# Elastic EDR Problem

**URL:** <https://discuss.elastic.co/t/elastic-edr-problem/371748>\
**Category:** Endpoint Security\
**Tags:** elastic-stack-security\
**Created:** [December 10, 2024, 11:07am UTC](https://discuss.elastic.co/t/elastic-edr-problem/371748 "2024-12-10T11:07:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aliya\_Khalel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aliya_khalel/32/132809_2.png) [@Aliya\_Khalel](https://discuss.elastic.co/u/Aliya_Khalel)\
**Post date:** [December 10, 2024, 11:07am UTC](https://discuss.elastic.co/t/elastic-edr-problem/371748/1 "2024-12-10T11:07:07Z")

</div>

We using Fleet-managed Elastic Agent.  
All agents has policies have Elastic Defend integration.  
We are using Enteprise License.

1. Can EDR decrease speed of downloading files from Whatsapp?
2. Why I don't see Malware Prevention Alert in Detection Rules?  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c3e88bc84c72c4b455a322095892260be86200a9.png)

---

<div class="post-metadata">

**Author:** ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)\
**Post date:** [December 12, 2024, 6:03pm UTC](https://discuss.elastic.co/t/elastic-edr-problem/371748/2 "2024-12-12T18:03:01Z")

</div>

Hi @Aliya_Khalel,

> [@Aliya\_Khalel](#):
>
> Can EDR decrease speed of downloading files from Whatsapp?

Depending on how WhatsApp behaves at an API level, it's possible the "Scan files upon modification" feature may be firing more than necessary. For example, if WhatsApp is repeatedly reopening the file each time it needs append a newly-downloaded chunk of the file, this could trigger Defend's malware protection to repeatedly scan the file. On which OS are you encountering this?

> [@Aliya\_Khalel](#):
>
> Why I don't see Malware Prevention Alert in Detection Rules?

Two possible causes come to mind:

1. Make sure the `Endpoint Security` SIEM rule is enabled in `/app/security/rules/management`.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d77f774140d835de0a9e38a963faaae7251013d3.png)
2. Your stack has [Rule Exceptions](https://www.elastic.co/guide/en/security/current/detections-ui-exceptions.html) for [Endpoint alerts](https://www.elastic.co/guide/en/security/current/add-exceptions.html#endpoint-rule-exceptions). See this explanation: [Elastic Security Rule Exceptions vs Endpoint Exceptions - #2 by ferullo](https://discuss.elastic.co/t/elastic-security-rule-exceptions-vs-endpoint-exceptions/355404/2)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2025, 6:03pm UTC](https://discuss.elastic.co/t/elastic-edr-problem/371748/3 "2025-01-09T18:03:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
