Hello WithSecure Community,
I would like to ask about the behavior of the email notifications generated by WithSecure Elements Endpoint Protection.
Currently, we receive emails like the attached example. The notification indicates that an event was detected and provides the report name, organization, time period, and number of events. However, it does not include the details of the actual event, such as:
- Affected device/hostname
- Detection name
- Detection time
- Action taken (Blocked, Quarantined, etc.)
- Infected or detected object
- File path/location
- SHA1 or other relevant information
For example, the email only indicates that 1 event was detected and provides a "Go to Portal" button.
From a cybersecurity monitoring perspective, I believe it would be much more useful if the alert email included the event details directly, or if the system could automatically attach a CSV or PDF report containing the information at the moment the alert is generated.
The current behavior requires the analyst to log in to the portal to determine which device generated the alert and what was detected. If the analyst does not have an active session or immediate access to the portal, the email notification alone does not provide enough information to identify and respond to the incident.
My questions are:
- Is there a way to configure these email notifications to include the complete event details?
- Is it possible to automatically attach a CSV or PDF report containing the detected event?
- Is there another recommended configuration or reporting mechanism for receiving real-time alerts with the affected device and detection details?
We currently use these notifications as part of our security monitoring process, so having the relevant event information directly in the email would significantly improve our response time.
Thank you for any guidance or recommendations.