Conversation
23e0fe4 to
1db8012
Compare
Co-authored-by: Cursor <cursoragent@cursor.com>
1db8012 to
9ac2456
Compare
Adds process.Ext.process_vm_access.target_start_time_ns so a target named by PID can be told apart from an unrelated process that later reuses that PID. target_pid's description now records that the kernel resolves it, so it is a host PID even when the caller runs in a PID namespace and is therefore comparable to process.pid. Also adds short descriptions for target_pid and bytes_transferred, whose descriptions exceed the 120-character single-line limit. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Superseded by #800. The redesign keeps the hybrid architecture (syscall result + |
Summary
Add ECS mappings for Linux
process_vm_accessevents so Defend documents can carrycross-process memory access details from
process_vm_readv/process_vm_writev.Fields sit under
process.Ext.process_vm_access.*next to other Linux process telemetry.Issue: https://github.com/elastic/endpoint-dev/issues/21204
event.action: process_vm_accesstarget_pid,target_start_time_ns,remote_addr, byte counts and ioveccounts (
long);operation(keyword)target_pidis resolved by the kernel from the pid passed to the call, so it is a hostPID even when the caller runs in a PID namespace and is directly comparable to
process.pid.target_start_time_nspairs with it so a target cannot be confused withan unrelated process that later reuses the same PID.
bytes_transferredpreserves the raw syscall return value, including negative errnovalues for failed attempts
make clean && make all; only the threeprocess.Ext.process_vm_access.*fields moveProof
20260910T102925Z-process-vm-access(Endpoint 9.4.2),accepted build
endpoint-9.4.2-aba0979dc8d75bb920260910T114814Z-process-vm-access-volumeon that build(PASS, 1h) — 0
process_vm_accessdocuments against 91,643 documents/hourevent.action=process_vm_accesswith operation, targetidentity and byte fields
Supersedes the evidence quoted in earlier revisions of this PR: the quark side was
redesigned to resolve the target at
mm_accessrather than from the namespace-relativesyscall argument, and all three gates were rerun against that design.
Companion PRs