Skip to content
Threat Feed
high advisory

Correlation of Multiple Machine Learning Alerts by Influencer Field

This detection rule identifies potential account compromise by correlating three or more distinct machine learning alert triggers associated with the same non-system influencer field.

This brief details a higher-order detection rule developed for the Elastic Security platform, designed to improve the prioritization of machine learning (ML) alerts. By correlating multiple disparate ML jobs that share the same influencer entity (such as a username), the rule identifies clusters of suspicious activity that might otherwise be ignored if triaged in isolation.

The logic filters out system accounts like "root" or "SYSTEM" to reduce noise and requires a threshold of at least three distinct ML job IDs triggered by the same influencer. This approach helps security operations center (SOC) analysts identify potentially compromised accounts exhibiting a progression of anomalous behaviors across different monitored vectors, such as unusual login patterns, process execution, or file access. This rule is intended to be used as a triage prioritization mechanism rather than a standalone detector of a specific exploit.

Impact

The failure to identify correlated anomalies from an account can allow attackers to progress through an environment undetected. If an account is compromised, attackers may leverage diverse techniques such as privilege escalation, lateral movement, or data exfiltration. Aggregating these individual anomalous signals into a single high-risk alert enables defenders to isolate compromised entities more rapidly, limiting the potential scope of damage to the organization's network and data.

Recommendation

Deploy the Elastic Security higher-order rule "Multiple Machine Learning Alerts by Influencer Field" to your production SIEM environment.

  • Review the "Investigation Guide" metadata provided in the source documentation for specific tuning recommendations per environment.
  • Implement role-based exceptions for IT administrators and high-volume users in customer support or sales to minimize false-positive fatigue.
  • Schedule known maintenance windows and automated update processes as exclusions within the SIEM detection logic to avoid false positives from legitimate background tasks.
  • Ensure that telemetry sources for machine learning jobs are correctly configured and ingesting into the .alerts-security index pattern.

Immediate actions

Deploy the ESQL detection rule to the production Elastic Security instance.

Detection Engineering 48h

Threat Hunt

Identify users triggering >3 ML jobs in 30 minutes that are not yet flagged by higher-order rules.

T1204 medium medium confidence hunt now

Data: ML job alerts