Skip to content

ssi_all: cel integrations do not properly guard against null #18788

Description

@efd6

The data streams below all have the pattern has(x.f) && size(x.f) != 0 or similar. This is used to guard against empty arrays. However, it does not guard against null in place of an empty array, and idiom that is reasonably common (an example of this caused a runtime failure in the aws.config data stream (ref).

The pattern is not always unsafe; it may be that the program sets the field to an array and so there is static proof that the test is always successful, or the API might document that the value is always an array. It might though just be simpler to always apply the fix (has(x.f) && x.f != null && size(x.f) != 0).

Integration Data stream File Lines
abnormal_security ai_security_mailbox cel.yml.hbs 28
abnormal_security ai_security_mailbox_not_analyzed cel.yml.hbs 51
abnormal_security audit cel.yml.hbs 60, 61
abnormal_security case cel.yml.hbs 27
abnormal_security threat cel.yml.hbs 29, 77
abnormal_security vendor_case cel.yml.hbs 28
airlock_digital agent cel.yml.hbs 44, 88
airlock_digital execution_histories cel.yml.hbs 58
airlock_digital server_activities cel.yml.hbs 54
armis alert cel.yml.hbs 92
armis device cel.yml.hbs 93
armis vulnerability cel.yml.hbs 73, 92, 140
auth0 logs cel.yml.hbs 117
bitsight vulnerability cel.yml.hbs 96, 129, 189, 250
cisco_duo auth cel.yml.hbs 97
cisco_duo telephony_v2 cel.yml.hbs 99, 112
cisco_duo trust_monitor cel.yml.hbs 95, 108
claroty_xdome alert cel.yml.hbs 26, 96, 128, 302
claroty_xdome event cel.yml.hbs 96
claroty_xdome vulnerability cel.yml.hbs 26, 109, 141, 317
cloudflare audit cel.yml.hbs (matched)
dataminr_pulse alerts stream.yml.hbs 140
github security_advisories cel.yml.hbs 65, 78
imperva_cloud_waf event cel.yml.hbs 26
m365_defender vulnerability cel.yml.hbs 123
microsoft_defender_endpoint vulnerability cel.yml.hbs 123
microsoft_sentinel alert cel.yml.hbs 31, 83
microsoft_sentinel incident cel.yml.hbs 50
mimecast archive_search_logs cel.yml.hbs 93
mimecast audit_events cel.yml.hbs 86
mimecast dlp_logs cel.yml.hbs 93
mimecast message_release_logs cel.yml.hbs (matched)
mimecast ttp_ap_logs cel.yml.hbs 93
mimecast ttp_ip_logs cel.yml.hbs 93
mimecast ttp_url_logs cel.yml.hbs 93
nozomi_networks alert cel.yml.hbs 52
nozomi_networks asset cel.yml.hbs 52
nozomi_networks audit cel.yml.hbs 52
nozomi_networks health cel.yml.hbs 52
nozomi_networks node cel.yml.hbs 52
nozomi_networks node_cve cel.yml.hbs 52
nozomi_networks session cel.yml.hbs 52
nozomi_networks variable cel.yml.hbs 52
proofpoint_itm report cel.yml.hbs 40, 43
qualys_vmdr asset_host_detection input.yml.hbs 36, 62, 180
sentinel_one application cel.yml.hbs 28, 79
sentinel_one threat_event cel.yml.hbs 28, 79
servicenow event cel.yml.hbs (matched)
snyk audit_logs cel.yml.hbs (matched)
sublime_security message_event cel.yml.hbs 27, 57
sysdig cspm cel.yml.hbs 38, 50
tenable_io scan cel.yml.hbs 28, 61
ti_flashpoint alert cel.yml.hbs 48, 58
ti_flashpoint indicator cel.yml.hbs (matched)
ti_flashpoint vulnerability cel.yml.hbs 47, 68, 85
ti_google_threat_intelligence cryptominer cel.yml.hbs 45
ti_google_threat_intelligence first_stage_delivery_vectors cel.yml.hbs 45
ti_google_threat_intelligence infostealer cel.yml.hbs 45
ti_google_threat_intelligence ioc_stream cel.yml.hbs 48
ti_google_threat_intelligence iot cel.yml.hbs 45
ti_google_threat_intelligence linux cel.yml.hbs 45
ti_google_threat_intelligence malicious_network_infrastructure cel.yml.hbs 45
ti_google_threat_intelligence malware cel.yml.hbs 45
ti_google_threat_intelligence mobile cel.yml.hbs 45
ti_google_threat_intelligence osx cel.yml.hbs 45
ti_google_threat_intelligence phishing cel.yml.hbs 45
ti_google_threat_intelligence ransomware cel.yml.hbs 45
ti_google_threat_intelligence threat_actor cel.yml.hbs 45
ti_google_threat_intelligence trending cel.yml.hbs 45
ti_google_threat_intelligence vulnerability_weaponization cel.yml.hbs 45
ti_greynoise ip cel.yml.hbs 43
ti_opencti indicator cel.yml.hbs (matched)
ti_recordedfuture playbook_alert cel.yml.hbs 30, 108
trend_micro_vision_one endpoint_activity cel.yml.hbs 60, 75
trend_micro_vision_one network_activity cel.yml.hbs 60, 75
vectra_rux audit cel.yml.hbs 47
vectra_rux detection_event cel.yml.hbs 47
vectra_rux entity_event cel.yml.hbs 49, 53

