Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Request] Crowdstrike additional third-party response actions #6365

Open
raqueltabuyo opened this issue Dec 18, 2024 · 4 comments
Open

[Request] Crowdstrike additional third-party response actions #6365

raqueltabuyo opened this issue Dec 18, 2024 · 4 comments
Assignees
Labels
Docset: ESS Issues that apply to docs in the Stack release Docset: Serverless Issues for Serverless Security Effort: Medium Issues that take moderate but not substantial time to complete Priority: Medium Issues that have relevance, but aren't urgent Team: EDR Workflows Formerly Defend Workflows, Onboarding and Lifecycle Management v8.18.0

Comments

@raqueltabuyo
Copy link

raqueltabuyo commented Dec 18, 2024

What can we change to make the docs better?

Description
We are adding new third-party actions to Crowdstrike response actions, which will allow users to execute remote commands using Crowdstrike agent through Elastic Security.

This is similar to the functionality (and docs) we previously added for Sentinel One and Crowdstrike: https://www.elastic.co/guide/en/security/current/third-party-actions.html

Background & resources
PRs:

Issues/metas: https://github.com/elastic/security-team/issues/10873
Point of contact: @caitlinbetz @tomsonpl @raqueltabuyo @ashokaditya @paul-tavares
Test environments:

Doc URL

This is similar to the functionality (and docs) we previously added for Sentinel One and Crowdstrike: https://www.elastic.co/guide/en/security/current/third-party-actions.html
Github issue link(s)/Other resources:
https://github.com/elastic/security-team/issues/10873

Which documentation set needs improvement?

ESS and serverless

Software version

ESS release
8.18

Serverless release
Monday January 20

Feature differences
Feature will be the same in serverless/ESS

ESS release: 8.18

API docs impact
TBD

Prerequisites, privileges, feature flags
ESS & Serverless, Kibana privileges:

Security solution privilege: TBD

Actions and Connectors privilege:: EDR Connectors

@raqueltabuyo raqueltabuyo added the suggestion Suggestions to improve documentation label Dec 18, 2024
@natasha-moore-elastic natasha-moore-elastic self-assigned this Dec 18, 2024
@natasha-moore-elastic natasha-moore-elastic added Team: EDR Workflows Formerly Defend Workflows, Onboarding and Lifecycle Management Priority: Medium Issues that have relevance, but aren't urgent Effort: Medium Issues that take moderate but not substantial time to complete Docset: Serverless Issues for Serverless Security Docset: ESS Issues that apply to docs in the Stack release v8.18.0 and removed suggestion Suggestions to improve documentation labels Dec 18, 2024
@tomsonpl
Copy link

tomsonpl commented Jan 8, 2025

@natasha-moore-elastic Hey 👋
I tried to leave as much details as possible in the PRs' description, but please reach out if there's something you'd like to talk about :)

@natasha-moore-elastic
Copy link
Contributor

natasha-moore-elastic commented Jan 8, 2025

Hi @tomsonpl! I have a few questions to start with:

@tomsonpl
Copy link

tomsonpl commented Jan 9, 2025

Hey 👋

  1. I am working on the env as of this moment and will send you the details asap 👍 However, it's not gonna be fully operational since I can't share credentials to access CrowdStrike (needed to return successful results)
  2. No, just runscript this time :)
  3. I don't think we need to mention sub-actions at all, it's an internal detail.
  4. You're right, it's a public API. It wasn't included in OAS docs by coincidence. I am working on the fix [EDR Workflows] Add Runscript openApi schema  kibana#206044 so it will be included 👍

@tomsonpl
Copy link

Ok, I prepared both cloud and serverless environments, details below:
https://p.elstc.co/paste/267wQ-uV#1cF9ukTQ9jb8zXQQQsYd4mEviL3xtTxMJUXO1PihePm

In order to see CrowdStrike alert, please go to Security Alerts and change lookup time for 1 year (it's a pretty old alert). There will be just one created. Then use respond take action button to open Response Console.

Unfortunately we are limited with CrowdStrike access so the functionality will always return error, but you should be able to see the UI and --help.

If you'd prefer to have some Success results, I can arrange that (I'll provide screenshots).

Sorry for the inconvenience, and thanks for the help, hope this is enough :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Docset: ESS Issues that apply to docs in the Stack release Docset: Serverless Issues for Serverless Security Effort: Medium Issues that take moderate but not substantial time to complete Priority: Medium Issues that have relevance, but aren't urgent Team: EDR Workflows Formerly Defend Workflows, Onboarding and Lifecycle Management v8.18.0
Projects
None yet
Development

No branches or pull requests

3 participants