13.3 Elastic Defend Administration & Endpoint Policy Controls
Key Takeaways
Elastic Defend runs inside Elastic Agent and is configured through Fleet integration policies, with malware, ransomware (Windows), memory threat and malicious behavior protections set to Detect or Prevent.
Trusted applications stop Elastic Endpoint from monitoring a process at all, an intentional blind spot meant for conflicting security software.
Endpoint alert exceptions suppress alerts and preventions for a verified false positive while Defend keeps monitoring everything else.
Event filters keep matching events out of Elasticsearch to save storage, but Elastic Endpoint still analyzes those events for threats.
Host isolation (Platinum or higher) blocks a host from talking to other hosts while it still sends data to Elasticsearch and Kibana, and host isolation exceptions allow specific IPs.
Endpoint security represents both the frontline defense and the highest-volume telemetry source in modern enterprise security architectures. The Elastic Defend integration (formerly Endpoint Security) combines kernel-level behavioral monitoring, signatureless machine learning, anti-ransomware defenses, and real-time containment into the unified Elastic Agent. Administering Elastic Defend requires balancing aggressive threat prevention against operational stability: tuning out benign high-volume events, whitelisting proprietary enterprise software, generating diagnostic bundles during operational anomalies, and executing emergency host isolation during active breaches.
1. Elastic Defend Architecture & Fleet Policy Orchestration
Unlike legacy endpoint architectures that rely on separate standalone agents for EDR, log forwarding, and osquery, Elastic Defend operates as an integrated extension of the Unified Elastic Agent:
- Fleet Control Plane: Defend configurations are managed entirely through Fleet Agent Policies in Kibana. When an administrator modifies a Defend integration policy (e.g., toggling Ransomware protection from Detect to Prevent), Fleet Server delivers the updated policy to enrolled agents over their outbound HTTPS check-in connection (port 8220 by default).
- User-Space & Kernel Architecture: Elastic Defend consists of an endpoint daemon running in user-space coupled with platform-specific kernel drivers:
- Windows: A kernel driver that receives process, file, network and registry events.
- macOS: Apple's Endpoint Security framework through a system extension (which needs Full Disk Access).
- Linux: Kernel instrumentation such as eBPF (with a tracefs fallback on older kernels) and
fanotifyfor file scanning.
2. Protection Engines and Operating Modes
Elastic Defend's policy has four primary protections (plus attack surface reduction settings such as credential hardening on Windows). Each can be independently set to Detect or Prevent (or turned off). Ransomware protection applies to Windows, and the presets other than Data Collection turn on all preventions by default:
+-------------------------------------------------------------------------+
| Elastic Defend Integration |
+--------------------+--------------------+-------------------------------+|
| Protection Engine | Operating Mode | Primary SecOps Detection Scope |
+--------------------+--------------------+-------------------------------+|
| Malware Protection | Detect / Prevent | Malicious binaries, DLLs via signatures and ML |
| Ransomware Protect | Detect / Prevent | Mass encryption, canary tampering, VSS purge |
| Memory Threat Prot | Detect / Prevent | Shellcode, reflective DLLs, process hollowing |
| Malicious Behavior | Detect / Prevent | LOLBAS abuse, suspicious process trees, LSASS |
+--------------------+--------------------+-------------------------------+|
Operating Modes: Detect vs. Prevent
- Detect Mode: When an engine detects a threat, it generates a security alert, records full event metadata (process ancestry, hashes, command lines), and transmits the telemetry to Elasticsearch. However, the offending process is permitted to continue execution. Detect mode is critical during initial baselining or when rolling out policies to mission-critical servers, allowing engineers to verify that line-of-business applications are not disrupted.
- Prevent Mode: When a threat is detected, Defend blocks it, for example by stopping the offending process or preventing the malicious file from running, and publishes an alert documenting the prevention action.
Detailed Engine Capabilities
- Malware Protection: Scans executables, dynamic libraries, and scripts upon creation, modification, or execution. Uses a local signature engine combined with on-device machine learning models to detect known and novel malware variants.