Activity

  1. added
    Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]
    Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]
    on May 4, 2026
  2. infra-vault-gh-plugin-prod commented on May 4, 2026

    @infra-vault-gh-plugin-prod

    Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

  3. github-actions commented on May 4, 2026

    @github-actions
    Contributor

    tl;dr: The strongest evidence points to a null-guard gap in the Proofpoint Essentials CEL stream for /v2/siem/all (packages/proofpoint_essentials/data_stream/threat/agent/stream/cel.yml.hbs), where response fields are dereferenced as arrays/timestamps without optional/null protection.

    Recommendation

    Update the proofpoint_essentials threat CEL program to treat nullable API fields as optional before mapping/parsing, then add/extend stream-level coverage for null response members. This is the most likely place matching the issue title (ssi_all appears to correspond to /v2/siem/all).

    Findings
    1. Unguarded nullable field access in CEL stream

      • packages/proofpoint_essentials/data_stream/threat/agent/stream/cel.yml.hbs:75-78 maps directly over:
        • body.clicksBlocked
        • body.clicksPermitted
        • body.messagesBlocked
        • body.messagesDelivered
      • packages/proofpoint_essentials/data_stream/threat/agent/stream/cel.yml.hbs:82,84 parses body.queryEndTime directly.
    2. No local ssi_all symbol in repo; endpoint match is /v2/siem/all

      • git grep -i "ssi_all" -- packages returned no matches.
      • packages/proofpoint_essentials/docs/README.md:10,14 explicitly documents /v2/siem/all as the threat source endpoint.
    3. Established safe pattern elsewhere in CEL streams

      • Example guarded mapping pattern: packages/microsoft_sentinel/data_stream/incident/agent/stream/cel.yml.hbs:46
        • body.?value.orValue([]).map(...)
      • This pattern avoids null dereference on optional arrays.
    4. Parallel investigation outcome (Pick Three, Keep One)

      • 3 sub-agents ran with distinct angles.
      • Selected winner: Proofpoint /v2/siem/all stream finding above (best evidence + issue-title alignment).
      • Other candidates were lower-confidence or broader (noop / unrelated stream).
    Verification

    I validated with local commands:

    $ git --no-pager grep -n -i "ssi_all" -- packages
    # (no matches)
    
    $ nl -ba packages/proofpoint_essentials/data_stream/threat/agent/stream/cel.yml.hbs | sed -n '67,86p'
    67  ... "/v2/siem/all?..."
    75  body.clicksBlocked.map(...)
    76  body.clicksPermitted.map(...)
    77  body.messagesBlocked.map(...)
    78  body.messagesDelivered.map(...)
    82  ... body.queryEndTime.parse_time(...)
    84  ... body.queryEndTime.parse_time(...)
    
    $ nl -ba packages/microsoft_sentinel/data_stream/incident/agent/stream/cel.yml.hbs | sed -n '45,48p'
    46  "events": body.?value.orValue([]).map(e, {
    Detailed Action Plan
    1. Harden nullable lists in Proofpoint threat stream

      • File: packages/proofpoint_essentials/data_stream/threat/agent/stream/cel.yml.hbs
      • Replace direct list maps (:75-78) with guarded defaults, e.g. body.?clicksBlocked.orValue([]).map(...) (and same for the other 3 lists).
    2. Harden nullable timestamp parsing

      • Same file (:82,84)
      • Guard queryEndTime before parse_time, with fallback strategy:
        • fallback cursor to time_range.end_time, or
        • skip want_more continuation when timestamp is absent and emit structured error event.
    3. Add regression coverage for null fields

      • Add/extend stream test input(s) for HTTP 200 response with one or more null members (e.g., clicksBlocked: null, queryEndTime: null).
      • Assert stream does not error and either emits zero events or the non-null event sets only.
    4. Sanity-check docs/examples if needed

      • If behavior changes in cursor semantics, update docs/comments where /v2/siem/all pagination behavior is described.
    Related Items
    Type Link/Path Relevance
    Issue #18788 Triage target
    File packages/proofpoint_essentials/data_stream/threat/agent/stream/cel.yml.hbs:75-78,82,84 Unguarded nullable dereferences
    File packages/proofpoint_essentials/docs/README.md:10,14 /v2/siem/all endpoint mapping
    File packages/microsoft_sentinel/data_stream/incident/agent/stream/cel.yml.hbs:46 Known-good null-safe CEL pattern
    Issues/PRs search keyword searches in repo No directly matching prior issue/PR found via available queries

    Note

    🔒 Integrity filter blocked 7 items

    The following items were blocked because they don't meet the GitHub integrity level.

    • #18788 issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #18788 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #17623 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #11284 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #11314 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #12047 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #12046 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".

    To allow these resources, lower min-integrity in your GitHub frontmatter:

    tools:
      github:
        min-integrity: approved  # merged | approved | unapproved | none

    What is this? | From workflow: Issue Triage

    Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions