Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

File Access Authorization Event Upload #157

Open
ltk opened this issue Dec 3, 2024 · 1 comment
Open

File Access Authorization Event Upload #157

ltk opened this issue Dec 3, 2024 · 1 comment
Labels
enhancement New feature or request
Milestone

Comments

@ltk
Copy link

ltk commented Dec 3, 2024

Is there any current support for uploading FAA events to a sync server? (I've been playing around with this for a bit, and my impression is no.)

Centrally storing/consuming execution event data is very straightforward with the /eventupload endpoint and we'd love to use something similar for FAA events.

@mlw
Copy link
Contributor

mlw commented Dec 4, 2024

This is not currently supported but something we've thought a bit about. We'd like to be able to begin support FAA rule management via the sync protocol, and having some way to generate events to allow exception flows for users via the sync protocol would be a natural extension.

A quick side note worth mentioning - you may be familiar already, but want to state here for posterity: while consuming execution events received via the sync protocol can provide some understanding about the breadth of executables in use throughout a fleet, these are not meant to be considered "telemetry". They are not 1-to-1 for all executions on a host (e.g. multiple cache layers can bypass a previously evaluated binary's execution from being sent during a sync) and they only contain a subset of the overall wealth of enriched data stored in logs. If the goal is to glean useful security information from executions on the fleet, the telemetry logs are the source of truth.

@pmarkowsky pmarkowsky added the enhancement New feature or request label Dec 4, 2024
@pmarkowsky pmarkowsky added this to the 2025.3 milestone Jan 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants