Product
medium
advisory
Linux Segfault from Sensitive Process Detected
2 rules 3 TTPsThis rule detects segfault messages in kernel logs originating from sensitive processes on Linux systems, indicating potential exploitation attempts that could lead to arbitrary code execution or credential access.
Elastic Agent +2
credential-access
execution
linux
2r
3t
high
threat
Cobalt Strike Command and Control Beacon Detected
2 rules 2 TTPsThis brief documents the detection of Cobalt Strike command and control activity through identifying specific domain naming conventions used by its implant beacons, indicative of network attack and exploitation campaigns.
packetbeat +2
FIN7
+2
command-and-control
cobalt-strike
domain-generation-algorithm
2r
2t