Endpoint protection rules
editEndpoint protection rules
editEndpoint protection rules are prebuilt rules designed to help you manage and respond to alerts generated by Elastic Endpoint, the installed component that performs Elastic Defend’s threat monitoring and prevention. These rules include the Endpoint Security rule as well as additional detection and prevention rules for different Elastic Defend protection features.
To receive Elastic Endpoint alerts, you must install Elastic Agent and the Elastic Defend integration on your hosts (refer to Install Elastic Defend).
When endpoint protection rules are triggered, Elastic Endpoint alerts are displayed as detection alerts in the Elastic Security app. The detection alert name is taken from the Elastic Endpoint alert message and overwrites the prebuilt rule name in the Alerts table. For example, for malware protection, the following Elastic Endpoint alerts are displayed as detection alerts:
- Malware Prevention Alert
- Malware Detection Alert
Endpoint Security rule
editThe Endpoint Security rule automatically creates an alert from all incoming Elastic Endpoint alerts.
When you install Elastic prebuilt rules, the Elastic Defend is enabled by default.
Feature-specific protection rules
editThe following endpoint protection rules give you more granular control over how you handle the generated alerts. These rules are tailored for each of Elastic Defend’s endpoint protection features—malware, ransomware, memory threats, and malicious behavior. Enabling these rules allows you to configure more specific actions based on the protection feature and whether the malicious activity was prevented or detected.
- Behavior - Detected - Elastic Defend
- Behavior - Prevented - Endpoint Defend
- Malicious File - Detected - Elastic Defend
- Malicious File - Prevented - Elastic Defend
- Memory Signature - Detected - Elastic Defend
- Memory Signature - Prevented - Elastic Defend
- Ransomware - Detected - Elastic Defend
- Ransomware - Prevented - Elastic Defend
If you choose to use the feature-specific protection rules, we recommend that you disable the Endpoint Security rule, as using both will result in duplicate alerts.
To use these rules, you need to manually enable them from the Rules page in the Elastic Security app. Follow the instructions for installing and enabling Elastic prebuilt rules.
Endpoint security exception handling
editAll endpoint protection rules share a common exception list called the Endpoint Security Exception List. This ensures that if you switch between using the Endpoint Security rule and the feature-specific protection rules, your existing Elastic Endpoint exceptions continue to apply.