Skip to content

Commit 2ebb985

Browse files
[Security] Adds links for endpoint protection rules (#2620)
Contributes to elastic/security-docs#6182 by adding links from the Endpoint protection rules page to the prebuilt rule docs for those rules. Preview: [Endpoint protection rules](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/2620/solutions/security/manage-elastic-defend/endpoint-protection-rules)
1 parent 419a3ec commit 2ebb985

File tree

1 file changed

+13
-13
lines changed

1 file changed

+13
-13
lines changed

solutions/security/manage-elastic-defend/endpoint-protection-rules.md

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ products:
1313

1414
# Endpoint protection rules [endpoint-protection-rules]
1515

16-
Endpoint protection rules are [prebuilt rules](../detect-and-alert/install-manage-elastic-prebuilt-rules.md) designed to help you manage and respond to alerts generated by {{elastic-endpoint}}, the installed component that performs {{elastic-defend}}'s threat monitoring and prevention. These rules include the Endpoint Security rule as well as additional detection and prevention rules for different {{elastic-defend}} protection features.
16+
Endpoint protection rules are [prebuilt rules](../detect-and-alert/install-manage-elastic-prebuilt-rules.md) designed to help you manage and respond to alerts generated by {{elastic-endpoint}}, the installed component that performs {{elastic-defend}}'s threat monitoring and prevention. These rules include the Endpoint Security ({{elastic-defend}}) rule as well as additional detection and prevention rules for different {{elastic-defend}} protection features.
1717

1818
::::{important}
1919
To receive {{elastic-endpoint}} alerts, you must install {{agent}} and the {{elastic-defend}} integration on your hosts (refer to [Install {{elastic-defend}}](../configure-elastic-defend/install-elastic-defend.md)).
@@ -28,10 +28,10 @@ When endpoint protection rules are triggered, {{elastic-endpoint}} alerts are di
2828

2929
## Endpoint Security rule [endpoint-sec-rule]
3030

31-
The Endpoint Security rule automatically creates an alert from all incoming {{elastic-endpoint}} alerts.
31+
The [Endpoint Security ({{elastic-defend}})](detection-rules://rules/integrations/endpoint/elastic_endpoint_security.md) rule automatically creates an alert from all incoming {{elastic-endpoint}} alerts.
3232

3333
::::{note}
34-
When you install Elastic prebuilt rules, the {{elastic-defend}} is enabled by default.
34+
When you install Elastic prebuilt rules, the Endpoint Security ({{elastic-defend}}) rule is enabled by default.
3535
::::
3636

3737

@@ -40,17 +40,17 @@ When you install Elastic prebuilt rules, the {{elastic-defend}} is enabled by de
4040

4141
The following endpoint protection rules give you more granular control over how you handle the generated alerts. These rules are tailored for each of {{elastic-defend}}'s endpoint protection features—malware, ransomware, memory threats, and malicious behavior. Enabling these rules allows you to configure more specific actions based on the protection feature and whether the malicious activity was prevented or detected.
4242

43-
* Behavior - Detected - {{elastic-defend}}
44-
* Behavior - Prevented - {{elastic-defend}}
45-
* Malicious File - Detected - {{elastic-defend}}
46-
* Malicious File - Prevented - {{elastic-defend}}
47-
* Memory Signature - Detected - {{elastic-defend}}
48-
* Memory Signature - Prevented - {{elastic-defend}}
49-
* Ransomware - Detected - {{elastic-defend}}
50-
* Ransomware - Prevented - {{elastic-defend}}
43+
* [Behavior - Detected - {{elastic-defend}}](detection-rules://rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.md)
44+
* [Behavior - Prevented - {{elastic-defend}}](detection-rules://rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.md)
45+
* [Malicious File - Detected - {{elastic-defend}}](detection-rules://rules/integrations/endpoint/execution_elastic_malicious_file_detected.md)
46+
* [Malicious File - Prevented - {{elastic-defend}}](detection-rules://rules/integrations/endpoint/execution_elastic_malicious_file_prevented.md)
47+
* [Memory Threat - Detected - {{elastic-defend}}](detection-rules://rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.md)
48+
* [Memory Threat - Prevented - {{elastic-defend}}](detection-rules://rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.md)
49+
* [Ransomware - Detected - {{elastic-defend}}](detection-rules://rules/integrations/endpoint/impact_elastic_ransomware_detected.md)
50+
* [Ransomware - Prevented - {{elastic-defend}}](detection-rules://rules/integrations/endpoint/impact_elastic_ransomware_prevented.md)
5151

5252
::::{note}
53-
If you choose to use the feature-specific protection rules, we recommend that you disable the Endpoint Security rule, as using both will result in duplicate alerts.
53+
If you choose to use the feature-specific protection rules, we recommend that you disable the Endpoint Security ({{elastic-defend}}) rule, as using both will result in duplicate alerts.
5454
::::
5555

5656

@@ -59,4 +59,4 @@ To use these rules, you need to manually enable them from the **Rules** page in
5959

6060
## Endpoint security exception handling [_endpoint_security_exception_handling]
6161

62-
All endpoint protection rules share a common exception list called the Endpoint Security Exception List. This ensures that if you switch between using the Endpoint Security rule and the feature-specific protection rules, your existing [{{elastic-endpoint}} exceptions](../detect-and-alert/add-manage-exceptions.md#endpoint-rule-exceptions) continue to apply.
62+
All endpoint protection rules share a common exception list called the Endpoint Security Exception List. This ensures that if you switch between using the Endpoint Security ({{elastic-defend}}) rule and the feature-specific protection rules, your existing [{{elastic-endpoint}} exceptions](../detect-and-alert/add-manage-exceptions.md#endpoint-rule-exceptions) continue to apply.

0 commit comments

Comments
 (0)