain Generation Algorithm Detection Integration:lmd Lateral Movement Detection Integration:problemchild Living off the Land Attack Detection Team:Security-Applied ML Elastic Security Protections Machine Learning (ML) team [elastic/sec-applied-ml]
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants