Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Crowdstrike bidirectional integration (tech preview) [Request] #5446

Closed
4 of 5 tasks
caitlinbetz opened this issue Jun 18, 2024 · 4 comments
Closed
4 of 5 tasks

Crowdstrike bidirectional integration (tech preview) [Request] #5446

caitlinbetz opened this issue Jun 18, 2024 · 4 comments
Assignees
Labels
Docset: ESS Issues that apply to docs in the Stack release Docset: Serverless Issues for Serverless Security Feature: Response actions also includes response console Team: EDR Workflows Formerly Defend Workflows, Onboarding and Lifecycle Management v8.15.0

Comments

@caitlinbetz
Copy link

caitlinbetz commented Jun 18, 2024

Description

We are releasing our bidirectional capability with Crowdstrike, which will allow users to execute host isolation / release of a crowdstrike agent through elastic security. Functionalities include:

  • check CS host status (+ name)
  • isolate/release the host
  • see process tree in Analyzer

This is similar to the functionality (and docs) we previously added for Sentinel One: https://www.elastic.co/guide/en/security/current/response-actions-config.html (see also, S1 docs ticket: #4312)

Background & resources

Additional info

  • Which documentation set does this change impact? ESS and serverless

  • ESS release: 8.15

  • Serverless release: Week of July 1, 2024

  • Feature differences: n/a

  • API docs impact: @tomsonpl - can you provide?

  • Prerequisites, privileges, feature flags:

    ESS:

    • Actions and Connectors : All
    • Security: Host Isolation: All

Tasks & Pull Requests

Preview Give feedback
@joepeeples joepeeples self-assigned this Jun 18, 2024
@joepeeples
Copy link
Contributor

@caitlinbetz Thanks for opening the ticket! I'll need a bit more time than June 24 to deliver serverless docs; we generally shoot for 2-week turnaround and I'm on PTO the rest of this week. But I can tackle this as soon as I get back and give you an updated ETA

@joepeeples joepeeples added Team: EDR Workflows Formerly Defend Workflows, Onboarding and Lifecycle Management Feature: Response actions also includes response console Docset: Serverless Issues for Serverless Security Docset: ESS Issues that apply to docs in the Stack release v8.15.0 labels Jul 8, 2024
@lcawl
Copy link
Contributor

lcawl commented Jul 8, 2024

Hi! I noticed the Crowdstrike connector showing up in my screenshots but it's not in the API docs or the Kibana docs yet. If it's ready to be documented, typically the dev owners create the first draft of the latter by using the layout in https://github.com/elastic/kibana/blob/main/docs/action-type-template.asciidoc. I'm happy to help add details to the API document (currently manually maintained in https://github.com/elastic/kibana/tree/main/x-pack/plugins/actions/docs/openapi/components/schemas) too

@joepeeples
Copy link
Contributor

@lcawl I actually just asked the dev team about this over on another docs issue, so I referenced your comment too. Thanks for checking up on this!

@lcawl
Copy link
Contributor

lcawl commented Sep 10, 2024

FYI I've created elastic/kibana#192526 to add this connector to the API docs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Docset: ESS Issues that apply to docs in the Stack release Docset: Serverless Issues for Serverless Security Feature: Response actions also includes response console Team: EDR Workflows Formerly Defend Workflows, Onboarding and Lifecycle Management v8.15.0
Projects
None yet
Development

No branches or pull requests

3 participants