Product
low
advisory
Unusual Process Detected for Privileged Commands by a User on Linux
2 TTPsElastic's machine learning rule identifies anomalous execution of privileged commands by a user on Linux systems, indicative of potential privilege escalation or misuse of valid accounts.
Privileged Access Detection integration +6
linux
machine-learning
privileged-access
privilege-escalation
anomaly-detection
2t
low
advisory
Unusual Process Writing Data to an External Device Detected by Machine Learning
22 TTPsElastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.
Elastic Defend +15
exfiltration
machine-learning
elastic-defend
endpoint
lateral-movement
rdp
anomaly-detection
privilege-escalation
+29
22t