Kibana 8.17.3 – Malware Detection of security_labs Knowledge Base File (TROJ_FRS.VSNTIA26)

Hello Elastic Team,

We are investigating a security alert involving the Kibana 8.17.3 Docker image deployed in our OpenShift environment.

Our endpoint security product detected the following file as:

Detection: TROJ_FRS.VSNTIA26
Action: Deleted

/usr/share/kibana/node_modules/@kbn/elastic-assistant-plugin/server/knowledge_base/security_labs/siestagraph_new_implant_uncovered_in_asean_member_foreign_ministry.md

The detection occurred on two separate servers, and the reported file path was under the Kibana container overlay filesystem.

Kibana Image

The image deployed in our environment is:

s4d1plrga01.ocp-prd-s4d1-01.sbilife.co.in:8443/kibana/kibana:8.17.3

Image ID:

sha256:1800828c430b4974ffe0d61380bf235441140c6119ebaaba05daec5219bf407d

Detection Details

Server 1

Hostname: S4D2RLRGA01
IP: 172.19.13.120
Detection: 14-Sep-2026 04:27:58

Server 2

Hostname: S4D1LBSA01
IP: 172.17.163.120
Detection: 14-Sep-2026 02:52:40

Both detections reported the same filename and the same container overlay ID:

a20b2187cd48a1efb5faaf415d5bb55ed41cd82d4ef90097f3f50927f0903219

The file has subsequently been deleted by the security product and is no longer present at the reported path.

Request for Elastic Confirmation

Could someone from the Kibana/Elastic Security team please confirm:

  1. Is siestagraph_new_implant_uncovered_in_asean_member_foreign_ministry.md legitimate content shipped with Kibana 8.17.3?

  2. Is the following directory expected in the official Kibana distribution?

@kbn/elastic-assistant-plugin/server/knowledge_base/security_labs/

  1. Is this particular Markdown file part of the Elastic Assistant / Security Labs knowledge base?

  2. If it is legitimate, why might an endpoint security product identify this file as TROJ_FRS.VSNTIA26?

  3. Is this a known false positive or known detection associated with Kibana 8.17.3?

  4. Can you provide an official source/repository/release artifact that confirms the file is part of the Kibana 8.17.3 distribution?

  5. Can you confirm whether the file exists in the official Kibana 8.17.3 image corresponding to the image digest above?

  6. If the file is not expected in the official Kibana 8.17.3 image, are there any known issues that could result in this file being introduced into the container?

Investigation Objective

Our security team needs to determine whether this detection represents:

  • legitimate Kibana application content,

  • a false-positive malware detection,

  • content originating from the official Kibana image, or

  • an unexpected modification/injection into the container.

Since the same file was detected on two separate servers, we would particularly appreciate confirmation of the file's origin and authenticity.

Any official Elastic documentation, GitHub source reference, release information, or other authoritative evidence would be helpful for our security investigation and audit justification.

Thank you for your assistance.