forked from elastic/kibana
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[EDR Workflows] Workflow Insights - filter trusted apps by policy (el…
…astic#209340) This PR updates the logic for determining whether an Insight has already been addressed by Trusted Apps. While we’ve been querying Trusted Apps based on the Insight’s reported path and, for Windows and macOS, the signature, this approach had a limitation: it didn’t account for cases where a matching Trusted App existed but was assigned to a policy unrelated to the endpoint where the Insight was generated. To address this, we’ve extended the query to include an additional filter for the specific policy ID associated with the endpoint, as well as any global policies (policy:all). https://github.com/user-attachments/assets/96470d0b-b7ea-4f59-af0a-e865ad7fd22c
- Loading branch information
1 parent
b750d46
commit 8831e5b
Showing
3 changed files
with
125 additions
and
45 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters