# Endpoint Security

**URL:** https://discuss.elastic.co/c/security/endpoint-security/80.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Submitting False Positives](https://discuss.elastic.co/t/submitting-false-positives/232322)

<div class="topic-metadata">

**Author:** [@mark.dufresne](https://discuss.elastic.co/u/mark.dufresne)\
**Replies:** 0\
**Last updated:** [May 12, 2020, 8:43pm UTC](https://discuss.elastic.co/t/submitting-false-positives/232322 "2020-05-12T20:43:13Z")

</div>

We welcome your False Positive (FP) report for Elastic’s malware detection engine. These FP reports help us improve our security products. Please note that as of June 5, 2024 we have updated our False Positive review pr…

---

## [About the Endpoint Security category](https://discuss.elastic.co/t/about-the-endpoint-security-category/204977)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 1\
**Last updated:** [October 24, 2019, 1:08pm UTC](https://discuss.elastic.co/t/about-the-endpoint-security-category/204977 "2019-10-24T13:08:00Z")

</div>

Stop threats in their tracks Elastic Endpoint Security is the only endpoint protection product to fully combine prevention, detection, and response into a single, autonomous agent. It's easy to use, built for speed, and …

---

## [License dection rules](https://discuss.elastic.co/t/license-dection-rules/390802)

<div class="topic-metadata">

**Author:** [@vas-vas777](https://discuss.elastic.co/u/vas-vas777)\
**Replies:** 1\
**Last updated:** [October 6, 2026, 3:53pm UTC](https://discuss.elastic.co/t/license-dection-rules/390802 "2026-10-06T15:53:00Z")

</div>

Hello, everyone! I develope my self-made EDR application. In this application I use YARA app from VirusTotal. In future. I will plan sell my software for third parties. Can I use your yara rules (protections-artifacts/ya…

---

## [False Positive](https://discuss.elastic.co/t/false-positive/390842)

<div class="topic-metadata">

**Author:** [@JasperHedge](https://discuss.elastic.co/u/JasperHedge)\
**Replies:** 0\
**Last updated:** [October 5, 2026, 1:15pm UTC](https://discuss.elastic.co/t/false-positive/390842 "2026-10-05T13:15:41Z")

</div>

Hi there, I know I should report false positives through the form. And I did, but nothing happened. No response and it still keeps flagging as malicious. We've got it with almost all our software, somehow. And we don't …

---

## [Elastic defend (Automatic Response Action Isnt Working )](https://discuss.elastic.co/t/elastic-defend-automatic-response-action-isnt-working/390597)

<div class="topic-metadata">

**Author:** [@jatin3101](https://discuss.elastic.co/u/jatin3101)\
**Replies:** 1\
**Last updated:** [September 25, 2026, 9:17am UTC](https://discuss.elastic.co/t/elastic-defend-automatic-response-action-isnt-working/390597 "2026-09-25T09:17:29Z")

</div>

Hi , i came across this problem that my response action arent working & somehad the same issue but their was solved and i dont undertsand how detection rule- firewall disabled issue- want to run a script for enablin…

---

## [Integration with omega-scan](https://discuss.elastic.co/t/integration-with-omega-scan/390677)

<div class="topic-metadata">

**Author:** [@wessorh](https://discuss.elastic.co/u/wessorh)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:07am UTC](https://discuss.elastic.co/t/integration-with-omega-scan/390677 "2026-09-25T08:07:24Z")

</div>

I'm interested in testing a opensource sample scanner called omega-scan and am looking for documentation on what capabilities there are for calling 3rd party file scanners. A pointer would be greatly appreciated.

---

## [Can Elastic Defend Event Collection interfere with software installation?](https://discuss.elastic.co/t/can-elastic-defend-event-collection-interfere-with-software-installation/389935)

<div class="topic-metadata">

**Author:** [@marrc.rousseau](https://discuss.elastic.co/u/marrc.rousseau)\
**Replies:** 5\
**Last updated:** [September 9, 2026, 4:43pm UTC](https://discuss.elastic.co/t/can-elastic-defend-event-collection-interfere-with-software-installation/389935 "2026-09-09T16:43:35Z")

</div>

Hello, I have a Windows server on which Elastic Defend is enabled, but only the Event Collection component is active. Nothing else is enabled — no malware protection, no ransomware protection, etc... The sole purpose i…

---

## [Elastic Defend Service Enhancement](https://discuss.elastic.co/t/elastic-defend-service-enhancement/389619)

<div class="topic-metadata">

**Author:** [@Shailesk](https://discuss.elastic.co/u/Shailesk)\
**Replies:** 1\
**Last updated:** [August 28, 2026, 8:52pm UTC](https://discuss.elastic.co/t/elastic-defend-service-enhancement/389619 "2026-08-28T20:52:54Z")

</div>

\*"Elastic Defend scan response action should include scan statistics in the response payload: files scanned count, threats detected count, and scan duration breakdown." \* Reference the field path where it should appear…

---

## [Endpoint does not show up in Asset management page](https://discuss.elastic.co/t/endpoint-does-not-show-up-in-asset-management-page/387505)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 3\
**Last updated:** [July 3, 2026, 6:51pm UTC](https://discuss.elastic.co/t/endpoint-does-not-show-up-in-asset-management-page/387505 "2026-07-03T18:51:03Z")

</div>

Hello, I have a deployment on Elastic Cloud for tests and I'm doing a test with Elastic Defend. I have a policy that has Elastic Defend configured with 1 agent enrolled with healthy status. But when I go into Asset…

---

## [False Positive Report — 4K\_Render\_Automation.exe — Malicious (high Confidence)](https://discuss.elastic.co/t/false-positive-report-4k-render-automation-exe-malicious-high-confidence/386586)

<div class="topic-metadata">

**Author:** [@Qu\_c\_Chau](https://discuss.elastic.co/u/Qu_c_Chau)\
**Replies:** 4\
**Last updated:** [June 4, 2026, 2:23pm UTC](https://discuss.elastic.co/t/false-positive-report-4k-render-automation-exe-malicious-high-confidence/386586 "2026-06-04T14:23:14Z")

</div>

Reporting a false positive for Elastic's malware detection engine. File: 4K\_Render\_Automation.exe SHA256: 8e8ab81e34a69221ff50b5b94f033cc31969cc39214efd0346f06a48957b991f Detection: Malicious (high Confidence) VT lin…

---

## [Define proxy for AI connector](https://discuss.elastic.co/t/define-proxy-for-ai-connector/386278)

<div class="topic-metadata">

**Author:** [@hairless\_mess](https://discuss.elastic.co/u/hairless_mess)\
**Replies:** 1\
**Last updated:** [May 11, 2026, 1:44pm UTC](https://discuss.elastic.co/t/define-proxy-for-ai-connector/386278 "2026-05-11T13:44:05Z")

</div>

Hi everyone! I'm trying to add an AI connector and I'm running into a connection problem because the connector can't reach the AI solution as it needs to pass through our proxy. Is there a way to add a proxy configuratio…

---

## [Some prebuilt security rules have missing fields](https://discuss.elastic.co/t/some-prebuilt-security-rules-have-missing-fields/386132)

<div class="topic-metadata">

**Author:** [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Replies:** 1\
**Last updated:** [May 3, 2026, 1:54pm UTC](https://discuss.elastic.co/t/some-prebuilt-security-rules-have-missing-fields/386132 "2026-05-03T13:54:18Z")

</div>

As the title suggests, some prebuilt security rules are failing due to some fields not being present in the Elastic Defend telemetry. From this example, the rule logic has process.command\_line , However, the file teleme…

---

## [False Positive Report - itzOpti.exe - Elastic](https://discuss.elastic.co/t/false-positive-report-itzopti-exe-elastic/385949)

<div class="topic-metadata">

**Author:** [@Luca1](https://discuss.elastic.co/u/Luca1)\
**Replies:** 1\
**Last updated:** [April 29, 2026, 9:40pm UTC](https://discuss.elastic.co/t/false-positive-report-itzopti-exe-elastic/385949 "2026-04-29T21:40:26Z")

</div>

Hello, I am reporting a false positive detection for my file. Vendor: Elastic Detection name: Malicious (high Confidence) SHA256: 6ed1f7c0565b84201b7f9b7ed47eee7f73fddad453ae9e4ce7914369b9ad1311 VirusTotal: VirusTot…

---

## [False Positive Report – EXO Panda Installer (Elastic Detection)](https://discuss.elastic.co/t/false-positive-report-exo-panda-installer-elastic-detection/386082)

<div class="topic-metadata">

**Author:** [@Jude\_Tallent](https://discuss.elastic.co/u/Jude_Tallent)\
**Replies:** 1\
**Last updated:** [April 29, 2026, 9:29pm UTC](https://discuss.elastic.co/t/false-positive-report-exo-panda-installer-elastic-detection/386082 "2026-04-29T21:29:52Z")

</div>

Hello Elastic Team, I'm the owner of EXO Panda (exopanda.com), a legitimate macro and tutorial hub for Roblox players. I'm reaching out regarding a false positive detection by Elastic's engine on VirusTotal for our inst…

---

## [The response action does not work](https://discuss.elastic.co/t/the-response-action-does-not-work/385980)

<div class="topic-metadata">

**Author:** [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Replies:** 8\
**Last updated:** [April 24, 2026, 9:19am UTC](https://discuss.elastic.co/t/the-response-action-does-not-work/385980 "2026-04-24T09:19:13Z")

</div>

Good afternoon! Tell me, please. I have created a custom rule defining the creation of a local user account, configured it so that the isolation of the host is performed using a "response action", but nothing happens. …

---

## [Guidance for running Elastic Defend on ECE hosts](https://discuss.elastic.co/t/guidance-for-running-elastic-defend-on-ece-hosts/385617)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [March 25, 2026, 8:48pm UTC](https://discuss.elastic.co/t/guidance-for-running-elastic-defend-on-ece-hosts/385617 "2026-03-25T20:48:11Z")

</div>

Hello, Is it supported to run Elastic Agent with the Defend integration (ofc first in detect mode initially) on ECE hosts? Should we configure Trusted Applications? If so, which ones? Best regards, Willem

---

## [ElasticDefendStatus - File not found (v9.3.0)](https://discuss.elastic.co/t/elasticdefendstatus-file-not-found-v9-3-0/384899)

<div class="topic-metadata">

**Author:** [@adamsmesher](https://discuss.elastic.co/u/adamsmesher)\
**Replies:** 4\
**Last updated:** [February 6, 2026, 6:39pm UTC](https://discuss.elastic.co/t/elasticdefendstatus-file-not-found-v9-3-0/384899 "2026-02-06T18:39:33Z")

</div>

Hi Everyone! After updating to version 9.3, the Elastic Defend status is not displayed on the endpoints. file:///C:/Program%20Files/Elastic/Endpoint/cache/ElasticDefendStatus.html Register as antivirus - Sync with …

---

## [Elatic fleet custom fields to Elastic Defend](https://discuss.elastic.co/t/elatic-fleet-custom-fields-to-elastic-defend/384794)

<div class="topic-metadata">

**Author:** [@GyciakasGh0st](https://discuss.elastic.co/u/GyciakasGh0st)\
**Replies:** 1\
**Last updated:** [January 29, 2026, 1:26pm UTC](https://discuss.elastic.co/t/elatic-fleet-custom-fields-to-elastic-defend/384794 "2026-01-29T13:26:57Z")

</div>

Hi, I have the issue. For my elastic fleet policy in settings i seted two custom fields. For all other integrations documents these fields appearing during ingest. But only for elastic defend these two custom fields …

---

## [Ad-hoc antivirus scan](https://discuss.elastic.co/t/ad-hoc-antivirus-scan/384575)

<div class="topic-metadata">

**Author:** [@i.raisr](https://discuss.elastic.co/u/i.raisr)\
**Replies:** 1\
**Last updated:** [January 16, 2026, 2:24pm UTC](https://discuss.elastic.co/t/ad-hoc-antivirus-scan/384575 "2026-01-16T14:24:30Z")

</div>

Dear, Please could you suggest an efficient approach of using Elastic EDR for ad-hoc file antivirus/malware scanning. We would like to integrate our existing Elastic Security platform with the Document Management System…

---

## [Endpoint Agent Healthy changes to unhealthy and has not logs](https://discuss.elastic.co/t/endpoint-agent-healthy-changes-to-unhealthy-and-has-not-logs/383340)

<div class="topic-metadata">

**Author:** [@Jeffrey\_Barda](https://discuss.elastic.co/u/Jeffrey_Barda)\
**Replies:** 4\
**Last updated:** [November 12, 2025, 3:31pm UTC](https://discuss.elastic.co/t/endpoint-agent-healthy-changes-to-unhealthy-and-has-not-logs/383340 "2025-11-12T15:31:12Z")

</div>

My Endpoint Health Status changed to unhealthy on my Windows Endpoint a few minutes after it had shown healthy. I have disabled my Windows firewall and checked my policy configuration. What could be the problem?

---

## [Custom Elastic Defend endpoint protection rules？](https://discuss.elastic.co/t/custom-elastic-defend-endpoint-protection-rules/383149)

<div class="topic-metadata">

**Author:** [@GeShanDaKongQi233](https://discuss.elastic.co/u/GeShanDaKongQi233)\
**Replies:** 3\
**Last updated:** [November 6, 2025, 1:57pm UTC](https://discuss.elastic.co/t/custom-elastic-defend-endpoint-protection-rules/383149 "2025-11-06T13:57:40Z")

</div>

The YARA rules and behavioral rules of Elastic Defend are shared with the community, allowing blue teams and defenders to learn from them and improve their defenses. However, we have also observed that many red team memb…

---

## [Elastic Defend Windows Defender question](https://discuss.elastic.co/t/elastic-defend-windows-defender-question/383157)

<div class="topic-metadata">

**Author:** [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Replies:** 9\
**Last updated:** [November 3, 2025, 1:44pm UTC](https://discuss.elastic.co/t/elastic-defend-windows-defender-question/383157 "2025-11-03T13:44:45Z")

</div>

From the attached pic, I don’t understand this warning restriction. I also need some clarification with: Enable to register Elastic as an official Antivirus solution for Windows OS. This will also disable Windows Defe…

---

## [Oracle DB integration with Unified logs](https://discuss.elastic.co/t/oracle-db-integration-with-unified-logs/383160)

<div class="topic-metadata">

**Author:** [@Alaeddine\_khadraoui](https://discuss.elastic.co/u/Alaeddine_khadraoui)\
**Replies:** 1\
**Last updated:** [November 2, 2025, 1:49pm UTC](https://discuss.elastic.co/t/oracle-db-integration-with-unified-logs/383160 "2025-11-02T13:49:48Z")

</div>

We Have Oracle DB configured with Unified Auditing, under unified auditing all DB audit records stored in a single file, we dont have \*.aud files generated which is used and expected by the Oracle Integration What the o…

---

## [Elastic Defend Integration 8.18.1 not detecting/preventing at all?](https://discuss.elastic.co/t/elastic-defend-integration-8-18-1-not-detecting-preventing-at-all/382817)

<div class="topic-metadata">

**Author:** [@boredchilada](https://discuss.elastic.co/u/boredchilada)\
**Replies:** 3\
**Last updated:** [October 21, 2025, 5:44pm UTC](https://discuss.elastic.co/t/elastic-defend-integration-8-18-1-not-detecting-preventing-at-all/382817 "2025-10-21T17:44:55Z")

</div>

I just noticed that for some reason one of my policies was not detecting or preventing anything. I reinstalled the agent which applied the default endpoint initial policy which still had the 8.17.0 elastic defend integra…

---

## [USB Serial Number in file.Ext.device.serial\_number Always Zero or Random one digit Value](https://discuss.elastic.co/t/usb-serial-number-in-file-ext-device-serial-number-always-zero-or-random-one-digit-value/382051)

<div class="topic-metadata">

**Author:** [@alrolo3](https://discuss.elastic.co/u/alrolo3)\
**Replies:** 5\
**Last updated:** [September 18, 2025, 5:11pm UTC](https://discuss.elastic.co/t/usb-serial-number-in-file-ext-device-serial-number-always-zero-or-random-one-digit-value/382051 "2025-09-18T17:11:13Z")

</div>

Hello everyone, I’m opening this topic because I couldn’t find any solution or open issue related to this problem, either in GitHub or other forums. We are currently using Elastic Security as our SIEM, and one of our m…

---

## [Manage Endpoint exceptions by group of enpoints](https://discuss.elastic.co/t/manage-endpoint-exceptions-by-group-of-enpoints/381304)

<div class="topic-metadata">

**Author:** [@sebem](https://discuss.elastic.co/u/sebem)\
**Replies:** 2\
**Last updated:** [August 26, 2025, 10:04am UTC](https://discuss.elastic.co/t/manage-endpoint-exceptions-by-group-of-enpoints/381304 "2025-08-26T10:04:32Z")

</div>

Hi, We are evaluating to deploy Elastic Defend EDR (8.19) in our environement with +10000 endpoints. And I've a question about exceptions/exclusions management in such a large environment. How do you manage exclusions…

---

## [Agent stuck sending documents over and over](https://discuss.elastic.co/t/agent-stuck-sending-documents-over-and-over/381030)

<div class="topic-metadata">

**Author:** [@michael-a](https://discuss.elastic.co/u/michael-a)\
**Replies:** 2\
**Last updated:** [August 20, 2025, 12:20pm UTC](https://discuss.elastic.co/t/agent-stuck-sending-documents-over-and-over/381030 "2025-08-20T12:20:20Z")

</div>

Not sure what this is, as far as I know it’s a first for us, but we have an agent on a LInux client that’s continously - 2 or 3 times per second - logging that it’s sending documents to Elasticsearch, the actual message …

---

## [Elastic Defend not recognized from Windows Server operating system](https://discuss.elastic.co/t/elastic-defend-not-recognized-from-windows-server-operating-system/380995)

<div class="topic-metadata">

**Author:** [@francesco.amato](https://discuss.elastic.co/u/francesco.amato)\
**Replies:** 3\
**Last updated:** [August 13, 2025, 3:46pm UTC](https://discuss.elastic.co/t/elastic-defend-not-recognized-from-windows-server-operating-system/380995 "2025-08-13T15:46:57Z")

</div>

Hello, we have encountered this problem On all Windows Server machines where we have installed the Elastic Agent with their Elastic Defend policy, Defend isn’t recognzed as antivirus software I searched on internet an…

---

## [Offline Decoding of EDR logs](https://discuss.elastic.co/t/offline-decoding-of-edr-logs/380934)

<div class="topic-metadata">

**Author:** [@Mash1](https://discuss.elastic.co/u/Mash1)\
**Replies:** 2\
**Last updated:** [August 12, 2025, 4:04pm UTC](https://discuss.elastic.co/t/offline-decoding-of-edr-logs/380934 "2025-08-12T16:04:02Z")

</div>

Hello, If an Elastic EDR agent is offline, not ingesting logs, while it is running autonomously, then we copy the log files ( such as documents-2025-MM-0DDT024007.log) out-of-band to an offline location while the agent …

---

## [How to protect elastic-agent service? (Anti-tampering protection)](https://discuss.elastic.co/t/how-to-protect-elastic-agent-service-anti-tampering-protection/380715)

<div class="topic-metadata">

**Author:** [@Hoang\_Hoang](https://discuss.elastic.co/u/Hoang_Hoang)\
**Replies:** 10\
**Last updated:** [August 6, 2025, 5:27pm UTC](https://discuss.elastic.co/t/how-to-protect-elastic-agent-service-anti-tampering-protection/380715 "2025-08-06T17:27:03Z")

</div>

Is there a way to prevent (using kernel-mode drivers) the administrator from stopping the elastic-agent service? I want to use Elastic-Agent combined with Elastic Defense for EDR, but the administrator can turn off the …

[Next page](https://discuss.elastic.co/c/security/endpoint-security/80.md?page=1)
