Tag
Unusual DNS Activity Detected by Machine Learning
4 TTPsAn Elastic machine learning rule detects rare and unusual DNS queries that indicate potential malicious network activity, including initial access via phishing or malicious documents, persistence, command-and-control (C2) communication, or data exfiltration attempts by adversaries.
Unusual Web User Agent Detected via Machine Learning
1 TTPElastic's machine learning rule identifies rare and anomalous web user agents originating from local systems, indicating potential command-and-control, data exfiltration, or persistence activities by malware or specialized tools, enabling detection engineers to investigate unusual web browsing from non-browser processes.
Unusual Web Request Detection via Machine Learning
3 TTPsElastic's machine learning job identifies rare and unusual URLs accessed through web browsing or network traffic, signaling potential initial access, persistence, command-and-control, or data exfiltration activities that deviate from normal user behavior or legitimate application traffic patterns.
Potential DGA Activity Detected by Elastic Machine Learning
2 TTPsAn Elastic machine learning rule detects potential Domain Generation Algorithm (DGA) activity, commonly used by malware for command and control (C2) communication, by analyzing DNS requests from source IP addresses to identify aggregate patterns indicative of DGA usage.
Halfbaked Malware Command and Control Beaconing Detected
1 rule 2 TTPs 1 IOCFIN7 is leveraging Halfbaked malware to establish persistence and conduct command and control (C2) operations within compromised networks, using HTTP and TLS protocols with specific URL structures (e.g., `http://[IP_ADDRESS]/cd`) and common ports (53, 80, 8080, 443) for detection evasion and data exfiltration.
Possible FIN7 DGA Command and Control Behavior
1 rule 2 TTPsFIN7 threat group utilizes a specific Domain Generation Algorithm (DGA) for command and control (C2), characterized by domains with 4-5 alphabetic characters and specific top-level domains such as .pw, .us, .club, .info, .site, or .top, enabling persistence and continued operations within target networks.
Cobalt Strike Command and Control Beacon Detection
1 rule 2 TTPsAdversaries, notably FIN7, deploy Cobalt Strike beacons on compromised systems to establish command and control (C2) channels, utilizing specific network activity algorithms and domain naming conventions for communication over protocols like HTTP or TLS, posing a critical risk of further compromise and data exfiltration.
RPC (Remote Procedure Call) Services Exposed to the Internet
1 rule 3 TTPsThreat actors frequently exploit internet-exposed Remote Procedure Call (RPC) services, primarily on port TCP/135, as an initial access or backdoor vector, leading to unauthorized system access, internal network compromise, and potentially data exfiltration or ransomware deployment.
Potential Data Exfiltration to Unusual Geographic Region via Machine Learning
2 rules 1 TTPA machine learning job has detected potential data exfiltration activity to an unusual geographical region, specifically by region name, indicating exfiltration over command and control channels.
Detecting RPC Traffic to the Internet
2 rules 2 TTPsThis brief focuses on detecting Remote Procedure Call (RPC) traffic originating from internal networks and reaching the public internet, which is indicative of potential initial access or backdoor activity.
Suspicious SMTP Activity on Port 26/TCP
2 rules 3 TTPsThis rule detects SMTP traffic on TCP port 26, an alternative to the standard port 25 that the BadPatch malware family has used for command and control of Windows systems.
Large ICMP Traffic Detection
2 rules 1 TTPThis analytic identifies excessive ICMP traffic to external IP addresses exceeding 1,000 bytes, potentially indicating command and control activity, data exfiltration, or covert communication channels.