Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[Elastic Defend] Add
windows.ransomware.dump_process
for endpoint a…
…dvanced policy setting (#212439) ## Summary This PR exposes `windows.ransomware.dump_process` as an advanced policy option for Elastic Defend. If enabled, this option will make the endpoint generate a memory dump of the ransomware process before killing it, assisting the ransomware investigation process. ### Checklist Check the PR satisfies following conditions. Reviewers should verify this PR satisfies this list as well. - [x] Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md) --------- Co-authored-by: kibanamachine <42973632+kibanamachine@users.noreply.github.com> (cherry picked from commit e9813b8)
- Loading branch information