{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/elastic-defend-8.18-and-above/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Elastic Defend (8.18 and above)","Lateral Movement Detection integration","Fleet","Kibana (min_stack_version 9.4.0)"],"_cs_severities":["low"],"_cs_tags":["lateral-movement","collection","data-exfiltration","machine-learning","anomaly-detection","elastic-defend"],"_cs_type":"advisory","_cs_vendors":["Elastic"],"content_html":"\u003cp\u003eThe Elastic machine learning rule, \u0026quot;Unusual Remote File Size\u0026quot;, identifies potential lateral movement or data exfiltration by flagging abnormally large file sizes transferred from remote hosts. Attackers often consolidate data into single large files to circumvent detection mechanisms that might trigger on multiple smaller transfers. This rule, part of the Lateral Movement Detection integration, leverages Elastic's Anomaly Detection feature to analyze file and Windows RDP process events, requiring the \u003ccode\u003ehost.ip\u003c/code\u003e field to be populated. For Elastic Defend versions 8.18 and above, explicit configuration is needed to enable host IP collection. The integration also requires the installation of preconfigured anomaly detection jobs within Fleet. This detection helps defenders identify suspicious network activity that could indicate an adversary moving within the network or preparing to exfiltrate data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eIf attackers successfully transfer unusually large files for lateral movement or data exfiltration, organizations face significant risks including the theft of sensitive information, establishment of further persistence within the network, and potential system compromise. The consolidation of data into large files allows adversaries to achieve their objectives with a higher likelihood of evading traditional security alerts. This could lead to severe data breaches, regulatory non-compliance fines, and substantial reputational damage for the affected entities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable \u003ccode\u003ehost.ip\u003c/code\u003e field collection for Elastic Defend events, especially for versions 8.18 and above, by following Elastic's official configuration steps outlined in their helper guide.\u003c/li\u003e\n\u003cli\u003eInstall the Lateral Movement Detection integration assets in Kibana, ensuring all prerequisites are met and preconfigured anomaly detection jobs are added as described in the \u003ccode\u003esetup\u003c/code\u003e section.\u003c/li\u003e\n\u003cli\u003eReview the alert details for \u003ccode\u003eUnusual Remote File Size\u003c/code\u003e to identify specific remote hosts and file sizes involved in detected anomalies.\u003c/li\u003e\n\u003cli\u003eAnalyze network logs to trace the origin and destination of any suspicious large file transfers.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to limit lateral movement capabilities within the environment if a detected anomaly indicates malicious activity.\u003c/li\u003e\n\u003cli\u003eConduct thorough analysis of the contents and origin of unusually large file transfers to determine if sensitive data was involved and reset credentials for any associated compromised accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T18:08:45Z","date_published":"2026-07-28T18:07:58Z","id":"https://feed.craftedsignal.io/briefs/2026-07-unusual-remote-file-size/","summary":"An Elastic machine learning job detects unusually large file transfers by remote hosts, indicating potential lateral movement or data exfiltration by adversaries who consolidate data into single large files to avoid detection.","title":"Unusual Remote File Size Detected by ML","url":"https://feed.craftedsignal.io/briefs/2026-07-unusual-remote-file-size/"}],"language":"en","title":"CraftedSignal Threat Feed - Elastic Defend (8.18 and Above)","version":"https://jsonfeed.org/version/1.1"}