Skip to content

disable malware protection by default #632

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 4 commits into from
Apr 9, 2025

Conversation

aarz-snl
Copy link
Collaborator

@aarz-snl aarz-snl commented Mar 26, 2025

🗣 Description

#626

This disables malware protection by default from Elastic Defend. Users can then decide to turn on malware protections as needed.

This also added a quick comment to documentation on Windows integration to only use Metrics if absolutely required. This requires manual intervention... user MUST click to disable.

💭 Motivation and context

Elastic Defend and conflict with Windows Defender. This should be off by default since Defender is pretty common on all Windows Endpoints. Users can decide to use if wanted.

📷 Screenshots (DELETE IF UNAPPLICABLE)

🧪 Testing

Performed install, and in fleet verified that Malware protections were turned off by default.

Must verify that defender doesn't get disabled on a Windows machine

✅ Pre-approval checklist

  • Changes are limited to a single goal AND
    the title reflects this in a clear human readable format
  • Issue that this PR solves has been selected in the Development section
  • I have read and agree to LME's CONTRIBUTING.md document.
  • The PR adheres to LME's requirements in RELEASES.md
  • These code changes follow cisagov code standards.
  • All relevant repo and/or project documentation has been updated to reflect the changes in this PR.

✅ Pre-merge Checklist

  • All tests pass
  • PR has been tested and the documentation for testing is above
  • Squash and merge all commits into one PR level commit

✅ Post-merge Checklist

  • Delete the branch to keep down number of branches

@aarz-snl
Copy link
Collaborator Author

aarz-snl commented Mar 26, 2025

To confirm after install go to Fleet -> Agent policies

See Elastic Defend policy

Scroll down and ensure Malware is turned off -- need to test with a windows machine and ensure defender isn't turned off.

@tylmorr-snl tylmorr-snl requested a review from rishagg01 March 26, 2025 18:39
Copy link
Collaborator

@rishagg01 rishagg01 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ran cluster run on this PR. It Passed. PR is approved.

@tylmorr-snl
Copy link
Collaborator

Confirmed that this fix will stop defender from being disabled. Recommend that we merge with main.

@Roger-CISA Roger-CISA merged commit 4d74a19 into main Apr 9, 2025
4 checks passed
@github-project-automation github-project-automation bot moved this from 🆕 Product Backlog to ✅ Done in LME-Development Apr 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: ✅ Done
Development

Successfully merging this pull request may close these issues.

5 participants