Skip to content

[Bug] Sensitive File Access - Cloud Credentials (only supports Windows) #19

@tstromberg

Description

@tstromberg

Describe the bug

The "Sensitive File Access - Cloud Credentials" rule only supports Windows. Could it please be ported to Linux and macOS?

To Reproduce

  1. View https://github.com/elastic/protections-artifacts/blob/main/behavior/rules/credential_access_sensitive_file_access_cloud_credentials.toml
  2. Notice that os_list = ["windows"]

Expected behavior

Support for Linux and macOS (our primary platforms)

Desktop (please complete the following information):

  • OS: macOS
  • Version: 14.4

Additional context

If it helps, we're new Defend customers, and credential theft is our #1 concern.

Metadata

Metadata

Labels

Area: RADbehaviorEndpoint behavior issuesbugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions