We using Fleet-managed Elastic Agent.
All agents has policies have Elastic Defend integration.
We are using Enteprise License.
- Can EDR decrease speed of downloading files from Whatsapp?
- Why I don't see Malware Prevention Alert in Detection Rules?
We using Fleet-managed Elastic Agent.
All agents has policies have Elastic Defend integration.
We are using Enteprise License.
Hi @Aliya_Khalel,
Depending on how WhatsApp behaves at an API level, it's possible the "Scan files upon modification" feature may be firing more than necessary. For example, if WhatsApp is repeatedly reopening the file each time it needs append a newly-downloaded chunk of the file, this could trigger Defend's malware protection to repeatedly scan the file. On which OS are you encountering this?
Two possible causes come to mind:
Endpoint Security
SIEM rule is enabled in /app/security/rules/management
.© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.