Skip to content
Threat Feed

Product

Elastic Agent

15 briefs RSS
medium advisory

Detection of Data Exfiltration via Curl Utility

Adversaries frequently abuse the legitimate curl command-line utility to exfiltrate collected sensitive data to external Command and Control (C2) servers via network protocols.

Elastic Agent +1 exfiltration living-off-the-land detection-engineering curl
1r 3t
low advisory

Unusual Web User Agent Detected via Machine Learning

Elastic's machine learning rule identifies rare and anomalous web user agents originating from local systems, indicating potential command-and-control, data exfiltration, or persistence activities by malware or specialized tools, enabling detection engineers to investigate unusual web browsing from non-browser processes.

Kibana +4 command-and-control network-traffic machine-learning elastic
1t
low advisory

Host Detected with Suspicious Windows Processes via Machine Learning

Elastic's machine learning job, utilizing the ProblemChild supervised model and unsupervised techniques, detects Windows hosts exhibiting clusters of suspicious processes with unusually high malicious probability scores, often indicative of defense evasion through Living Off The Land Binaries (LOLbins) and masquerading techniques.

Elastic Defend +6 defense-evasion masquerading lolbins machine-learning windows ml-detection endpoint-security
2t
low advisory

Unusual Process Writing Data to an External Device Detected by Machine Learning

Elastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.

Elastic Defend +15 exfiltration machine-learning elastic-defend endpoint lateral-movement rdp anomaly-detection privilege-escalation +29
22t
low advisory

Potential Data Exfiltration Activity to an Unusual IP Address

Elastic's machine learning rule detects potential data exfiltration by identifying anomalous network traffic, specifically large data transfers to unusual geo-locations via IP addresses, indicating possible exfiltration over command and control channels.

Data Exfiltration Detection integration +5 machine-learning network-security exfiltration data-loss-prevention elastic
1t
low advisory

Unusual Linux Network Activity Detected by Machine Learning

This Elastic machine learning rule detects anomalous network activity originating from Linux processes that typically do not engage in network communication, signifying potential command-and-control, lateral movement, persistence, or data exfiltration activity, often via process exploitation or injection.

Elastic Defend +2 endpoint linux threat-detection machine-learning detection-rule
3t updated
low advisory

Unusual Hour for a User to Logon

An Elastic machine learning rule detects unusual user logon times, which can indicate credential compromise or unauthorized access, particularly when attackers operate from different time zones or during non-business hours, prompting investigation into the affected user account and related activities.

Elastic Defend +8 identity-and-access-audit threat-detection machine-learning initial-access
1t
low advisory

Detection of Rare PowerShell Scripts on Windows Systems

Elastic's machine learning job detects rare PowerShell script executions on Windows hosts, identified by their script block hash, indicating potential malware activity or persistence mechanisms that deviate from an established baseline.

Kibana 9.4.0+ +4 windows machine-learning powershell execution threat-detection
1t updated
low advisory

Spike in User Account Management Events

Elastic Security's machine learning rule detects an unusual spike in Windows user account management events, including account creation, modification, or deletion, indicating potential privilege escalation or unauthorized activity by an adversary.

Privileged Access Detection integration +7 privileged-access-detection machine-learning anomaly-detection windows account-management privilege-escalation persistence
5t updated
high advisory

Unusual Child Process Execution by Web Servers on Linux

This detection rule identifies suspicious child process executions originating from web server processes on Linux systems, indicating that attackers may have exploited web application vulnerabilities such as command injection or remote file inclusion to establish persistence or execute malicious commands.

Elastic Defend +45 persistence execution command-and-control initial-access linux webserver webshell privilege-escalation +4
2r 5t 13i updated
medium advisory

File Creation in World-Writable Directory by Unusual Process

An Elastic detection rule identifies when an unusual process creates files within world-writable directories on Linux systems, a tactic employed by attackers for defense evasion and lateral movement by staging payloads and hiding malicious activities.

Elastic Defend +5 linux defense-evasion persistence lateral-movement
1r 1t
low advisory

Suspicious Command Execution via Busybox Proxy on Linux

This brief details the detection of a defense evasion technique where adversaries leverage Busybox on Linux systems to execute commands capable of spawning shells or establishing network connections, thereby attempting to bypass endpoint security controls.

Elastic Defend +4 linux execution defense-evasion command-and-control endpoint
1r 3t
medium advisory

Linux Segfault from Sensitive Process Detected

This rule detects segfault messages in kernel logs originating from sensitive processes on Linux systems, indicating potential exploitation attempts that could lead to arbitrary code execution or credential access.

Elastic Agent +2 credential-access execution linux
2r 3t
medium advisory

Potential Evasion via Windows Filtering Platform Blocking Security Software

Adversaries may add malicious Windows Filtering Platform (WFP) rules to prevent endpoint security solutions from sending telemetry data, impairing defenses, which this rule detects by identifying multiple WFP block events where the process name is associated with endpoint security software.

Windows Filtering Platform +2 defense-evasion windows-filtering-platform endpoint-security
2r 2t
medium advisory

Elastic Agent Service Termination Attempt

This rule detects attempts to stop the Elastic endpoint agent service, which may indicate a defense evasion tactic employed by adversaries to disable security monitoring and evade detection.

Elastic Agent defense-evasion endpoint elastic-agent
3r 1t