Correlation of Multiple Machine Learning Alerts by Influencer Field
This detection rule identifies potential account compromise by correlating three or more distinct machine learning alert triggers associated with the same non-system influencer field.
This brief details a higher-order detection rule developed for the Elastic Security platform, designed to improve the prioritization of machine learning (ML) alerts. By correlating multiple disparate ML jobs that share the same influencer entity (such as a username), the rule identifies clusters of suspicious activity that might otherwise be ignored if triaged in isolation.
The logic filters out system accounts like "root" or "SYSTEM" to reduce noise and requires a threshold of at least three distinct ML job IDs triggered by the same influencer. This approach helps security operations center (SOC) analysts identify potentially compromised accounts exhibiting a progression of anomalous behaviors across different monitored vectors, such as unusual login patterns, process execution, or file access. This rule is intended to be used as a triage prioritization mechanism rather than a standalone detector of a specific exploit.
Impact
The failure to identify correlated anomalies from an account can allow attackers to progress through an environment undetected. If an account is compromised, attackers may leverage diverse techniques such as privilege escalation, lateral movement, or data exfiltration. Aggregating these individual anomalous signals into a single high-risk alert enables defenders to isolate compromised entities more rapidly, limiting the potential scope of damage to the organization's network and data.
Recommendation
Deploy the Elastic Security higher-order rule "Multiple Machine Learning Alerts by Influencer Field" to your production SIEM environment.
- Review the "Investigation Guide" metadata provided in the source documentation for specific tuning recommendations per environment.
- Implement role-based exceptions for IT administrators and high-volume users in customer support or sales to minimize false-positive fatigue.
- Schedule known maintenance windows and automated update processes as exclusions within the SIEM detection logic to avoid false positives from legitimate background tasks.
- Ensure that telemetry sources for machine learning jobs are correctly configured and ingesting into the .alerts-security index pattern.
Immediate actions
Deploy the ESQL detection rule to the production Elastic Security instance.
Threat Hunt
Identify users triggering >3 ML jobs in 30 minutes that are not yet flagged by higher-order rules.
Data: ML job alerts