You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
The Malware Detection section has a built in filter for rule.groups: rootcheck - This results in malware detection events being missed such as through the group windows_defender
To Reproduce
Steps to reproduce the behavior:
On a Windows machine with Wazuh Agent, download the EICAR test txt file.
Attempt to open the file, and have Microsoft Defender block the action and quarantine the file.
In Wazuh dashboards, navigate to: Endpoints Summary > Your Windows PC > Malware Detection OR navigate just to Malware Detection
You will not see the Defender event anywhere here, due to that rule.groups: rootcheck filter.
Expected behavior windows_defender and any other possible Malware Detection groups should be included by default.
Additionally, these built in filters ideally should be overridable in this view in case you know that they aren't correct, such as with rootcheck.
Describe the bug
The Malware Detection section has a built in filter for
rule.groups: rootcheck
- This results in malware detection events being missed such as through the groupwindows_defender
To Reproduce
Steps to reproduce the behavior:
rule.groups: rootcheck
filter.Expected behavior
windows_defender
and any other possible Malware Detection groups should be included by default.Additionally, these built in filters ideally should be overridable in this view in case you know that they aren't correct, such as with rootcheck.
OpenSearch Version
Wazuh-Indexer: 4.9.0-1
Dashboards Version
4.9.0-2
Plugins
Screenshots
Host/Environment (please complete the following information):
Additional context
The text was updated successfully, but these errors were encountered: