Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Fleet/Agent docs for Agent tamper protection (Elastic Defend) #674

Conversation

joepeeples
Copy link
Contributor

@joepeeples joepeeples commented Nov 9, 2023

Contributes to elastic/security-docs#3183 by updating the Fleet & Elastic Agent guide with some notes and links regarding Elastic Defend's Agent tamper protection feature, which is configured and accessed via Agent policy and Fleet UI. Links to Elastic Security docs created via elastic/security-docs#4232.

Previews:

@joepeeples joepeeples self-assigned this Nov 9, 2023

This comment was marked as resolved.

@joepeeples joepeeples changed the title Agent tamper protection for Elastic Defend Update Fleet/Agent docs for Agent tamper protection (Elastic Defend) Nov 9, 2023
@joepeeples joepeeples marked this pull request as ready for review November 13, 2023 20:49
Copy link
Contributor

@pierrehilbert pierrehilbert left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thx for this.
cc @amolnater-qasource as you had questions about it.

Copy link
Contributor

@kilfoyle kilfoyle left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks a lot @joepeeples

@kilfoyle
Copy link
Contributor

Joe, do you think it would make sense to also add an entry in this list, just to mention that tamper protection as another benefit?

https://www.elastic.co/guide/en/fleet/current/agent-policy.html#policy-benefits

Screenshot 2023-11-14 at 9 56 02 AM

@joepeeples
Copy link
Contributor Author

Joe, do you think it would make sense to also add an entry in this list, just to mention that tamper protection as another benefit?

@kilfoyle I'm thinking no, because tamper protection is only supported for a subset of Agent use cases (only Elastic Defend). If it could be enabled on all Agent policies, it'd probably be worth mentioning, but it doesn't sound like there's any plan for wider support outside of Elastic Defend.

@kilfoyle
Copy link
Contributor

kilfoyle commented Nov 14, 2023

@kilfoyle I'm thinking no, because tamper protection is only supported for a subset of Agent use cases (only Elastic Defend). If it could be enabled on all Agent policies, it'd probably be worth mentioning, but it doesn't sound like there's any plan for wider support outside of Elastic Defend.

Sounds good! I agree with your reasoning. Thanks Joe!

@joepeeples joepeeples merged commit 91ab5ed into elastic:main Nov 14, 2023
3 checks passed
mergify bot pushed a commit that referenced this pull request Nov 14, 2023
…674)

* Add note about uninstall tokens in command

* Include "Uninstall tokens" tab in Fleet UI list

* Add links, comment out for now

* Update links to published Security docs URLs

* Edit link anchor text

(cherry picked from commit 91ab5ed)
@joepeeples joepeeples deleted the uninstall-agent-tamper-protection-defend-jbp branch November 14, 2023 16:43
joepeeples added a commit that referenced this pull request Nov 14, 2023
…674) (#680)

* Add note about uninstall tokens in command

* Include "Uninstall tokens" tab in Fleet UI list

* Add links, comment out for now

* Update links to published Security docs URLs

* Edit link anchor text

(cherry picked from commit 91ab5ed)

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants