Skip to content

Comments

[Security] 9.3.1 release notes#5218

Open
natasha-moore-elastic wants to merge 1 commit intomainfrom
sec-rn-9.3.1
Open

[Security] 9.3.1 release notes#5218
natasha-moore-elastic wants to merge 1 commit intomainfrom
sec-rn-9.3.1

Conversation

@natasha-moore-elastic
Copy link
Contributor

@natasha-moore-elastic natasha-moore-elastic commented Feb 19, 2026

Summary

Resolves #5101: adds the 9.3.1 Security and Endpoint release notes.

Generative AI disclosure

  1. Did you use a generative AI (GenAI) tool to assist in creating this contribution?
  • Yes
  • No

Tool(s) and model(s) used:
Cursor, claude-4.5-opus-high

@natasha-moore-elastic natasha-moore-elastic self-assigned this Feb 19, 2026
@github-actions
Copy link
Contributor

✅ Vale Linting Results

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide.

To use Vale locally or report issues, refer to Elastic style guide for Vale.

@github-actions
Copy link
Contributor

🔍 Preview links for changed docs

Copy link

@hop-dev hop-dev left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Entity Analytics Changes LGTM

@jonwalstedt
Copy link

The notes for #250921, #251656, #251962 and #252263 looks good

Copy link
Contributor

@paul-tavares paul-tavares left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good 👍

* Adds a `region` field to the Amazon Bedrock connector [#252960]({{kib-pull}}252960), [#252956]({{kib-pull}}252956).
* Improves Automatic Migration performance by reducing the number of {{es}} calls when updating field mappings [#252431]({{kib-pull}}252431).
* Updates the `fast-xml-parser` package dependency to version 5.3.4 [#251644]({{kib-pull}}251644).
* Further reduces {{elastic-defend}} behavioral protection CPU usage for trusted applications.
Copy link
Contributor

@gabriellandau gabriellandau Feb 19, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This one landed in the final 9.3.0 BC.

Suggested change
* Further reduces {{elastic-defend}} behavioral protection CPU usage for trusted applications.

* Reduces {{elastic-defend}} CPU usage when suppressing activity from trusted applications on Windows. This might be especially noticeable in applications that are JIT-heavy like PowerShell and .NET.
* Improves {{elastic-defend}} visibility into image load events in mixed-architecture scenarios, such as during .NET library loading when the library and main executable might use different architectures. This only applies to Windows 10, version 1709 and later.
* Refactors {{elastic-defend}} Windows file scanning behavior to reduce the risk of file sharing conflicts with other applications and improve the reliability of malware-on-write and event enrichments that rely on file contents such as code signatures and imphashes.
* Improves the accuracy of thread CPU usage reported in {{elastic-defend}} metrics documents.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* Improves the accuracy of thread CPU usage reported in {{elastic-defend}} metrics documents.
* Further reduces {{elastic-defend}} behavioral protection CPU usage for trusted applications.

Copy link

@nikitaindik nikitaindik left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! 👍 Rule Management team owned updates LGTM.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security 9.3.1 release notes

6 participants