<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Correlation - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/correlation/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 19:21:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/correlation/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Cross-Telemetry Correlation of Endpoint and Network Security Alerts</title><link>https://feed.craftedsignal.io/briefs/2026-09-elastic-correlation-rule/</link><pubDate>Fri, 18 Sep 2026 19:21:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-elastic-correlation-rule/</guid><description>Detection engineering logic that correlates Elastic Defend endpoint alerts with network security events from PAN-OS, FortiGate, and Suricata to identify potentially compromised hosts based on multi-source telemetry.</description><content:encoded><![CDATA[<p>This detection brief details a higher-order correlation rule designed for the Elastic Security platform to identify system compromises by analyzing telemetry across heterogeneous security sources. The rule monitors for concurrent suspicious activity reported by both host-based endpoint protection (Elastic Defend) and perimeter or network-level security controls, including Palo Alto Networks PAN-OS, Fortinet FortiGate, and Suricata.</p>
<p>By requiring that a host triggers distinct alerts across at least two separate security modules, the logic significantly reduces the noise associated with isolated alerts. The rule utilizes ESQL to normalize IP-based telemetry across these disparate data sources, focusing on high-risk indicators such as command and control (C2) communication, malware detection, unauthorized remote access, and exploit attempts. This approach is intended to pinpoint hosts exhibiting behavior characteristic of an active adversary, such as lateral movement or data staging, which often trigger alerts on both the compromised endpoint and the gateway monitoring its traffic.</p>
<h2 id="impact">Impact</h2>
<p>Successful attacks identified by this correlation logic typically involve advanced persistent threats or automated malware campaigns that interact with external infrastructure. If left unmitigated, these incidents could lead to full system compromise, exfiltration of sensitive data, or the use of the host as a staging point for broader lateral movement within the network. This rule assists security operations centers (SOC) in prioritizing high-fidelity alerts where multiple security layers have independently flagged a specific asset as suspicious.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for detection engineering and incident response:</p>
<ul>
<li>Deploy the ESQL correlation rule to your Elastic Security SIEM to unify alerts from Elastic Defend and existing network security appliances.</li>
<li>Enable host IP collection for Elastic Defend (version 8.18+) to ensure the <code>host.ip</code> field is populated, as this is a prerequisite for the correlation logic.</li>
<li>Tune the rule by identifying and excluding known benign noise sources, such as administrative scanning tools or legitimate internal vulnerability management scanners that may trigger overlapping network and endpoint alerts.</li>
<li>Use the gathered context from the rule (including process command lines and destination IPs) to drive proactive threat hunting across the environment for related IOCs.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>correlation</category><category>multi-datasource</category><category>network-security</category><category>endpoint-security</category><category>phishing</category><category>email-security</category></item></channel></rss>