Tag
low
advisory
Potential Data Exfiltration Activity to an Unusual IP Address
1 TTPElastic's machine learning rule detects potential data exfiltration by identifying anomalous network traffic, specifically large data transfers to unusual geo-locations via IP addresses, indicating possible exfiltration over command and control channels.
Data Exfiltration Detection integration +5
machine-learning
network-security
exfiltration
data-loss-prevention
elastic
1t
medium
advisory
CrowdStrike Falcon Data Security Introduction
2 rules 2 TTPsCrowdStrike's Falcon Data Security aims to protect sensitive data by providing visibility into data movement across various environments and preventing data theft.
data-security
data-loss-prevention
crowdstrike
2r
2t