Hey everyone, I'm relatively new to the Elastic ecosystem, coming from a marketing ops background where my security exposure is mostly around securing our customer data and email platforms. This new CVE-2024-***** has our IT team on high alert, and they've asked my team to review any potential exposure in our marketing systems.
Since we recently rolled out Elastic Endpoint across the company, I'm trying to understand its real-world effectiveness. The vendor blog post says coverage is in place, but I'd love to hear from anyone who has actually validated this. Did you have to push a specific detection rule update, or was it blocked by a default behavioral rule? More importantly, were there any gaps in coverage for certain attack vectors that you had to supplement?
I'm particularly curious about the reporting side of things. If Endpoint did block an attack attempt, how clear was the alert in the SIEM? Could you easily trace it back to a user or endpoint? We need to provide assurance to our compliance folks that we can not only prevent but also document these incidents. Any screenshots or example event logs you could describe would be super helpful.