Product
high
advisory
Unusual Child Process Execution by Web Servers on Linux
2 rules 5 TTPs 13 IOCsThis detection rule identifies suspicious child process executions originating from web server processes on Linux systems, indicating that attackers may have exploited web application vulnerabilities such as command injection or remote file inclusion to establish persistence or execute malicious commands.
Elastic Defend +45
persistence
execution
command-and-control
initial-access
linux
webserver
webshell
privilege-escalation
+4
2r
5t
13i
updated
critical
advisory
LLM-Based Compromised User Triage
2 rules 2 TTPsThis rule correlates multiple security alerts involving the same user, analyzes them with an LLM, and flags potentially compromised accounts based on MITRE tactics, geographic anomalies, and multi-host activity, helping analysts prioritize users exhibiting indicators of credential theft or unauthorized access.
Elastic Cloud
Domain: Identity
Domain: LLM
Use Case: Threat Detection
Use Case: Identity and Access Audit
Resources: Investigation Guide
Rule Type: Higher-Order Rule
2r
2t