Elastic EDR Problem

We using Fleet-managed Elastic Agent.
All agents has policies have Elastic Defend integration.
We are using Enteprise License.

  1. Can EDR decrease speed of downloading files from Whatsapp?
  2. Why I don't see Malware Prevention Alert in Detection Rules?

Hi @Aliya_Khalel,

Depending on how WhatsApp behaves at an API level, it's possible the "Scan files upon modification" feature may be firing more than necessary. For example, if WhatsApp is repeatedly reopening the file each time it needs append a newly-downloaded chunk of the file, this could trigger Defend's malware protection to repeatedly scan the file. On which OS are you encountering this?

Two possible causes come to mind:

  1. Make sure the Endpoint Security SIEM rule is enabled in /app/security/rules/management.
  2. Your stack has Rule Exceptions for Endpoint alerts. See this explanation: Elastic Security Rule Exceptions vs Endpoint Exceptions - #2 by ferullo