You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/detections/detection-engine-intro.asciidoc
+1-45Lines changed: 1 addition & 45 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -84,52 +84,8 @@ In addition, the following support restrictions are in place:
84
84
<<detections-permissions-section>> provides detailed information on all the
85
85
permissions required to initiate and use the Detections feature.
86
86
87
-
[discrete]
88
-
[[malware-prevention]]
89
-
== Malware prevention
90
-
91
-
Malware, short for malicious software, is any software program designed to damage or execute unauthorized actions on a
92
-
computer system. Examples of malware include viruses, worms, Trojan horses, adware, scareware, and spyware. Some
93
-
malware, such as viruses, can severely damage a computer's hard drive by deleting files or directory information. Other
94
-
malware, such as spyware, can obtain user data without their knowledge.
95
-
96
-
Malware may be stealthy and appear as legitimate executable code, scripts, active content, and other software. It is also
97
-
often embedded in non-malicious files, non-suspicious websites, and standard programs — sometimes making the root
98
-
source difficult to identify. If infected and not resolved promptly, malware can cause irreparable damage to a computer
99
-
network.
100
-
101
-
For information on how to enable malware protection on your host, see <<malware-protection, Malware Protection>>.
102
-
103
-
[discrete]
104
-
[[machine-learning-model]]
105
-
=== Machine learning model
106
-
107
-
To determine if a file is malicious or benign, a machine learning model looks for static attributes of files (without executing
108
-
the file) that include file structure, layout, and content. This includes information such as file header data, imports, exports,
109
-
section names, and file size. These attributes are extracted from millions of benign and malicious file samples, which then
110
-
are passed to a machine-learning algorithm that distinguishes a benign file from a malicious one. The machine learning
111
-
model is updated as new data is procured and analyzed.
112
-
113
-
[discrete]
114
-
=== Threshold
115
-
116
-
A malware threshold determines the action the agent should take if malware is detected. The Elastic Agent uses a recommended threshold level that generates a balanced number of alerts with a low probability of undetected malware. This threshold also minimizes the number of false positive alerts.
117
-
118
-
[discrete]
119
-
[[ransomware-prevention]]
120
-
== Ransomware prevention
121
-
122
-
Ransomware is computer malware that installs discreetly on a user's computer and encrypts data until a specified amount of money (ransom) is paid. Ransomware is usually similar to other malware in its delivery and execution, infecting systems
123
-
through spear-phishing or drive-by downloads. If not resolved immediately, ransomware can cause irreparable damage to an entire computer network.
124
-
125
-
Behavioral ransomware prevention on the Elastic Endpoint detects and stops ransomware attacks on Windows systems by analyzing data from low-level system processes, and is effective across an array of widespread ransomware families — including those targeting the system’s master boot record.
126
-
127
-
For information on how to enable ransomware protection on your host, see <<ransomware-protection>>.
128
-
129
-
NOTE: Ransomware prevention is a paid feature and is enabled by default if you have a https://www.elastic.co/pricing[Platinum or Enterprise license].
130
-
131
87
[float]
132
-
=== Resolve UI error messages
88
+
== Resolve UI error messages
133
89
134
90
Depending on your privileges and whether detection system indices have already
135
91
been created for the {kib} space, you might get one of these error messages when you
0 commit comments