Skip to content
Threat Feed

Product

Kibana

14 briefs RSS
low advisory

Host Detected with Suspicious Windows Processes via Machine Learning

Elastic's machine learning job, utilizing the ProblemChild supervised model and unsupervised techniques, detects Windows hosts exhibiting clusters of suspicious processes with unusually high malicious probability scores, often indicative of defense evasion through Living Off The Land Binaries (LOLbins) and masquerading techniques.

Elastic Defend +6 defense-evasion masquerading lolbins machine-learning windows ml-detection endpoint-security
2t
low advisory

Unusual Process Spawned by a User Detected by ML

A machine learning job from Elastic's ProblemChild integration detects suspicious Windows processes, classified as malicious by a supervised ML model and anomalous due to unusual user contexts identified by an unsupervised ML model, indicating potential misuse of LOLbins or masquerading tactics for defense evasion.

problemchild +6 Endpoint Windows Elastic Defend Elastic Endgame Living off the Land Attack Detection ML Machine Learning Defense Evasion +1
2t
low advisory

Unusual Process Detected for Privileged Commands by a User on Linux

Elastic's machine learning rule identifies anomalous execution of privileged commands by a user on Linux systems, indicative of potential privilege escalation or misuse of valid accounts.

Privileged Access Detection integration +6 linux machine-learning privileged-access privilege-escalation anomaly-detection
2t
low advisory

Unusual Process Writing Data to an External Device Detected by Machine Learning

Elastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.

Elastic Defend +15 exfiltration machine-learning elastic-defend endpoint lateral-movement rdp anomaly-detection privilege-escalation +29
22t
low advisory

Potential Data Exfiltration Activity to an Unusual Region

Elastic's machine learning job identifies potential data exfiltration activity to unusual geo-locations by detecting anomalies in network traffic patterns, indicating adversaries leveraging command and control channels to transfer data outside normal organizational patterns.

Elastic Stack +5 exfiltration data-exfiltration machine-learning elastic network-detection command-and-control initial-access persistence
4t
low advisory

Potential Data Exfiltration Activity to an Unusual IP Address

Elastic's machine learning rule detects potential data exfiltration by identifying anomalous network traffic, specifically large data transfers to unusual geo-locations via IP addresses, indicating possible exfiltration over command and control channels.

Data Exfiltration Detection integration +5 machine-learning network-security exfiltration data-loss-prevention elastic
1t
low advisory

Unusual Hour for a User to Logon

An Elastic machine learning rule detects unusual user logon times, which can indicate credential compromise or unauthorized access, particularly when attackers operate from different time zones or during non-business hours, prompting investigation into the affected user account and related activities.

Elastic Defend +8 identity-and-access-audit threat-detection machine-learning initial-access
1t
low advisory

Detection of Rare PowerShell Scripts on Windows Systems

Elastic's machine learning job detects rare PowerShell script executions on Windows hosts, identified by their script block hash, indicating potential malware activity or persistence mechanisms that deviate from an established baseline.

Kibana 9.4.0+ +4 windows machine-learning powershell execution threat-detection
1t updated
low advisory

Spike in User Account Management Events

Elastic Security's machine learning rule detects an unusual spike in Windows user account management events, including account creation, modification, or deletion, indicating potential privilege escalation or unauthorized activity by an adversary.

Privileged Access Detection integration +7 privileged-access-detection machine-learning anomaly-detection windows account-management privilege-escalation persistence
5t updated
high advisory

Unusual Child Process Execution by Web Servers on Linux

This detection rule identifies suspicious child process executions originating from web server processes on Linux systems, indicating that attackers may have exploited web application vulnerabilities such as command injection or remote file inclusion to establish persistence or execute malicious commands.

Elastic Defend +45 persistence execution command-and-control initial-access linux webserver webshell privilege-escalation +4
2r 5t 13i updated
medium advisory

File Creation in World-Writable Directory by Unusual Process

An Elastic detection rule identifies when an unusual process creates files within world-writable directories on Linux systems, a tactic employed by attackers for defense evasion and lateral movement by staging payloads and hiding malicious activities.

Elastic Defend +5 linux defense-evasion persistence lateral-movement
1r 1t
low advisory

Suspicious Command Execution via Busybox Proxy on Linux

This brief details the detection of a defense evasion technique where adversaries leverage Busybox on Linux systems to execute commands capable of spawning shells or establishing network connections, thereby attempting to bypass endpoint security controls.

Elastic Defend +4 linux execution defense-evasion command-and-control endpoint
1r 3t
high advisory

Multiple Vulnerabilities in Elastic Kibana

Multiple vulnerabilities in Elastic Kibana allow for privilege escalation, remote denial of service, data breach, server-side request forgery (SSRF), and cross-site scripting (XSS).

Kibana +2 vulnerability privilege escalation denial of service data breach SSRF XSS
2r 3t 5c
high advisory

Kibana Fleet API Authorization Bypass (CVE-2026-33461)

Kibana is vulnerable to an authorization bypass (CVE-2026-33461) where users with limited Fleet privileges can access sensitive configuration data, including private keys and authentication tokens, via an internal API endpoint.

Kibana authorization-bypass privilege-escalation
2r 2t 1c