Product
low
advisory
Unusual Process Detected for Privileged Commands by a User on Linux
2 TTPsElastic's machine learning rule identifies anomalous execution of privileged commands by a user on Linux systems, indicative of potential privilege escalation or misuse of valid accounts.
Privileged Access Detection integration +6
linux
machine-learning
privileged-access
privilege-escalation
anomaly-detection
2t
low
advisory
Unusual Process Writing Data to an External Device Detected by Machine Learning
22 TTPsElastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.
Elastic Defend +15
exfiltration
machine-learning
elastic-defend
endpoint
lateral-movement
rdp
anomaly-detection
privilege-escalation
+29
22t
low
advisory
Spike in User Account Management Events
5 TTPsElastic Security's machine learning rule detects an unusual spike in Windows user account management events, including account creation, modification, or deletion, indicating potential privilege escalation or unauthorized activity by an adversary.
Privileged Access Detection integration +7
privileged-access-detection
machine-learning
anomaly-detection
windows
account-management
privilege-escalation
persistence
5t
updated