Product
low
advisory
Host Detected with Suspicious Windows Processes via Machine Learning
2 TTPsElastic's machine learning job, utilizing the ProblemChild supervised model and unsupervised techniques, detects Windows hosts exhibiting clusters of suspicious processes with unusually high malicious probability scores, often indicative of defense evasion through Living Off The Land Binaries (LOLbins) and masquerading techniques.
Elastic Defend +6
defense-evasion
masquerading
lolbins
machine-learning
windows
ml-detection
endpoint-security
2t
low
advisory
Unusual Process Writing Data to an External Device Detected by Machine Learning
22 TTPsElastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.
Elastic Defend +15
exfiltration
machine-learning
elastic-defend
endpoint
lateral-movement
rdp
anomaly-detection
privilege-escalation
+29
22t