Product
low
advisory
Unusual Process Writing Data to an External Device Detected by Machine Learning
22 TTPsElastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.
Elastic Defend +15
exfiltration
machine-learning
elastic-defend
endpoint
lateral-movement
rdp
anomaly-detection
privilege-escalation
+29
22t
low
advisory
Unusual Hour for a User to Logon
1 TTPAn Elastic machine learning rule detects unusual user logon times, which can indicate credential compromise or unauthorized access, particularly when attackers operate from different time zones or during non-business hours, prompting investigation into the affected user account and related activities.
Elastic Defend +8
identity-and-access-audit
threat-detection
machine-learning
initial-access
1t