Question about malware sample distribute / sharing

I'm a pentester exploring malware dev and want to setup Elastic EDR locally for testing, for the life of me i can't not find anything about detected sample getting share further analysis in Elastic documents.

A friend from work / the red teaming field said there is and i should just turn of the internet for local testing but this will take away some of the capabilities, so my question is does Elastic EDR have a sample sharing thing similar to Microsoft sample submission and if yes how or could i turn it off as a free trial user?

We are working to improve documentation on what is collected by default and the associated configuration options. I believe the applicable option here is [os].advanced.alerts.sample_collection. You can find it in the "advanced" section of the Elastic Defend policy configuration policy. This can be set to false to disable sample collection.