A new field EDR agent ID
was added in Assets of type Host
.
The absence of EDR agent ID
in Assets prevented easy configuration of playbooks for EDR targeted actions.
A new asset discovery rule will now populate the IDs of all EDR agent availables on a host to facilitate containment actions.
Technical detail
The EDR agent ID
field is automatically populated from agent.id
and agent.type
ECS fields collected in events.