- Ransomware Protection: Monitors file system activity for behavioral patterns characteristic of ransomware, including rapid file encryption velocities, modification of high-entropy files, tampering with canary files placed in sensitive directories, and execution of volume shadow copy deletion commands (
vssadmin.exe delete shadows /all /quiet). - Memory Threat Protection: Defends against advanced in-memory exploitation techniques that bypass disk-based scanners. Detects shellcode injection, process hollowing, reflective DLL loading, thread execution hijacking, and asynchronous procedure call (APC) injection.
- Malicious Behavior Protection: Analyzes live process behaviors targeting living-off-the-land binaries (LOLBAS). Detects suspicious child process relationships (e.g.,
word.exespawningpowershell.exewith base64 encoded parameters) and attempts to dump credentials from the Local Security Authority Subsystem Service (lsass.exe).
3. Diagnostic Bundles & Endpoint Troubleshooting
When an Elastic Agent exhibits communication issues, high resource consumption, or driver conflicts with third-party software, engineers must collect forensic diagnostic data without manual SSH or RDP sessions.
Generating Diagnostic Bundles via Fleet
- In Kibana, open Fleet → Agents.
- Locate the affected host, click the Actions menu (
...), and select Request diagnostics .zip. - Fleet Server dispatches an instruction to the endpoint. The agent collects:
- Active configuration JSON files (
elastic-agent.yml, policy snapshots). - Agent daemon logs (
elastic-agent.log) and Defend service logs (endpoint-security.log). - Driver operational states, kernel extension statuses, and crash dump files.
- System resource utilization metrics (CPU, memory, handle counts) and network socket tables.
- Active configuration JSON files (
- The endpoint compresses the diagnostic payload into a zip or tar archive and streams it back through Fleet Server. The administrator can download the bundle directly from the Kibana interface for analysis.
4. Policy Tuning: Endpoint Artifacts and Exceptions
Elastic's Optimize Elastic Defend guidance separates four tools. Choosing the wrong one either leaves noise or creates a blind spot.
Trusted Applications
- Purpose: Resolve conflicts and performance problems with other software, usually other antivirus or endpoint security products.
- Effect: Elastic Endpoint stops monitoring the process for threats and generates no events for it, except process events used internally for visualizations. This is an intentional blind spot: attackers can abuse trusted processes, for example through DLL side-loading. Use trusted applications sparingly.
- Matching: One field type per entry: hash (MD5, SHA-1 or SHA-256), full path (wildcards allowed with matches), or, on Windows, the signer name. Entries apply globally or, with Platinum or higher, to specific Elastic Defend policies.
Endpoint Alert Exceptions
- Purpose: Stop false-positive alerts and preventions for a specific, verified behavior.
- Effect: Elastic Endpoint does not generate the alert or stop the process when the exception matches. It keeps monitoring everything else, and checks exceptions early, which can also save CPU. Add one from an Endpoint alert with Take action → Add Endpoint exception.
Event Filters
- Purpose: Reduce storage by keeping noisy, benign event documents out of Elasticsearch.
- Effect: Matching events are not written to Elasticsearch, but Elastic Endpoint still monitors them for threats. Event filters do not lower CPU use on the endpoint.
Blocklist
- Purpose: Extend protection by preventing known-bad applications (by hash, path or signer) from running.
- Effect: Not intended for blocking benign software for non-security reasons.
(Host isolation exceptions are a fifth artifact type. They list IP addresses that isolated hosts may still reach.)
5. Host Isolation Mechanics & Emergency Network Containment
During an active incident, such as an adversary running a reverse shell or lateral movement tools, responders must contain the host without losing visibility.
+-------------------------------------------------------------------------+
| Host Isolation Engaged |
+-------------------------------------------------------------------------+
| Attacker C2 traffic -----> [ BLOCKED ] |
| Lateral SMB / RDP to peers -----> [ BLOCKED ] |
| Internal subnet scans -----> [ BLOCKED ] |
| |
| Data to Elasticsearch/Kibana <====> [ ALLOWED - telemetry continues ] |
| Host isolation exception IPs <====> [ ALLOWED - e.g. VPN or DNS host ] |
+-------------------------------------------------------------------------+
Mechanism of Host Isolation
When an analyst chooses Isolate host from the alert details flyout, the Endpoints page, or the response console (isolate, Enterprise):
- Requirements: Host isolation needs a Platinum or Enterprise subscription and the Host Isolation privilege. It is supported on Windows, macOS and supported Linux distributions running Elastic Defend.
- Network Blocking: The endpoint is blocked from communicating with other hosts on the network, which cuts C2 channels and stops lateral spread.
- Preserved Visibility: Isolated hosts can still send data to Elasticsearch and Kibana, so responders keep receiving telemetry and can continue response actions.
- Exceptions: Host isolation exceptions list specific IP addresses that isolated hosts may still reach, for example a VPN concentrator or a DNS server.
- Release: When remediation is finished, responders choose Release host. Every isolate and release action is recorded in the host's response actions history, and an Isolated status appears next to the agent status.
6. Comprehensive Tuning Artifact Comparison
| Tool | What It Changes | Protection | Events in Elasticsearch | Typical Use |
|---|---|---|---|---|
| Trusted application | Elastic Endpoint stops monitoring the process | None for that process (intentional blind spot) | Only internal process events | Another antivirus or EDR product that conflicts with Defend |
| Endpoint alert exception | Suppresses alerts and preventions for a matching behavior | Still active for everything else | Unchanged | A verified false positive, such as an in-house app blocked by malicious behavior protection |
| Event filter | Keeps matching events out of Elasticsearch | Unchanged: events are still analyzed | Not stored | High-volume benign activity, such as backup software file reads |
| Blocklist | Prevents specified applications from running | Extended | Unchanged | Known malware not yet caught by other protections |
| Host isolation exception | Allows specific IPs while a host is isolated | Not applicable | Unchanged | Keeping a VPN or DNS server reachable during isolation |
An enterprise backup utility running nightly on database servers generates over 45 million file-read events per hour, saturating the Hot tier indexing queue and consuming unnecessary cluster disk space. The SOC engineer wants to prevent the backup utility from streaming file-access telemetry to Elasticsearch, but must guarantee that the backup executable remains actively monitored by Defend for malicious process injection or tampering. Which tuning control should be configured?
Configure an Event Filter matching the backup utility's process path and file event category to discard telemetry at the kernel driver layer.
Add the backup utility binary to the Trusted Applications list using its SHA-256 hash.
Switch the Elastic Defend integration policy from Prevent mode to Detect mode across all database servers.
Configure Document-Level Security (DLS) on the database servers to drop incoming file telemetry.
During an investigation of an active compromise, an incident responder triggers 'Isolate host' from the Elastic Security alert details flyout on an infected Windows laptop. Which network communication behavior occurs on the endpoint following isolation?
All physical and wireless network interface controllers are disabled in the operating system device manager.
All inbound network traffic is blocked, but outbound network traffic remains open so the endpoint can download operating system patches.
The endpoint is blocked from communicating with other hosts on the network, but it can still send data to Elasticsearch and Kibana and reach any IP addresses configured as host isolation exceptions.
All network traffic is throttled to 10 Kbps while a forensic memory dump is transmitted via TFTP to the SOC.
A proprietary in-house transaction processing engine is repeatedly terminated upon startup by Elastic Defend, with alerts citing 'Malicious Behavior Protection: Suspicious Memory Modification'. Security engineers confirm that this is a benign false positive resulting from the application's proprietary memory management routine. Which action resolves this issue permanently without weakening the organization's overall threat posture?
Disable the Malicious Behavior Protection engine across the enterprise by switching its operating mode to Detect.
Add an Endpoint alert exception (from the alert's Take action menu) scoped to the application's hash or signer and the behavior that fired, so Defend stops alerting on and blocking that verified behavior.
Add the application to the Trusted Applications list so Elastic Endpoint stops monitoring the process entirely.
Assign the transaction server to a separate Kibana Space where detection rules are disabled.
Sections you finish are checked off in the contents.