Product
low
advisory
Unusual Process Detected for Privileged Commands by a User on Linux
2 TTPsElastic's machine learning rule identifies anomalous execution of privileged commands by a user on Linux systems, indicative of potential privilege escalation or misuse of valid accounts.
Privileged Access Detection integration +6
linux
machine-learning
privileged-access
privilege-escalation
anomaly-detection
2t
low
advisory
Spike in User Account Management Events
5 TTPsElastic Security's machine learning rule detects an unusual spike in Windows user account management events, including account creation, modification, or deletion, indicating potential privilege escalation or unauthorized activity by an adversary.
Privileged Access Detection integration +7
privileged-access-detection
machine-learning
anomaly-detection
windows
account-management
privilege-escalation
persistence
5t
updated