Skip to content

[LotL] Update problemchild inference pipeline and remove support for endgame - #21511

Draft
sodhikirti07 wants to merge 4 commits into
mainfrom
problemchild_model_update
Draft

sodhikirti07 wants to merge 4 commits into
mainfrom
problemchild_model_update

Conversation

@sodhikirti07

Copy link
Copy Markdown
Contributor

Proposed commit message

Update problemchild inference pipeline to add new features and remove support for endgame and blocklist label

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Author's Checklist

  • Update changelog.yml and manifest.yml
  • Update inference pipeline to add new features and remove support for endgame and blocklist label
  • Add updated model based on the new features (model was trained on same data, the difference is in the features not input data)
  • Update ML jobs to include high probability malicious predictions

How to test this PR locally

  • ITP

Related issues

Screenshots

@sodhikirti07 sodhikirti07 added documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:problemchild Living off the Land Attack Detection labels Sep 21, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

History

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Security-ML Integrations Test Pipeline — Integrations CI (run #3)

🟢 All packages passed

Package Stack version Result
problemchild unknown 🟢

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:problemchild Living off the Land Attack Detection

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant