# Elastic Endpoint Security - Testing detections - Whoami rule

**URL:** <https://discuss.elastic.co/t/elastic-endpoint-security-testing-detections-whoami-rule/253622>\
**Category:** Endpoint Security\
**Created:** [October 28, 2020, 9:37pm UTC](https://discuss.elastic.co/t/elastic-endpoint-security-testing-detections-whoami-rule/253622 "2020-10-28T21:37:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![StephItUp](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@StephItUp](https://discuss.elastic.co/u/StephItUp)\
**Post date:** [October 28, 2020, 9:37pm UTC](https://discuss.elastic.co/t/elastic-endpoint-security-testing-detections-whoami-rule/253622/1 "2020-10-28T21:37:36Z")

</div>

Hi Folks,

I have installed elasticagent and enrolled my device via ingest manager. I have 3 integrations within my configuration:

- System

- Windows

- Elastic Endpoint Security

I imported the Elastic Detection rules and activated these rules. When looking at the rules I noticed the following: "WhoAmI process activity" - Identifies use of whoami.exe which displays user, group, and privileges information for the user who is currently logged on to the local system. - I figured such rules are created to detect potential threat actor who are "living off the land" - using legitimate tools for information gathering and to accomplish their goals

I figured I would test this out by running a few whoami commands on my device (Windows 10) to see whether such activity would be registered within the detection dashboard in Kibana. Surprisingly nothing appeared! No detection. There are other detection appearing in Kiabana so unsure at this point whether its the rule itself which isn't picking up such activity.

Any ideas?

---

<div class="post-metadata">

**Author:** ![variable](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/variable/32/118277_2.png) [@variable](https://discuss.elastic.co/u/variable)\
**Post date:** [October 29, 2020, 2:52pm UTC](https://discuss.elastic.co/t/elastic-endpoint-security-testing-detections-whoami-rule/253622/2 "2020-10-29T14:52:54Z")

</div>

Hello @StephItUp!

Thanks for the question, and it's a good one.

I would assume that you're running Kibana `7.9.2`, which doesn't have the updated `Whoami Process Activity` detection logic.

Currently, that rule uses the following detection logic for the `winlogbeat-*` index pattern:

```auto
process.name:whoami.exe and event.code:1

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/6/f64a999d23c7c2e5ee040f3d140af4b0b13e5e77.png)

Since you're using the Endpoint, the index pattern would need to be updated to use `logs-endpoint.events.*` and the detection logic as follows:

```auto
event.category:process and event.type:(start or process_started) 
and process.name:whoami.exe

```

The above is reflected in our [public Detection Rules repository](https://github.com/elastic/detection-rules) for this [rule](https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_whoami_command_activity.toml) and should be updated in the next release of Kibana.

Running this updated detection logic against the right index pattern returned the expected results:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2d2d0a08028bc38677e6dc17d9e0230615922fe9.png)

In the event that you cannot wait for the update, you can clone the Detection Rules repository (linked above) and simply upload that rule using the [`upload-rules` command for the `detection_rules` Python module](https://github.com/elastic/detection-rules/blob/main/CLI.md#uploading-rules-to-kibana).

---

<div class="post-metadata">

**Author:** ![StephItUp](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@StephItUp](https://discuss.elastic.co/u/StephItUp)\
**Post date:** [October 29, 2020, 5:20pm UTC](https://discuss.elastic.co/t/elastic-endpoint-security-testing-detections-whoami-rule/253622/3 "2020-10-29T17:20:31Z")

</div>

Hi Andrew,

Correct on all fronts. I am running KIbana 7.9.2 and the detection rule applies to winlogbeat-.\* index which explains why its not finding these events. Will try creating the rule in order to have it search through logs-endpoint.events.\*

Thanks for the response! Very clear explanation!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2020, 5:20pm UTC](https://discuss.elastic.co/t/elastic-endpoint-security-testing-detections-whoami-rule/253622/4 "2020-11-26T17:20:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
