Skip to content

[Request]Identify AV/EDR compatibility issues on endpoints with genAI (endpoint insights) #6301

Closed
@caitlinbetz

Description

@caitlinbetz

Description

This feature leverages generative AI to detect if any AV/Security programs are running on a host. Once identified, we guide users through adding detected tools as trusted applications. This solution is targeted to ease the workflow for security operations teams and security admins that manage complex environments with multiple security tools, and need to ensure that all agents/endpoints are optimally functioning.

Background & resources

Which documentation set does this change impact?

ESS and serverless

ESS release

9.0

Serverless release

Monday January 27

Feature differences

Slated for 9.0 for ESS release
No changes between serverless/ESS

API docs impact

TBD

Prerequisites, privileges, feature flags

ESS:

  • Enterprise tier
  • Privileges: New Insights privilege to run insights scan, Trusted Apps privilege to add TA entry

Serverless:

  • Security Analytics Complete, with Endpoint Complete
  • Privileges: New Insights privilege to run insights scan, Trusted Apps privilege to add TA entry

Metadata

Metadata

Assignees

Labels

Docset: ESSIssues that apply to docs in the Stack releaseDocset: ServerlessIssues for Serverless SecurityEffort: MediumIssues that take moderate but not substantial time to completeFeature: Elastic DefendPriority: MediumIssues that have relevance, but aren't urgentTeam: EDR WorkflowsFormerly Defend Workflows, Onboarding and Lifecycle Managementv9.0.0

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions