Tag
medium
advisory
Detection of LOLBAS Network Connections on Uncommon Ports
1 rule 3 TTPsAn analytic identification of Living Off the Land Binaries and Scripts (LOLBAS) initiating public network connections over non-standard destination ports, indicating potential staging or command-and-control activity.
Windows
LOLBAS
network-anomaly
defense-evasion
windows-endpoint
1r
3t
low
advisory
Unusual Process Writing Data to an External Device Detected by Machine Learning
22 TTPsElastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.
Elastic Defend +15
exfiltration
machine-learning
elastic-defend
endpoint
lateral-movement
rdp
anomaly-detection
privilege-escalation
+29
22t